arXiv:2609.21419v1 Announce Type: cross Abstract: Software Bills of Materials (SBOMs) have emerged as a key mechanism for software supply chain governance in enterprise architectures. However, their adoption across organizations remains limited due to concerns about exposing sensitive dependency information. To address this limitation, we propose TrustBOM, a scalable architecture for confidential

Topological visualization of TrustBOM: A Scalable Architecture for Confidentiality-Preserving SBOMs Across Organizations
Brave API

TrustBOM is a scalable, confidentiality-preserving architecture for Software Bills of Materials (SBOMs) that allows providers to verify compliance without exposing proprietary dependency graphs. It utilizes zero-knowledge non-membership proofs over a Sparse Merkle Tree to attest that specific vulnerabilities or restricted licenses are absent from the software.

The system decouples SBOM commitment from verification, enabling constraint-linear scalability where proof generation time depends on the number of policy constraints rather than the SBOM size. Empirical results show an average proof generation time of 0.9 seconds per constraint on commodity hardware, with costs remaining constant regardless of the underlying dependency count.

A key limitation is that the cryptographic proof attests to the committed SBOM representation rather than the actual deployed software artifact; a malicious provider could theoretically commit a clean SBOM but deploy different, non-compliant software. This gap suggests TrustBOM should be paired with out-of-band artifact integrity checks, such as Trusted Execution Environment (TEE) remote attestation, for end-to-end supply chain security.

Generated 13d ago
Open-Weights Reasoning

TrustBOM addresses a central obstacle to broader SBOM adoption: the tension between supply-chain transparency and the confidentiality of dependency information. SBOMs are increasingly important for vulnerability triage, provenance tracking, compliance, and enterprise software governance, but organizations often resist sharing them because they can reveal sensitive details about internal components, vendor relationships, dependency versions, and architectural choices. The paper positions this confidentiality concern as a design problem rather than an inherent limitation, proposing a scalable architecture that enables SBOMs to be used across organizational boundaries without requiring full disclosure.

The key contribution is an architecture for confidentiality-preserving SBOMs that supports cross-organizational governance at enterprise scale. Rather than treating SBOMs as either fully public artifacts or purely internal documents, TrustBOM appears to introduce controlled trust boundaries and selective disclosure mechanisms that allow participants to verify, correlate, or act on SBOM data while protecting sensitive dependency details. The emphasis on scalability suggests that the design is intended to accommodate large, heterogeneous enterprise environments where many organizations, components, and policy constraints must coexist.

This matters because SBOM utility depends on sharing, but sharing is often blocked by legitimate confidentiality concerns. If TrustBOM can enable coordinated vulnerability response, due diligence, and compliance checks without exposing competitive or operational secrets, it could make cross-organizational SBOM ecosystems more practical and politically feasible. More broadly, the work is relevant to software supply-chain security, provenance governance, and the design of trust frameworks that balance transparency with data minimization.

Generated 13d ago
Sources