Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain

📅 2025-10-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Centralized package registries (e.g., PyPI, npm) strengthen security controls, yet their authority collapses at distribution boundaries—including mirrors, corporate proxies, repackaging, and air-gapped transfers—rendering them insufficient for source authentication, integrity assurance, and accountability. Method: This paper proposes a trust extension model tailored to modern software distribution, formally characterizing the necessity and adaptability requirements of cryptographic signing across mirrors, proxies, and offline environments; it evaluates the synergistic defensive efficacy of centralized registries and end-to-end signing through historical practice and trust boundary theory. Contribution/Results: We establish software signing as a foundational trust primitive that transcends registry-level governance, providing a verifiable, traceable, and auditable technical basis for cross-boundary trusted distribution—thereby enabling robust provenance verification, tamper-evident integrity, and enforceable accountability across heterogeneous deployment contexts.

Technology Category

Data Mining & Knowledge Management: Representing, Reasoning, and Using Provenance, TrustMultiagent Systems: Distributed Problem SolvingApplication Domains: Security

Application Category

Security and Privacy: Blockchains and distributed ledgersWeb Mining and Content Analysis: Web data provenance, reliability, and authenticitySystems and Infrastructure for Web, Mobile and WoT: Decentralized Web and Fediverse systems
📝 Abstract
Software signing provides a formal mechanism for provenance by ensuring artifact integrity and verifying producer identity. It also imposes tooling and operational costs to implement in practice. In an era of centralized registries such as PyPI, npm, Maven Central, and Hugging Face, it is reasonable to ask whether hardening registry security controls obviates the need for end-to-end artifact signing. In this work, we posit that the core guarantees of signing, provenance, integrity, and accountability are not automatically carried across different software distribution boundaries. These boundaries include mirrors, corporate proxies, re-hosting, and air-gapped transfers, where registry security controls alone cannot provide sufficient assurance. We synthesize historical practice and present a trust model for modern distribution modes to identify when signing is necessary to extend trust beyond registry control. Treating signing as a baseline layer of defense strengthens software supply chain assurance even when registries are secure.
Problem

Research questions and friction points this paper is trying to address.

Software signing ensures artifact integrity and verifies producer identity
Registry security alone cannot guarantee trust across distribution boundaries
Signing provides essential defense layer for software supply chain assurance
Innovation

Methods, ideas, or system contributions that make the work stand out.

Software signing ensures artifact integrity and producer identity
Signing extends trust beyond centralized registry security controls
Treating signing as baseline defense strengthens supply chain assurance
K
Kelechi G. Kalu
Purdue University
J
James C. Davis
Purdue University