Repository accompanying the poster/proposal by Jiarou Deng, Yang Yang (Johns Hopkins University), and Michael Rushanan (Harbor Labs). Special thanks to Dorian Liu for contributions.
This repo contains preliminary code and artifacts supporting topics discussed in the proposal and poster.
- Whats in this Repo
- Quickstart
- Reproducing Results
- Artifacts
- Citation
- Contributions
- Responsible Use
- License
- Contact
Health and Medical Security (HMS) lab research projects organize tools and data with implications beyond the research poster in their own top-level directories. The artifacts directory includes code and data relevant to the poster and reproducibility of the research. The paper directory contains a LaTeX clone of the poster proposal, written in Overleaf. The poster directory contains the camera-ready poster clone, made in Microsoft PowerPoint.
├── artifacts/ # Reproduction steps, intermediate outputs, figures
│ ├── figures/ # Figures generated externally to Draw.io
├── paper/ # LaTeX source for the manuscript
└── poster/ # PowerPoint source for the poster
The poster and analysis in this repository represent preliminary work; therefore, we do not release in-progress research artifacts.
Our analysis is considered preliminary; therefore, we do not share any in-progress results other than those in artifacts/figures.
We captured our artifacts in the ./artifacts directory.
@inproceedings{deng-yang-rushanan-acsac-2025-zk-sbom,
author = {Jiarou Deng and Yang Yang and Michael Rushanan},
title = {A Zero-Knowledge Framework for Confidential and Verifiable {SBOM} Validation},
booktitle = {Proceedings of the Annual Computer Security Applications Conference (ACSAC 2025)},
note = {Poster}
location = {Honolulu, Hawaii, USA},
date = {2025-12-11},
year = {2025},
publisher = {IEEE},
url = {https://www.acsac.org/2025/program/posters}
}Research posters facilitate academic networking and collaboration. While we do not directly support contributions to this poster, we welcome engagement and feedback. Please get in touch with the authors listed below to discuss potential contributions, including insights related to:
- Input Normalization Challenges: SBOMs often include inconsistent naming conventions, varying version formats (including scoped ranges like <2.1.3), and pre-release identifiers. Existing pipelines (including ours) apply minimal normalization (e.g., basic parsing, CPE mapping) and conservatively flag ambiguous cases. Feedback on more advanced or alternative normalization methods would be valuable.
- Scalability of ZKP Verification: Efficient verification over large SBOMs (thousands of components) remains critical. Our approach uses batch proofs, Merkle forests, RSA accumulators, and compact systems like Groth16. Comparative insights or related work on scaling ZKPs in similar high-volume verification contexts are welcome.
- Updatability and Point-in-Time Validation: With vulnerability databases updating hourly, our system binds proofs to specific snapshot timestamps and supports reissuance via incremental roots. We invite perspectives on maintaining temporal correctness and update efficiency in evolving ecosystems.
- Adoption and Trust Models: Determining responsibility for generating, verifying, and trusting ZKP attestations poses organizational and governance challenges. We encourage insights on deployment models, incentives, and trust frameworks for secure supply chain verification.
- Research use only: This repository should be for research only.
See LICENSE.md.
Please contact Dr. Michael Rushanan, the principal investigator, for any reason not described above.