{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:5VJZ5QVI22TXCJ5HR62FGV4WB7","short_pith_number":"pith:5VJZ5QVI","canonical_record":{"source":{"id":"2211.13195","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-23T18:28:39Z","cross_cats_sorted":[],"title_canon_sha256":"cd5e594a733dd44d0c9113c340355b0119146884157fda2bdb08fe3da2fb4930","abstract_canon_sha256":"e08a36a492f8fa2a6855ddd6faa3292fa3195d8ecb3b8cf9878826265567aa5c"},"schema_version":"1.0"},"canonical_sha256":"ed539ec2a8d6a77127a78fb45357960fec02c5602391e4ef9cec84587bdf2877","source":{"kind":"arxiv","id":"2211.13195","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2211.13195","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"arxiv_version","alias_value":"2211.13195v1","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2211.13195","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_12","alias_value":"5VJZ5QVI22TX","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_16","alias_value":"5VJZ5QVI22TXCJ5H","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_8","alias_value":"5VJZ5QVI","created_at":"2026-07-05T05:18:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:5VJZ5QVI22TXCJ5HR62FGV4WB7","target":"record","payload":{"canonical_record":{"source":{"id":"2211.13195","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-23T18:28:39Z","cross_cats_sorted":[],"title_canon_sha256":"cd5e594a733dd44d0c9113c340355b0119146884157fda2bdb08fe3da2fb4930","abstract_canon_sha256":"e08a36a492f8fa2a6855ddd6faa3292fa3195d8ecb3b8cf9878826265567aa5c"},"schema_version":"1.0"},"canonical_sha256":"ed539ec2a8d6a77127a78fb45357960fec02c5602391e4ef9cec84587bdf2877","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:18:59.306540Z","signature_b64":"r9O18IVh5KhN35C9Vhx4HUI2oM76YuhnzhBV/JqX3T6BJWO9Vt/ldBWKI4dsgKjKEDsj+e7bywsHHuxt31oOCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ed539ec2a8d6a77127a78fb45357960fec02c5602391e4ef9cec84587bdf2877","last_reissued_at":"2026-07-05T05:18:59.306155Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:18:59.306155Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2211.13195","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T05:18:59Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vkaGp8d8wMHYX0KBENF0h3iBRhlXQYVYBI89+t19RoVx6e96Y6hKkyrTXcqWV8sKlmnwFTTQLEylZknWvlFcCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-10T14:42:51.348943Z"},"content_sha256":"ac63abe13c3d35022db79baf3f1b092e0ec2be8e547e9ac27932e34e28e7e0e3","schema_version":"1.0","event_id":"sha256:ac63abe13c3d35022db79baf3f1b092e0ec2be8e547e9ac27932e34e28e7e0e3"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:5VJZ5QVI22TXCJ5HR62FGV4WB7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Privacy-Preserving Application-to-Application Authentication Using Dynamic Runtime Behaviors","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Maliheh Shirvanian, Mihai Christodorescu, Shams Zawoad","submitted_at":"2022-11-23T18:28:39Z","abstract_excerpt":"Application authentication is typically performed using some form of secret credentials such as cryptographic keys, passwords, or API keys. Since clients are responsible for securely storing and managing the keys, this approach is vulnerable to attacks on clients. Similarly a centrally managed key store is also susceptible to various attacks and if compromised, can leak credentials. To resolve such issues, we propose an application authentication, where we rely on unique and distinguishable application's behavior to lock the key during a setup phase and unlock it for authentication. Our system"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2211.13195","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2211.13195/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T05:18:59Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IQLY9TaWGW+8vKjDpZsmZbUubjtsIDFCoC8SnjbKmTf8uGsvqgum6mN5BErdWhMPJx2KasjfzfBDeBF8D42CBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-10T14:42:51.349668Z"},"content_sha256":"d88f02ea077ad335b8cf69656102e3f40b01369b378ec01029bd357e6e38f2e2","schema_version":"1.0","event_id":"sha256:d88f02ea077ad335b8cf69656102e3f40b01369b378ec01029bd357e6e38f2e2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/bundle.json","state_url":"https://pith.science/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-10T14:42:51Z","links":{"resolver":"https://pith.science/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7","bundle":"https://pith.science/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/bundle.json","state":"https://pith.science/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/5VJZ5QVI22TXCJ5HR62FGV4WB7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:5VJZ5QVI22TXCJ5HR62FGV4WB7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e08a36a492f8fa2a6855ddd6faa3292fa3195d8ecb3b8cf9878826265567aa5c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-23T18:28:39Z","title_canon_sha256":"cd5e594a733dd44d0c9113c340355b0119146884157fda2bdb08fe3da2fb4930"},"schema_version":"1.0","source":{"id":"2211.13195","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2211.13195","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"arxiv_version","alias_value":"2211.13195v1","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2211.13195","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_12","alias_value":"5VJZ5QVI22TX","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_16","alias_value":"5VJZ5QVI22TXCJ5H","created_at":"2026-07-05T05:18:59Z"},{"alias_kind":"pith_short_8","alias_value":"5VJZ5QVI","created_at":"2026-07-05T05:18:59Z"}],"graph_snapshots":[{"event_id":"sha256:d88f02ea077ad335b8cf69656102e3f40b01369b378ec01029bd357e6e38f2e2","target":"graph","created_at":"2026-07-05T05:18:59Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2211.13195/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Application authentication is typically performed using some form of secret credentials such as cryptographic keys, passwords, or API keys. Since clients are responsible for securely storing and managing the keys, this approach is vulnerable to attacks on clients. Similarly a centrally managed key store is also susceptible to various attacks and if compromised, can leak credentials. To resolve such issues, we propose an application authentication, where we rely on unique and distinguishable application's behavior to lock the key during a setup phase and unlock it for authentication. Our system","authors_text":"Maliheh Shirvanian, Mihai Christodorescu, Shams Zawoad","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-23T18:28:39Z","title":"Privacy-Preserving Application-to-Application Authentication Using Dynamic Runtime Behaviors"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2211.13195","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ac63abe13c3d35022db79baf3f1b092e0ec2be8e547e9ac27932e34e28e7e0e3","target":"record","created_at":"2026-07-05T05:18:59Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e08a36a492f8fa2a6855ddd6faa3292fa3195d8ecb3b8cf9878826265567aa5c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-23T18:28:39Z","title_canon_sha256":"cd5e594a733dd44d0c9113c340355b0119146884157fda2bdb08fe3da2fb4930"},"schema_version":"1.0","source":{"id":"2211.13195","kind":"arxiv","version":1}},"canonical_sha256":"ed539ec2a8d6a77127a78fb45357960fec02c5602391e4ef9cec84587bdf2877","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ed539ec2a8d6a77127a78fb45357960fec02c5602391e4ef9cec84587bdf2877","first_computed_at":"2026-07-05T05:18:59.306155Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T05:18:59.306155Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"r9O18IVh5KhN35C9Vhx4HUI2oM76YuhnzhBV/JqX3T6BJWO9Vt/ldBWKI4dsgKjKEDsj+e7bywsHHuxt31oOCg==","signature_status":"signed_v1","signed_at":"2026-07-05T05:18:59.306540Z","signed_message":"canonical_sha256_bytes"},"source_id":"2211.13195","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ac63abe13c3d35022db79baf3f1b092e0ec2be8e547e9ac27932e34e28e7e0e3","sha256:d88f02ea077ad335b8cf69656102e3f40b01369b378ec01029bd357e6e38f2e2"],"state_sha256":"c0ffc5bddd81d73bdc1030c2296a0963474e420bc71529563d1d1adffe5bd231"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mqRPD+kuNEB0wiknOjX6fDQQGqzp1qbF4qN+wJYC8GR1nc4ae6WwOVg+PZmEidupNt/P12l7ZRETtKMwmcQiBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-10T14:42:51.353450Z","bundle_sha256":"e5e659bc9aed9e2097103330caeccabb5b9f1e67adbde6377e17220538c252d8"}}