implementing solutions for different use cases. These
use cases cover the use of the presented solution by
end users through a Web based user interface, the pro-
vision of the solution’s functionality through a well-
defined SOAP based Web-service interface, and the
realization of a comprehensive test framework that as-
sists is assessing the correct functionality of our solu-
tion. The realization of further use cases such as the
implementation of mobile smartphone apps that make
use of the presented signature-verification tool is re-
garded as future work.
Due to its modular architecture, the presented so-
lution is dynamically extensible especially with re-
spect to new document formats and communication
interfaces. This distinguishes the presented solution
from other signature-verification tools that are avail-
able on the market. A conducted survey has revealed
that these tools are typically limited to certain docu-
ment and signature formats, or to certain communica-
tion interfaces. The presented solution removes these
limitations and thereby contributes to the security, us-
ability, and efficiency of present and future electronic-
signature based applications.
REFERENCES
Adobe Corporation (2008). Document management -
Portable document format Part 1: PDF 1.7.
Bray, T., Paoli, J., Sperberg-McQueen, C., Maler, E.,
Yergeau, F., and Cowan, J. (2006). Extensible Markup
Language (XML) 1.1 (Second Edition). http://
www.w3.org/TR/2006/REC-xml11-20060816/.
ETSI TS 101 903 (2010). Electronic Signatures and Infras-
tructures (ESI); XML Advanced Electronic Signatures
(XAdES) V1.4.2.
European Commission (2011). European Commission
Decision, Establishing minimum requirements for the
cross-border processing of documents signed elec-
tronically by competent authorities under Directive
2006/123/EC of the European Parliament and of the
Council on services in the internal market, notified
under document C(2011) 1081, 2011/130/EU. http://
eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:
L:2011:053:0066:0072:EN:PDF.
Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter,
L., Leach, P., and Berners-Lee, T. (1999). Hypertext
transfer protocol – http/1.1. http://www.ietf.org/ rfc/
rfc2616.txt.
Gudgin, M., Hadley, M., Mendelsohn, N., Moreau, J.-J.,
and Nielsen, H. F. (2007). Soap version 1.2 part
1: Messaging framework. http://www.w3.org/TR/
soap12-part1/.
Housley, R. (2009). Cryptographic Message Syntax (CMS).
http://www.ietf.org/rfc/rfc5652.txt.
Leitold, H., Posch, R., and R
¨
ossler, T. (2009). Media-
break resistant eSignatures in eGovernment-An Aus-
trian experience. In Dimitris Gritzalis, J. L., editor,
Emerging Challenges for Security, Privacy, and Trust
- 24th IFIP SEC, volume IFIP AICT 297 of IFIP Ad-
vances in Information and Communication Technolo-
gies, pages 109 – 118. Springer.
Leitold, H., Posch, R., and R
¨
ossler, T. (2010). Reconstruc-
tion of electronic signatures from eDocument print-
outs. Computers and Security, 29(5):523 – 532. Chal-
lenges for Security, Privacy and Trust.
Leitold H., Hollosi A., P. R. (2002). Security Architecture
of the Austrian Citizen Card Concept. In Proceed-
ings of 18th Annual Computer Security Applications
Conference (ACSAC’2002), Las Vegas, 9-13 Decem-
ber 2002. pp. 391-400, IEEE Computer Society, ISBN
0-7695-1828-1, ISSN 1063-9527., pages 391–400.
OASIS (2007). Digital Signature Service Core Protocols,
Elements, and Bindings Version 1.0. http://docs.oasis-
open.org/dss/v1.0/oasis-dss-core-spec-v1.0-os.pdf.
Ramsdell, B. and Turner, S. (2010). Secure/Multipurpose
Internet Mail Extensions (S/MIME) Version 3.2 Mes-
sage Specification. http://tools.ietf.org/html/rfc5751.
RSA Laboratories (1993). PKCS#7: Cryptographic Mes-
sage Syntax Standard. ftp://ftp.rsasecurity.com/pub/
pkcs/ascii/pkcs-7.asc.
Stranacher, K. and Kawecki, T. (2012). Interoperable Elec-
tronic Documents. In Scholl, Flak, Janssen, Macin-
tosh, Moe, Sbø, and Wimmer, editors, Electronic Gov-
ernment and Electronic Participation - Joint Proceed-
ings of Ongoing Research and Projects of IFIP EGOV
and IFIP ePart 2012, volume 39 of Informatik, pages
81 – 88. Trauner.
The European Parliament and the Council of the Eu-
ropean Union (2000). Directive 1999/93/EC
of the European Parliament and of the Coun-
cil of 13 December 1999 on a Community
framework for electronic signatures. http://
eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:
L:2000:013:0012:0020:EN:PDF.
The European Parliament and the Council of the Euro-
pean Union (2006). Directive 2006/123/EC of the
European Parliament and of the Council of 12 De-
cember 2006 on services in the internal market. http://
eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:
L:2006:376:0036:0068:en:PDF.
World Wide Web Consortium (2008a). Web Con-
tent Accessibility Guidelines (WCAG) 2.0. http://
www.w3.org/TR/WCAG/.
World Wide Web Consortium (2008b). XML Signa-
ture Syntax and Processing (Second Edition). http://
www.w3.org/TR/xmldsig-core/.
Zefferer, T., Tauber, A., Zwattendorfer, B., and Knall,
T. (2011). Secure and Reliable Online-Verification
of Electronic Signatures in the Digital Age. In
Bebo White, P. I. and Santoro, F. M., editors, Proceed-
ings of the IADIS International Conference WWW/IN-
TERNET 2011, pages 269 – 276.
WEBIST2013-9thInternationalConferenceonWebInformationSystemsandTechnologies
334