This thesis describes the curricular internship carried out at the Research and Development department of Zucchetti S.p.A., focused on the security analysis of RVC, a distributed version control system developed internally by the company. At the time of the internship, the use of cryptography and file signing to guarantee the authenticity and integrity of changes had been planned at an architectural level but not yet implemented, and it had not been verified whether the design covered all relevant cases. The work involved analysing the system, simulating attack scenarios to identify its gaps, and defining a formal security model specifying the guarantees to be met. The model was then implemented in the source code and verified by repeating the same simulations on the updated version. At the end of the internship, a distributed infrastructure prototype was developed, consisting of multiple interconnected servers, for the secure exchange of data between nodes.
Questo elaborato descrive il tirocinio curricolare svolto presso il reparto Ricerca e Sviluppo di Zucchetti S.p.A., dedicato all'analisi della sicurezza di RVC, un sistema di versionamento distribuito sviluppato internamente all'azienda. Al momento del tirocinio, l'uso di crittografia e firma dei file per garantire autenticità e integrità delle modifiche era stato pianificato a livello architetturale ma non ancora implementato, né era stato verificato se la progettazione coprisse tutti i casi rilevanti. Il lavoro ha consistito nell'analizzare il sistema, simulare scenari di attacco per individuarne le lacune e definire un modello di sicurezza formale che specificasse le garanzie da soddisfare. Il modello è stato poi implementato nel codice sorgente e verificato ripetendo le stesse simulazioni sulla versione aggiornata. A completamento del tirocinio è stato realizzato un prototipo di infrastruttura distribuita, composta da più server collegati fra loro, per la distribuzione sicura dei dati tra i nodi della rete.
Analisi di sicurezza e integrità crittografica di un sistema di versionamento distribuito
STEVANIN, MICHELE
2025/2026
Abstract
This thesis describes the curricular internship carried out at the Research and Development department of Zucchetti S.p.A., focused on the security analysis of RVC, a distributed version control system developed internally by the company. At the time of the internship, the use of cryptography and file signing to guarantee the authenticity and integrity of changes had been planned at an architectural level but not yet implemented, and it had not been verified whether the design covered all relevant cases. The work involved analysing the system, simulating attack scenarios to identify its gaps, and defining a formal security model specifying the guarantees to be met. The model was then implemented in the source code and verified by repeating the same simulations on the updated version. At the end of the internship, a distributed infrastructure prototype was developed, consisting of multiple interconnected servers, for the secure exchange of data between nodes.| File | Dimensione | Formato | |
|---|---|---|---|
|
tesi.pdf
accesso aperto
Dimensione
3.01 MB
Formato
Adobe PDF
|
3.01 MB | Adobe PDF | Visualizza/Apri |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/111065