Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Schorlemmer, Taylor R., Burmane, Ethan H., Kalu, Kelechi G., Torres-Arias, Santiago, Davis, James C.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916589658439680
author Schorlemmer, Taylor R.
Burmane, Ethan H.
Kalu, Kelechi G.
Torres-Arias, Santiago
Davis, James C.
author_facet Schorlemmer, Taylor R.
Burmane, Ethan H.
Kalu, Kelechi G.
Torres-Arias, Santiago
Davis, James C.
contents Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and the changes introduced by next-generation signing platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2407_03949
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
Schorlemmer, Taylor R.
Burmane, Ethan H.
Kalu, Kelechi G.
Torres-Arias, Santiago
Davis, James C.
Cryptography and Security
Software Engineering
Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and the changes introduced by next-generation signing platforms.
title Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2407.03949