← All blockchain use cases

Verify software builds in a tamper-proof manner

Sector: Tertiary sector · Industry: IT security · Organisation: Microsoft · Maturity level: Production

Microsoft records production builds of selected cloud services in a publicly accessible and cryptographically protected ledger. Only software builds registered in this registry are permitted to be deployed to the production systems of the relevant cloud infrastructure. Customers and independent auditors can use public verification tooling to independently validate the integrity and provenance of software artifacts.

Documentation status

Description

Microsoft relies on the Signing Transparency Ledger, a tamper-proof register, to make the origin and correctness of cloud software publicly verifiable. In modern IT, unnoticed interventions in development and build pipelines represent one of the greatest security risks for companies. By linking cryptographic proofs to strict rollout policies, it is ensured that unverified software cannot be executed in practice.

With the Microsoft Signing Transparency (MST) initiative, Microsoft addresses the trust issue in the software supply chain at its root. Production builds of selected cloud services are automatically recorded in an append-only ledger based on the Confidential Consortium Framework and the Azure Confidential Ledger. The implementation follows the standards of the IETF SCITT working group to ensure cross-vendor interoperability. Deployment in the production environments of the respective services is technically blocked if there is no valid entry in the ledger for the respective build artefact. Customers and independent auditors have the opportunity to validate the cryptographic chain completely via open verification tools without needing to view confidential source codes.

Perspectives

B2B — organisations perspective

Companies using cloud services can independently verify with this technology whether the executed software exactly matches the approved state. This reduces audit efforts and facilitates compliance with strict regulatory requirements in critical industries.

B2C — consumers perspective

End users indirectly benefit from a more stable and better-protected cloud infrastructure, as the risk of tampering through manipulated software updates is minimised.

Employees perspective

Development teams work within an infrastructure that secures builds through automated cryptographic anchoring. This noticeably reduces the administrative effort for manual signature checks and deployment approvals.

Benefits

General

B2B — organisations

Employees

Challenges

General

B2B — organisations

Employees

Technology foundation

The solution is based on Azure Confidential Ledger and the Confidential Consortium Framework using SCITT standards (Supply Chain Integrity, Transparency, and Trust) for a tamper-proof append-only register.

Implementation examples

Microsoft Signing Transparency for cloud services

Companies face the problem that conventional signatures do not provide transparency about when, by whom, and under what conditions a build was created and signed, which favours supply chain attacks.

Microsoft has transitioned Microsoft Signing Transparency, a tamper-proof public register for software builds, into production. Only artefacts recorded in the register may be deployed for selected cloud services.

As part of the Microsoft Signing Transparency project, Microsoft implemented an SCITT-compliant register based on Azure Confidential Ledger and the Confidential Consortium Framework. The system securely records signature events and build identifiers of selected cloud services in a tamper-proof append-only data structure. Production systems enforce via standardised policies that versions not recorded in the ledger are rejected, while customers gain access to public proofs through audit tools.

Prevention of unnoticed manipulation of binary files and elimination of non-transparent software distribution processes in global cloud infrastructures.

Tags

Software Supply Chain, Confidential Computing, Integrity Verification, IT Compliance, Transparency

Sources

  1. About Microsoft's Signing Transparency Ledger
  2. Microsoft Leads a New Era of Software Supply Chain Transparency