Uptane Standard for Design and Implementation, Version 2.1.0¶
Uptane Alliance. Uptane Standard for Design and Implementation, Version 2.1.0.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Domain-specific¶
- Uptane
- Standard 2.1.0 deliberately leaves wire encoding, cryptographic algorithm choices, transport, implementation language, storage design, and many deployment decisions open
This sourceUptane Alliance (formerly under IEEE-ISTO; now hosted by the Linux Foundation's Joint Development Foundation). The Standard's own text disclaims mandating implementation details, wire encoding/format, or specific technology choices, leaving them to implementers. The Standard's own role definitions for Root, Targets, Snapshot, and Timestamp match this description of each role's binding responsibility. The Standard's Out of Scope section explicitly excludes supply-chain compromise (build system, version control, packaging process) and malware embedded in an already-trusted package. The Standard describes POUFs as recording implementation choices outside its abstract core, but never itself spells out the acronym; the expansion comes from Moore et al. (2020), not this document. Both halves of this threat-model bound are the Standard's own explicit attacker-capability assumptions (Section 4.2), stated in exactly this parallel form.
- Standard 2.1.0 deliberately leaves wire encoding, cryptographic algorithm choices, transport, implementation language, storage design, and many deployment decisions open
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:6b858de17666 · see in the full table