Modeling Trust in Enterprise Architecture: A Pattern Language for ArchiMate

I use the patterns develop in this paper to model trust relationships (trust boarders, trust anchors) in Zero Trust Architectures.

As an example, I model the process of Downloading an NetBSD ISO Install Image, which has been signed by the NetBSD security officer with a detached GnuPG signature. This is SLSA Level 1 according to the »Supply-chain Levels for Software Artifacts«

I will extend the process from SLSA Level 1 to SLSA Level 4, which will include Reproducible Builds and an immutable linked list of hashes in concatenated Merkle trees.

Archimate Diagrams

Example from Paper

Applied to the NetBSD download

:6-3a.svg

:6-3c.svg

:8-7a-Trust-Composition.svg

:8-7-GnuPG-Trust-Composition.svg

:RSO9-10-RiskSecurityOverlay.svg

:RSO9-10-GnuPG-RiskSecurityOverlay.svg

:9-9-RiskAssessmentPattern.svg

:9-9-GnuPG-RiskAssessmentPattern.svg

:9-9-GnuPG-RiskAssessmentPattern2.svg

:9-9-GnuPG-RiskAssessmentPattern3.svg