Digital Repository

CredentialLog, A Transparency Log to Store the Signed Credentials of Artefacts

Show simple item record

dc.contributor.author Kurukulasuriya, Miran
dc.date.accessioned 2025-06-12T05:27:50Z
dc.date.available 2025-06-12T05:27:50Z
dc.date.issued 2024
dc.identifier.citation Kurukulasuriya, Miran (2024) CredentialLog, A Transparency Log to Store the Signed Credentials of Artefacts. BSc. Dissertation, Informatics Institute of Technology en_US
dc.identifier.issn 20200897
dc.identifier.uri http://dlib.iit.ac.lk/xmlui/handle/123456789/2519
dc.description.abstract This project offers a novel strategy to support software supply chain security systems in response to the growing concerns about software supply chain security. The main novelty is the use of a transparent log based on Merkle trees that is intended just to store credentials for artefact signatures. The transparent log promotes transparency and accountability in the credential management process by acting as an auditable, publicly accessible record. In addition to meeting the demand for more security, this transparency makes it easier for end users to verify information. The project seeks to strengthen user confidence in the software supply chain by making it simple for users to track and confirm the authenticity and provenance of software artefacts via the transparent log. The system's capabilities are further enhanced by the emphasis on artefact signature credentials. This involves recording distinct characteristics and cryptographic signatures linked to every artefact, providing a more detailed and customised method for managing credentials. Due to users' ability to rapidly determine the authenticity of individual artefacts, this specificity improves security while simultaneously streamlining the verification process. Effective and safe data verification is ensured by the transparent log's structure, which makes use of Merkle trees. Merkle trees' hierarchical structure makes it possible to quickly identify any credential tampering or irregularities. This cryptographic foundation enhances the system's efficiency and scalability while simultaneously bolstering its integrity. This project aims to promote broader use of Software Supply Chain Security Systems by developing an intuitive and safe approach that combines the efficiency of Merkle trees, specificity of artefact signature credentials, and transparency of logs. The ultimate goal is to simplify the verification process for end users and offer a strong defence against potential security risks throughout the software development lifecycle. This will help to build confidence and trust in the larger software supply chain ecosystem. en_US
dc.language.iso en en_US
dc.subject Digital Signatures en_US
dc.subject Transparency en_US
dc.subject Verification en_US
dc.title CredentialLog, A Transparency Log to Store the Signed Credentials of Artefacts en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search


Advanced Search

Browse

My Account