Архітектура передачі довіри в механізмах оновлення програмного забезпечення: концепція Update Trust Chain
Software update mechanisms have become one of the fundamental components of modern digital trust. Existing approaches to software update security primarily focus on protecting individual components of the update process, including digital signatures, software repositories, communication channels, software supply chains, and build environments. However, recent supply chain attacks have demonstrated that the compromise of trust often occurs not through breaking cryptographic primitives but through compromising the trust relationships between different stages of the software lifecycle. This paper proposes the Update Trust Chain (UTC) concept, which models the software update process as a continuous trust propagation architecture extending from source code development to software installation on the target system. Unlike existing approaches that evaluate individual security mechanisms independently, the proposed model considers the entire update process as a unified trust architecture in which each stage inherits and propagates trust to subsequent stages. To support formal analysis, the Update Trust Chain is represented as a directed trust graph, and the notion of Kleptographic Surface (KS) is introduced to identify critical architectural elements whose compromise may result in cascading trust propagation throughout the update lifecycle. The proposed approach is validated through the analysis of well-known software supply chain incidents, including SolarWinds Orion, M.E.Doc (NotPetya), CCleaner, ASUS Live Update (ShadowHammer), 3CX Desktop App, and XZ Utils. The results demonstrate that these incidents can be interpreted as different manifestations of compromises within the same trust propagation architecture rather than isolated failures of individual security mechanisms. The proposed concepts establish a foundation for architectural trust analysis of software update mechanisms and provide a basis for future quantitative trust assessment and secure software update architecture design.
Authors
- Тарас Петренко
- Алла Гребенник
- Михайло Шелест
Publication Details
- Journal
- The Scientific Issues of Ternopil Volodymyr Hnatiuk National Pedagogical University Series pedagogy
- Published
- 2026-09-21
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00