arrow
Return

A Hyperledger Fabric-Based SBOM Management System for Secure Software Supply Chain Integrity

delete2026-06-11
delete0
delete
OA
AI
G
Geunhee Cho
Y
Yoomin Go
M
Mihui Kim *
DOI:10.3390/electronics15122573delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Recently, there has been an increasing prevalence of software supply chain attacks on software component suppliers. These attacks have targeted suppliers with relatively weak security or they have exploited vulnerabilities in open-source software. The software bill of materials (SBOM) has gained significant attention as a mechanism for improving software supply chain transparency and traceability. In this study, we propose an SBOM distribution architecture based on Hyperledger Fabric, which is a permissioned blockchain platform, to facilitate secure SBOM management. This approach utilizes Hyperledger Fabric private data collections (PDCs) to separate SBOM metadata from sensitive component information, thereby enabling confidential data sharing while reducing the blockchain storage overhead compared to a fully on-chain approach. The proposed PDC-based architecture achieves lower latency and higher throughput than the fully on-chain approach under the evaluated workload conditions, while supporting integrity verification and controlled sharing of sensitive component data.
Keywords:
software bill of materials
hyperledger fabric
software supply chain attacks

Journal

Electronics cover
Electronics
IF:
2.6
Papers:
9.3K
Citations:
4.7W

Organization

Hankyong National University cover
Hankyong National University
Scholars:
812
Papers: 1.0K
Citations: 759