2021/06/17 by Marcela S. Melara, Melara, Marcela S., Mic Bowman +1 · 1 citation
Computer Science · Decision Sciences · #Cloud Computing and Resource Management #Cloud Data Security Solutions #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Scientific Computing and Data Management #Security and Verification in Computing
paper · pdf · doi:10.48550/arxiv.2106.09843
openalex publication_date 2021/06/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Deployed microservices must adhere to a multitude of application-level\nsecurity requirements and regulatory constraints imposed by mutually\ndistrusting application principals--software developers, cloud providers, and\neven data owners. Although these principals wish to enforce their individual\nsecurity requirements, they do not currently have a common way of easily\nidentifying, expressing and automatically enforcing these requirements at\ndeployment time. CDI (Code Deployment Integrity) is a security policy framework\nthat enables distributed application principals to establish trust in deployed\ncode through high-integrity provenance information. We observe that principals\nexpect the software supply chain to preserve certain code security properties\nthroughout the creation of an executable bundle, even if the code is\ntransformed or inspected through various tools (e.g., compilation inserts stack\ncanaries for memory safety). Our key insight in designing CDI is that even if\napplication principals do not trust each other directly, they can trust a\nmicroservice bundle to meet their security policies if they can trust the tools\ninvolved in creating the bundle.\n