Software Bill of Materials (SBOM) serves as a critical pillar in ensuring software supply chain security by providing a detailed inventory of the components and dependencies integral to software development. However, challenges abound in the sharing of SBOMs, including potential data tampering and hesitation among software vendors to disclose comprehensive information. These obstacles have stifled widespread adoption and utilization of SBOMs, underscoring the need for a more secure and flexible mechanism for SBOM sharing. This study proposes a novel solution to these challenges by introducing a blockchain-empowered architecture for SBOM sharing, leveraging verifiable credentials to allow for selective disclosure. This strategy not only heightens security but also offers flexibility. Furthermore, this paper broadens the remit of SBOM to encompass AI systems, thereby coining the term AI Bill of Materials (AIBOM). This extension is motivated by the rapid progression in AI technology and the escalating necessity to track the lineage and composition of AI software and systems. The evaluation of our solution indicates the feasibility and flexibility of the proposed SBOM sharing mechanism, positing a new solution for securing (AI) software supply chains.
翻译:软件物料清单(SBOM)通过提供软件开发所涉及的组件与依赖项的详细清单,成为保障软件供应链安全的关键支柱。然而,SBOM的共享面临诸多挑战,包括潜在的数据篡改风险以及软件供应商对披露全面信息的犹豫不决。这些障碍抑制了SBOM的广泛采用与利用,凸显了构建更安全、更灵活的SBOM共享机制的必要性。本研究针对上述挑战提出了一种创新解决方案,通过引入基于区块链的SBOM共享架构,利用可验证凭证实现选择性披露。该策略不仅增强了安全性,还提升了灵活性。此外,本文进一步拓展了SBOM的适用范围以涵盖人工智能系统,从而首次提出“人工智能物料清单”(AIBOM)这一术语。这一扩展源于AI技术的迅猛发展以及追踪AI软件与系统来源及构成的日益迫切需求。实验评估表明,所提出的SBOM共享机制具有可行性与灵活性,为保障(AI)软件供应链安全提供了一种新的解决方案。