Policy Transparency: Authorization Logic Meets General Transparency to Prove Software Supply Chain Integrity

被引:3
|
作者
Ferraiuolo, Andrew [1 ]
Behjati, Razieh [1 ]
Santoro, Tiziano [1 ]
Laurie, Ben [1 ]
机构
[1] Google Res, London, England
关键词
transparency; logic programming; policies; identity; authorization; authorization logic; supply chain security; reproducible builds; deterministic builds;
D O I
10.1145/3560835.3564549
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building reliable software is challenging because today's software supply chains are built and secured from tools and individuals from a broad range of organizations with complex trust relationships. In this setting, tracking the origin of each piece of software and understanding the security and privacy implications of using it is essential. In this work we aim to secure software supply chains by using verifiable policies in which the origin of information and the trust assumptions are first-order concerns and abusive evidence is discoverable. To do so, we propose Policy Transparency, a new paradigm in which policies are based on authorization logic and all claims issued in this policy language are made transparent by inclusion in a transparency log. Achieving this goal in a real-world setting is non-trivial and to do so we propose a novel software architecture called PolyLog. We find that this combination of authorization logic and transparency logs is mutually beneficial - transparency logs allow authorization logic claims to be widely available aiding in discovery of abuse, and making claims interpretable with policies allows misbehavior captured in the transparency logs to be handled proactively.
引用
收藏
页码:3 / 13
页数:11
相关论文
共 50 条
  • [21] Providing transparency in the business of software: a modeling technique for software supply networks
    Utrecht University, Netherlands
    不详
    IFIP Advances in Information and Communication Technology, 2007, (677-686)
  • [22] On Blockchain Integration with Supply Chain: Overview on Data Transparency
    Hellani, Houssein
    Sliman, Layth
    Samhat, Abed Ellatif
    Exposito, Ernesto
    LOGISTICS-BASEL, 2021, 5 (03):
  • [23] Shaping patient perceptions with healthcare supply chain transparency
    Duan, Yanji
    Xu, Jing
    Zhao, Mei
    An, Lian
    TRANSPORTATION JOURNAL, 2024, 63 (04) : 226 - 244
  • [24] Inducing Supply Chain Transparency through Supplier Encroachment
    Guan, Xu
    Liu, Baoshan
    Chen, Ying-ju
    Wang, Hongwei
    PRODUCTION AND OPERATIONS MANAGEMENT, 2020, 29 (03) : 725 - 749
  • [25] Effects of Information Transparency on Supply Chain Quality Management
    Xiao, Jing Hua
    Cheng, Zhao Lin
    Zhang, Cai Wen
    Xie, Kang
    2012 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2012, : 966 - 970
  • [26] Impacts of Vertical Information Transparency on an Agricultural Supply Chain
    Yu, Mingzhu
    Wang, Qi
    Yi, Zelong
    Zhang, Zizhen
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND SYSTEMS MANAGEMENT (IESM 2019), 2019, : 440 - 445
  • [27] Supply chain transparency: Consumer reactions to incongruent signals
    Mollenkopf, Diane A.
    Peinkofer, Simone T.
    Chu, Yu
    JOURNAL OF OPERATIONS MANAGEMENT, 2022, 68 (04) : 306 - 327
  • [28] Bond Market Transparency and Innovation Along the Supply Chain
    Chen, Jun
    Liu, Jianfeng
    Ma, Xiaofang
    Wang, Wenming
    PRODUCTION AND OPERATIONS MANAGEMENT, 2025,
  • [29] Blockchain as supply chain technology: considering transparency and security
    Xu, Pei
    Lee, Joonghee
    Barth, James R.
    Richey, Robert Glenn
    INTERNATIONAL JOURNAL OF PHYSICAL DISTRIBUTION & LOGISTICS MANAGEMENT, 2021, 51 (03) : 305 - 324
  • [30] Supply chain transparency and governance in supplier codes of conduct
    Vorosmarty, Gyongyi
    BENCHMARKING-AN INTERNATIONAL JOURNAL, 2025,