Sigstore: Software Signing for Everybody

Sigstore: Software Signing for Everybody
复制标题

Sigstore:适合所有人的软件签名

DOI:
10.1145/3548606.3560596
复制
发表时间:
2022
期刊:
ACM
影响因子:
--
通讯作者:
Torres-Arias, Santiago
Torres-Arias, Santiago
中科院分区:
--
文献类型:
--
作者:
Newman, Zachary;Meyers, John Speed;Torres-Arias, Santiago

文献摘要

参考文献

被引文献

相似文献

软件供应链的妥协正在上升。从XcodeGhost到SolarWinds的影响,黑客们已经发现,瞄准供应链中的薄弱环节可以让他们危及美国政府机构等高价值目标以及谷歌和微软等企业目标。软件签名是许多此类攻击的一种有希望的缓解方法,但在开源和企业生态系统中的应用有限。在本文中,我们提出了一个提供广泛软件签名能力的系统Sigstore。为此,我们将系统设计为提供基准构件签名功能,以最大限度地减少开发人员的采用障碍。为此,Sigstore利用了三种不同的机制:首先,它使用类似于ACME的协议通过OIDC对开发人员进行身份验证,将签名与现有的和广泛使用的身份绑定在一起。其次,它使开发人员能够使用临时密钥对其构件进行签名,从而降低了密钥管理的不便和风险。最后,Sigstore通过人工制品和身份日志实现了用户身份验证,为软件签名带来了透明性。Sigstore正迅速成为互联网基础设施的关键组成部分,在Kubernetes和Distroless等关键软件上拥有超过220万个签名。
Software supply chain compromises are on the rise. From the effects of XCodeGhost to SolarWinds, hackers have identified that targeting weak points in the supply chain allows them to compromise high-value targets such as U.S. government agencies and corporate targets such as Google and Microsoft. Software signing, a promising mitigation for many of these attacks, has seen limited adoption in open-source and enterprise ecosystems.In this paper, we propose Sigstore, a system to provide widespread software signing capabilities. To do so, we designed the system to provide baseline artifact signing capabilities that minimize the adoption barrier for developers. To this end, Sigstore leverages three distinct mechanisms: First, it uses a protocol similar to ACME to authenticate developers through OIDC, tying signatures to existing and widely-used identities. Second, it enables developers to use ephemeral keys to sign their artifacts, reducing the inconvenience and risk of key management. Finally, Sigstore enables user authentication by means of artifact and identity logs, bringing transparency to software signatures. Sigstore is quickly becoming a critical piece of Internet infrastructure with more than 2.2M signatures over critical software such as Kubernetes and Distroless.
照照镜子:对包管理器的攻击
DOI: 10.1145/1455770.1455841
发表时间: 2008
期刊: Proceedings of the 15th ACM conference on Computer and communications security
影响因子: --
作者:
Justin Cappos;Justin Samuel;S. Baker;J. Hartman
通讯作者: J. Hartman
使用主干和边缘流量监控 TLS 采用情况
DOI: 10.1109/infcomw.2018.8406957
发表时间: 2018
期刊: IEEE INFOCOM 2018 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)
影响因子: --
作者:
Chia;Romain Fontugne;Kenjiro Cho;Shigeki Goto
通讯作者: Shigeki Goto
Uptane:确保汽车软件更新安全
DOI: --
发表时间: 2016
期刊:
影响因子: --
作者:
T. Karthik;Kuppusamy;Damon McCoy
通讯作者: Damon McCoy
in-toto:为比特和字节提供从农场到餐桌的保证
DOI: 10.5555/3361338.3361435
发表时间: 2019
期刊: Proc. of the 28th USENIX Security Symposium
影响因子: --
作者:
Torres-Arias, Santiago;Afzali, Hammad;Kuppusamy, Trishank Karthik;Curtmola, Reza;Cappos, Justin
通讯作者: Cappos, Justin
DOI: --
发表时间: 2019
期刊: Request for Comments
影响因子: --
作者:
B. Laurie;Eran Messeri;R. Stradling
通讯作者: R. Stradling