Skip to main navigation Skip to search Skip to main content

Supply Chain Security of Critical Infrastructure Protection Software Blueprints: Deployment Aspects

  • Djibrilla Amadou Kountche*
  • , Meisam Gordan
  • , Manh Dung Nguyen
  • , Efstathios Zavvos
  • , Jocelyn Aubert
  • , Daniel McCrum
  • , Mona Soroudi
  • , Lorcan Connolly
  • , Stefan Schauer
  • , Jose Carlos Carrasco
  • , Nicola Gregorio Durante
  • , Marisa Escalante Martinez
  • , Zisis Palaskas
  • , Páraic Caroll
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Cloud Computing (CC) technologies are gradually being used in the Operational Technologies (OT) of Critical InfrastructuresCritical Infrastructures (CI) (CI) which enables the use of the concept of blueprint introduced in the previous chapter. This chapter explores the practical deployment and management of blueprintsBlueprints in CIs. It also explores mechanisms to secure the supply chainSupply chainof Critical Infrastructure ProtectionCritical Infrastructure Protection (CIP) (CIP) assets using Software Bills of Material (SBOM)Software Bills Of Materials (SBOM)and DevSecOpsDevSecOps. More specifically this chapter details: i) the enabling technologies of the concept of blueprint such as the support of virtualization in safety critical systems and the virtualization of OT; ii) Software Bills of Material tools such as CycloneDXCycloneDXand SPDXSystem Package Data Exchange (SPDX) used in software supply chainSupply chain security; and iii) the application of these technologies for the deployments of key software building blocks used in CIP and the support of software supply chain security in DevSecOps pipelines. Finally, this chapter presents our new prototype on CIP blueprintsBlueprints deployment and its description using Topology and Orchestration Specification for Cloud Applications (TOSCA)Topology and Orchestration Specification for Cloud Applications (TOSCA) Service Templates (STs) as well as our approach to include software supply chain protection mechanism in the blueprints.

Original languageEnglish
Title of host publicationSignals and Communication Technology
PublisherSpringer Science and Business Media Deutschland GmbH
Pages59-85
Number of pages27
DOIs
Publication statusPublished - 2026

Publication series

NameSignals and Communication Technology
VolumePart F1412
ISSN (Print)1860-4862
ISSN (Electronic)1860-4870

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Keywords

  • Blueprints
  • Critical infrastructures
  • CycloneDX
  • DevSecOps
  • SBOM
  • SPDX
  • TOSCA

Fingerprint

Dive into the research topics of 'Supply Chain Security of Critical Infrastructure Protection Software Blueprints: Deployment Aspects'. Together they form a unique fingerprint.

Cite this