USENIX Security2017Top-tier venue
CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified Builds
Kirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Justin Cappos, Bryan Ford
Abstract
Software-update mechanisms are critical to the security of modern systems, but their typically centralized design presents a lucrative and frequently attacked target. In this work, we propose CHAINIAC, a decentralized softwareupdate framework that eliminates single points of failure, enforces transparency, and provides efficient verifiability of integrity and authenticity for software-release processes. Independent witness servers collectively verify conformance of software updates to release policies, build verifiers validate the source-to-binary correspondence, and a tamper-proof release log stores collectively signed updates, thus ensuring that no release is accepted by clients before being widely disclosed and validated. The release log embodies a skipchain, a novel data structure, enabling arbitrarily out-of-date clients to efficiently validate updates and signing keys. Evaluation of our CHAINIAC prototype on reproducible Debian packages shows that the automated update process takes the average of 5 minutes per release for individual packages, and only 20 seconds for the aggregate timeline. We further evaluate the framework using real-world data from the PyPI package repository and show that it offers clients security comparable to verifying every single update themselves while consuming only one-fifth of the bandwidth and having a minimal computational overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 147d1118-335e-4c7f-bf1e-ee0cec09549eCited by top-tier papers21
- OmniLedger: A Secure, Scale-Out, Decentralized Ledger via ShardingEleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly et al.S&P 2018 · 1,145 citations
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
- Transparency Logs via Append-Only Authenticated DictionariesAlin Tomescu, Vivek Bhupatiraju, Dimitrios Papadopoulos, Charalampos Papamanthou et al.CCS 2019 · 69 citations
- Vault: Fast Bootstrapping for the Algorand CryptocurrencyDerek Leung, Adam Suhl, Yossi Gilad, Nickolai ZeldovichNDSS 2019 · 53 citations
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
Builds on5
- Enhancing Bitcoin Security and Performance with Strong Consistency via Collective SigningEleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Ismail Khoffi et al.USENIX Security 2016 · 769 citations
- Scalable Bias-Resistant Distributed RandomnessEwa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly et al.S&P 2017 · 327 citations
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 33 citations
Related papers
- Catena: Efficient Non-equivocation via BitcoinAlin Tomescu, Srinivas DevadasS&P 2017 · 144 citations
- Message Chains for Distributed System VerificationFederico Mora, Ankush Desai, Elizabeth Polgreen, Sanjit A. SeshiaOOPSLA 2023 · 7 citations
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl et al.ICSE 2025 · 1 citation
- An Empirical Study of Observability Limits in Advanced Software Supply Chain AttacksZhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley et al.CCS 2026 · 3 citations
- Scaling Verifiable Computation Using Efficient Set AccumulatorsAlex Ozdemir, Riad S. Wahby, Barry Whitehat, Dan BonehUSENIX Security 2020
