Policy Transparency: Authorization Logic Meets General Transparency to Prove Software Supply Chain Integrity

被引:3
|
作者
Ferraiuolo, Andrew [1 ]
Behjati, Razieh [1 ]
Santoro, Tiziano [1 ]
Laurie, Ben [1 ]
机构
[1] Google Res, London, England
关键词
transparency; logic programming; policies; identity; authorization; authorization logic; supply chain security; reproducible builds; deterministic builds;
D O I
10.1145/3560835.3564549
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building reliable software is challenging because today's software supply chains are built and secured from tools and individuals from a broad range of organizations with complex trust relationships. In this setting, tracking the origin of each piece of software and understanding the security and privacy implications of using it is essential. In this work we aim to secure software supply chains by using verifiable policies in which the origin of information and the trust assumptions are first-order concerns and abusive evidence is discoverable. To do so, we propose Policy Transparency, a new paradigm in which policies are based on authorization logic and all claims issued in this policy language are made transparent by inclusion in a transparency log. Achieving this goal in a real-world setting is non-trivial and to do so we propose a novel software architecture called PolyLog. We find that this combination of authorization logic and transparency logs is mutually beneficial - transparency logs allow authorization logic claims to be widely available aiding in discovery of abuse, and making claims interpretable with policies allows misbehavior captured in the transparency logs to be handled proactively.
引用
收藏
页码:3 / 13
页数:11
相关论文
共 50 条
  • [31] Improving supply chain transparency: from the perspective of suppliers
    Yang, Liguo
    Lu, Lin
    ANNALS OF OPERATIONS RESEARCH, 2024,
  • [32] How Supply Chain Transparency Boosts Business Value
    Kraft, Tim
    Zheng, Yanchong
    MIT SLOAN MANAGEMENT REVIEW, 2021, 63 (01) : 34 - 40
  • [33] Supply chain transparency: A bibliometric review and research agenda
    Montecchi, Matteo
    Plangger, Kirk
    West, Douglas C.
    INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 2021, 238
  • [34] Supply chain transparency: A bibliometric review and research agenda
    Montecchi, Matteo
    Plangger, Kirk
    West, Douglas C.
    International Journal of Production Economics, 2021, 238
  • [35] A Framework for Traceability and Transparency in the Dairy Supply Chain Networks
    Pant, R. R.
    Prakash, Gyan
    Farooquie, Jamal A.
    OPERATIONS MANAGEMENT IN DIGITAL ECONOMY, 2015, 189 : 385 - 394
  • [36] Supply chain transparency: theoretical perspectives for future research
    Morgan, Tyler R.
    Gabler, Colin B.
    Manhart, Pamela S.
    INTERNATIONAL JOURNAL OF LOGISTICS MANAGEMENT, 2023, : 1422 - 1445
  • [37] On the Financing Benefits of Supply Chain Transparency and Blockchain Adoption
    Chod, Jiri
    Trichakis, Nikolaos
    Tsoukalas, Gerry
    Aspegren, Henry
    Weber, Mark
    MANAGEMENT SCIENCE, 2020, 66 (10) : 4378 - 4396
  • [38] Communicating supply chain sustainability: transparency and framing effects
    Duan, Yanji
    Aloysius, John A.
    Mollenkopf, Diane A.
    INTERNATIONAL JOURNAL OF PHYSICAL DISTRIBUTION & LOGISTICS MANAGEMENT, 2022, 52 (01) : 68 - 87
  • [39] Transparency, traceability and deforestation in the Ivorian cocoa supply chain
    Renier, Cecile
    Vandromme, Mathil
    Meyfroidt, Patrick
    Ribeiro, Vivian
    Kalischek, Nikolai
    Zu Ermgassen, Erasmus K. H. J.
    ENVIRONMENTAL RESEARCH LETTERS, 2023, 18 (02)
  • [40] Establishing supply chain transparency and its impact on supply chain risk management and resilience
    Liu, Yutong
    Du, Jian
    Kang, Taewon
    Kang, Mingu
    OPERATIONS MANAGEMENT RESEARCH, 2024, 17 (03) : 1157 - 1171