Attestation-Based SBOM Integrity Verification for Secure and Transparent Software Supply Chains
JungA Kim, Yiseul Choi, Seongmin Kim · 2025
Ensuring the integrity of the Software Bill of Materials (SBOM) is a growing challenge in securing the software supply chain. SBOMs are critical for identifying software components and managing dependencies, but recent studies have shown that automated generation tools often produce incomplete or inaccurate results. Existing integrity verification methods focus solely on post-generation tampering detection and cannot confirm authenticity at creation time. To address these limitations, We propose a novel SBOM integrity verification framework inspired by remote attestation protocol, embedding metadata during SBOM generation. This enables verification of both SBOM content and the trustworthiness of its creator. To improve completeness, outputs from heterogeneous SBOM standards are generated in parallel and merged to fill missing components. We demonstrate that our method enhances transparency and tamper detection in software supply chains with case studies.