CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified Builds
Kirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Justin Cappos, Bryan Ford
摘要
Software-update mechanisms are critical to the security of modern systems, but their typically centralized design presents a lucrative and frequently attacked target. In this work, we propose CHAINIAC, a decentralized softwareupdate framework that eliminates single points of failure, enforces transparency, and provides efficient verifiability of integrity and authenticity for software-release processes. Independent witness servers collectively verify conformance of software updates to release policies, build verifiers validate the source-to-binary correspondence, and a tamper-proof release log stores collectively signed updates, thus ensuring that no release is accepted by clients before being widely disclosed and validated. The release log embodies a skipchain, a novel data structure, enabling arbitrarily out-of-date clients to efficiently validate updates and signing keys. Evaluation of our CHAINIAC prototype on reproducible Debian packages shows that the automated update process takes the average of 5 minutes per release for individual packages, and only 20 seconds for the aggregate timeline. We further evaluate the framework using real-world data from the PyPI package repository and show that it offers clients security comparable to verifying every single update themselves while consuming only one-fifth of the bandwidth and having a minimal computational overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper21
- OmniLedger: A Secure, Scale-Out, Decentralized Ledger via ShardingEleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly 等S&P 2018 · 被引用 1,145 次
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz 等S&P 2019 · 被引用 126 次
- Transparency Logs via Append-Only Authenticated DictionariesAlin Tomescu, Vivek Bhupatiraju, Dimitrios Papadopoulos, Charalampos Papamanthou 等CCS 2019 · 被引用 69 次
- Vault: Fast Bootstrapping for the Algorand CryptocurrencyDerek Leung, Adam Suhl, Yossi Gilad, Nickolai ZeldovichNDSS 2019 · 被引用 53 次
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang 等S&P 2021 · 被引用 51 次
它引用的顶会 Paper5
- Enhancing Bitcoin Security and Performance with Strong Consistency via Collective SigningEleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Ismail Khoffi 等USENIX Security 2016 · 被引用 769 次
- Scalable Bias-Resistant Distributed RandomnessEwa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly 等S&P 2017 · 被引用 327 次
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky 等S&P 2016 · 被引用 285 次
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 被引用 100 次
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 被引用 33 次
相关 Paper
- Catena: Efficient Non-equivocation via BitcoinAlin Tomescu, Srinivas DevadasS&P 2017 · 被引用 144 次
- Message Chains for Distributed System VerificationFederico Mora, Ankush Desai, Elizabeth Polgreen, Sanjit A. SeshiaOOPSLA 2023 · 被引用 7 次
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl 等ICSE 2025 · 被引用 1 次
- An Empirical Study of Observability Limits in Advanced Software Supply Chain AttacksZhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley 等CCS 2026 · 被引用 3 次
- Scaling Verifiable Computation Using Efficient Set AccumulatorsAlex Ozdemir, Riad S. Wahby, Barry Whitehat, Dan BonehUSENIX Security 2020
