From 0c7f33663339ffeab917443901a07914ff58709b Mon Sep 17 00:00:00 2001 From: stefan Date: Sat, 21 Feb 2026 21:32:50 +0100 Subject: GnuPG Signature modelliert, Innentäter begonnen MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- PlantUML-ModelingTrust/index.html | 1448 ++++++++++++++++++++++--------------- 1 file changed, 870 insertions(+), 578 deletions(-) (limited to 'PlantUML-ModelingTrust/index.html') diff --git a/PlantUML-ModelingTrust/index.html b/PlantUML-ModelingTrust/index.html index e2906d4..9f9b0bb 100644 --- a/PlantUML-ModelingTrust/index.html +++ b/PlantUML-ModelingTrust/index.html @@ -1,578 +1,870 @@ - - - - - - - - -Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate - - - - - -
-
-

Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate

-
-
- -
-
-

I use the patterns develop in this paper to model trust relationships (trust boarders, trust anchors) in Zero Trust Architectures.

-
-
-

As an example, I model the process of Downloading an NetBSD ISO Install Image, which has been signed by the NetBSD security officer with a detached GnuPG signature. This is SLSA Level 1 according to the »Supply-chain Levels for Software Artifacts«

-
-
-

I will extend the process from SLSA Level 1 to SLSA Level 4, which will include Reproducible Builds and an immutable linked list of hashes in concatenated Merkle trees.

-
-
-
-
-

Archimate Diagrams

-
- ----- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Example from PaperApplied to the NetBSD download
-
-6 3a -
-
-
-6 3c -
-
-
-8 7a Trust Composition -
-
-
-8 7 GnuPG Trust Composition -
-
-
-RSO9 10 RiskSecurityOverlay -
-
-
-RSO9 10 GnuPG RiskSecurityOverlay -
-
-
-9 9 RiskAssessmentPattern -
-
-
-9 9 GnuPG RiskAssessmentPattern -
-
-
-
-
- - - \ No newline at end of file + + + + + + +Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate + + + + + +
+
+

Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate

+
+
+

I use the patterns develop in this paper to model trust relationships (trust boarders, trust anchors) in Zero Trust Architectures.

+

As an example, I model the process of Downloading an NetBSD ISO Install Image, which has been signed by the NetBSD security officer with a detached GnuPG signature. This is SLSA Level 1 according to the »Supply-chain Levels for Software Artifacts«

+

I will extend the process from SLSA Level 1 to SLSA Level 4, which will include Reproducible Builds and an immutable linked list of hashes in concatenated Merkle trees.

+
+
+
+

Archimate Diagrams

+
+
+ ++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Example from Paper

Applied to the NetBSD download

+:6-3a.svg +

+:6-3c.svg +

+:8-7a-Trust-Composition.svg +

+:8-7-GnuPG-Trust-Composition.svg +

+:RSO9-10-RiskSecurityOverlay.svg +

+:RSO9-10-GnuPG-RiskSecurityOverlay.svg +

+:9-9-RiskAssessmentPattern.svg +

+:9-9-GnuPG-RiskAssessmentPattern.svg +

+:9-9-GnuPG-RiskAssessmentPattern2.svg +

+:9-9-GnuPG-RiskAssessmentPattern3.svg +

+
+
+
+
+

+ + + -- cgit v1.2.3