Архітектура передачі довіри в механізмах оновлення програмного забезпечення: концепція Update Trust Chain

Software update mechanisms have become one of the fundamental components of modern digital trust. Existing approaches to software update security primarily focus on protecting individual components of the update process, including digital signatures, software repositories, communication channels, software supply chains, and build environments. However, recent supply chain attacks have demonstrated that the compromise of trust often occurs not through breaking cryptographic primitives but through compromising the trust relationships between different stages of the software lifecycle. This paper proposes the Update Trust Chain (UTC) concept, which models the software update process as a continuous trust propagation architecture extending from source code development to software installation on the target system. Unlike existing approaches that evaluate individual security mechanisms independently, the proposed model considers the entire update process as a unified trust architecture in which each stage inherits and propagates trust to subsequent stages. To support formal analysis, the Update Trust Chain is represented as a directed trust graph, and the notion of Kleptographic Surface (KS) is introduced to identify critical architectural elements whose compromise may result in cascading trust propagation throughout the update lifecycle. The proposed approach is validated through the analysis of well-known software supply chain incidents, including SolarWinds Orion, M.E.Doc (NotPetya), CCleaner, ASUS Live Update (ShadowHammer), 3CX Desktop App, and XZ Utils. The results demonstrate that these incidents can be interpreted as different manifestations of compromises within the same trust propagation architecture rather than isolated failures of individual security mechanisms. The proposed concepts establish a foundation for architectural trust analysis of software update mechanisms and provide a basis for future quantitative trust assessment and secure software update architecture design.

Authors

Publication Details

Journal
The Scientific Issues of Ternopil Volodymyr Hnatiuk National Pedagogical University Series pedagogy
Published
2026-09-21
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Архітектура передачі довіри в механізмах оновлення програмного забезпечення: концепція Update Trust Chain

Тарас Петренко, Алла Гребенник, Михайло Шелест
The Scientific Issues of Ternopil Volodymyr Hnatiuk National Pedagogical University Series pedagogy
Security and Verification in Computing
article

Архітектура передачі довіри в механізмах оновлення програмного забезпечення: концепція Update Trust Chain

Тарас Петренко, Алла Гребенник, Михайло Шелест
article en

Abstract

Software update mechanisms have become one of the fundamental components of modern digital trust. Existing approaches to software update security primarily focus on protecting individual components of the update process, including digital signatures, software repositories, communication channels, software supply chains, and build environments. However, recent supply chain attacks have demonstrated that the compromise of trust often occurs not through breaking cryptographic primitives but through compromising the trust relationships between different stages of the software lifecycle. This paper proposes the Update Trust Chain (UTC) concept, which models the software update process as a continuous trust propagation architecture extending from source code development to software installation on the target system. Unlike existing approaches that evaluate individual security mechanisms independently, the proposed model considers the entire update process as a unified trust architecture in which each stage inherits and propagates trust to subsequent stages. To support formal analysis, the Update Trust Chain is represented as a directed trust graph, and the notion of Kleptographic Surface (KS) is introduced to identify critical architectural elements whose compromise may result in cascading trust propagation throughout the update lifecycle. The proposed approach is validated through the analysis of well-known software supply chain incidents, including SolarWinds Orion, M.E.Doc (NotPetya), CCleaner, ASUS Live Update (ShadowHammer), 3CX Desktop App, and XZ Utils. The results demonstrate that these incidents can be interpreted as different manifestations of compromises within the same trust propagation architecture rather than isolated failures of individual security mechanisms. The proposed concepts establish a foundation for architectural trust analysis of software update mechanisms and provide a basis for future quantitative trust assessment and secure software update architecture design.

The Scientific Issues of Ternopil Volodymyr Hnatiuk National Pedagogical University Series pedagogy
Openalex Percentile: Top 8%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Архітектура передачі довіри в механізмах оновлення програмного забезпечення: концепція Update Trust Chain — Тарас Петренко, Алла Гребенник, et al. · The Scientific Issues of Ternopil Volodymyr Hnatiuk National Pedagogical University Series pedagogy (2026) | TGRS Research Map | TGRS