{"id":"https://openalex.org/W4399667984","doi":"https://doi.org/10.1145/3661167.3661212","title":"An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management","display_name":"An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management","publication_year":2024,"publication_date":"2024-06-14","ids":{"openalex":"https://openalex.org/W4399667984","doi":"https://doi.org/10.1145/3661167.3661212"},"language":"en","primary_location":{"id":"doi:10.1145/3661167.3661212","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3661167.3661212","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3661167.3661212?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3661167.3661212?download=true","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5013716682","display_name":"Nguyen Khoi Tran","orcid":"https://orcid.org/0000-0002-9538-7476"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"The University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Nguyen Khoi Tran","raw_affiliation_strings":["CREST, The University of Adelaide, Australia"],"raw_orcid":"https://orcid.org/0000-0002-9538-7476","affiliations":[{"raw_affiliation_string":"CREST, The University of Adelaide, Australia","institution_ids":["https://openalex.org/I5681781"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009445234","display_name":"Samodha Pallewatta","orcid":"https://orcid.org/0000-0002-5342-9551"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"The University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Samodha Pallewatta","raw_affiliation_strings":["CREST, The University of Adelaide, Australia"],"raw_orcid":"https://orcid.org/0000-0002-5342-9551","affiliations":[{"raw_affiliation_string":"CREST, The University of Adelaide, Australia","institution_ids":["https://openalex.org/I5681781"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103075476","display_name":"Muhammad Ali Babar","orcid":"https://orcid.org/0000-0001-9696-3626"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"The University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Muhammad Ali Babar","raw_affiliation_strings":["CREST, The University of Adelaide, Australia and Cyber Security Cooperative Research Centre, Australia"],"raw_orcid":"https://orcid.org/0000-0001-9696-3626","affiliations":[{"raw_affiliation_string":"CREST, The University of Adelaide, Australia and Cyber Security Cooperative Research Centre, Australia","institution_ids":["https://openalex.org/I5681781"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5013716682"],"corresponding_institution_ids":["https://openalex.org/I5681781"],"apc_list":null,"apc_paid":null,"fwci":2.0241,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.88795122,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"38","last_page":"47"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10703","display_name":"Business Process Modeling and Analysis","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1404","display_name":"Management Information Systems"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10703","display_name":"Business Process Modeling and Analysis","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1404","display_name":"Management Information Systems"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10679","display_name":"Service-Oriented Architecture and Web Services","score":0.993399977684021,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11891","display_name":"Big Data and Business Intelligence","score":0.9919999837875366,"subfield":{"id":"https://openalex.org/subfields/1404","display_name":"Management Information Systems"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/metadata","display_name":"Metadata","score":0.7718403339385986},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.711419939994812},{"id":"https://openalex.org/keywords/reference-architecture","display_name":"Reference architecture","score":0.5647165179252625},{"id":"https://openalex.org/keywords/software-architecture","display_name":"Software architecture","score":0.4883684515953064},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.45272189378738403},{"id":"https://openalex.org/keywords/supply-chain","display_name":"Supply chain","score":0.4446370601654053},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.44114723801612854},{"id":"https://openalex.org/keywords/supply-chain-management","display_name":"Supply chain management","score":0.4327365458011627},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.42391863465309143},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.34967803955078125},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.34307539463043213},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.16338101029396057},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.1414830982685089}],"concepts":[{"id":"https://openalex.org/C93518851","wikidata":"https://www.wikidata.org/wiki/Q180160","display_name":"Metadata","level":2,"score":0.7718403339385986},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.711419939994812},{"id":"https://openalex.org/C55356503","wikidata":"https://www.wikidata.org/wiki/Q2136675","display_name":"Reference architecture","level":4,"score":0.5647165179252625},{"id":"https://openalex.org/C35869016","wikidata":"https://www.wikidata.org/wiki/Q846636","display_name":"Software architecture","level":3,"score":0.4883684515953064},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.45272189378738403},{"id":"https://openalex.org/C108713360","wikidata":"https://www.wikidata.org/wiki/Q1824206","display_name":"Supply chain","level":2,"score":0.4446370601654053},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.44114723801612854},{"id":"https://openalex.org/C44104985","wikidata":"https://www.wikidata.org/wiki/Q492886","display_name":"Supply chain management","level":3,"score":0.4327365458011627},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.42391863465309143},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.34967803955078125},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.34307539463043213},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.16338101029396057},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.1414830982685089},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3661167.3661212","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3661167.3661212","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3661167.3661212?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3661167.3661212","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3661167.3661212","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3661167.3661212?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.46000000834465027,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320315885","display_name":"Australian Government","ror":"https://ror.org/0314h5y94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4399667984.pdf","grobid_xml":"https://content.openalex.org/works/W4399667984.grobid-xml"},"referenced_works_count":14,"referenced_works":["https://openalex.org/W1975675278","https://openalex.org/W1982098236","https://openalex.org/W1985045902","https://openalex.org/W2013437002","https://openalex.org/W2055504431","https://openalex.org/W2087133653","https://openalex.org/W2128200145","https://openalex.org/W2200491502","https://openalex.org/W3000417117","https://openalex.org/W4308562555","https://openalex.org/W4316829841","https://openalex.org/W4365136957","https://openalex.org/W4366818484","https://openalex.org/W6739592249"],"related_works":["https://openalex.org/W2983500849","https://openalex.org/W3024999678","https://openalex.org/W388184414","https://openalex.org/W2026811664","https://openalex.org/W1583260306","https://openalex.org/W2053107757","https://openalex.org/W2017266164","https://openalex.org/W1152672851","https://openalex.org/W1552148294","https://openalex.org/W2354797847"],"abstract_inverted_index":{"With":[0],"the":[1,17,34,105,120,134,191,200,214],"rapid":[2],"rise":[3],"in":[4,33,118],"Software":[5,68],"Supply":[6,69],"Chain":[7,70],"(SSC)":[8],"attacks,":[9],"organisations":[10,62],"need":[11],"thorough":[12],"and":[13,28,51,94,112,129,150,170,196,212],"trustworthy":[14],"visibility":[15,45],"over":[16],"entire":[18],"SSC":[19,38,48,59,86,125,172,187],"of":[20,36,77,85,107,124,146,180,184,216],"their":[21],"software":[22,78],"inventory":[23],"to":[24,42,63,104,115],"detect":[25],"risks":[26],"early":[27],"identify":[29],"compromised":[30],"assets":[31],"rapidly":[32],"event":[35],"an":[37,55,99,139,151,164,181,204],"attack.":[39],"One":[40],"way":[41],"achieve":[43],"such":[44,89],"is":[46,101,160],"through":[47],"metadata,":[49],"machine-readable":[50],"authenticated":[52],"documents":[53,88],"describing":[54],"artefact\u2019s":[56],"lifecycle.":[57],"Adopting":[58],"metadata":[60,87,126],"requires":[61],"procure":[64],"or":[65,97],"develop":[66],"a":[67,75,108,147],"Metadata":[71],"Management":[72],"system":[73],"(SCM2),":[74],"suite":[76],"tools":[79,189],"for":[80,154,207],"performing":[81],"life":[82],"cycle":[83],"activities":[84],"as":[90,203],"creation,":[91],"signing,":[92],"distribution,":[93],"consumption.":[95],"Selecting":[96],"developing":[98],"SCM2":[100,155,210,218],"challenging":[102],"due":[103],"lack":[106],"comprehensive":[109],"domain":[110,148],"model":[111,149],"architectural":[113,152,182],"blueprint":[114,153],"aid":[116],"practitioners":[117],"navigating":[119],"vast":[121],"design":[122],"space":[123],"terminologies,":[127],"frameworks,":[128],"solutions.":[130],"This":[131],"paper":[132],"addresses":[133],"above-mentioned":[135],"challenge":[136],"by":[137],"presenting":[138],"empirically":[140],"grounded":[141],"Reference":[142],"Architecture":[143],"(RA)":[144],"comprising":[145],"systems.":[156,219],"Our":[157,175],"proposed":[158,201],"RA":[159,202],"constructed":[161],"systematically":[162],"on":[163,190],"empirical":[165],"foundation":[166],"built":[167],"with":[168],"industry-driven":[169],"peer-reviewed":[171],"security":[173,188],"frameworks.":[174],"theoretical":[176],"evaluation,":[177],"which":[178],"consists":[179],"mapping":[183],"five":[185],"prominent":[186],"RA,":[192],"ensures":[193],"its":[194],"validity":[195],"applicability,":[197],"thus":[198],"affirming":[199],"effective":[205],"framework":[206],"analysing":[208],"existing":[209],"solutions":[211],"guiding":[213],"engineering":[215],"new":[217]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-12T06:13:28.667946","created_date":"2025-10-10T00:00:00"}
