
Dela via

CarrierControlSignatureSchema schema

The CarrierControlSignatureSchema schema defines elements that are used to describe the signature appended to the provisioning file. It is based on the XML DSIG specification with only minor deviations that are explicitly described below. All of the elements are in the namespace Not all elements are in every profile, as some elements are optional.

The following table lists all of the elements in this schema, sorted alphabetically by name.

Element Description

Defines the canonicalization method applied to SignedInfo as specified in XML DSIG. Must be of type Canonical XML.


Defines a Digital Signature Algorithm (DSA) public key as specified in XML DSIG .


Defines the algorithm used to generate DigestValue as specified in XML DSIG.


Defines the digest value as specified in XML DSIG . The algorithm used to generate DigestValue is defined in DigestMethod.


Defines the RSA public key exponent as specified in XML DSIG .


Defines an integer with certain properties with respect to P and Q as specified in XML DSIG.


Defines the length, in bits, of the SignatureValue element as specified in XML DSIG.


Defines (P - 1) / Q as specified in XML DSIG.


Defines all key information used to validate the signature as specified in XML DSIG .


Defines a single public key as specified in XML DSIG .


Defines the RSA public key modulus as specified in XML DSIG .


Defines a prime modulus meeting the DSAwithSHA1 requirements as specified in XML DSIG.


Defines a Digital Signature Algorithm (DSA) prime generation counter as specified in XML DSIG .


Defines an integer in the range 2**159 < Q < 2**160 which is a prime divisor of P-1 as specified in XML DSIG.


Defines a RSA public key as specified in XML DSIG .


Defines a digest value, digest method, and transforms as specified in XML DSIG .


Defines a Digital Signature Algorithm (DSA) prime generation seed as specified in XML DSIG .


Defines the root element of an XML DSIG compliant signature. Signature is the unique root element for a provisioning file signature.


Defines the algorithm used to generate the signature thumbprint in SignatureValue as specified in XML DSIG.


Defines the signature thumbprint as specified in XML DSIG . The algorithm used to generate SignatureValue is defined in SignatureMethod.


Defines all signed content within the signature as specified in XML DSIG .


Defines a transform applied to the digested data object prior to DigestMethod as specified in XML DSIG.


Defines a an ordered list of transforms applied to the digested data object as specified in XML DSIG .


Defines an X.509 compliant signature as defined in XML DSIG .


Defines one or more X.509 compliant signatures as defined in XML DSIG .


Defines G **X mod P (where X is part of the private key and not made public) as specified in XML DSIG.


The full CarrierControlSignatureSchema schema is below:

<?xml version="1.0" encoding="utf-8"?>  
<schema xmlns=""  
        version="0.1" elementFormDefault="qualified">
<simpleType name="CryptoBinary">  
  <restriction base="base64Binary">  
<element name="Signature" type="ds:SignatureType"/>  
<complexType name="SignatureType">  
    <element ref="ds:SignedInfo"/>   
    <element ref="ds:SignatureValue"/>   
    <element ref="ds:KeyInfo" minOccurs="0"/>   
  <attribute name="Id" type="ID" use="optional"/>  
  <element name="SignatureValue" type="ds:SignatureValueType"/>   
  <complexType name="SignatureValueType">  
      <extension base="base64Binary">  
        <attribute name="Id" type="ID" use="optional"/>  
<element name="SignedInfo" type="ds:SignedInfoType"/>  
<complexType name="SignedInfoType">  
    <element ref="ds:CanonicalizationMethod"/>   
    <element ref="ds:SignatureMethod"/>   
    <element ref="ds:Reference"/>   
  <attribute name="Id" type="ID" use="optional"/>   
  <element name="CanonicalizationMethod" type="ds:CanonicalizationMethodType"/>   
  <complexType name="CanonicalizationMethodType" mixed="true">  
    <attribute name="Algorithm" use="required">   
        <restriction base="anyURI">  
          <enumeration value=""/>  
          <enumeration value=""/>  
          <enumeration value=""/>  
          <enumeration value=""/>  
  <element name="SignatureMethod" type="ds:SignatureMethodType"/>  
  <complexType name="SignatureMethodType" mixed="true">  
      <element name="HMACOutputLength" minOccurs="0" type="ds:HMACOutputLengthType"/>  
      <any namespace="##other" minOccurs="0" maxOccurs="unbounded"/>   
    <attribute name="Algorithm" type="anyURI" use="required"/>   
<element name="Reference" type="ds:ReferenceType"/>  
<complexType name="ReferenceType">  
    <element ref="ds:Transforms"/>   
    <element ref="ds:DigestMethod"/>   
    <element ref="ds:DigestValue"/>   
  <attribute name="Id" type="ID" use="optional"/>    
  <attribute name="URI">  
      <restriction base="anyURI">  
        <maxLength value="0"/>  
  <element name="Transforms" type="ds:TransformsType"/>  
  <complexType name="TransformsType">  
      <element ref="ds:Transform" maxOccurs="1"/>    
  <element name="Transform" type="ds:TransformType"/>  
  <complexType name="TransformType" mixed="true">  
    <attribute name="Algorithm" use="required">   
        <restriction base="anyURI">  
          <enumeration value=""/>  
<element name="DigestMethod" type="ds:DigestMethodType"/>  
<complexType name="DigestMethodType" mixed="true">   
    <any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>  
  <attribute name="Algorithm" type="anyURI" use="required"/>   
<element name="DigestValue" type="ds:DigestValueType"/>  
<simpleType name="DigestValueType">  
  <restriction base="base64Binary"/>  
<element name="KeyInfo" type="ds:KeyInfoType"/>   
<complexType name="KeyInfoType" mixed="true">  
  <choice maxOccurs="unbounded">       
    <element ref="ds:KeyValue"/>   
    <element ref="ds:X509Data"/>   
    <any processContents="lax" namespace="##other"/> 
  <attribute name="Id" type="ID" use="optional"/>   
  <element name="KeyValue" type="ds:KeyValueType"/>   
  <complexType name="KeyValueType" mixed="true">  
     <element ref="ds:DSAKeyValue"/>  
     <element ref="ds:RSAKeyValue"/>  
     <any namespace="##other" processContents="lax"/>  

<element name="X509Data" type="ds:X509DataType"/>   
<complexType name="X509DataType">  
  <sequence maxOccurs="unbounded">  
      <element name="X509Certificate" type="base64Binary"/>  

<simpleType name="HMACOutputLengthType">  
  <restriction base="integer"/>  
<element name="DSAKeyValue" type="ds:DSAKeyValueType"/>  
<complexType name="DSAKeyValueType">  
    <sequence minOccurs="0">  
      <element name="P" type="ds:CryptoBinary"/>  
      <element name="Q" type="ds:CryptoBinary"/>  
    <element name="G" type="ds:CryptoBinary" minOccurs="0"/>  
    <element name="Y" type="ds:CryptoBinary"/>  
    <element name="J" type="ds:CryptoBinary" minOccurs="0"/>  
    <sequence minOccurs="0">  
      <element name="Seed" type="ds:CryptoBinary"/>  
      <element name="PgenCounter" type="ds:CryptoBinary"/>  
<element name="RSAKeyValue" type="ds:RSAKeyValueType"/>  
<complexType name="RSAKeyValueType">  
    <element name="Modulus" type="ds:CryptoBinary"/>   
    <element name="Exponent" type="ds:CryptoBinary"/>   