Trustworthy and Confidential SBOM Exchange

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ishgair, Eman Abu, Okafor, Chinenye, Melara, Marcela S., Torres-Arias, Santiago
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914387279740928
author Ishgair, Eman Abu
Okafor, Chinenye
Melara, Marcela S.
Torres-Arias, Santiago
author_facet Ishgair, Eman Abu
Okafor, Chinenye
Melara, Marcela S.
Torres-Arias, Santiago
contents Software Bills of Materials (SBOMs) have become a regulatory requirement for improving software supply chain security and trust by means of transparency regarding components that make up software artifacts. However, enterprise and regulated software vendors commonly wish to restrict who can view confidential software metadata recorded in their SBOMs due to intellectual property or security vulnerability information. To address this tension between transparency and confidentiality, we propose Petra, an SBOM exchange system that empowers software vendors to interoperably compose and distribute redacted SBOM data using selective encryption. Petra enables software consumers to search redacted SBOMs for answers to specific security questions without revealing information they are not authorized to access. Petra leverages a format-agnostic, tamper-evident SBOM representation to generate efficient and confidentiality-preserving integrity proofs, allowing interested parties to cryptographically audit and establish trust in redacted SBOMs. Exchanging redacted SBOMs in our Petra prototype requires less than 1 extra KB per SBOM, and SBOM decryption accounts for at most 1% of the performance overhead during an SBOM query
format Preprint
id arxiv_https___arxiv_org_abs_2509_13217
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Trustworthy and Confidential SBOM Exchange
Ishgair, Eman Abu
Okafor, Chinenye
Melara, Marcela S.
Torres-Arias, Santiago
Cryptography and Security
Software Bills of Materials (SBOMs) have become a regulatory requirement for improving software supply chain security and trust by means of transparency regarding components that make up software artifacts. However, enterprise and regulated software vendors commonly wish to restrict who can view confidential software metadata recorded in their SBOMs due to intellectual property or security vulnerability information. To address this tension between transparency and confidentiality, we propose Petra, an SBOM exchange system that empowers software vendors to interoperably compose and distribute redacted SBOM data using selective encryption. Petra enables software consumers to search redacted SBOMs for answers to specific security questions without revealing information they are not authorized to access. Petra leverages a format-agnostic, tamper-evident SBOM representation to generate efficient and confidentiality-preserving integrity proofs, allowing interested parties to cryptographically audit and establish trust in redacted SBOMs. Exchanging redacted SBOMs in our Petra prototype requires less than 1 extra KB per SBOM, and SBOM decryption accounts for at most 1% of the performance overhead during an SBOM query
title Trustworthy and Confidential SBOM Exchange
topic Cryptography and Security
url https://arxiv.org/abs/2509.13217