4 papers
Trustworthy and Confidential SBOM Exchange
Eman Abu Ishgair, Chinenye Okafor, Marcela S. Melara +1
Software Bills of Materials (SBOMs) have become a regulatory requirement for improving software supply chain security and trust by means of transparency regarding components that m…
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
Chinenye Okafor, James C. Davis, Santiago Torres-Arias
Identity-based code signing enables software developers to digitally sign their code using cryptographic keys. This key is then linked to an identity (e.g., through an identity pro…
An Industry Interview Study of Software Signing for Supply Chain Security
Kelechi G. Kalu, Tanya Singla, Chinenye Okafor +2
Many software products are composed of components integrated from other teams or external parties. Each additional link in a software product's supply chain increases the risk of t…
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
Chinenye Okafor, Taylor R. Schorlemmer, Santiago Torres-Arias +1
This paper systematizes knowledge about secure software supply chain patterns. It identifies four stages of a software supply chain attack and proposes three security properties cr…