  • @inproceedings{BuS2004,
    	vgclass =	{refpap},
    	author =	{Laurence Bull and David McG.\ Squire},
    	title =	{{XML} Signature Extensibility Using Custom Transforms},
    	booktitle =	{The Fifth International Conference on Web Information
    	Systems Engineering (WISE 2004)},
    	address =	{Brisbane, Australia},
    	number =	{3306},
    	series =	{Lecture Notes in Computer Science},
    	pages =	{102--112},
    	publisher =	{Springer-Verlag},
    	month =	{22--24~November},
    	year =	{2004},
    	doi =	{},
    	abstract =	{The XML Signature specification defines a set of
    	algorithms to be used to ensure security and application
    	inter-operability for content signed using an XML Signature. In this
    	paper we propose two ways to use and disseminate newly defined, or
    	custom, transformation algorithms to address a limitation with XML
    	Signatures arising from their extensibility. This involves downloading
    	the algorithm on-demand and embedding the algorithm in the signature
    	itself.  Finally, we highlight a possible vulnerability to attack in
    	the existing XML Signature Core Validation process when using newly
    	defined, or custom transforms, and suggest an extension to the XML
    	Signature standard to remedy this.},