a Secarta project ...

HTTPsec Authentication Protocol


Preamble

1. Introduction

This specification describes a public key authentication scheme for HTTP transactions. It provides a minimal HTTP extension for mutual authentication and message origin authentication. It offers integrity protection of a defined set of HTTP message headers, message sequence integrity, content integrity, and content ciphering.

This scheme is designed to fit into the generic authentication framework of RFC2616 [HTTP], as exploited in RFC2617 [HTTP-Authentication].