Ilmu Komputer & AI editorial
Open AccessOA2026
TrustBOM: A Scalable Architecture for Confidentiality-Preserving SBOMs Across Organizations
Zero-knowledge non-membership proofs enable selective SBOM attestation without revealing dependency graphs
Van Thang Nguyen; Frederic Rupprecht; Tom Lawrence; Lucca Di Benedetto; Sören Schubert; Amor Rezgui; Sebastian Werner; Maria C. Borges; Stefan Tai· 2026· DOI 10.48550/arXiv.2609.21419
The core problem
Software Bills of Materials (SBOMs) have emerged as a key mechanism for software supply chain governance in enterprise architectures. However, their adoption across organizations remains limited due to concerns about exposing sensitive dependency information. This paper addresses that limitation by proposing TrustBOM, a scalable architecture for confidentiality-preserving SBOMs integrated into enterprise CI/CD workflows. TrustBOM enables software providers to attest that specific vulnerabilities or restricted licenses are absent from their software without revealing the underlying dependency graph. The approach is grounded in zero-knowledge non-membership proofs, applied selectively based on consumer-defined policy constraints. The architecture is designed to ensure that proof generation scales linearly with the number of asserted constraints rather than with the size of the SBOM, enabling efficient operation in large-scale enterprise environments.
Innovation
Empirical evaluation demonstrates linear performance, with an average proof generation time of 0.9 seconds per constraint on commodity hardware. This linear scaling confirms that proof generation grows with the number of asserted constraints rather than with the size of the SBOM. The measured performance indicates the feasibility of deployment in enterprise platform ecosystems, where SBOMs can be large and constraints numerous. The results support the central architectural claim: confidentiality-preserving attestation can be practical when proofs are scoped to consumer-defined policy constraints. The evaluation focuses on proof generation time as the primary metric, with commodity hardware representing realistic enterprise deployment conditions.
Software Bills of Materials (SBOMs) have emerged as a key mechanism for software supply chain governance in enterprise architectures. However, their adoption across organizations remains limited due to concerns about exposing sensitive dependency information. This paper addresses that limitation by proposing TrustBOM, a scalable architecture for confidentiality-preserving SBOMs integrated into enterprise CI/CD workflows. TrustBOM enables software providers to attest that specific vulnerabilities or restricted licenses are absent from their software without revealing the underlying dependency graph. The approach is grounded in zero-knowledge non-membership proofs, applied selectively based on consumer-defined policy constraints. The architecture is designed to ensure that proof generation scales linearly with the number of asserted constraints rather than with the size of the SBOM, enabling efficient operation in large-scale enterprise environments.
TrustBOM integrates into existing enterprise CI/CD pipelines to produce and verify confidentiality-preserving SBOM attestations. The core cryptographic primitive is a zero-knowledge non-membership proof: a provider proves that a given element (e.g., a vulnerable package or restricted license) is not present in its dependency set, without disclosing the set itself. Proofs are generated selectively according to consumer-defined policy constraints, so only the properties required by a consumer are attested. The architecture separates proof generation from SBOM size by structuring proofs around the number of asserted constraints. Formally, if is the set of asserted constraints and is the SBOM dependency set, the proof system demonstrates for each constraint that while revealing no additional information about . The expected proof generation cost is therefore rather than , which is the key scalability property. The system is intended for deployment in enterprise platform ecosystems where multiple organizations exchange attestations under heterogeneous policies.
Why it matters
The linear scaling of proof generation with respect to the number of constraints, rather than SBOM size, addresses a fundamental tension in supply chain governance: organizations need visibility into dependency risks but are reluctant to expose sensitive dependency graphs. By enabling selective attestation of absence—whether of specific vulnerabilities or restricted licenses—TrustBOM allows providers to satisfy consumer policies without full disclosure. This selective approach aligns with enterprise CI/CD workflows, where policy constraints are defined by consumers and enforced through automated verification. The 0.9 seconds per constraint average on commodity hardware suggests that even policy sets with dozens of constraints remain operationally tractable. The architecture's reliance on zero-knowledge non-membership proofs provides a cryptographic foundation for trust across organizational boundaries, potentially lowering adoption barriers for SBOMs in enterprise architectures. Future work may explore broader policy languages, proof aggregation, and integration with existing SBOM formats and vulnerability databases.
Who should read this
CS practitioners and researchers
Opening member content…