summaryrefslogtreecommitdiff
path: root/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml
diff options
context:
space:
mode:
authorstefan <stefan@i3mint.local>2026-02-24 20:36:44 +0100
committerstefan <stefan@i3mint.local>2026-02-24 20:36:44 +0100
commit2993aae60e019804e249de3f56e48eca365723df (patch)
treeb894165e436a60faf4c70db44a9eb483c6fa557b /PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml
parent130b63ade620f4a2619233feb3e5e4ea56d58983 (diff)
Risk/Security Overlay im Business/Motivation Layer angefangen
Diffstat (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml')
-rw-r--r--PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml135
1 files changed, 135 insertions, 0 deletions
diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml
new file mode 100644
index 0000000..f183b2a
--- /dev/null
+++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml
@@ -0,0 +1,135 @@
+@startuml
+!include <archimate/Archimate>
+
+left to right direction
+skinparam rectangle {
+ BackgroundColor #FFF6F6
+ BorderColor #550000
+}
+skinparam note {
+ BackgroundColor #FFFFCC
+}
+
+' makes Rel_ green
+skinparam ArrowFontColor<<greenRel>> green
+
+
+' Anchor as SVG sprite
+sprite $anchor <svg viewBox="0 0 204.851 204.851">
+ <path fill="#000000" d="M139.518,128.595l16.834,16.336c0,0-20.644,29.877-42.725,30.473
+ c0.479,0,0.117-84.092,0.039-104.472c14.694-4.797,25.402-18.182,25.402-34.117
+ c0-20.009-16.697-36.218-37.273-36.218c-20.615,0-37.312,16.209-37.312,36.208
+ c0,15.671,10.376,28.929,24.748,33.961l0.098,104.277c-26.643-1.837-42.061-27.474-42.061-27.474
+ l17.997-17.41L0,120.505l9.887,63.301l17.362-16.795c15.036,12.105,32.017,37.244,72.876,37.244
+ c51.332-1.309,63.184-28.939,76.344-39.804l18.993,18.514l9.389-63.907L139.518,128.595z
+ M82.558,36.208c0-10.298,8.608-18.661,19.218-18.661s19.257,8.363,19.257,18.661
+ c0,10.327-8.647,18.681-19.257,18.681S82.558,46.535,82.558,36.208z"/>
+</svg>
+
+
+
+
+right header
+= Threat Model - Reproducible Builds according to SLSA Level 4
+using independent GnuPG signatures and keys
+as well as Reproducible Builds according to SLSA Level 4
+corresponding to the Tor Browser release process, as well as NixOS, Debian and NetBSD
+= %date("yyyy-MM-dd hh:mm")
+endheader
+
+right footer
+= Advantages:
+* Consistency between source code and binaries through Reproducible Builds
+* No single trust anchor -> at least 2 independent builders
+* Subsequent manipulation detectable through checksums in the Git Transparency Log
+* Insider attacks made more difficult through multiple signatures
+* Key misuse detectable through checksums in the Git Transparency Log and temporal correlation via timestamps
+* Each box is a trust boarder
+endfooter
+
+
+
+caption
+= Threat Model - Reproducible Builds according to SLSA Level 4
+endcaption
+
+actor "Downloader\n(Verifier)" as User #Green
+actor "Internet\n(Insecure)" as Net
+actor "NTP Server 1" as NTP1
+actor "NTP Server 2 " as NTP2
+actor "Attacker\n(Insider / External)" as Attacker #Red
+'actor "Trusted Commiter 1" as Committer1
+'actor "Trusted Commiter 2" as Committer2
+
+actor "Keyserver 1" as Keyserver1
+actor "Keyserver 2" as Keyserver2
+
+
+rectangle "Maintainer" {
+ rectangle "Source Code\n(in Git) <$anchor{scale=0.1,color=green}>" as Source
+ rectangle "Git Release Tag\n(GnuPG-signed) <$anchor{scale=0.1,color=green}>" as Tag
+}
+
+rectangle "Independent build pipelines\n(at least 2)" {
+ rectangle "Pipe A <$anchor{scale=0.1,color=lightgreen}>b1" as B1
+ rectangle "Pipe B <$anchor{scale=0.1,color=lightgreen}>b2" as B2
+}
+
+Motivation_Goal(TAb, "combined Trust")
+' Rel_Aggregation(TAb, B1, "combines", $lineColor="green", $textColor="green")
+TAb o-- B1 : <color:green>combines TA</color>
+TAb o-- B2 : <color:green>combines TA</color>
+
+
+
+
+
+
+rectangle "Download artefacts" {
+ rectangle "Artefact A\n(Checksum)" as A1
+ rectangle "Artefact B\n(Checksum)" as A2
+}
+
+rectangle "Git Transparency Log\n(tamper-hardened) <$anchor{scale=0.1,color=green}>" as Log
+rectangle "Distributed ledger with\n Merkle Tree records\n (Blockchain) <$anchor{scale=0.1,color=green}>" as Ledger
+
+rectangle "Operational environment\n(of the downloader)" {
+ rectangle "Known public signing keys\n(obtained from at least\n 2 independent trust paths)" as Keys
+ rectangle "Rebuild pipeline\n(Reproducible)" as Rebuild
+ rectangle "Verification policy\n (organisational measure\n from BSI TR)" as Policy
+}
+
+NTP1 --> Log : Time
+NTP2 --> Log : Time
+
+Keyserver1 --> Keys : retrieves
+Keyserver2 --> Keys : retrieves
+
+Source --> B1
+Source --> B2
+
+B1 --> A1
+B2 --> A2
+
+A1 --> Log : Checksum
+A2 --> Log : Checksum
+
+A1 --> Ledger : Checksum
+A2 --> Ledger : Checksum
+
+Tag --> Source
+
+Net --> User
+Attacker -[#Red]-> B1 : compromises
+Attacker -[#Red]-> Net : controls
+Attacker -[#Red]-> Tag : compromises private key
+'// Commiter1 --> Tag : generates valid signature
+'// Commiter2 --> Tag : generates valid signature
+
+
+User --> Rebuild
+User --> Log
+Keys --> Policy
+Rebuild --> Policy
+Policy --> User : ACCEPT / REJECT
+@enduml