Tuesday, 31 July 2018

Statement of Comprehensive Income-Btechnd

Statement of Comprehensive Income-Btechnd

STATEMENT OF COMPREHENSIVE INCOME:

This reports the accountant’s primary measure of performance of a business, revenues fewer expenses during the accounting period.
The components of another comprehensive income include:
  • Change in revaluation surplus
  • Actuarial gains and losses arising from translating the financial statements of a foreign operation (IAS 21)

An entity has a choice of presenting:

  • A single statement of comprehensive income or
  • Two statements
  • An income statement displaying components of profit or loss land
  • A statement of comprehensive income that begins with profit or loss.

Statement of Comprehensive Income-BtechndSTATEMENT OF CASH FLOWS:

This is a financial statement that shows how to changes in balance sheet accounts and income cash and cash equivalents, and breaks the analysis down to operating, investing and financing activities. Its particular focus is on the types of activities that create and use cash, which are operations investments, and financing.
 STATEMENT OF CHANGES IN EQUITY:
A statement of changes in equity presents an entity’s profit or loss for a reporting period, items of income and expense recognized in other comprehensive income for the period.
Total comprehensive income for the period showing the amounts attributed to owners of the parent and to non-controlling interests.
 (Dyson, J R   2010)
 NOTES TO THE FINANCIAL STATEMENTS:
This is also referred to as footnotes. These provide additional information pertaining to a company’s operational and financial position and are considered to be an integral part of the financial statements. The notes must be Present information about the basis of preparation of the financial statements and the specific accounting policies used.                          f (Dyson, J R   2010)
  1. R. Riggs are operating sole trader, the company was owned by an individual and the decision about the company lied solely on him, this could be seen in the financial statement of the account
  2. R. Riggs operates just single account balance sheet this is due to the fact that the company was owned by a just single person.
  3. Also, we could see that balance sheet shown no salary paid to anyone which is what normally happened if a company belong to just one person.
1.While the J &B associate operates partnership company. The company was owned by 2 individual and the decision of the company lied on the 2 individual that owned it. This could be seen on the balance sheet of the company
  1. The company also operates 2 separate account statement which indicates the company was owned by more than one person this can be seen in the balance sheet of the company.
3.A closer look at the balance sheet shown salary of 30,000 pounds was paid to J while B received none. All the evidence above showed that j and b associates are into partnership
Gross Profit Margin = Revenue – Cost of goods sold /Revenue x100%
From the financial statement of R. Riggs
£157,165 –  £94,520 = £62,645
62,645/157,165 x 100%
= 0.398 x 100
= 39 %
Net Profit Margin = Net profit/Net sales x100%
£23,937/ £157,165 x 100%
0.152 x 100%
=15.23%
Current Ratio = Current Assets/Current Liabilities
£18,874/5,657
=3.33 x 100 %
= 333
Quick Ratio = Current Asset – inventory/Current Liabilities
£18,874 – 2400/5,657 =16,474/5,657
        = 2.9
For J&B Associates:
Gross Profit Margin = Revenue – Cost of goods sold /Revenue x100%
363,111 – 198,530/363,111 x 100
363,111 –  198,530 =164,581
164,581/363,111 x100
=0.45 x100 %
= 45%
Net Profit Margin = Net profit/Net sales x100%
860,065/363,111 x100
860,065/363111 = 2.368
=2.368 x100%
23.7%
Current Ratio = Current Assets/Current Liabilities
140,490/72525 x100
1.93 x 100 = 194
Quick Ratio = Current Asset – inventory/Current Liabilities
Current Assets = 140,490
 Inventory =74,210
Current Liability = 72,525
140,490 -74,210/72,525 x100
66,280/72,525
= 0.91
Conclusion:
The investors and creditors make use of Current Ratio to understand the liquidity of a company before investing in them or given out a loan.
This gives them the knowledge to know whether a company will be able to pay off its current liabilities or not. This express a company current debt in terms of current assets.
  1. Riggs has a ratio 3.33 while J & B associates has a current ratio of 1.9.
It shows that R. Riggs has 3 times more currents assets than liabilities while J & B Associates has 1.9 times more current assets than current liabilities.
It means R. Riggs is good in paying his liabilities than J & B Associates.
Liabilities should be covered by the asset 2: 1 before the company could be approved for a loan.
  1. Riggs would be able to get approval for a loan from the bank while J & B Associates will find it very difficult to get a loan.
  • Gearing:
Gearing = Long term Debt /Capital Employed x100
Capital Employed = Total Assets – Current Liabilities
Long term Debt =7880000
7880000/ 13800000 + 478600+597680 – 1187600
13800000+478600+597680 = 14,876,280
14,876,280 – 11876000 = 13,688,680
7,880000/13,688,680 x100
0.57 x100 = 57%.
 (ii) Earnings Per Share (EPS):
Earnings Per share = Dividend/Number of issued ordinary shares
750,000/5,000,000 = 0.15p
(iii) Dividend per share:
Dividend per share =   Dividend /number of ordinary share issues.
200,000/5,000,000 = 0.04 (DPS)
(iv) Dividend Yield:
Dividend yield: Dividend per share /price per share x100
Dividend per share = 0.04
0.04/1 = 0.04
0.04 x100 = 4 %
(v) Dividend Cover:
Dividend Cover: Earning per share /Dividend per share
EPS =0.15p
Dividend per share =0.04
0.15/0.04 = 3 .75 times
Price/Earnings Ratio:
Price/earnings ratio: Market price per share/Earnings per share
EPS =0.15
0.80/0.15 = 5.33
To: jane
From: Gbenga
Subject: A report advising Jane whether or not she should invest in Staton Plc
Introduction: A brief Report to Advise Jane whether to invest in Staton PLC.
 Body:
From the account published by Staton Plc, after calculating the Gearing, I found that it is 57 percentages which means the company is running 57 percentage debt.
Earnings per share is 0.15p which is a little lower when investing in a company.
Dividend per share is 0.04p which show jane could only receive 0.04 pence on every 80 p invested which is too low compared to the previous year.
Dividend yield is 4 % which means Jane will be receiving 0.04p on every 80p she invested.
Dividend cover is 3.75 which implies that Staton Plc has sufficient earning to pay dividend in 3 times during the next dividend pay-out.
For a company to be profitable to invest it must be able to pay dividend cover for 2 times or more. This indicate that Staton Plc is retaining a higher portion of its earning to meet subsequent pay out.
Price/Earnings ratio is 5.33 which means Jane would be 5 times getting out her earning to cover the price. Company that are losing money will either have Nil or negative Price/ Earnings Ratio.
Conclusion: It is advisable for Jane not to invest in Stanton Plc because the company is 57 percentages in debt which implies the company could go bankrupt and not be able to pay subsequent share price.
REFERENCE
Atrill, p. and Mclaney, E (2012). Accounting and finance for Non- specialist, 8th edition.Order Now

Part-1 Programming Assignment Help

Part-1 Programming Assignment Help

“A programmer is ideally an essayist who works with traditional aesthetic and literary forms as well as mathematical concepts, to communicate the way that an algorithm works and to convince a reader that the results will be correct.”
Computer programming is perhaps the perfect amalgamation of the aesthetic qualities, literary forms and mathematical concepts. Students are required to have all these qualities in order to come up with the perfect program that would revolutionize the way we use computers. But this is not an easy job. As a discipline, it has a notoriety to be esoteric while the field itself is extremely competitive. However, help is at hand. cheapassignmenthelp.co.uk brings you programming help so that you can fulfill your dream of becoming a successful programming expert. Here is an overview on computer programming and programming assignments.
programming help

Understanding Computer Programming

Definition

A computer programming is the process that transforms a computing problem into an executable computer program.

Explanation

A computer runs on a program. A program is a series of instruction that is received by the computer at its Central Processing Unit (CPU) and is executed by the computer in order to fulfill a particular task. The program has to be written in a human-readable language. The codes in which the computer languages are written are called source codes and are developed by programmers.
The science of writing, developing and perfecting codes is basically called computer programming. It is a highly competitive discipline and US, UK and Australian universities usually have a record number of applicants for programming courses. The following article summarizes the basics of computer programming for those needing programming help.

Uses of Computer Programming

Computer Programming is used for a variety of purposes:
1. Computer programming helps in developing programming languages which are used for transforming computing problems into instructions. While there is a long history of programming languages, popular programming languages that have been developed include Action Script, C++, C#, Haskell, PHP, Java, Python, Ruby, Smalltalk, SQL and Visual Basic. These are increasingly abstracted language, allowing programmers to develop source code much easily.
2. Programming languages have helped in the development of the internet which has brought people closer.
3. Programming is one of the chief stages of software development process. Software is a collection of computer programs and other data. Software development involves several stages including programming, testing, bug fixing documenting etc. A software developer or a programmer has to have the knowledge of all the stages and also a specialized knowledge about one particular field.
4. Finally from the point of view of students, programming helps them to understand how to solve computing problems. As you develop more and more programs, your confidence level surges.

Major Areas of Computer Programming

Programming Language

A programming language is a special kind of language meant to give instructions to a computer. The various elements of programming include syntax, semantics, design and implementation etc. Languages can be classified according to programming paradigms and domain of use.
There are four types of languages based on domain of use:
i. General-Purpose programming languages
ii. System programming languages
iii. Scripting languages
iv. Domain-specific programming languages
On the basis of programming paradigms, languages may be classified into:
i. Imperative programming languages
ii. Declarative programming languages
iii. Procedural programming
iv. Object-oriented programming
v. Functional programming
vi. Logic programming etc.
Some key languages needed by students for their programming languages assignments are:
C++: This is a general programming language. A version of it has been standardized by ISO. C++ is generally helpful in desktop applications, servers and entertainment applications.
C#: This is a multi paradigm specific language that helps in different paradigms like imperative, declarative, functional, generic, object-oriented etc.
Java: It is a general purpose computer programming language that has fewer implementation dependencies i.e. the code that runs one platform does not need to be recompiled when the platform is changed.
JavaScript: It is another kind of multi-paradigm, object-oriented programming language with imperative and functional styles.
Visual Basic: It is programming language from Microsoft. It provides rapid application development of graphical user interface (GUI).
Coffee Script: An improvement on JavaScript that enhances the compactness and the readability.
Swift: Another multi-paradigm programming language which is object oriented, functional and imperative.

Data Structure

Data structure refers to a particular way of organizing data. As a programming language concept, it is usually associated with C. A number of data structures are available. They are array, associative array, union, tagged union, set, graphs etc.

DBMS

A data is a sequence of symbols on the basis of which operations are performed by a computer. An organized collection of data is called a database. DBMS stands for database management systems. They are computer software applications which interact with other applications, users and databases in order to store, retrieve and process data.

Source Coding

A series of computer instructions written in a computer programming language is called a source-code. A source code is transformed into a machine code. The machine code is then stored for execution at a later time. Learning about source code is a major area of software development and is important for programming assignments.

Debugging

A bug is basically a software defect. Debugging is a methodical process of finding and removing that defect from the computer system and the software so that they can run as expected. There are numerous debugging methods:
Interactive Debugging Control Flow Integration Testing Log Files Monitoring Profiling Statistical Process Control

Networking

A computer network is telecommunications network that allows computers to exchange data. Although networking is not strictly a domain of computer programming yet it is an important sub domain of computer science in general. A student seeking networking assignment help usually finds difficulties in the following area:
Network packet Network typology Network nodes Network structures Protocols Network performanceNetwork security

Chief Functions of a Computer Programmer

So, what does a computer programmer do? What are the stages of software programming development? A programmer’s basic job is to turn a computing problem into a software program. Programming involves definite steps common to any problem solving.

Defining the problem

The problem has to be defined in terms of what is given (input given data) and what is to be obtained (output the result).

Planning the solution

A solution has to be planned either by preparing a flowchart or by writing a pseudo code. Ideally, a programmer should do both.

Coding the program

This is perhaps the most important step of computer programming. A programmer should express the solution in a programming language.

Testing the program

The program has to be tested for bugs. If found, they have to be removed by the process of debugging.

Documenting the program

Documentation is perhaps the most tedious process of program development. Once the program is made, a detailed descriptive analysis has to be given.

Computer Programming and Information Technology

Computers have revolutionized the contemporary society. Information technology (IT) uses all the three domains of computer science: computer hardware, computer networking and computer programming.
i. Information technology helps to store, retrieve and manipulate data for the benefit of businesses.
ii. IT is a booming industry and a thriving academic discipline.
iii. Worldwide IT spending forecast for the year 2015 is 3888 billion dollars respectively.
iv. More importantly US, UK and Australian universities have introduced undergraduate and graduate programs in IT.

Computer Programming Assignments: an overview

Computer programming as mentioned before has developed into a major domain of computer science. Computer science deals with three major domains. They are:

Computer hardware

The physical elements that constitute a computer system are collectively called computer hardware. The science that deals with the functions and the mechanics of computer science is called computer hardware.

Computer networking

Computer networking deals with the science of connecting different computer networks and sharing of data.

Computer programming

Programming is the third major sub-domain of computer sciences. A computer programming student needs to learn about the following sub-domains. They are divided into the following according to theory and applications:

  Theories of Computer Programming

  Areas of Applications

  Theory of computation
Information and coding theories
Data structures and algorithms
Programming language theories like those of Java, C++,   and Visual Basic etc.
  Databases
Software architecture
Computer performance analysis
Computer security

Programming courses require coursework, assignments, lab-work and examinations on the above areas of the discipline.

Major Challenges Faced by Students in their Computer Programming Assignments

Computer programming is much sought after discipline. Companies like Microsoft, IBM, and Intel hire computer programming students for bringing innovative products and developing path breaking software. However, the road to success and glory is never free from impediments. Such was the case with even with Bill Gates, one of the best computer programmers of our times. While he dropped out because of other reasons, many programming students cannot handle the pressure of academic life. Here are some general and specific problems which student face in the computer programming assignments.
General Problems: Some of the most quotidian problems faced by students are problems of deadline, writing in English and following the lectures. Let us look at each of these issues and try to find out how they can affect (sometimes seriously) the academic life of a student:

Deadlines

Many students miss their deadlines, sometimes intentionally, sometimes unintentionally. Students often multi-task between studies, part-time jobs and extra-curricular activities. On the other hand, many students intentionally delay their assignments until the day of submission has arrived. Both can be dangerous. Handing out assignments late can create a very negative impact on students.

Language issue

Students with English as their second language often fail to follow the lectures of the professors. Computer science books are often abstruse in nature. Writing in English is another area of difficulty. All these may seriously jeopardize the career of a student.
Specific Problems:Computer science students often squabble over the question: which is the most difficult domain in computer science? While some argue it is programming, others argue that it is networking. In any case, programming student has to face a lot of issues of their own:

Writing codes

Perhaps the most tedious job of computer programming. A simple fault in the codes can lead to a bug and as such coders have to be extra cautious.

Developing program language

A wide variety of programming languages are available and new languages are being developed. Industry demands newer technological innovations in programming languages. Java as a programming language thrived during the internet boom of early 2000. However, changes in the industry demanded better programming languages. A student needs to be aware of the changes in order to develop better programming languages.

Debugging

Debugging is another tricky programming area. Once a bug is detected, the computer program has to be debugged. All these create a lot of problems for students.

How can Online Assignment Help Services aid in Solving these Problems?

Assignment help is now provided by several online assignment help service providers which provide quality assignment help to students in need. They provide assignment help, essay help and even dissertation editing and proofreading help. A number of benefits can be accrued from these services:
1. Students can see a marked improvement in their grades.
2. Students can get expert help in difficult sub-domains like computer source coding, programming languages and debugging.
3. Timely delivery of articles can ensure extra grade points from the teacher.
4. Expert assignment help on difficult domains can ensure that weaker students can get that extra help they need.

How cheapassignmenthelp.co.uk can help students in their programming language assignments?

cheapassignmenthelp.co.uk is a leading assignment help service provider of the world which provides assignment help solutions to students in need.
Our students come from a variety of disciplines. We entertain students from law, management, nursing, engineering etc. Within programming, we help out students in programming languages, database management, networking etc.
You can also log on to our website and browse through our computer programming assignment samples to have an idea of the kind of work we produce.
Our support team is there 24×7 to answer any query. All assignments are 100 percent original and specifically tailor-made for the student concerned.
In order to order, just log on to our website, fill out the application form and get free assignment quotes. Once you have paid your fees, we shall assign our best writer on your assignment. Your customized assignment will reach your mail box much ahead of the deadline.

Operating System Assignment Help

Operating System Assignment Help

This is not at all my favorite subject, but what to do, I have to complete the given assignment. Well, such phrases come under the consideration very often when a student is supposed to complete the assignment of operating-system-assignment-helptheir hatred subjects. While pursuing the I.T. studies, there are various subjects come which create problems  and students find themselves helpless when they are supposed to submit an assignment. But now the solution of such issues is at your door.

What is Operating System?

Well, this is one of the important subjects of Computer Science or I.T. Stream. This subject describes all the information related to the internal working of the process and resources.   The definition of the term states that “Operating System is an interface between the hardware and software”. It makes possible to communicate with the computer software.
“An operating system is a collection of programs that control the application software that users run and provides a link between the hardware and software currently running on the computer”. It is also responsible for managing and controlling the multiple resources like memory, monitor, hard drives, etc. All these resources are meant to be shared amongst the different application programs that may be running simultaneously.
Example – MS Windows, Google Android, Mac O.S., Linux and many more.
Some of the main topics of O.S. are listed below:
  • Fundamentals and principles of O.S.
  • Advanced Scheduling
  • Dynamic Memory Allocation
  • Locks, Semaphores and Monitors
  • Segmentation and Paging
  • Xv6 process operations
  • Interrupts and System Calls
  • Threads and Synchronization
  • Concurrency Errors
  • Interprocess communication and many others

Types of Operating System

The presence of operating systems is there from the very first computer generation. It has been evolving for past decades. There are few of the important types of O.S. mentioned below:
  • Simple Batch System – In this type of system, there is no direct interaction takes place between the user and the computer. This is treated as  the oldest type, as in this user was required to submit all the process of the  same type in a batch , that is why it is known as Batch system O.S.
  • Multiprogramming Batch System – In this O.S. type, O.S. and C.P.U. always get busy in executing the multiple jobs. Once job needs an I/O operation, O.S. switches to another job.
  • Multiprocessor System – This type of system consists of several processors which share a common physical memory. It increases the speed of computing performance as several processors operate under a single operating system.
  • Distributed Operating System – The agenda of developing this sort of O.S. is the availability of inexpensive and powerful microprocessors in communication technology. Low price and performance ratio is the main benefit of distributed O.S.
  • Real time Operating System – It is defined as an O.S. which gives maximum time for each of the critical operations that it performs. It is further divided into 2 main parts : Hard Real time and Soft Real time.

How does cheapassignmenthelp.co.uk render Operating System assignment help

Without being pretentious, cheapassignmenthelp.co.uk renders an excellent operating system assignment help online to the students. We understand that it is a technical topic, so how to explain in the best way is our concern. As we have professional writers who know an appropriate way to complete the assignment. By describing each and every topic in the perfect manner with examples is the way of attempting the difficult assignments. We make sure that our students get the completed assignment before time. Not only this, there are also other effective features which make you impress. It would be great when students get O.S assignment help from cheapassignmenthelp.co.uk, because all we serve what you need.
So, do not miss the chance to get  high grades,  just contact us and book your assignment .

Exploring XML Encryption Assignment Help

Exploring XML Encryption Assignment Help

Demonstrating the secure exchange of structured data
XML Encryption provides end-to-end security for applications that require secure exchange of structured data. XML itself is the most popular technology for structuring data, and therefore XML-based encryption is the natural way to handle complex requirements for security in data interchange applications. Here in part 1 of this two-part series, Bilal explains how XML and security are proposed to be integrated into the W3C’s Working Draft for XML Encryption.
  • expandTable of contents
Currently, Transport Layer Security (TLS) is the de facto standard for secure communication over the Internet. TLS is an end-to-end security protocol that follows the famous Secure Socket Layer (SSL). SSL was originally designed by Netscape, and its version 3.0 was later adapted by the Internet Engineering Task Force (IETF) while they were designing TLS. This is a very secure and reliable protocol that provides end-to-end security sessions between two parties. XML Encryption is not intended to replace or supersede SSL/TLS. Rather, it provides a mechanism for security requirements that are not covered by SSL. The following are a two important areas not addressed by SSL:
  • Encrypting part of the data being exchanged
  • Secure sessions between more than two parties
With XML Encryption, each party can maintain secure or insecure states with any of the communicating parties. Both secure and non-secure data can be exchanged in the same document. For example, think of a secure chat application containing a number of chat rooms with several people in each room. XML-encrypted files can be exchanged between chatting partners so that data intended for one room will not be visible to other rooms.
XML Encryption can handle both XML and non-XML (e.g. binary) data. We’ll now demonstrate a simple exchange of data, making it secure through XML Encryption. We’ll then slowly increase the complexity of the security requirements and explain the XML Encryption schema and the use of its different elements.

A simple example of secure exchange of XML data

Suppose you want to send the XML file in Listing 1 to a publishing company. This file contains details of a book that you want to purchase. In addition, it also contains your credit card information for payment. Naturally, you would like to use secure communication for this sensitive data. One option is to use SSL, which secures the whole communication. The alternative is to use XML Encryption. As already mentioned, XML Encryption is not an alternative to SSL/TLS. If the application requires that the whole communication be secure, you’ll use SSL. On the other hand, XML Encryption is the best choice if the application requires a combination of secure and insecure communication (which means that some of the data will be securely exchanged and the rest will be exchanged as is).
Listing 1. The sample XML file to be encrypted
<purchaseOrder>
<Order>
<Item>book</Item>
<Id>123-958-74598</Id>
<Quantity>12</Quantity>
</Order>
<Payment>
<CardId>123654-8988889-9996874</CardId>
<CardName>visa</CardName>
<ValidDate>12-10-2004</ValidDate>
</Payment>
</purchaseOrder>
Note: We have intentionally kept the XML file in Listing 1 very simple. This helps in keeping our focus on encryption-related issues. Real-world XML files in collaborative commerce or Web services will be similar in structure but more verbose. WSDL (Web Services Definition Language) and SOAP (Simple Object Access Protocol) are XML-based grammars that are frequently used in B2B integration. Both WSDL and SOAP can use XML Encryption to provide secure communication across the enterprise. Visit the W3C for details about them (see Resources).

Encrypting complete documents with XML Encryption

XML Encryption offers various options. Listing 2, Listing 3, and Listing 4 show the different encrypted results. Let’s look at them in detail, one by one.
Listing 2 shows the resulting XML-encrypted file, in case you decide to encrypt the entire XML document in Listing 1. Notice the<CipherData>and<CipherValue>tags. The actual encrypted data appears as contents of the<CipherValue>tag. The completeCipherDataelement appears within anEncryptedDataelement. TheEncryptedDataelement contains the XML namespace used for encryption. For example, your original data before encryption was XML and the official type definition by the Internet Assigned Numbers Authority (IANA) for XML is //www.isi.edu/in-notes/iana/assignments/media-types/text/xml. This appears as the value of theTypeattribute. XML Encryption uses the type definitions by IANA for various popular data formats such as RTF, PDF, and JPG. Refer to their Web site for complete details (see Resources). If you have special application data types (perhaps your own DTDs or XSDs that belong to your company’s content management system), you can specify them in theTypeattribute ofEncryptedDataelement. The other attribute, xmlns, specifies the XML Encryption namespace that we used to encrypt the XML data.

Encrypting a single element with XML Encryption

You may want to encrypt only one element in Listing 1 — for example, thePaymentelement. In this case, the result is illustrated in Listing 3. Compare Listing 2 and Listing 3 and you’ll find the following differences:
  1. Listing 2 contains only XML Encryption’s schema, while Listing 3 contains both XML Encryption as well as elements from the original data in Listing 1. In Listing 3, the XML Encryption is embedded inside the user’s XML.
  2. Listing 3 also has aTypeattribute in<EncryptedData>, but its value is //www.w3.org/2001/04/xmlenc#Element. We are no longer using the IANA type; instead, we are using the type that XML Encryption has specified.
  3. Note particularly the fragment #Element at the end that means EncryptedData — this represents one element.

Encrypting the content of an element

Listing 4 will be the result if you want to encrypt only the content inCardId, an element in Listing 1. This time, we have used //www.w3.org/2001/04/xmlenc#Content as theTypeattribute value. We use this value whenever we have to encrypt only the content.

Encrypting non-XML data

What if you want to send, say, a JPEG file through XML Encryption? Listing 5 is a typical file that will result. The complete JPEG file in an encrypted sequence of bytes will appear as the content of theCipherValueelement. Notice that there is only one difference between Listing 2 and Listing 5: theTypeattribute of theEncrypted Data element. Listing 5 includes the IANA type for the JPEG format. Similarly, you can encrypt any format by providing IANA values (refer to the IANA Web site, see Resources).

Keys for XML Encryption

In Listings 1 through 5, we have demonstrated encryption, which is not possible without keys (see the sidebar Public, private, and secret keys). With XML Encryption, all key-related issues are divided into two parts:
  • Exchange of keys (asymmetric encryption)
  • Using keys that were previously exchanged (symmetric encryption)
This way, users can exchange keys and use them later.

Asymmetric keys for exchange of secret keys

In this scenario, one party sends its public key to a second party. The second party uses this public key to encrypt its secret key. This exchange of data is shown in Listing 6 (request) and Listing 7 (response). We will imagine Imran and Ali as the first party and second party, respectively, communicating with each other. Imran initializes the public key exchange request and sends his public key in the element named KeyValue . The attributeCarriedKeyNamerepresents the name of the key that is being transported. Note that the root element of this structure isEncryptedKey, which contains theds:KeyInfoandds:KeyValueelements. Theds: KeyInfoandds:KeyValueelements belong to the XML Digital Signature (ds:) namespace. XML Encryption relies entirely on the XML Digital Signature specification for key exchange. Therefore, both<ds:EncryptedKey>and<ds:KeyValue>belong to the XML Digital Signature specification namespace. Listing 7 is what Ali sends in response. TheCipherValueelement in Listing 7 contains a newly generated secret key, which is encrypted with the public key of the first party. Looking closely at Listing 6 and Listing 7, you’ll notice that both request and response contain anEncryptedKeyelement. Theds:KeyInfoandds:KeyValueelements within theEncryptedKeyelement carry the public key (Listing 6). On the other hand, theCipherDataandCipherValueelements inside theEncryptedKeyelement (Listing 7) will transport the secret (encrypted) keys. Also notice that theEncryptedKeyelement always contains aCarriedKeyNameattribute to specify the name of the key it is carrying.

Using keys we have already exchanged in the past

In the previous section, we exchanged a secret key. We’ll now use that key to encrypt data. We will assume that Imran sends an XML message (Listing 8) in response to Listing 7 (recall that Listing 7 contains an encrypted secret key whose name is “Imran Ali”). Imran will decrypt this secret key with his (Imran’s own) private key (as Ali encrypted this secret key with Imran’s public key). Imran can encrypt the data he wants to send to Ali using this secret key and placing it inside theCipherValueelement in Listing 8.
Theds:KeyInfoelement in Listing 8 contains aKeyNameelement. This combination refers to the name of the key that Imran uses for data encryption.
Figure 1 is a visual diagram showing this exchange of XML files for secure data exchange.
Figure 1. Sequence of key and data exchange with XML Encryption
Sequence of key and data exchange with XML Encryption.

Referring external encrypted data from our XML Encryption file

theCipherDataelement can appear within anEncryptedDataelement or anEncryptedKeyelement. We use aCipherDataelement to refer to either the encrypted data (when it appears inside anEncryptedDataelement) or the encrypted key (when it appears inside anEncryptedKeyelement). In both Listings 5 and 7, there is aCipherValuechild element inside theCipherDataelement that contains the actual encrypted data.
We can also refer to external encrypted data or encrypted keys. This means that actual encrypted data or keys will be present somewhere else (perhaps somewhere on the Internet) and not inside our XML Encryption file. In this case we will useCipherReferenceinstead of theCipherValuechild element insideCipherData. We’ll refer to the actual encrypted data through a URI.

Referencing a particular element of an external XML file

 illustrates a variation of referring external XML files. Here we have referenced only a portion of the external file that the URI is pointing to. There is aTransformschild element inside theCipherReferenceelement. ThisTransformselement may contain a number ofTransformelements, each of which will contain a single XPath element. This XPath element specifies an XPath expression that refers to a particular node of the external XML document.

The DOM structure of our API

We have already demonstrated how to author XML Encryption files and exchange encrypted data. We will now propose a Java API for XML Encryption and provide a sample implementation. We will use DOM for this purpose.
Our DOM implementation consists of a set of classes (Listings 11 to 16). TheXmlEncryptionclass  is a wrapper for the rest of the classes, which means users of our API will only need to interact with this class. It uses the functionality of other classes internally.
 is a wrapper class that can generate a complete XML encrypted file.
 authors theEncryptedDataelement.
 authors theEncryptionMethodelement.
 authors theKeyInfoelement.
 authors theCipherDataelement.
 contains names of Algorithms as static integers and their corresponding namespaces as strings.
TheXmlEncryptionclass  contains various public Get/Set methods. The user will call Set methods to specify encryption parameters, which include the following:
  1. Name of the file to be encrypted
  2. Name of the resulting XML Encryption file
  3. Name of the algorithm for encryption
  4. Name of the key that we will use for encryption
  5. An ID for identification of<EncryptedData>structure
We have demonstrated the use of theXmlEncryptionclass  through amain ()method. In themain ()method, we have created an instance of this class. The constructor instantiates DOM so that all underlying classes will use the same object.
We have used three technical terms related to keys (public, private, and secret keys). Although these terms are well known to developers working with end-to-end security, XML developers might not be familiar with them. Let’s clarify these terms:
Public and private keys: We use them as a pair. Some algorithms generate a pair of public and private keys. We send the public key to anyone who wants to exchange encrypted data with us. With a public key, we can only encrypt data of limited size. Our communicating partner encrypts the data with our public key and sends the encrypted data to us. We then decrypt the data with our private key. This is asymmetric encryption.
Secret key: We use public and private keys to exchange a secret key. We normally generate secret keys randomly. Once we have exchanged a secret key with our communicating partner through asymmetric encryption, we then use this key for encrypting data at both ends. This is symmetric encryption.
This implementation only supports encryption of complete files, as illustrated in. TheEncryptCompleteXmlFile ()method will do this job by calling the following methods in a sequence:
  1. GetEncryptedDataDoc()returns the object of theEncryptedDataclass . It contains the structure of theEncryptedDataelement.
  2. GetEncryptionMethodDoc()returns the Document object, which contains the XML structure corresponding to theEncryptionMethodelement.GetEncryptionMethodDoc()usesEncryption Methodclass  to author XML.
  3. GetKeyInfoDoc()returns theDocumentobject, which contains the XML structure corresponding to KeyInfo element.GetKeyInfoDoc()uses the object ofGenericKeyInfoclass  to author the XML. This class only provides the minimum necessary functionality (support forKeyNameandKeyValueelements) you will inherit fromGenericKeyInfoclass to provide the complete functionality, which includes support for X509 Certificates, PGP Data, etc.
  4. ReadFile()fetches the data (complete XML file) that we want to encrypt.
  5. GetEncryptedData()for the time being is not doing anything. We’ll implement this method in the next part of this article. It is supposed to create the encrypted form of XML data that we fetched in step 4. We have briefly discussed our encryption strategy in the last section (Java Cryptographic Architecture).
  6. GetCipherDataDoc()takes the encrypted data as an argument and returns the Document Object containing theCipherDataelement.GetCipherDataDoc()uses the Object ofCipherDataclass  to author XML.
  7. At the end,addChild()method of Object ofEncryptedData is called thrice, which will take the Document Objects of steps 2, 3, and 6 and adds them to the<EncryptedData>structure, which is the parent of all of them.
  8. SaveEncryptedFile()saves the completed XML Encryption file.
AlgoNames is a helper class that only specifies namespace declarations required by XML Encryption.
TheXmlEncryptionclass can also be used as a server-side component. In the next part of this series, we’ll demonstrate its use inside independent as well as server-side applications.
The set of classes that we have developed only performs DOM-based XML authoring. We need to implement cryptographic functionality as well. We will now try to form a strategy for cryptographic support. For this purpose, we need to study the Java Cryptographic Architecture (JCA).
Java offers complete support for cryptography. For this purpose, there are several packages inside J2SE, covering all the main features of security architecture such as access controls, signatures, certificates, key pairs, key stores, and message digests.
The primary principle of JCA design is to separate cryptographic concepts from algorithmic implementations, so that different vendors can offer their tools within the JCA framework.

JCA Engine classes

JCA defines a series of Engine classes, where each Engine provides a cryptographic function. For example, there are several different standards of MD (Message Digest) algorithm. All these standards differ in the implementation, but at the Engine API level they are all the same. Different vendors are free to provide implementations of specific algorithms.

Java Cryptographic Extension (JCE)

All independent (third party) vendor implementations of cryptographic algorithms are called Java Cryptographic Extensions (JCEs). Sun Microsystems has also provided an implementation of JCE. Whenever we use JCE, we need to configure it with JCA. For this, we need to do the following:
1. Add the address of the jar file to configure the provider (all JCE implementations are called providers) in theCLASSPATHenvironment variables.
2. Configure the provider in the list of your approved providers by editing the java.security file. This file is located in JavaHome/jre/lib/security folder. The following is the syntax to specify the priority:security.provider.<n>=<masterClassName>. Here, n is the priority number (1, 2, 3, etc.).MasterClassNameis the name of master class to which the engine classes will call for a specific algorithm implementation. The provider’s documentation will specify its master class name. For example, consider the following entries in a java.security file:
  • security.provider.1=sun.security.provider.Sun
  • security.provider.2=com.sun.rsajca.Provider
  • security.provider.3=com.sun.net.ssl.internal.ssl.Provider
These entries mean that the engine class will search for any algorithm implementation in the above mentioned order. It will execute the implementation found first. After these simple steps, we are all set to use JCA/JCE in our XML Encryption application.

Using JCA and JCE in our implementation of XML Encryption

TheGetEncryptedData()function in our wrapper class,Xml Encryption, is the place to handle all JCA/JCE-related issues. Currently this method only returns the string “This is Cipher Data”. We have not yet written JCA/JCE-related classes. This method takes the unencrypted data and returns it as an encrypted string. We will handle all the algorithm- and key-related issues in this method after writing the wrapper classes for JCA/JCE.
Next time: In our next installment of this series of articles, we will discuss and implement the details of cryptography. We’ll demonstrate the working of encryption and decryption classes and their interaction with parsing logic, and present applications of XML Encryption in Web services.