Policy Transparency: Authorization Logic Meets General Transparency to Prove Software Supply Chain Integrity

被引:3
|
作者
Ferraiuolo, Andrew [1 ]
Behjati, Razieh [1 ]
Santoro, Tiziano [1 ]
Laurie, Ben [1 ]
机构
[1] Google Res, London, England
关键词
transparency; logic programming; policies; identity; authorization; authorization logic; supply chain security; reproducible builds; deterministic builds;
D O I
10.1145/3560835.3564549
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building reliable software is challenging because today's software supply chains are built and secured from tools and individuals from a broad range of organizations with complex trust relationships. In this setting, tracking the origin of each piece of software and understanding the security and privacy implications of using it is essential. In this work we aim to secure software supply chains by using verifiable policies in which the origin of information and the trust assumptions are first-order concerns and abusive evidence is discoverable. To do so, we propose Policy Transparency, a new paradigm in which policies are based on authorization logic and all claims issued in this policy language are made transparent by inclusion in a transparency log. Achieving this goal in a real-world setting is non-trivial and to do so we propose a novel software architecture called PolyLog. We find that this combination of authorization logic and transparency logs is mutually beneficial - transparency logs allow authorization logic claims to be widely available aiding in discovery of abuse, and making claims interpretable with policies allows misbehavior captured in the transparency logs to be handled proactively.
引用
收藏
页码:3 / 13
页数:11
相关论文
共 50 条
  • [41] The Impact of Supply Chain Analytics on Operational Supply Chain Transparency: An Information Processing View
    Zhu, Suning
    Song, Jiahe
    Cegielski, Casey
    Lee, Kang Bok
    AMCIS 2017 PROCEEDINGS, 2017,
  • [42] Making transparency transparent: a systematic literature review to define and frame supply chain transparency in the context of sustainability
    Schaefer, Naemi
    MANAGEMENT REVIEW QUARTERLY, 2023, 73 (02) : 579 - 604
  • [43] Efforts to Improve and Utilize Security Transparency in Software Supply Chains
    Wada, Yasunori
    Arakawa, Reika
    NTT Technical Review, 2024, 22 (11): : 64 - 68
  • [44] Blockchain-Powered Traceability Solutions: Pioneering Transparency to Eradicate Counterfeit Products and Revolutionize Supply Chain Integrity
    Onu, Peter
    Mbohwa, Charles
    Pradhan, Anup
    5TH INTERNATIONAL CONFERENCE ON INDUSTRY 4.0 AND SMART MANUFACTURING, ISM 2023, 2024, 232 : 1420 - 1427
  • [45] The environmental committee: corruption, accountability and sustainable supply chain transparency
    Karaman, Abdullah S.
    Viana, Fernando Luiz E.
    Ellili, Nejla Ould Daoud
    Uyar, Ali
    MANAGEMENT DECISION, 2025,
  • [46] Supply chain and logistics controller - two promising professions for supporting transparency in supply chain management
    Dobroszek, Justyna
    SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2020, 25 (05) : 505 - 519
  • [47] The Role of Blockchain in Supply Chain Transparency for E-Commerce
    Tashtemirovich, Astanakulov Olim
    Balbaa, Muhammad Eid
    INTERNET OF THINGS, SMART SPACES, AND NEXT GENERATION NETWORKS AND SYSTEMS, PT I, NEW2AN 2023, RUSMART 2023, 2024, 14542 : 365 - 376
  • [48] Internet of Things Platform for Transparency and Traceability of Food Supply Chain
    Haroon, Ahmed
    Basharat, Mehak
    Khattak, Asad Masood
    Ejaz, Waleed
    2019 IEEE 10TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2019, : 13 - 19
  • [49] Enhancing Supply Chain Transparency through Blockchain Product Passports
    Canciani, Andrea
    Felicioli, Claudio
    Severino, Fabio
    Tortola, Domenico
    2024 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS AND OTHER AFFILIATED EVENTS, PERCOM WORKSHOPS, 2024, : 751 - 756
  • [50] Addressing Supply Chain Security Risks through Security Transparency
    Goto, Atsuhiro
    Nakajima, Yoshiaki
    NTT Technical Review, 2024, 22 (11): : 48 - 52