Skip to content

Latest commit

 

History

11 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

A Zero-Knowledge Framework for Confidential and Verifiable SBOM Validation

Repository accompanying the poster/proposal by Jiarou Deng, Yang Yang (Johns Hopkins University), and Michael Rushanan (Harbor Labs). Special thanks to Dorian Liu for contributions.

This repo contains preliminary code and artifacts supporting topics discussed in the proposal and poster.

Table of Contents

Whats in this Repo

Health and Medical Security (HMS) lab research projects organize tools and data with implications beyond the research poster in their own top-level directories. The artifacts directory includes code and data relevant to the poster and reproducibility of the research. The paper directory contains a LaTeX clone of the poster proposal, written in Overleaf. The poster directory contains the camera-ready poster clone, made in Microsoft PowerPoint.

├── artifacts/         # Reproduction steps, intermediate outputs, figures
│   ├── figures/       # Figures generated externally to Draw.io
├── paper/             # LaTeX source for the manuscript
└── poster/            # PowerPoint source for the poster

Quickstart

The poster and analysis in this repository represent preliminary work; therefore, we do not release in-progress research artifacts.

Reproducing Results

Our analysis is considered preliminary; therefore, we do not share any in-progress results other than those in artifacts/figures.

Artifacts

We captured our artifacts in the ./artifacts directory.

Citation

@inproceedings{deng-yang-rushanan-acsac-2025-zk-sbom,
  author    = {Jiarou Deng and Yang Yang and Michael Rushanan},
  title     = {A Zero-Knowledge Framework for Confidential and Verifiable {SBOM} Validation},
  booktitle = {Proceedings of the Annual Computer Security Applications Conference (ACSAC 2025)},
  note      = {Poster}
  location  = {Honolulu, Hawaii, USA},
  date      = {2025-12-11},
  year      = {2025},
  publisher = {IEEE},
  url       = {https://www.acsac.org/2025/program/posters}
}

Contributions

Research posters facilitate academic networking and collaboration. While we do not directly support contributions to this poster, we welcome engagement and feedback. Please get in touch with the authors listed below to discuss potential contributions, including insights related to:

  1. Input Normalization Challenges: SBOMs often include inconsistent naming conventions, varying version formats (including scoped ranges like <2.1.3), and pre-release identifiers. Existing pipelines (including ours) apply minimal normalization (e.g., basic parsing, CPE mapping) and conservatively flag ambiguous cases. Feedback on more advanced or alternative normalization methods would be valuable.
  2. Scalability of ZKP Verification: Efficient verification over large SBOMs (thousands of components) remains critical. Our approach uses batch proofs, Merkle forests, RSA accumulators, and compact systems like Groth16. Comparative insights or related work on scaling ZKPs in similar high-volume verification contexts are welcome.
  3. Updatability and Point-in-Time Validation: With vulnerability databases updating hourly, our system binds proofs to specific snapshot timestamps and supports reissuance via incremental roots. We invite perspectives on maintaining temporal correctness and update efficiency in evolving ecosystems.
  4. Adoption and Trust Models: Determining responsibility for generating, verifying, and trusting ZKP attestations poses organizational and governance challenges. We encourage insights on deployment models, incentives, and trust frameworks for secure supply chain verification.

Responsible Use

  • Research use only: This repository should be for research only.

License

See LICENSE.md.

Contact

Please contact Dr. Michael Rushanan, the principal investigator, for any reason not described above.

About

A Zero-Knowledge Framework for Confidential and Verifiable SBOM Validation

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages