XML encryption classifies a course of action for encrypting plain text data, generating ciphertext, and decrypting the ciphertext to retrieve the plaintext data.
XML encryption classifies a course of action for encrypting plain text data, generating ciphertext, and decrypting the ciphertext to retrieve the plaintext data.
Both the
If the recipient does not know the decryption key in advance, then the sender generates and sends it. The key can be protected in transit by encrypting method or key agreement.
If the plaintext data to encrypt is an XML element or content, you encode it using UTF-8 and perform any necessary transforms to it, otherwise, if it is an external resource, you simply consider it as an octet sequence. You then encrypt the data, creating CipherValue, which you place in EncryptedData.
Care must be taken when signing content that may later be encrypted; clearly; the content must be restored to exactly the original plaintext form for the signature to validate properly. To restore the plaintext in the signed content, use the decryption transform method for XML signature defined by the XML encrypt joint W3C and IETF working group.
This transform also allows specifications of XML fragments that were encrypted and then signed with rest of the document and, therefore, are not decrypted to validate the signature. Often, encrypted fragments are removed from the signed information by using the XPATH transform in the reference element, since the meaningful information is the plaintext.
We can sign the plaintext version of an encrypted element by including the appropriate reference element pointing to it. When the signed document is confidential and encrypted after being signed, you should also protect against surreptitious forwarding in which the recipient forwards the signed confidential document to a competitor, encrypted by the competitor public key, trying to make it look as if the sender sent the confidential information. To prevent surreptitious forwarding, the signer should append the recipient identities to the document being signed.
If the recipient does not know the decryption key in advance, then the sender generates and sends it. The key can be protected in transit by encrypting method or key agreement.
If the plaintext data to encrypt is an XML element or content, you encode it using UTF-8 and perform any necessary transforms to it, otherwise, if it is an external resource, you simply consider it as an octet sequence. You then encrypt the data, creating CipherValue, which you place in EncryptedData.
Care must be taken when signing content that may later be encrypted; clearly; the content must be restored to exactly the original plaintext form for the signature to validate properly. To restore the plaintext in the signed content, use the decryption transform method for XML signature defined by the XML encrypt joint W3C and IETF working group.
This transform also allows specifications of XML fragments that were encrypted and then signed with rest of the document and, therefore, are not decrypted to validate the signature. Often, encrypted fragments are removed from the signed information by using the XPATH transform in the reference element, since the meaningful information is the plaintext.
We can sign the plaintext version of an encrypted element by including the appropriate reference element pointing to it. When the signed document is confidential and encrypted after being signed, you should also protect against surreptitious forwarding in which the recipient forwards the signed confidential document to a competitor, encrypted by the competitor public key, trying to make it look as if the sender sent the confidential information. To prevent surreptitious forwarding, the signer should append the recipient identities to the document being signed.
Articles Source - www.artices-hub.com
Saturday, June 16, 2007
Overview of XML Encryption
Posted by
Mohammed Ebied
at
5:05 AM
0
comments
Labels: XML
Thursday, June 14, 2007
Create your own XML channel within 10 minutes.
Short, step by step ysw web tutorial shows how to create very simple and functional XML channel (RSS) for distrubution of media content as adio or video files.
Posted by
Mohammed Ebied
at
2:34 AM
0
comments
Tuesday, June 12, 2007
XML Parser and Their Types
By Balaji B
XML parser is a software module to read documents and a means to provide access to their content. XML parser generates a structured tree to return the results to the browser. An XML parser is similar to a processor that determines the structure and properties of the data. An XML parser can read a XML document to create an output to generate a display form. There are a number of parsers available and a few of them are listed below:
The Xerces Java Parser
The main applications of the Xerces Java parser is the building up of the XML-savvy web servers and to ensure the integrity of e-business data expressed in XML.
expat XML parser
The expat XML parser is written in C and runs on UNIX or W32.The expat XML parser is not a validating processor that is you can use it only to write an XML parser. This parser is contributed by James Clark.
XP and XT
XP is a Java based, XML validating parser and XT is an XSL processor. Both are written in Java.XP detects all non well formed documents. It gives high performance and aims to be the fastest conformant XML parser in Java. On the other hand XT is a set of tools for building program transformation systems. The tools include pretty printing; bundling of systems, tree transformation etc,
SAX
Simple API for XML (SAX) was developed by the members of a public mailing list (XML-DEV).It gives an event based approach to XML parsing. It means that instead of going from node to node, it goes from event to event. SAX is an event driven interface. Events include XML tag, detecting errors etc,
XML pull parser
It is optimal for applications that require fast and a small XML parser. It should be used when all the process has to be performed quickly and efficiently to input elements.
XML parser for Java
It runs on any platform where there is Java virtual machine. It is sometimes called XML4J.It has an interface which allows you to take a string of XML formatted text, pick the XML tags and use them to extract the tagged information.
Posted by
Mohammed Ebied
at
5:49 PM
0
comments
Labels: XML
An Introduction To XML
By Leena Vijayakumar
Extensible Markup Language (XML ) is a mark up language that provides a format for describing structured data. This facilitates more precise declarations of content and more meaningful search results across multiple platforms. XML thus enables a new generation of web based data viewing and manipulation applications.
Outwardly, XML looks like HTML. XML is a subset of SGML (Standard Generalised Markup Language) that is optimised for delivery over the web. XML standards are defined by the World Wide Web Consortium ( W3C ) and they ensure that structured data will be uniform and independent of application or vendors. HTML specifies how to display data in a browser while XML defines the content. XML documents are extensible, structured and self- validating. In XML, you can define an unlimited set of tags. XML provides a framework for tagging structured data. An XML element can declare its data to be a retail price, book title or any other desired data element.
XML provides a means of including metadata in web documents. Metadata is information about information. The display of XML documents is typically accomplished with style sheets such as Extensible Style Language( XSL ) and Cascading Style Sheets (CSS).
XML is only a specification. A document is entitled to be called an XML document only if it adheres to the rules laid down in the XML specification. XML documents are designed for use by XML processors.XML processor has a component called the XML parser that analyses XML markup and determines the structure of the document data.
A Masters student in computer applications interested in writing articles,editing and proof reading Contact at: leenavijayakumar@gmail.com
Posted by
Mohammed Ebied
at
5:27 PM
0
comments
Integrating XML into SAP Business Connector
By: Jim Pretin
When the internet was first introduced, all websites were written in HTML. HTML was the only programming language used to describe and display data on the World Wide Web. It was simple and fairly easy to learn. As time progressed, programmers started to realize that they were being stymied by HTML. Web designers wanted to be able to describe data more effectively. This need for a better way to deal with data resulted in the development of a new specification called XML.
What is XML? XML stands for Extensible Markup Language. So, just like HTML, XML is a markup language. A markup language is any language that is used to describe or define information and text. XML is not a substitute for HTML. It is to be used in conjunction with HTML.
HTML focuses on describing how data or text is supposed to be displayed. The XML language does something totally different. XML describes what the data is. So, XML is not something that is apparent on a web page, because it does not actually do anything. As information and data presented on the World Wide Web became more complex, XML was invented to effectively structure, store, and send this information.
What makes XML truly unique is that there are no predefined tags like we have with HTML. All of the tags used in HTML have already been defined, such as the paragraph tag, the header tag, and all the various style tags. XML is not defined. You can make your own tags!
So, the question is, why do we need XML? Why do we need a more versatile specification like XML to describe data? After all, HTML works fine if used properly, so why do we need XML? Well, the answer is simple. XML is a device independent, cross-platform language.
This is extremely important, because people are now using a wide variety of gadgets to connect to the internet, as almost every electronic device on the market now comes equipped with email and internet access. Cell phones, palm tops, computers installed in automobiles, they all have built-in web access. Each of these devices display text and graphics differently, and utilize different platforms and a variety of web browsers.
As a result, someone using a cell phone to access a certain web site may not be able to view the data on that website properly because the browser running on that cell phone might not be able to properly display the HTML. The platforms that run on some of these newfangled products and devices are simply not 100% compatible with HTML.
XML solves this problem by making sure that the most important data on your website can be displayed across all of these different platforms. This is what makes XML so valuable. The other important features of XML is that it enables data to be exchanged between incompatible systems, and because XML files are plain text files, basically anyone using any system can view the contents of the text file.
So, if you are a programmer, you need to learn to use XML for describing, storing, and sending data on the web. With so many different means available to connect to the internet, you should learn to use programming languages like XML.
Article Source: http://www.articlerich.com
Posted by
Mohammed Ebied
at
4:38 PM
0
comments
Labels: XML
Monday, June 11, 2007
What Is This RSS, XML, RDF, and Atom Business?
It's been a long day at work and you're in no mood to cook dinner or go out. Time to count on the reliable pizza delivery guy. The order is called in and he promptly arrives with smokin' hot pizza within 30 minutes as promised. If it were only that easy with a picky family where no one can agree on the same restaurant for dinner. One wants Mexican, another wants Chinese, and another wants a burger and Mexican. Instead of running to three different places, you call a delivery service that goes to all of them and brings it to you. What could be easier in getting a meal without cooking it or fetching it?
RSS, XML, RDF, and Atom are the food delivery guy of the Internet. The content they deliver is mixed and cooked elsewhere on the Internet just like the meal isn't made on your door step and the acronym fellows bring the content to you via software or an online application. Instead of trying to remember all the places where you like to go to get the latest news, it all comes to you once you order your food.
Click on any of those orange or blue RSS, XML, or RDF buttons and you see unreadable text. Some of it is readable, but reading between the
When the software or application is ready to go, click on the orange or blue button (or "Syndicate This Page," or whatever is along these lines) and copy the resulting URL from the address box. Paste it into the application to cook the ingredients where it's delivered to you ready for your enjoyment.
Syndication is a not a new concept on the Internet, but it’s growing in popularity as more Web sites and newsletters are churning content to turn it into syndicated files, which are fed into an aggregator. Think of it as the content that's ready to travel anywhere it needs to go. Grab the feed and feed it to the aggregator, another way of bookmarking (or creating a favorite) a site because you wish to come back again another time. But how often did you go back to the site through your bookmarks / favorites?
Instead of schlepping from site to site in search of information, I have it all in front of me via the aggregator. The feeds are sorted in folders by topic for easy finding. If I'm writing about the latest virus or worm, then I open the security folder with the security-related feeds and scan them. Scanning content through aggregators is easier than on a Web site because it's in one folder with headlines and maybe a short summary. On a Web site, you're only getting the benefit of that site's news and no where else. The folder has news from over ten resources including blogs, news sites, and newsletters.
Any content can be syndicated. It's a matter of having the backend process in place, which is dependent on the application used for managing the content. If a site doesn't have such resources, then there is software for entering content to create a file with the feed for posting on the site.
Most aggregators have exporting capabilities so the feed can be shared with others interested in the same topic. If you're interested in my security feeds, I can export them into, in most cases, an OPML file and you can import it into your aggregator.
Spam filters are preventing readers from getting newsletters or they get lost in the spam pool. Offering a feed for the newsletter is a compromise. Readers can get the content, only instead of it coming to the emailbox, it comes through the aggregator. It's a way around spam. Like everything else, it has its advantages and disadvantages:
Advantages:
- Filters can't stop the newsletter from reaching its destination.
- The recipient will get it - if the server is down, it'll download next time and email can get lost.
- The feed can be syndicated providing more exposure for your content.
Disadvantages:
- Rely on readers to open aggregators like they open email client, but some aggregators are built-in with an email client like NewsGator and there are online aggregators like Bloglines, which can be your home page.
- Metrics won't be as complete, but it's still there through the links.
- Not as pretty as HTML-based newsletters.
If the feed is automatically created, what have you got to lose? You're providing another way for your readers to get your content just like you can get pizza in different ways: go to the restaurant, have it delivered, or make it at home. More applications are adding syndication capabilities, which make the process effortless. Some have said they won’t read something unless it has a feed.
Syndication works better than bookmarks. With bookmarks, you click on a site that might have the security information and arrive there to find it doesn't. So, back to the bookmarks to click on another site. Lather, rinse, repeat. With aggregators, there is no jumping from site to site. Scan the headlines right there until you find what you need.
There was a time when we didn't have the option to have pizza delivered to our doorstep. When we're too tired, we know we can rely on the delivery guy. In term of content, expect to see it show up at your doorstep more often than the pizza guy plus it's cheaper with the cost only coming from the software though there are many free options available. Syndication is here to stay and should be added to a company’s communication toolbox rather than as a replacement. Witness it by watching for RSS, XML, RDF, and Atom out there.
Meryl K. Evans is the Content Maven behind meryl.net who increases conversion rates by writing and editing content so organization can focus on their core business. She is the editor-in-chief of the eNewsletter Journal and Shavlik's The Remediator Security Digest. Visit her Web site at http://www.meryl.net/blog/.
Posted by
Mohammed Ebied
at
9:29 AM
0
comments
Sunday, June 10, 2007
Displaying RSS Feeds
by: S. Housley
RSS offers webmasters a unique opportunity to display fresh content on websites. While publishing an RSS feed is a great way to generate site interest and increase communication, syndicating and displaying feeds from related relevant sources can also generate interest, increase traffic and improve search engine ranking.
RSS Radars
Webmasters with limited time or capacity can syndicate related content. In a nut shell, webmasters can create RSS radars by combining a mix of content from related sources by grouping similarly-themed feeds. RSS feeds are updated at different intervals, providing an ever-changing collection of related information.
RSS is a form of eXtensible Markup Language or XML. Viewing an RSS feed in a web browser generally produces code that is not easy for website visitors to decipher. As a result, webmasters use tools to display the content contained in an RSS feed.
Content contained in RSS feeds can be added to websites a number of different ways. Each method for displaying the RSS feed has pros and cons associated with it. Webmasters will need to determine which option will best meet their hosting and technology needs.
Using Javascript to Display RSS
Javascript is the easiest way to display RSS feeds on a website. There are a number of sites that will allow you to generate code that can be inserted into a website. The javascript will auto-update, showing the latest headlines as the feed is updated. Each time a visitor visits the website the javascript pulls the data from the feed. Often, the various scripts can be customized so that the look of the feed can be made to match a specific websiteeeds with hopes that the search engines will devour and spider the contents, you will be disappointed. When javascript is used to display RSS feeds, search engines do not actually "see" the contents of the feed, meaning that the search engines will not index the contents of the feed within the website.
Feedroll - Feedroll is a free service for syndicating RSS and ATOM news feeds on your website. Simply select a feed, customize the design, then copy and paste the code provided onto your page.
Using PHP to Display RSS
PHP is a slightly more complex solution for displaying RSS. Like javascript, as the contents of the feed updates, the web page contents will update as the page is refreshed. The benefit of using PHP to display RSS is that the contents of the feed displayed with the webpage can be spidered and indexed by search engines. The result is a feed that always displays the most current information from the RSS feed and the web page content is considered search engine spider and robot-friendly.
rss2html.php - The rss2html.php script allows users to create web pages that will always display the most current information from the RSS feed, and because the resulting page is pure HTML, it will be in a format friendly to search engine robots. Using rss2html.php, webmasters can customize the format and look of the web page created from the feed. The RSS feed's contents can easily be integrated into an existing website's theme. The rss2html.php script parses the RSS file, extracts the pertinent information, formats it, and serves it up as regular HTML.
http://www.feedforall.com/free-php-script.htm
FeedRoll Pro - FeedRollPro was really designed to enable publishers to syndicate their own content on other sites. But it can be used to syndicate news feeds from other sites on your own pages. http://www.feedrollpro.com
Using ASP to Display RSS
ASP is similar to PHP. The free ASP/ASP.NET scripts can be used to convert RSS feeds into HTML and display on ASP/ASP.NET web-server.
rss2html.asp - ByteScout has implemented a guide for displaying of RSS/XML feed using free RSS2HTML.ASP script in ASP or ASP.NET environment. This script can be used free of charge on any ASP or ASP.NET web-server and generate HTML from RSS feed. This free ASP script uses MSXML to load RSS feed from URL and display it. You can use it as a standalone or call from script on HTML page to generate HTML content from RSS feed and then display on your HTML page.
http://bytescout.com/how_to_display_rss_using_asp.html
RssFeed - RssFeed is an open-source custom ASP.NET server control that displays the contents of a specified RSS feed in an ASP.NET web page.
http://www.scottonwriting.com/sowBlog/RssFeed.htm
If PHP or ASP is used to update feeds, the website will have free fresh, relevant content each time the feeds referenced are updated.
Export RSS to HTML
If you wish to dress up the feed's appearance you can use a template exporting the feed as HTML or an HTML table. Publishers can incorporate exported tables into an HTML template using a server-side include. Each time the feed is updated, the feed will need to be exported to HTML and uploaded along with the feed. Though this only takes a few moments, exporting RSS to HTML does require webmaster intervention to update the content. The end result, though, is a complete web page with an RSS feed in it that will be search engine-friendly.
FeedForAll - FeedForAll allows users to export RSS feeds from RSS to HTML. The look of the HTML can be modified to match an existing website's design.
Using Services
There are a number of services available that host and display RSS feeds, in many cases free of charge. Because these services operate on a different domain server there is little benefit to end-users displaying their feeds in this fashion. That said, the services are generally free of charge, so you get what you pay for.
RSS2HTML.com - Select a layout, color scheme and enter the URL of the feed. A web page URL will be generated that will display the feed in the selected scheme.
FeedBurner - FeedBurner provides a number of online services. Among them is a service that displays RSS feeds on a website.
Using XSL to Display RSS
Although using XSL and CSS stylesheets to display XML directly is easy to understand in theory, it is rather tricky to implement in the real world and is very tough for novices to use successfully. Webmasters must be fairly familiar with CSS and XSL to have the formatting work well, and webmasters then have to address browser incompatibilities and exceptions. As a result, not a lot of resources or services yet exist to display RSS using XSL.
Using highly targeted feeds, webmasters can enhance their websites with themed content. Ultimately, providing relevant, educational or newsworthy information from reputable related sources will establish expertise in a specific area.
Posted by
Mohammed Ebied
at
2:40 AM
0
comments