diff options
| author | Stefan Schumacher <public@cryptomancer.de> | 2026-05-05 17:53:09 +0200 |
|---|---|---|
| committer | Stefan Schumacher <public@cryptomancer.de> | 2026-05-05 17:53:09 +0200 |
| commit | dc79114e67cf4343d21152c52af1b936b581755e (patch) | |
| tree | 3ae1fee65b915ca36e60f8822c22caeb4b1058ea | |
| parent | 6c779fd161e8d2957dfec041139d45c4ecc86697 (diff) | |
Pages Versionpages
| -rw-r--r-- | PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc | 41 | ||||
| -rw-r--r-- | PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html | 72 | ||||
| -rw-r--r-- | PlantUML-ModelingTrust/GnuPG-WoT-Download/README.pdf | bin | 500848 -> 513735 bytes | |||
| -rw-r--r-- | PlantUML-ModelingTrust/README.html | 615 | ||||
| -rw-r--r-- | PlantUML-ModelingTrust/README.pdf | bin | 162571 -> 189302 bytes | |||
| -rw-r--r-- | README.adoc | 29 | ||||
| -rw-r--r-- | README.html | 234 | ||||
| -rw-r--r-- | README.pdf | bin | 0 -> 518556 bytes | |||
| -rw-r--r-- | index.html | 234 |
9 files changed, 1199 insertions, 26 deletions
diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc index 7fa6b8b..fb7b965 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc @@ -1,8 +1,12 @@ -= PLantUML Diagrams for GnuPG Key Signing += PLantUML Diagrams for GnuPG Key Signing and Reproducible Builds (SLSA4) 0.0.2 :pdf-page-size: A3 :pdf-page-layout: landscape + + +// tag::inhalt[] + I am trying to model implicit and explicit trust in Zero Trust Architecture diagrams for Threat Modeling. So I need to bring together the Blue Team/White Hat perspective and the Red Team/Black Hat stuff. @@ -32,7 +36,9 @@ image::300-NetBSD-RelEng-STRIDE.png[] == Supply-chain Levels for Software Artifacts -A simple threat model for SLSA Level 1 and Leve 4 build and distribution pipelines. +=== SLSA L1 + +A simple threat model for SLSA Level 1: image::200-ThreatModel-SLSA1-DownloadSig.png[] @@ -40,7 +46,33 @@ image::200-ThreatModel-SLSA1-DownloadSig.png[] === Reproducible Builds SLSA L4 -Modeling Trust, Trust Anchors and Boundaries and Attack Vectors +Modeling Trust, Trust Anchors and Boundaries and Attack Vectors for SLSA4: + +The whole process draws heavy inspiration from those implemented by NetBSD, Debian, NixOS and the Tor Browser! + + +. general goals +.. Build process produces identical artefacts (bit-for-bit) from the same source and inputs +.. independent parties can rebuild and verify outputs match the original -> verify freedom from insider threat! +.. require a deterministic build environments +.. all build steps, dependencies, and tooling are tightly controlled and audited +. security goals: +.. detect tampering in build pipelines or artefacts +.. prevents hidden backdoors introduced during compilation or packaging by a malicious insider +.. ensure integrity of supply chain, dependencies and build tools +.. enables independent verification without trusting the original builder +.. drastrically reduce insider and supply chain attack surface +. Zero Trust: +.. never trust, always verify! +.. verifiable evidence (rebuild && compare) +.. eliminates implicit trust in build pipeline +.. build system considered untrustworthy +.. combine with signed artefacts and attestation frameworks for full supply chain integrity + + + + + ==== The whole implementation @@ -58,3 +90,6 @@ image::202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png[] === Motivation/Business Layer: Risk/Security Overlay image::203-SLSA4-ReproducibleBuilds-L1-Motivation.png[] + + +// end::inhalt[] diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html index 5bc2456..712e918 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html @@ -6,7 +6,7 @@ <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta name="generator" content="Asciidoctor 2.0.26"> <meta name="author" content="0.0.2"> -<title>PLantUML Diagrams for GnuPG Key Signing</title> +<title>PLantUML Diagrams for GnuPG Key Signing and Reproducible Builds (SLSA4)</title> <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open+Sans:300,300italic,400,400italic,600,600italic%7CNoto+Serif:400,400italic,700,700italic%7CDroid+Sans+Mono:400,700"> <style> /*! Asciidoctor default stylesheet | MIT License | https://asciidoctor.org */ @@ -437,7 +437,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </head> <body class="article toc2 toc-left"> <div id="header"> -<h1>PLantUML Diagrams for GnuPG Key Signing</h1> +<h1>PLantUML Diagrams for GnuPG Key Signing and Reproducible Builds (SLSA4)</h1> <div class="details"> <span id="author" class="author">0.0.2</span><br> </div> @@ -520,7 +520,71 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b <div class="sect2"> <h3 id="_reproducible_builds_slsa_l4">Reproducible Builds SLSA L4</h3> <div class="paragraph"> -<p>Modeling Trust, Trust Anchors and Boundaries and Attack Vectors</p> +<p>Modeling Trust, Trust Anchors and Boundaries and Attack Vectors for SLSA4:</p> +</div> +<div class="paragraph"> +<p>The whole process draws heavy inspiration from those implemented by NetBSD, Debian, NixOS and the Tor Browser!</p> +</div> +<div class="olist loweralpha"> +<div class="title">Goals:</div> +<ol class="loweralpha" type="a"> +<li> +<p>Build process produces identical artefacts (bit-for-bit) from the same source and inputs</p> +</li> +<li> +<p>independent parties can rebuild and verify outputs match the original → verify freedom from insider threat!</p> +</li> +<li> +<p>require a deterministic build environments</p> +</li> +<li> +<p>all build steps, dependencies, and tooling are tightly controlled and audited</p> +<div class="olist arabic"> +<ol class="arabic"> +<li> +<p>security goals:</p> +</li> +</ol> +</div> +</li> +<li> +<p>detect tampering in build pipelines or artefacts</p> +</li> +<li> +<p>prevents hidden backdoors introduced during compilation or packaging by a malicious insider</p> +</li> +<li> +<p>ensure integrity of supply chain, dependencies and build tools</p> +</li> +<li> +<p>enables independent verification without trusting the original builder</p> +</li> +<li> +<p>drastrically reduce insider and supply chain attack surface</p> +<div class="olist arabic"> +<ol class="arabic"> +<li> +<p>Zero Trust:</p> +</li> +</ol> +</div> +</li> +<li> +<p>never trust, always verify!</p> +</li> +<li> +<p>verifiable evidence (rebuild && compare)</p> +</li> +<li> +<p>eliminates implicit trust in build pipeline</p> +</li> +<li> +<p>build system considered untrustworthy</p> +</li> +<li> +<p>combine with signed artefacts and attestation frameworks for full supply chain integrity</p> +</li> +</ol> </div> <div class="sect3"> <h4 id="_the_whole_implementation">The whole implementation</h4> @@ -566,7 +630,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </div> <div id="footer"> <div id="footer-text"> -Last updated 2026-03-14 18:58:41 +0100 +Last updated 2026-05-05 17:43:18 +0200 </div> </div> </body> diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.pdf b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.pdf Binary files differindex 0e84285..fd9c3b0 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.pdf +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.pdf diff --git a/PlantUML-ModelingTrust/README.html b/PlantUML-ModelingTrust/README.html new file mode 100644 index 0000000..65e234e --- /dev/null +++ b/PlantUML-ModelingTrust/README.html @@ -0,0 +1,615 @@ +<!DOCTYPE html> +<html lang="en"> +<head> +<meta charset="UTF-8"> +<meta http-equiv="X-UA-Compatible" content="IE=edge"> +<meta name="viewport" content="width=device-width, initial-scale=1.0"> +<meta name="generator" content="Asciidoctor 2.0.26"> +<meta name="author" content="0.0.2"> +<title>Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate</title> +<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open+Sans:300,300italic,400,400italic,600,600italic%7CNoto+Serif:400,400italic,700,700italic%7CDroid+Sans+Mono:400,700"> +<style> +/*! Asciidoctor default stylesheet | MIT License | https://asciidoctor.org */ +/* Uncomment the following line when using as a custom stylesheet */ +/* @import "https://fonts.googleapis.com/css?family=Open+Sans:300,300italic,400,400italic,600,600italic%7CNoto+Serif:400,400italic,700,700italic%7CDroid+Sans+Mono:400,700"; */ +html{font-family:sans-serif;-webkit-text-size-adjust:100%} +a{background:none} +a:focus{outline:thin dotted} +a:active,a:hover{outline:0} +h1{font-size:2em;margin:.67em 0} +b,strong{font-weight:bold} +abbr{font-size:.9em} +abbr[title]{cursor:help;border-bottom:1px dotted #dddddf;text-decoration:none} +dfn{font-style:italic} +hr{height:0} +mark{background:#ff0;color:#000} +code,kbd,pre,samp{font-family:monospace;font-size:1em} +pre{white-space:pre-wrap} +q{quotes:"\201C" "\201D" "\2018" "\2019"} +small{font-size:80%} +sub,sup{font-size:75%;line-height:0;position:relative;vertical-align:baseline} +sup{top:-.5em} +sub{bottom:-.25em} +img{border:0} +svg:not(:root){overflow:hidden} +figure{margin:0} +audio,video{display:inline-block} +audio:not([controls]){display:none;height:0} +fieldset{border:1px solid silver;margin:0 2px;padding:.35em .625em .75em} +legend{border:0;padding:0} +button,input,select,textarea{font-family:inherit;font-size:100%;margin:0} +button,input{line-height:normal} +button,select{text-transform:none} +button,html input[type=button],input[type=reset],input[type=submit]{-webkit-appearance:button;cursor:pointer} +button[disabled],html input[disabled]{cursor:default} +input[type=checkbox],input[type=radio]{padding:0} +button::-moz-focus-inner,input::-moz-focus-inner{border:0;padding:0} +textarea{overflow:auto;vertical-align:top} +table{border-collapse:collapse;border-spacing:0} +*,::before,::after{box-sizing:border-box} +html,body{font-size:100%} +body{background:#fff;color:rgba(0,0,0,.8);padding:0;margin:0;font-family:"Noto Serif","DejaVu Serif",serif;line-height:1;position:relative;cursor:auto;-moz-tab-size:4;-o-tab-size:4;tab-size:4;word-wrap:anywhere;-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased} +a:hover{cursor:pointer} +img,object,embed{max-width:100%;height:auto} +object,embed{height:100%} +img{-ms-interpolation-mode:bicubic} +.left{float:left!important} +.right{float:right!important} +.text-left{text-align:left!important} +.text-right{text-align:right!important} +.text-center{text-align:center!important} +.text-justify{text-align:justify!important} +.hide{display:none} +img,object,svg{display:inline-block;vertical-align:middle} +textarea{height:auto;min-height:50px} +select{width:100%} +.subheader,.admonitionblock td.content>.title,.audioblock>.title,.exampleblock>.title,.imageblock>.title,.listingblock>.title,.literalblock>.title,.stemblock>.title,.openblock>.title,.paragraph>.title,.quoteblock>.title,table.tableblock>.title,.verseblock>.title,.videoblock>.title,.dlist>.title,.olist>.title,.ulist>.title,.qlist>.title,.hdlist>.title{line-height:1.45;color:#7a2518;font-weight:400;margin-top:0;margin-bottom:.25em} +div,dl,dt,dd,ul,ol,li,h1,h2,h3,#toctitle,.sidebarblock>.content>.title,h4,h5,h6,pre,form,p,blockquote,th,td{margin:0;padding:0} +a{color:#2156a5;text-decoration:underline;line-height:inherit} +a:hover,a:focus{color:#1d4b8f} +a img{border:0} +p{line-height:1.6;margin-bottom:1.25em;text-rendering:optimizeLegibility} +p aside{font-size:.875em;line-height:1.35;font-style:italic} +h1,h2,h3,#toctitle,.sidebarblock>.content>.title,h4,h5,h6{font-family:"Open Sans","DejaVu Sans",sans-serif;font-weight:300;font-style:normal;color:#ba3925;text-rendering:optimizeLegibility;margin-top:1em;margin-bottom:.5em;line-height:1.0125em} +h1 small,h2 small,h3 small,#toctitle small,.sidebarblock>.content>.title small,h4 small,h5 small,h6 small{font-size:60%;color:#e99b8f;line-height:0} +h1{font-size:2.125em} +h2{font-size:1.6875em} +h3,#toctitle,.sidebarblock>.content>.title{font-size:1.375em} +h4,h5{font-size:1.125em} +h6{font-size:1em} +hr{border:solid #dddddf;border-width:1px 0 0;clear:both;margin:1.25em 0 1.1875em} +em,i{font-style:italic;line-height:inherit} +strong,b{font-weight:bold;line-height:inherit} +small{font-size:60%;line-height:inherit} +code{font-family:"Droid Sans Mono","DejaVu Sans Mono",monospace;font-weight:400;color:rgba(0,0,0,.9)} +ul,ol,dl{line-height:1.6;margin-bottom:1.25em;list-style-position:outside;font-family:inherit} +ul,ol{margin-left:1.5em} +ul li ul,ul li ol{margin-left:1.25em;margin-bottom:0} +ul.circle{list-style-type:circle} +ul.disc{list-style-type:disc} +ul.square{list-style-type:square} +ul.circle ul:not([class]),ul.disc ul:not([class]),ul.square ul:not([class]){list-style:inherit} +ol li ul,ol li ol{margin-left:1.25em;margin-bottom:0} +dl dt{margin-bottom:.3125em;font-weight:bold} +dl dd{margin-bottom:1.25em} +blockquote{margin:0 0 1.25em;padding:.5625em 1.25em 0 1.1875em;border-left:1px solid #ddd} +blockquote,blockquote p{line-height:1.6;color:rgba(0,0,0,.85)} +@media screen and (min-width:768px){h1,h2,h3,#toctitle,.sidebarblock>.content>.title,h4,h5,h6{line-height:1.2} +h1{font-size:2.75em} +h2{font-size:2.3125em} +h3,#toctitle,.sidebarblock>.content>.title{font-size:1.6875em} +h4{font-size:1.4375em}} +table{background:#fff;margin-bottom:1.25em;border:1px solid #dedede;word-wrap:normal} +table thead,table tfoot{background:#f7f8f7} +table thead tr th,table thead tr td,table tfoot tr th,table tfoot tr td{padding:.5em .625em .625em;font-size:inherit;color:rgba(0,0,0,.8);text-align:left} +table tr th,table tr td{padding:.5625em .625em;font-size:inherit;color:rgba(0,0,0,.8)} +table tr.even,table tr.alt{background:#f8f8f7} +table thead tr th,table tfoot tr th,table tbody tr td,table tr td,table tfoot tr td{line-height:1.6} +h1,h2,h3,#toctitle,.sidebarblock>.content>.title,h4,h5,h6{line-height:1.2;word-spacing:-.05em} +h1 strong,h2 strong,h3 strong,#toctitle strong,.sidebarblock>.content>.title strong,h4 strong,h5 strong,h6 strong{font-weight:400} +.center{margin-left:auto;margin-right:auto} +.stretch{width:100%} +.clearfix::before,.clearfix::after,.float-group::before,.float-group::after{content:" ";display:table} +.clearfix::after,.float-group::after{clear:both} +:not(pre).nobreak{word-wrap:normal} +:not(pre).nowrap{white-space:nowrap} +:not(pre).pre-wrap{white-space:pre-wrap} +:not(pre):not([class^=L])>code{font-size:.9375em;font-style:normal!important;letter-spacing:0;padding:.1em .5ex;word-spacing:-.15em;background:#f7f7f8;border-radius:4px;line-height:1.45;text-rendering:optimizeSpeed} +pre{color:rgba(0,0,0,.9);font-family:"Droid Sans Mono","DejaVu Sans Mono",monospace;line-height:1.45;text-rendering:optimizeSpeed} +pre code,pre pre{color:inherit;font-size:inherit;line-height:inherit} +pre.nowrap,pre.nowrap pre{white-space:pre;word-wrap:normal} +em em{font-style:normal} +strong strong{font-weight:400} +.keyseq{color:rgba(51,51,51,.8)} +kbd{font-family:"Droid Sans Mono","DejaVu Sans Mono",monospace;display:inline-block;color:rgba(0,0,0,.8);font-size:.65em;line-height:1.45;background:#f7f7f7;border:1px solid #ccc;border-radius:3px;box-shadow:0 1px 0 rgba(0,0,0,.2),inset 0 0 0 .1em #fff;margin:0 .15em;padding:.2em .5em;vertical-align:middle;position:relative;top:-.1em;white-space:nowrap} +.keyseq kbd:first-child{margin-left:0} +.keyseq kbd:last-child{margin-right:0} +.menuseq,.menuref{color:#000} +.menuseq b:not(.caret),.menuref{font-weight:inherit} +.menuseq{word-spacing:-.02em} +.menuseq b.caret{font-size:1.25em;line-height:.8} +.menuseq i.caret{font-weight:bold;text-align:center;width:.45em} +b.button::before,b.button::after{position:relative;top:-1px;font-weight:400} +b.button::before{content:"[";padding:0 3px 0 2px} +b.button::after{content:"]";padding:0 2px 0 3px} +p a>code:hover{color:rgba(0,0,0,.9)} +#header,#content,#footnotes,#footer{width:100%;margin:0 auto;max-width:62.5em;*zoom:1;position:relative;padding-left:.9375em;padding-right:.9375em} +#header::before,#header::after,#content::before,#content::after,#footnotes::before,#footnotes::after,#footer::before,#footer::after{content:" ";display:table} +#header::after,#content::after,#footnotes::after,#footer::after{clear:both} +#content{margin-top:1.25em} +#content::before{content:none} +#header>h1:first-child{color:rgba(0,0,0,.85);margin-top:2.25rem;margin-bottom:0} +#header>h1:first-child+#toc{margin-top:8px;border-top:1px solid #dddddf} +#header>h1:only-child{border-bottom:1px solid #dddddf;padding-bottom:8px} +#header .details{border-bottom:1px solid #dddddf;line-height:1.45;padding-top:.25em;padding-bottom:.25em;padding-left:.25em;color:rgba(0,0,0,.6);display:flex;flex-flow:row wrap} +#header .details span:first-child{margin-left:-.125em} +#header .details span.email a{color:rgba(0,0,0,.85)} +#header .details br{display:none} +#header .details br+span::before{content:"\00a0\2013\00a0"} +#header .details br+span.author::before{content:"\00a0\22c5\00a0";color:rgba(0,0,0,.85)} +#header .details br+span#revremark::before{content:"\00a0|\00a0"} +#header #revnumber{text-transform:capitalize} +#header #revnumber::after{content:"\00a0"} +#content>h1:first-child:not([class]){color:rgba(0,0,0,.85);border-bottom:1px solid #dddddf;padding-bottom:8px;margin-top:0;padding-top:1rem;margin-bottom:1.25rem} +#toc{border-bottom:1px solid #e7e7e9;padding-bottom:.5em} +#toc>ul{margin-left:.125em} +#toc ul.sectlevel0>li>a{font-style:italic} +#toc ul.sectlevel0 ul.sectlevel1{margin:.5em 0} +#toc ul{font-family:"Open Sans","DejaVu Sans",sans-serif;list-style-type:none} +#toc li{line-height:1.3334;margin-top:.3334em} +#toc a{text-decoration:none} +#toc a:active{text-decoration:underline} +#toctitle{color:#7a2518;font-size:1.2em} +@media screen and (min-width:768px){#toctitle{font-size:1.375em} +body.toc2{padding-left:15em;padding-right:0} +body.toc2 #header>h1:nth-last-child(2){border-bottom:1px solid #dddddf;padding-bottom:8px} +#toc.toc2{margin-top:0!important;background:#f8f8f7;position:fixed;width:15em;left:0;top:0;border-right:1px solid #e7e7e9;border-top-width:0!important;border-bottom-width:0!important;z-index:1000;padding:1.25em 1em;height:100%;overflow:auto} +#toc.toc2 #toctitle{margin-top:0;margin-bottom:.8rem;font-size:1.2em} +#toc.toc2>ul{font-size:.9em;margin-bottom:0} +#toc.toc2 ul ul{margin-left:0;padding-left:1em} +#toc.toc2 ul.sectlevel0 ul.sectlevel1{padding-left:0;margin-top:.5em;margin-bottom:.5em} +body.toc2.toc-right{padding-left:0;padding-right:15em} +body.toc2.toc-right #toc.toc2{border-right-width:0;border-left:1px solid #e7e7e9;left:auto;right:0}} +@media screen and (min-width:1280px){body.toc2{padding-left:20em;padding-right:0} +#toc.toc2{width:20em} +#toc.toc2 #toctitle{font-size:1.375em} +#toc.toc2>ul{font-size:.95em} +#toc.toc2 ul ul{padding-left:1.25em} +body.toc2.toc-right{padding-left:0;padding-right:20em}} +#content #toc{border:1px solid #e0e0dc;margin-bottom:1.25em;padding:1.25em;background:#f8f8f7;border-radius:4px} +#content #toc>:first-child{margin-top:0} +#content #toc>:last-child{margin-bottom:0} +#footer{max-width:none;background:rgba(0,0,0,.8);padding:1.25em} +#footer-text{color:hsla(0,0%,100%,.8);line-height:1.44} +#content{margin-bottom:.625em} +.sect1{padding-bottom:.625em} +@media screen and (min-width:768px){#content{margin-bottom:1.25em} +.sect1{padding-bottom:1.25em}} +.sect1:last-child{padding-bottom:0} +.sect1+.sect1{border-top:1px solid #e7e7e9} +#content h1>a.anchor,h2>a.anchor,h3>a.anchor,#toctitle>a.anchor,.sidebarblock>.content>.title>a.anchor,h4>a.anchor,h5>a.anchor,h6>a.anchor{position:absolute;z-index:1001;width:1.5ex;margin-left:-1.5ex;display:block;text-decoration:none!important;visibility:hidden;text-align:center;font-weight:400} +#content h1>a.anchor::before,h2>a.anchor::before,h3>a.anchor::before,#toctitle>a.anchor::before,.sidebarblock>.content>.title>a.anchor::before,h4>a.anchor::before,h5>a.anchor::before,h6>a.anchor::before{content:"\00A7";font-size:.85em;display:block;padding-top:.1em} +#content h1:hover>a.anchor,#content h1>a.anchor:hover,h2:hover>a.anchor,h2>a.anchor:hover,h3:hover>a.anchor,#toctitle:hover>a.anchor,.sidebarblock>.content>.title:hover>a.anchor,h3>a.anchor:hover,#toctitle>a.anchor:hover,.sidebarblock>.content>.title>a.anchor:hover,h4:hover>a.anchor,h4>a.anchor:hover,h5:hover>a.anchor,h5>a.anchor:hover,h6:hover>a.anchor,h6>a.anchor:hover{visibility:visible} +#content h1>a.link,h2>a.link,h3>a.link,#toctitle>a.link,.sidebarblock>.content>.title>a.link,h4>a.link,h5>a.link,h6>a.link{color:#ba3925;text-decoration:none} +#content h1>a.link:hover,h2>a.link:hover,h3>a.link:hover,#toctitle>a.link:hover,.sidebarblock>.content>.title>a.link:hover,h4>a.link:hover,h5>a.link:hover,h6>a.link:hover{color:#a53221} +details,.audioblock,.imageblock,.literalblock,.listingblock,.stemblock,.videoblock{margin-bottom:1.25em} +details{margin-left:1.25rem} +details>summary{cursor:pointer;display:block;position:relative;line-height:1.6;margin-bottom:.625rem;outline:none;-webkit-tap-highlight-color:transparent} +details>summary::-webkit-details-marker{display:none} +details>summary::before{content:"";border:solid transparent;border-left:solid;border-width:.3em 0 .3em .5em;position:absolute;top:.5em;left:-1.25rem;transform:translateX(15%)} +details[open]>summary::before{border:solid transparent;border-top:solid;border-width:.5em .3em 0;transform:translateY(15%)} +details>summary::after{content:"";width:1.25rem;height:1em;position:absolute;top:.3em;left:-1.25rem} +.admonitionblock td.content>.title,.audioblock>.title,.exampleblock>.title,.imageblock>.title,.listingblock>.title,.literalblock>.title,.stemblock>.title,.openblock>.title,.paragraph>.title,.quoteblock>.title,table.tableblock>.title,.verseblock>.title,.videoblock>.title,.dlist>.title,.olist>.title,.ulist>.title,.qlist>.title,.hdlist>.title{text-rendering:optimizeLegibility;text-align:left;font-family:"Noto Serif","DejaVu Serif",serif;font-size:1rem;font-style:italic} +table.tableblock.fit-content>caption.title{white-space:nowrap;width:0} +.paragraph.lead>p,#preamble>.sectionbody>[class=paragraph]:first-of-type p{font-size:1.21875em;line-height:1.6;color:rgba(0,0,0,.85)} +.admonitionblock>table{border-collapse:separate;border:0;background:none;width:100%} +.admonitionblock>table td.icon{text-align:center;width:80px} +.admonitionblock>table td.icon img{max-width:none} +.admonitionblock>table td.icon .title{font-weight:bold;font-family:"Open Sans","DejaVu Sans",sans-serif;text-transform:uppercase} +.admonitionblock>table td.content{padding-left:1.125em;padding-right:1.25em;border-left:1px solid #dddddf;color:rgba(0,0,0,.6);word-wrap:anywhere} +.admonitionblock>table td.content>:last-child>:last-child{margin-bottom:0} +.exampleblock>.content{border:1px solid #e6e6e6;margin-bottom:1.25em;padding:1.25em;background:#fff;border-radius:4px} +.sidebarblock{border:1px solid #dbdbd6;margin-bottom:1.25em;padding:1.25em;background:#f3f3f2;border-radius:4px} +.sidebarblock>.content>.title{color:#7a2518;margin-top:0;text-align:center} +.exampleblock>.content>:first-child,.sidebarblock>.content>:first-child{margin-top:0} +.exampleblock>.content>:last-child,.exampleblock>.content>:last-child>:last-child,.exampleblock>.content .olist>ol>li:last-child>:last-child,.exampleblock>.content .ulist>ul>li:last-child>:last-child,.exampleblock>.content .qlist>ol>li:last-child>:last-child,.sidebarblock>.content>:last-child,.sidebarblock>.content>:last-child>:last-child,.sidebarblock>.content .olist>ol>li:last-child>:last-child,.sidebarblock>.content .ulist>ul>li:last-child>:last-child,.sidebarblock>.content .qlist>ol>li:last-child>:last-child{margin-bottom:0} +.literalblock pre,.listingblock>.content>pre{border-radius:4px;overflow-x:auto;padding:1em;font-size:.8125em} +@media screen and (min-width:768px){.literalblock pre,.listingblock>.content>pre{font-size:.90625em}} +@media screen and (min-width:1280px){.literalblock pre,.listingblock>.content>pre{font-size:1em}} +.literalblock pre,.listingblock>.content>pre:not(.highlight),.listingblock>.content>pre[class=highlight],.listingblock>.content>pre[class^="highlight "]{background:#f7f7f8} +.literalblock.output pre{color:#f7f7f8;background:rgba(0,0,0,.9)} +.listingblock>.content{position:relative} +.listingblock pre>code{display:block} +.listingblock code[data-lang]::before{display:none;content:attr(data-lang);position:absolute;font-size:.75em;top:.425rem;right:.5rem;line-height:1;text-transform:uppercase;color:inherit;opacity:.5} +.listingblock:hover code[data-lang]::before{display:block} +.listingblock.terminal pre .command::before{content:attr(data-prompt);padding-right:.5em;color:inherit;opacity:.5} +.listingblock.terminal pre .command:not([data-prompt])::before{content:"$"} +.listingblock pre.highlightjs{padding:0} +.listingblock pre.highlightjs>code{padding:1em;border-radius:4px} +.listingblock pre.prettyprint{border-width:0} +.prettyprint{background:#f7f7f8} +pre.prettyprint .linenums{line-height:1.45;margin-left:2em} +pre.prettyprint li{background:none;list-style-type:inherit;padding-left:0} +pre.prettyprint li code[data-lang]::before{opacity:1} +pre.prettyprint li:not(:first-child) code[data-lang]::before{display:none} +table.linenotable{border-collapse:separate;border:0;margin-bottom:0;background:none} +table.linenotable td[class]{color:inherit;vertical-align:top;padding:0;line-height:inherit;white-space:normal} +table.linenotable td.code{padding-left:.75em} +table.linenotable td.linenos,pre.pygments .linenos{border-right:1px solid;opacity:.35;padding-right:.5em;-webkit-user-select:none;-moz-user-select:none;-ms-user-select:none;user-select:none} +pre.pygments span.linenos{display:inline-block;margin-right:.75em} +.quoteblock{margin:0 1em 1.25em 1.5em;display:table} +.quoteblock:not(.excerpt)>.title{margin-left:-1.5em;margin-bottom:.75em} +.quoteblock blockquote,.quoteblock p{color:rgba(0,0,0,.85);font-size:1.15rem;line-height:1.75;word-spacing:.1em;letter-spacing:0;font-style:italic;text-align:justify} +.quoteblock blockquote{margin:0;padding:0;border:0} +.quoteblock blockquote::before{content:"\201c";float:left;font-size:2.75em;font-weight:bold;line-height:.6em;margin-left:-.6em;color:#7a2518;text-shadow:0 1px 2px rgba(0,0,0,.1)} +.quoteblock blockquote>.paragraph:last-child p{margin-bottom:0} +.quoteblock .attribution{margin-top:.75em;margin-right:.5ex;text-align:right} +.verseblock{margin:0 1em 1.25em} +.verseblock pre{font-family:"Open Sans","DejaVu Sans",sans-serif;font-size:1.15rem;color:rgba(0,0,0,.85);font-weight:300;text-rendering:optimizeLegibility} +.verseblock pre strong{font-weight:400} +.verseblock .attribution{margin-top:1.25rem;margin-left:.5ex} +.quoteblock .attribution,.verseblock .attribution{font-size:.9375em;line-height:1.45;font-style:italic} +.quoteblock .attribution br,.verseblock .attribution br{display:none} +.quoteblock .attribution cite,.verseblock .attribution cite{display:block;letter-spacing:-.025em;color:rgba(0,0,0,.6)} +.quoteblock.abstract blockquote::before,.quoteblock.excerpt blockquote::before,.quoteblock .quoteblock blockquote::before{display:none} +.quoteblock.abstract blockquote,.quoteblock.abstract p,.quoteblock.excerpt blockquote,.quoteblock.excerpt p,.quoteblock .quoteblock blockquote,.quoteblock .quoteblock p{line-height:1.6;word-spacing:0} +.quoteblock.abstract{margin:0 1em 1.25em;display:block} +.quoteblock.abstract>.title{margin:0 0 .375em;font-size:1.15em;text-align:center} +.quoteblock.excerpt>blockquote,.quoteblock .quoteblock{padding:0 0 .25em 1em;border-left:.25em solid #dddddf} +.quoteblock.excerpt,.quoteblock .quoteblock{margin-left:0} +.quoteblock.excerpt blockquote,.quoteblock.excerpt p,.quoteblock .quoteblock blockquote,.quoteblock .quoteblock p{color:inherit;font-size:1.0625rem} +.quoteblock.excerpt .attribution,.quoteblock .quoteblock .attribution{color:inherit;font-size:.85rem;text-align:left;margin-right:0} +p.tableblock:last-child{margin-bottom:0} +td.tableblock>.content{margin-bottom:1.25em;word-wrap:anywhere} +td.tableblock>.content>:last-child{margin-bottom:-1.25em} +table.tableblock,th.tableblock,td.tableblock{border:0 solid #dedede} +table.grid-all>*>tr>*{border-width:1px} +table.grid-cols>*>tr>*{border-width:0 1px} +table.grid-rows>*>tr>*{border-width:1px 0} +table.frame-all{border-width:1px} +table.frame-ends{border-width:1px 0} +table.frame-sides{border-width:0 1px} +table.frame-none>colgroup+*>:first-child>*,table.frame-sides>colgroup+*>:first-child>*{border-top-width:0} +table.frame-none>:last-child>:last-child>*,table.frame-sides>:last-child>:last-child>*{border-bottom-width:0} +table.frame-none>*>tr>:first-child,table.frame-ends>*>tr>:first-child{border-left-width:0} +table.frame-none>*>tr>:last-child,table.frame-ends>*>tr>:last-child{border-right-width:0} +table.stripes-all>*>tr,table.stripes-odd>*>tr:nth-of-type(odd),table.stripes-even>*>tr:nth-of-type(even),table.stripes-hover>*>tr:hover{background:#f8f8f7} +th.halign-left,td.halign-left{text-align:left} +th.halign-right,td.halign-right{text-align:right} +th.halign-center,td.halign-center{text-align:center} +th.valign-top,td.valign-top{vertical-align:top} +th.valign-bottom,td.valign-bottom{vertical-align:bottom} +th.valign-middle,td.valign-middle{vertical-align:middle} +table thead th,table tfoot th{font-weight:bold} +tbody tr th{background:#f7f8f7} +tbody tr th,tbody tr th p,tfoot tr th,tfoot tr th p{color:rgba(0,0,0,.8);font-weight:bold} +p.tableblock>code:only-child{background:none;padding:0} +p.tableblock{font-size:1em} +ol{margin-left:1.75em} +ul li ol{margin-left:1.5em} +dl dd{margin-left:1.125em} +dl dd:last-child,dl dd:last-child>:last-child{margin-bottom:0} +li p,ul dd,ol dd,.olist .olist,.ulist .ulist,.ulist .olist,.olist .ulist{margin-bottom:.625em} +ul.checklist,ul.none,ol.none,ul.no-bullet,ol.no-bullet,ol.unnumbered,ul.unstyled,ol.unstyled{list-style-type:none} +ul.no-bullet,ol.no-bullet,ol.unnumbered{margin-left:.625em} +ul.unstyled,ol.unstyled{margin-left:0} +li>p:empty:only-child::before{content:"";display:inline-block} +ul.checklist>li>p:first-child{margin-left:-1em} +ul.checklist>li>p:first-child>.fa-square-o:first-child,ul.checklist>li>p:first-child>.fa-check-square-o:first-child{width:1.25em;font-size:.8em;position:relative;bottom:.125em} +ul.checklist>li>p:first-child>input[type=checkbox]:first-child{margin-right:.25em} +ul.inline{display:flex;flex-flow:row wrap;list-style:none;margin:0 0 .625em -1.25em} +ul.inline>li{margin-left:1.25em} +.unstyled dl dt{font-weight:400;font-style:normal} +ol.arabic{list-style-type:decimal} +ol.decimal{list-style-type:decimal-leading-zero} +ol.loweralpha{list-style-type:lower-alpha} +ol.upperalpha{list-style-type:upper-alpha} +ol.lowerroman{list-style-type:lower-roman} +ol.upperroman{list-style-type:upper-roman} +ol.lowergreek{list-style-type:lower-greek} +.hdlist>table,.colist>table{border:0;background:none} +.hdlist>table>tbody>tr,.colist>table>tbody>tr{background:none} +td.hdlist1,td.hdlist2{vertical-align:top;padding:0 .625em} +td.hdlist1{font-weight:bold;padding-bottom:1.25em} +td.hdlist2{word-wrap:anywhere} +.literalblock+.colist,.listingblock+.colist{margin-top:-.5em} +.colist td:not([class]):first-child{padding:.4em .75em 0;line-height:1;vertical-align:top} +.colist td:not([class]):first-child img{max-width:none} +.colist td:not([class]):last-child{padding:.25em 0} +.thumb,.th{line-height:0;display:inline-block;border:4px solid #fff;box-shadow:0 0 0 1px #ddd} +.imageblock.left{margin:.25em .625em 1.25em 0} +.imageblock.right{margin:.25em 0 1.25em .625em} +.imageblock>.title{margin-bottom:0} +.imageblock.thumb,.imageblock.th{border-width:6px} +.imageblock.thumb>.title,.imageblock.th>.title{padding:0 .125em} +.image.left,.image.right{margin-top:.25em;margin-bottom:.25em;display:inline-block;line-height:0} +.image.left{margin-right:.625em} +.image.right{margin-left:.625em} +a.image{text-decoration:none;display:inline-block} +a.image object{pointer-events:none} +sup.footnote,sup.footnoteref{font-size:.875em;position:static;vertical-align:super} +sup.footnote a,sup.footnoteref a{text-decoration:none} +sup.footnote a:active,sup.footnoteref a:active,#footnotes .footnote a:first-of-type:active{text-decoration:underline} +#footnotes{padding-top:.75em;padding-bottom:.75em;margin-bottom:.625em} +#footnotes hr{width:20%;min-width:6.25em;margin:-.25em 0 .75em;border-width:1px 0 0} +#footnotes .footnote{padding:0 .375em 0 .225em;line-height:1.3334;font-size:.875em;margin-left:1.2em;margin-bottom:.2em} +#footnotes .footnote a:first-of-type{font-weight:bold;text-decoration:none;margin-left:-1.05em} +#footnotes .footnote:last-of-type{margin-bottom:0} +#content #footnotes{margin-top:-.625em;margin-bottom:0;padding:.75em 0} +div.unbreakable{page-break-inside:avoid} +.big{font-size:larger} +.small{font-size:smaller} +.underline{text-decoration:underline} +.overline{text-decoration:overline} +.line-through{text-decoration:line-through} +.aqua{color:#00bfbf} +.aqua-background{background:#00fafa} +.black{color:#000} +.black-background{background:#000} +.blue{color:#0000bf} +.blue-background{background:#0000fa} +.fuchsia{color:#bf00bf} +.fuchsia-background{background:#fa00fa} +.gray{color:#606060} +.gray-background{background:#7d7d7d} +.green{color:#006000} +.green-background{background:#007d00} +.lime{color:#00bf00} +.lime-background{background:#00fa00} +.maroon{color:#600000} +.maroon-background{background:#7d0000} +.navy{color:#000060} +.navy-background{background:#00007d} +.olive{color:#606000} +.olive-background{background:#7d7d00} +.purple{color:#600060} +.purple-background{background:#7d007d} +.red{color:#bf0000} +.red-background{background:#fa0000} +.silver{color:#909090} +.silver-background{background:#bcbcbc} +.teal{color:#006060} +.teal-background{background:#007d7d} +.white{color:#bfbfbf} +.white-background{background:#fafafa} +.yellow{color:#bfbf00} +.yellow-background{background:#fafa00} +span.icon>.fa{cursor:default} +a span.icon>.fa{cursor:inherit} +.admonitionblock td.icon [class^="fa icon-"]{font-size:2.5em;text-shadow:1px 1px 2px rgba(0,0,0,.5);cursor:default} +.admonitionblock td.icon .icon-note::before{content:"\f05a";color:#19407c} +.admonitionblock td.icon .icon-tip::before{content:"\f0eb";text-shadow:1px 1px 2px rgba(155,155,0,.8);color:#111} +.admonitionblock td.icon .icon-warning::before{content:"\f071";color:#bf6900} +.admonitionblock td.icon .icon-caution::before{content:"\f06d";color:#bf3400} +.admonitionblock td.icon .icon-important::before{content:"\f06a";color:#bf0000} +.conum[data-value]{display:inline-block;color:#fff!important;background:rgba(0,0,0,.8);border-radius:50%;text-align:center;font-size:.75em;width:1.67em;height:1.67em;line-height:1.67em;font-family:"Open Sans","DejaVu Sans",sans-serif;font-style:normal;font-weight:bold} +.conum[data-value] *{color:#fff!important} +.conum[data-value]+b{display:none} +.conum[data-value]::after{content:attr(data-value)} +pre .conum[data-value]{position:relative;top:-.125em} +b.conum *{color:inherit!important} +.conum:not([data-value]):empty{display:none} +dt,th.tableblock,td.content,div.footnote{text-rendering:optimizeLegibility} +h1,h2,p,td.content,span.alt,summary{letter-spacing:-.01em} +p strong,td.content strong,div.footnote strong{letter-spacing:-.005em} +p,blockquote,dt,td.content,td.hdlist1,span.alt,summary{font-size:1.0625rem} +p{margin-bottom:1.25rem} +.sidebarblock p,.sidebarblock dt,.sidebarblock td.content,p.tableblock{font-size:1em} +.exampleblock>.content{background:#fffef7;border-color:#e0e0dc;box-shadow:0 1px 4px #e0e0dc} +.print-only{display:none!important} +@page{margin:1.25cm .75cm} +@media print{*{box-shadow:none!important;text-shadow:none!important} +html{font-size:80%} +a{color:inherit!important;text-decoration:underline!important} +a.bare,a[href^="#"],a[href^="mailto:"]{text-decoration:none!important} +a[href^="http:"]:not(.bare)::after,a[href^="https:"]:not(.bare)::after{content:"(" attr(href) ")";display:inline-block;font-size:.875em;padding-left:.25em} +abbr[title]{border-bottom:1px dotted} +abbr[title]::after{content:" (" attr(title) ")"} +pre,blockquote,tr,img,object,svg{page-break-inside:avoid} +thead{display:table-header-group} +svg{max-width:100%} +p,blockquote,dt,td.content{font-size:1em;orphans:3;widows:3} +h2,h3,#toctitle,.sidebarblock>.content>.title{page-break-after:avoid} +#header,#content,#footnotes,#footer{max-width:none} +#toc,.sidebarblock,.exampleblock>.content{background:none!important} +#toc{border-bottom:1px solid #dddddf!important;padding-bottom:0!important} +body.book #header{text-align:center} +body.book #header>h1:first-child{border:0!important;margin:2.5em 0 1em} +body.book #header .details{border:0!important;display:block;padding:0!important} +body.book #header .details span:first-child{margin-left:0!important} +body.book #header .details br{display:block} +body.book #header .details br+span::before{content:none!important} +body.book #toc{border:0!important;text-align:left!important;padding:0!important;margin:0!important} +body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-break-before:always} +.listingblock code[data-lang]::before{display:block} +#footer{padding:0 .9375em} +.hide-on-print{display:none!important} +.print-only{display:block!important} +.hide-for-print{display:none!important} +.show-for-print{display:inherit!important}} +@media amzn-kf8,print{#header>h1:first-child{margin-top:1.25rem} +.sect1{padding:0!important} +.sect1+.sect1{border:0} +#footer{background:none} +#footer-text{color:rgba(0,0,0,.6);font-size:.9em}} +@media amzn-kf8{#header,#content,#footnotes,#footer{padding:0}} +</style> +</head> +<body class="article toc2 toc-left"> +<div id="header"> +<h1>Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate</h1> +<div class="details"> +<span id="author" class="author">0.0.2</span><br> +</div> +<div id="toc" class="toc2"> +<div id="toctitle">Table of Contents</div> +<ul class="sectlevel1"> +<li><a href="#_modeling_trust_in_enterprise_architecture_a_pattern_language_for_archimate">Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate</a></li> +<li><a href="#_applied_examples_gnupg_key_signing">Applied Examples: GnuPG Key Signing</a></li> +<li><a href="#_archimate_diagrams">Archimate Diagrams</a></li> +</ul> +</div> +</div> +<div id="content"> +<div class="sect1"> +<h2 id="_modeling_trust_in_enterprise_architecture_a_pattern_language_for_archimate">Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate</h2> +<div class="sectionbody"> +<div class="ulist"> +<ul> +<li> +<p>»Ontological Analysis and Redesign of Risk Modeling in ArchiMate«</p> +<div class="ulist"> +<ul> +<li> +<p>by Prince Sales, Tiago & Almeida, João & Santini, Sebastiano & Baião, Fernanda & Guizzardi, Giancarlo.</p> +<div class="ulist"> +<ul> +<li> +<p><a href="https://www.researchgate.net/publication/326835902_Ontological_Analysis_and_Redesign_of_Risk_Modeling_in_ArchiMate" class="bare">https://www.researchgate.net/publication/326835902_Ontological_Analysis_and_Redesign_of_Risk_Modeling_in_ArchiMate</a></p> +</li> +</ul> +</div> +</li> +</ul> +</div> +</li> +<li> +<p>»Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate«</p> +<div class="ulist"> +<ul> +<li> +<p>by Glenda Amaral, Tiago Prince Sales, Giancarlo Guizzardi, João Paulo A. Almeida, and Daniele Porello</p> +<div class="ulist"> +<ul> +<li> +<p><a href="https://www.researchgate.net/publication/344319377_Modeling_Trust_in_Enterprise_Architecture_A_Pattern_Language_for_ArchiMate" class="bare">https://www.researchgate.net/publication/344319377_Modeling_Trust_in_Enterprise_Architecture_A_Pattern_Language_for_ArchiMate</a></p> +</li> +</ul> +</div> +</li> +</ul> +</div> +</li> +</ul> +</div> +<div class="paragraph"> +<p>I use the patterns develop in this paper to model trust relationships (trust boarders, trust anchors) in Zero Trust Architectures.</p> +</div> +<div class="paragraph"> +<p>As an example, I model the process of Downloading an NetBSD ISO Install Image, which has been signed by the NetBSD security officer with a detached GnuPG signature. This is SLSA Level 1 according to the »Supply-chain Levels for Software Artifacts«</p> +</div> +<div class="paragraph"> +<p>I will extend the process from SLSA Level 1 to SLSA Level 4, which will include Reproducible Builds and an immutable linked list of hashes in concatenated Merkle trees.</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_applied_examples_gnupg_key_signing">Applied Examples: GnuPG Key Signing</h2> +<div class="sectionbody"> +<div class="paragraph"> +<p>The sub directory <code>GnuPG-WoT-Download</code> contains applied examples of the trust modeling. It is work in progress, but already contains some diagrams.</p> +</div> +<div class="paragraph"> +<p>My goal is to model a reproducible builds distribution process with a zero trust architecture. And threat model it in PASTA as well as STRIDE.</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_archimate_diagrams">Archimate Diagrams</h2> +<div class="sectionbody"> +<table class="tableblock frame-none grid-none stretch"> +<colgroup> +<col> +<col style="width: 5%;"> +<col> +</colgroup> +<thead> +<tr> +<th class="tableblock halign-left valign-top">Example from Paper</th> +<th class="tableblock halign-left valign-top"></th> +<th class="tableblock halign-left valign-top">Applied to the NetBSD download</th> +</tr> +</thead> +<tbody> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="6-3a.png" alt="6 3a"> +</div> +</div></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="6-3c.png" alt="6 3c"> +</div> +</div></div></td> +</tr> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="8-7a-Trust-Composition.png" alt="8 7a Trust Composition"> +</div> +</div></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="8-7-GnuPG-Trust-Composition.png" alt="8 7 GnuPG Trust Composition"> +</div> +</div></div></td> +</tr> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="RSO9-10-RiskSecurityOverlay.png" alt="RSO9 10 RiskSecurityOverlay"> +</div> +</div></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="RSO9-10-RiskSecurityOverlay.png" alt="RSO9 10 RiskSecurityOverlay"> +</div> +</div></div></td> +</tr> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="9-9-RiskAssessmentPattern.png" alt="9 9 RiskAssessmentPattern"> +</div> +</div></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="9-9-GnuPG-RiskAssessmentPattern.png" alt="9 9 GnuPG RiskAssessmentPattern"> +</div> +</div></div></td> +</tr> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="9-9-GnuPG-RiskAssessmentPattern2.png" alt="9 9 GnuPG RiskAssessmentPattern2"> +</div> +</div></div></td> +</tr> +<tr> +<td class="tableblock halign-left valign-top"><div class="content"></div></td> +<td class="tableblock halign-left valign-top"></td> +<td class="tableblock halign-left valign-top"><div class="content"><div class="imageblock"> +<div class="content"> +<img src="9-9-GnuPG-RiskAssessmentPattern3.png" alt="9 9 GnuPG RiskAssessmentPattern3"> +</div> +</div></div></td> +</tr> +</tbody> +</table> +</div> +</div> +</div> +<div id="footer"> +<div id="footer-text"> +Last updated 2026-03-14 19:15:07 +0100 +</div> +</div> +</body> +</html>
\ No newline at end of file diff --git a/PlantUML-ModelingTrust/README.pdf b/PlantUML-ModelingTrust/README.pdf Binary files differindex dc64d84..6a87708 100644 --- a/PlantUML-ModelingTrust/README.pdf +++ b/PlantUML-ModelingTrust/README.pdf diff --git a/README.adoc b/README.adoc index 7412102..e4ef49e 100644 --- a/README.adoc +++ b/README.adoc @@ -1,8 +1,27 @@ = Security Architecture Notes and Patterns +Stefan Schumacher <public@cryptomancer.de> +v0.0.1, 2026/01/03, Entwurf +:toc: left +:toclevels: 2 +:sectnums: all +:imagesdir: PlantUML-ModelingTrust/GnuPG-WoT-Download/ -. `GetPlantUML-CheatSheets.sh` +This is the pages version of Stefan Schumacher's Codeberg Repository at https://codeberg.org/0xKaishakunin/Architecture + +It contains several architecural patterns and exercises with PlantUML with regards to modeling trust and zero trust architecture patterns + + +== From GnuPG Keysigning Party to Reproducile Builds according to SLSA4 + +include::PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc[tags=inhalt] + + + +== Links + +. link:GetPlantUML-CheatSheets.sh[GetPlantUML-CheatSheets.sh] .. downloads some useful ArchiMate cheat sheets/overviews/examples via `wget` -. `PlantUML-ModelingTrust` -.. Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate -. `PlantUML-ModelingTrust/GnuPG-WoT-Download/` -.. A GnuPG Key Signing Party and Download Signatures (SLSA1) modeled in Archimate +. link:PlantUML-ModelingTrust/README.html[PlantUML-ModelingTrust] +.. Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate, some TextBook patterns +. link:PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html[PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html] +.. A GnuPG Key Signing Party and Download Signatures (SLSA1) as well as Reproducible Builds SLSA4 modeled in Archimate diff --git a/README.html b/README.html index 5bf5ec8..166f8de 100644 --- a/README.html +++ b/README.html @@ -5,6 +5,7 @@ <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta name="generator" content="Asciidoctor 2.0.26"> +<meta name="author" content="Stefan Schumacher"> <title>Security Architecture Notes and Patterns</title> <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open+Sans:300,300italic,400,400italic,600,600italic%7CNoto+Serif:400,400italic,700,700italic%7CDroid+Sans+Mono:400,700"> <style> @@ -434,15 +435,231 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b @media amzn-kf8{#header,#content,#footnotes,#footer{padding:0}} </style> </head> -<body class="article"> +<body class="article toc2 toc-left"> <div id="header"> <h1>Security Architecture Notes and Patterns</h1> +<div class="details"> +<span id="author" class="author">Stefan Schumacher</span><br> +<span id="email" class="email"><a href="mailto:public@cryptomancer.de">public@cryptomancer.de</a></span><br> +<span id="revnumber">version 0.0.1,</span> +<span id="revdate">2026/01/03, Entwurf</span> +</div> +<div id="toc" class="toc2"> +<div id="toctitle">Table of Contents</div> +<ul class="sectlevel1"> +<li><a href="#_from_gnupg_keysigning_party_to_reproducile_builds_according_to_slsa4">1. From GnuPG Keysigning Party to Reproducile Builds according to SLSA4</a></li> +<li><a href="#_dfd_keysigning_simple">2. DFD: Keysigning Simple</a></li> +<li><a href="#_seq_keysigning_with_id_check_and_wot">3. SEQ: Keysigning with ID check and WoT</a></li> +<li><a href="#_netbsd_releng_attack_stride">4. NetBSD RelEng Attack STRIDE</a></li> +<li><a href="#_supply_chain_levels_for_software_artifacts">5. Supply-chain Levels for Software Artifacts</a> +<ul class="sectlevel2"> +<li><a href="#_slsa_l1">5.1. SLSA L1</a></li> +<li><a href="#_reproducible_builds_slsa_l4">5.2. Reproducible Builds SLSA L4</a></li> +<li><a href="#_motivationbusiness_layer_risksecurity_overlay">5.3. Motivation/Business Layer: Risk/Security Overlay</a></li> +</ul> +</li> +<li><a href="#_links">6. Links</a></li> +</ul> +</div> </div> <div id="content"> +<div id="preamble"> +<div class="sectionbody"> +<div class="paragraph"> +<p>This is the pages version of Stefan Schumacher’s Codeberg Repository at <a href="https://codeberg.org/0xKaishakunin/Architecture" class="bare">https://codeberg.org/0xKaishakunin/Architecture</a></p> +</div> +<div class="paragraph"> +<p>It contains several architecural patterns and exercises with PlantUML with regards to modeling trust and zero trust architecture patterns</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_from_gnupg_keysigning_party_to_reproducile_builds_according_to_slsa4">1. From GnuPG Keysigning Party to Reproducile Builds according to SLSA4</h2> +<div class="sectionbody"> +<div class="paragraph"> +<p>I am trying to model implicit and explicit trust in Zero Trust Architecture diagrams for Threat Modeling.</p> +</div> +<div class="paragraph"> +<p>So I need to bring together the Blue Team/White Hat perspective and the Red Team/Black Hat stuff.</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_dfd_keysigning_simple">2. DFD: Keysigning Simple</h2> +<div class="sectionbody"> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png" alt="100 GnuPG Keysigning DFD"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_seq_keysigning_with_id_check_and_wot">3. SEQ: Keysigning with ID check and WoT</h2> +<div class="sectionbody"> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png" alt="100 GnuPG Keysigning SEQ KSP WoT"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_netbsd_releng_attack_stride">4. NetBSD RelEng Attack STRIDE</h2> +<div class="sectionbody"> +<div class="paragraph"> +<p>The ISO Image is built, signed and uploaded to the WWW server, as well as the Signature file and checksums.</p> +</div> +<div class="paragraph"> +<p>Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated one with a valid Signature.</p> +</div> +<div class="paragraph"> +<p>The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity.</p> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png" alt="300 NetBSD RelEng STRIDE"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_supply_chain_levels_for_software_artifacts">5. Supply-chain Levels for Software Artifacts</h2> +<div class="sectionbody"> +<div class="sect2"> +<h3 id="_slsa_l1">5.1. SLSA L1</h3> +<div class="paragraph"> +<p>A simple threat model for SLSA Level 1:</p> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png" alt="200 ThreatModel SLSA1 DownloadSig"> +</div> +</div> +</div> +<div class="sect2"> +<h3 id="_reproducible_builds_slsa_l4">5.2. Reproducible Builds SLSA L4</h3> +<div class="paragraph"> +<p>Modeling Trust, Trust Anchors and Boundaries and Attack Vectors for SLSA4:</p> +</div> +<div class="paragraph"> +<p>The whole process draws heavy inspiration from those implemented by NetBSD, Debian, NixOS and the Tor Browser!</p> +</div> <div class="olist arabic"> <ol class="arabic"> <li> -<p><code>GetPlantUML-CheatSheets.sh</code></p> +<p>general goals</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>Build process produces identical artefacts (bit-for-bit) from the same source and inputs</p> +</li> +<li> +<p>independent parties can rebuild and verify outputs match the original → verify freedom from insider threat!</p> +</li> +<li> +<p>require a deterministic build environments</p> +</li> +<li> +<p>all build steps, dependencies, and tooling are tightly controlled and audited</p> +</li> +</ol> +</div> +</li> +<li> +<p>security goals:</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>detect tampering in build pipelines or artefacts</p> +</li> +<li> +<p>prevents hidden backdoors introduced during compilation or packaging by a malicious insider</p> +</li> +<li> +<p>ensure integrity of supply chain, dependencies and build tools</p> +</li> +<li> +<p>enables independent verification without trusting the original builder</p> +</li> +<li> +<p>drastrically reduce insider and supply chain attack surface</p> +</li> +</ol> +</div> +</li> +<li> +<p>Zero Trust:</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>never trust, always verify!</p> +</li> +<li> +<p>verifiable evidence (rebuild && compare)</p> +</li> +<li> +<p>eliminates implicit trust in build pipeline</p> +</li> +<li> +<p>build system considered untrustworthy</p> +</li> +<li> +<p>combine with signed artefacts and attestation frameworks for full supply chain integrity</p> +</li> +</ol> +</div> +</li> +</ol> +</div> +<div class="sect3"> +<h4 id="_the_whole_implementation">5.2.1. The whole implementation</h4> +<div class="ulist"> +<ul> +<li> +<p>Trust Boundaries: Rectangles</p> +</li> +<li> +<p>Attack Vectors: Red Arrows</p> +</li> +</ul> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png" alt="201 ThreatModel SLSA4 ReproducibleBuilds"> +</div> +</div> +<div class="ulist"> +<ul> +<li> +<p>Trust Anchor: Green Anchor</p> +</li> +</ul> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png" alt="202 ThreatModel SLSA4 ReproducibleBuilds TrustAnchor"> +</div> +</div> +</div> +</div> +<div class="sect2"> +<h3 id="_motivationbusiness_layer_risksecurity_overlay">5.3. Motivation/Business Layer: Risk/Security Overlay</h3> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png" alt="203 SLSA4 ReproducibleBuilds L1 Motivation"> +</div> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_links">6. Links</h2> +<div class="sectionbody"> +<div class="olist arabic"> +<ol class="arabic"> +<li> +<p><a href="GetPlantUML-CheatSheets.sh">GetPlantUML-CheatSheets.sh</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> @@ -452,21 +669,21 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </div> </li> <li> -<p><code>PlantUML-ModelingTrust</code></p> +<p><a href="PlantUML-ModelingTrust/README.html">PlantUML-ModelingTrust</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> -<p>Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate</p> +<p>Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate, some TextBook patterns</p> </li> </ol> </div> </li> <li> -<p><code>PlantUML-ModelingTrust/GnuPG-WoT-Download/</code></p> +<p><a href="PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html">PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> -<p>A GnuPG Key Signing Party and Download Signatures (SLSA1) modeled in Archimate</p> +<p>A GnuPG Key Signing Party and Download Signatures (SLSA1) as well as Reproducible Builds SLSA4 modeled in Archimate</p> </li> </ol> </div> @@ -474,9 +691,12 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </ol> </div> </div> +</div> +</div> <div id="footer"> <div id="footer-text"> -Last updated 2026-02-23 08:18:20 +0100 +Version 0.0.1<br> +Last updated 2026-05-05 17:52:48 +0200 </div> </div> </body> diff --git a/README.pdf b/README.pdf Binary files differnew file mode 100644 index 0000000..3c3c90a --- /dev/null +++ b/README.pdf @@ -5,6 +5,7 @@ <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta name="generator" content="Asciidoctor 2.0.26"> +<meta name="author" content="Stefan Schumacher"> <title>Security Architecture Notes and Patterns</title> <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open+Sans:300,300italic,400,400italic,600,600italic%7CNoto+Serif:400,400italic,700,700italic%7CDroid+Sans+Mono:400,700"> <style> @@ -434,15 +435,231 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b @media amzn-kf8{#header,#content,#footnotes,#footer{padding:0}} </style> </head> -<body class="article"> +<body class="article toc2 toc-left"> <div id="header"> <h1>Security Architecture Notes and Patterns</h1> +<div class="details"> +<span id="author" class="author">Stefan Schumacher</span><br> +<span id="email" class="email"><a href="mailto:public@cryptomancer.de">public@cryptomancer.de</a></span><br> +<span id="revnumber">version 0.0.1,</span> +<span id="revdate">2026/01/03, Entwurf</span> +</div> +<div id="toc" class="toc2"> +<div id="toctitle">Table of Contents</div> +<ul class="sectlevel1"> +<li><a href="#_from_gnupg_keysigning_party_to_reproducile_builds_according_to_slsa4">1. From GnuPG Keysigning Party to Reproducile Builds according to SLSA4</a></li> +<li><a href="#_dfd_keysigning_simple">2. DFD: Keysigning Simple</a></li> +<li><a href="#_seq_keysigning_with_id_check_and_wot">3. SEQ: Keysigning with ID check and WoT</a></li> +<li><a href="#_netbsd_releng_attack_stride">4. NetBSD RelEng Attack STRIDE</a></li> +<li><a href="#_supply_chain_levels_for_software_artifacts">5. Supply-chain Levels for Software Artifacts</a> +<ul class="sectlevel2"> +<li><a href="#_slsa_l1">5.1. SLSA L1</a></li> +<li><a href="#_reproducible_builds_slsa_l4">5.2. Reproducible Builds SLSA L4</a></li> +<li><a href="#_motivationbusiness_layer_risksecurity_overlay">5.3. Motivation/Business Layer: Risk/Security Overlay</a></li> +</ul> +</li> +<li><a href="#_links">6. Links</a></li> +</ul> +</div> </div> <div id="content"> +<div id="preamble"> +<div class="sectionbody"> +<div class="paragraph"> +<p>This is the pages version of Stefan Schumacher’s Codeberg Repository at <a href="https://codeberg.org/0xKaishakunin/Architecture" class="bare">https://codeberg.org/0xKaishakunin/Architecture</a></p> +</div> +<div class="paragraph"> +<p>It contains several architecural patterns and exercises with PlantUML with regards to modeling trust and zero trust architecture patterns</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_from_gnupg_keysigning_party_to_reproducile_builds_according_to_slsa4">1. From GnuPG Keysigning Party to Reproducile Builds according to SLSA4</h2> +<div class="sectionbody"> +<div class="paragraph"> +<p>I am trying to model implicit and explicit trust in Zero Trust Architecture diagrams for Threat Modeling.</p> +</div> +<div class="paragraph"> +<p>So I need to bring together the Blue Team/White Hat perspective and the Red Team/Black Hat stuff.</p> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_dfd_keysigning_simple">2. DFD: Keysigning Simple</h2> +<div class="sectionbody"> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png" alt="100 GnuPG Keysigning DFD"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_seq_keysigning_with_id_check_and_wot">3. SEQ: Keysigning with ID check and WoT</h2> +<div class="sectionbody"> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png" alt="100 GnuPG Keysigning SEQ KSP WoT"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_netbsd_releng_attack_stride">4. NetBSD RelEng Attack STRIDE</h2> +<div class="sectionbody"> +<div class="paragraph"> +<p>The ISO Image is built, signed and uploaded to the WWW server, as well as the Signature file and checksums.</p> +</div> +<div class="paragraph"> +<p>Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated one with a valid Signature.</p> +</div> +<div class="paragraph"> +<p>The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity.</p> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png" alt="300 NetBSD RelEng STRIDE"> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_supply_chain_levels_for_software_artifacts">5. Supply-chain Levels for Software Artifacts</h2> +<div class="sectionbody"> +<div class="sect2"> +<h3 id="_slsa_l1">5.1. SLSA L1</h3> +<div class="paragraph"> +<p>A simple threat model for SLSA Level 1:</p> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png" alt="200 ThreatModel SLSA1 DownloadSig"> +</div> +</div> +</div> +<div class="sect2"> +<h3 id="_reproducible_builds_slsa_l4">5.2. Reproducible Builds SLSA L4</h3> +<div class="paragraph"> +<p>Modeling Trust, Trust Anchors and Boundaries and Attack Vectors for SLSA4:</p> +</div> +<div class="paragraph"> +<p>The whole process draws heavy inspiration from those implemented by NetBSD, Debian, NixOS and the Tor Browser!</p> +</div> <div class="olist arabic"> <ol class="arabic"> <li> -<p><code>GetPlantUML-CheatSheets.sh</code></p> +<p>general goals</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>Build process produces identical artefacts (bit-for-bit) from the same source and inputs</p> +</li> +<li> +<p>independent parties can rebuild and verify outputs match the original → verify freedom from insider threat!</p> +</li> +<li> +<p>require a deterministic build environments</p> +</li> +<li> +<p>all build steps, dependencies, and tooling are tightly controlled and audited</p> +</li> +</ol> +</div> +</li> +<li> +<p>security goals:</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>detect tampering in build pipelines or artefacts</p> +</li> +<li> +<p>prevents hidden backdoors introduced during compilation or packaging by a malicious insider</p> +</li> +<li> +<p>ensure integrity of supply chain, dependencies and build tools</p> +</li> +<li> +<p>enables independent verification without trusting the original builder</p> +</li> +<li> +<p>drastrically reduce insider and supply chain attack surface</p> +</li> +</ol> +</div> +</li> +<li> +<p>Zero Trust:</p> +<div class="olist loweralpha"> +<ol class="loweralpha" type="a"> +<li> +<p>never trust, always verify!</p> +</li> +<li> +<p>verifiable evidence (rebuild && compare)</p> +</li> +<li> +<p>eliminates implicit trust in build pipeline</p> +</li> +<li> +<p>build system considered untrustworthy</p> +</li> +<li> +<p>combine with signed artefacts and attestation frameworks for full supply chain integrity</p> +</li> +</ol> +</div> +</li> +</ol> +</div> +<div class="sect3"> +<h4 id="_the_whole_implementation">5.2.1. The whole implementation</h4> +<div class="ulist"> +<ul> +<li> +<p>Trust Boundaries: Rectangles</p> +</li> +<li> +<p>Attack Vectors: Red Arrows</p> +</li> +</ul> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png" alt="201 ThreatModel SLSA4 ReproducibleBuilds"> +</div> +</div> +<div class="ulist"> +<ul> +<li> +<p>Trust Anchor: Green Anchor</p> +</li> +</ul> +</div> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png" alt="202 ThreatModel SLSA4 ReproducibleBuilds TrustAnchor"> +</div> +</div> +</div> +</div> +<div class="sect2"> +<h3 id="_motivationbusiness_layer_risksecurity_overlay">5.3. Motivation/Business Layer: Risk/Security Overlay</h3> +<div class="imageblock"> +<div class="content"> +<img src="PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png" alt="203 SLSA4 ReproducibleBuilds L1 Motivation"> +</div> +</div> +</div> +</div> +</div> +<div class="sect1"> +<h2 id="_links">6. Links</h2> +<div class="sectionbody"> +<div class="olist arabic"> +<ol class="arabic"> +<li> +<p><a href="GetPlantUML-CheatSheets.sh">GetPlantUML-CheatSheets.sh</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> @@ -452,21 +669,21 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </div> </li> <li> -<p><code>PlantUML-ModelingTrust</code></p> +<p><a href="PlantUML-ModelingTrust/README.html">PlantUML-ModelingTrust</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> -<p>Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate</p> +<p>Modeling Trust/Risk/Trust Anchors, Chains, and Boarders in Archimate, some TextBook patterns</p> </li> </ol> </div> </li> <li> -<p><code>PlantUML-ModelingTrust/GnuPG-WoT-Download/</code></p> +<p><a href="PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html">PlantUML-ModelingTrust/GnuPG-WoT-Download/README.html</a></p> <div class="olist loweralpha"> <ol class="loweralpha" type="a"> <li> -<p>A GnuPG Key Signing Party and Download Signatures (SLSA1) modeled in Archimate</p> +<p>A GnuPG Key Signing Party and Download Signatures (SLSA1) as well as Reproducible Builds SLSA4 modeled in Archimate</p> </li> </ol> </div> @@ -474,9 +691,12 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b </ol> </div> </div> +</div> +</div> <div id="footer"> <div id="footer-text"> -Last updated 2026-02-23 08:18:20 +0100 +Version 0.0.1<br> +Last updated 2026-05-05 17:52:48 +0200 </div> </div> </body> |
