zk-Sigstore: System for Anonymous Certificate-Based Software Signing
Name
merrill-kmerrill-meng-eecs-2023-thesis.pdf
Description
Thesis PDF
Size
6.35 MB
Format
Adobe PDF
Checksum (MD5)
15e1ad32ff158c1e5b190329f5a34e9f
Author(s)
Merrill, Kelsey
Advisor(s)
Sollins, Karen R.
Date Issued
June 2023
Publisher
Massachusetts Institute of Technology
Abstract
Most software developers get their software dependencies from online repositories, allowing for greater efficiency during the development process. However, downloading software from the internet comes with security concerns, and issues with open source software security have led to several high-profile attacks. In order to combat the problem, many repositories have implemented digital signatures for packages to verify the contributor’s identity, but with limited success due to well-documented usability issues surrounding key management. The digital signature primitive itself also does not provide an answer to which signers have the authority to sign which artifact. Proposals like Sigstore aimed at fixing the usability problems with digital signatures come with privacy concerns that have limited uptake, and though they provide some answers to the signing authority question, these come with scalability, verifiability, and privacy concerns.
This thesis presents zk-Sigstore, a system for usable (certificate-based) and anonymous digital signatures for software. zk-Sigstore is a certificate-based signature system, but instead of publishing identities in the clear, identities are obfuscated with a cryptographic commitment. Techniques from key transparency verifiable key directories inform a scalable, verifiable, and private authorization record for mapping digital artifacts to the maintainers with the authority to sign them.
Using zk-Sigstore for software signing, signing and verifying times are on the order of hundreds of microseconds even for the largest of software repositories, and deployment of zk-Sigstore requires minimal changes to existing infrastructure, making it a practical solution to this real-world problem.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Attribution-NonCommercial 4.0 International (CC BY-NC 4.0)
Copyright retained by author(s)
Persistent DSpace Link