Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866916589658439680 |
|---|---|
| author | Schorlemmer, Taylor R. Burmane, Ethan H. Kalu, Kelechi G. Torres-Arias, Santiago Davis, James C. |
| author_facet | Schorlemmer, Taylor R. Burmane, Ethan H. Kalu, Kelechi G. Torres-Arias, Santiago Davis, James C. |
| contents | Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and the changes introduced by next-generation signing platforms. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2407_03949 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing Schorlemmer, Taylor R. Burmane, Ethan H. Kalu, Kelechi G. Torres-Arias, Santiago Davis, James C. Cryptography and Security Software Engineering Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and the changes introduced by next-generation signing platforms. |
| title | Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2407.03949 |