# VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs **VeriSBOM**, a trustless, selectively disclosed SBOM framework that provides cryptographic verifiability of SBOMs using zero-knowledge proofs. Within VeriSBOM, third parties can validate specific statements about a delivered software, mainly regarding the authenticity of the dependencies and policy compliance, without inspecting the content of an SBOM. Respectively, VeriSBOM allows independent third parties to verify if a software contains authentic dependencies distributed by official package managers and that the same dependencies satisfy rigorous policy constraints such as the absence of vulnerable dependencies or the adherence with specific licenses models. ## Key Features * **Selective Disclosure (Hiding):** Choose which proprietary components to hide from the public SBOM. The system generates a cryptographic proof that replaces the plaintext data, guaranteeing privacy. * **High-Performance Folding:** Powered by **Nova-Scotia**, utilizing recursive SNARKs to handle SBOMs. * **Interactive Dashboard:** A complete 4-step workflow (Package Manager, Auditor, Vendor, Client) built with **Streamlit**. ## Repository structure The repository contains three main folders: 1. **Empirical**: contains **Benchmarking** and **src**, for the analysis and source code, respectively. 2. **User study**: contains the code and results of the user study. 3. **README_Doc**: contains the images used for this documentation. ## VeriSBOM Architecture The system is divided into four main roles: 1. **Package Manager**: Maintains the package repository with the allowed packages. 2. **Auditor:** Represents the regulatory body marking the compliance status by checking the packages of the package manager. 3. **Software Vendor:** Represents the entity that provides software artefacts and wants to hide the related SBOMs for privacy reasons. He is responsible for the generation of the cryptographic proofs as verifiable substitutes of the hidden packages in SBOMs. 4. **Client:** The end-user who receives the cryptographic proofs along with the software artefact for verifying binding, inclusion and compliance status. ## Web Access (Recommended) **For direct access to the artefact, VeriSBOM can be accessed at this public link** https://verisbom-verisbom-software.hf.space ## Setup & Installation Follow the README within the artefact ## Operational Workflow The application follows a **linear workflow** composed of four steps. Each step depends on the output generated in the previous one. > **Performance Note** Due to the cryptographic operations involved, generating proofs may take some time depending on the number and complexity of the active policy constraints. In the current reference environment, proof generation takes approximately **~5 seconds**, while verification takes around **~3 seconds per proof**. ## Step 1 — Package Manager In this step, the **Package Manager initialises the package repository**. ### Instructions 1. Open the **Package Manager** tab. 2. Click **`Load repository`**. > For convenience, the system automatically loads a **default repository containing packages from the NPM ecosystem**. ### Expected Output After successful execution: - A **green confirmation message** is displayed. - The **package list** appears on the left panel. - The **dependencies of each package** can be inspected on the right panel using the search bar. - A **dependency graph** is displayed at the bottom of the interface. ## Step 2 — Auditor In this step, the **Auditor defines policy constraints** that will be applied to the packages in the repository. ### Instructions 1. Enter a **policy name** (e.g., `Vulnerabilities`, `MIT License`). 2. Click **`Add`** to create the policy constraint. 3. Use the **search bar** to locate target packages. 4. **Uncheck packages** to mark them as **non-compliant**. > By default, **all packages are marked as compliant**. 5. Click **`Save and Propagate`** to apply the policy. ### Optional - Repeat the previous steps to create additional policy constraints. - Remove policies that are no longer required. ### Expected Output - A **green confirmation message** appears. - A **dependency graph visualisation** shows how non-compliance propagates across dependencies for the selected policy (or combination of policies). ## Step 3 — Software Vendor In this step, the **Software Vendor generates cryptographic proofs for a given SBOM**. ### Instructions 1. Upload a **local SBOM file**. > For demonstration purposes, the system automatically loads an **example SBOM**. 2. In the **Selective Disclosure** section: - Select which SBOM packages should be used for proof generation. 3. Click **`Generate Proofs`**. 3. Click **`Download`**. - Download the SBOM with hidden components and plaintext components ### Expected Output - A **progress bar** indicates the proof generation process. - **Green confirmation messages** appear once proofs are generated successfully. > **Important:** Successful proof generation only means that the **cryptographic proof has been constructed correctly**. Compliance with policies is verified only in **Step 4**. ## Step 4 — Client In the final step, the **Client verifies the proofs generated by the vendor**. ### Instructions 1. Upload the **SBOM**. 2. Select a **policy** from the dropdown menu. 3. Click **`Verify`**. ### Expected Output - **Verified (green badge)** The SBOM satisfies the selected policy. - **Failed (red badge)** The verification failed, and the interface displays the reason for the failure.
Zero-knowledge virtual machine (zkVM) is a powerful infrastructure for proving the correctness of a program execution with a succinct proof, attracting significant interest from researchers, developers, and users. It has been widely used in applications such as blockchain rollups, privacy-preserving machine learning, and off-chain computation. As the field grows, a wide range of zkVMs have been proposed. However, they adopt different choices in instruction formats, trace layouts, and proving backends, which results in a highly heterogeneous design landscape and makes it difficult to understand the relations among these systems.To bridge this gap, we provide a comprehensive study of zkVMs that covers both their theoretical foundations and practical implementations. We decompose zkVMs into three layers: (1) the ISA layer, which defines instruction semantics and determines the structure of the execution trace, (2) the VM layer, which captures program execution and organizes constraints through modular circuit components, and (3) the proving layer, which converts execution traces into algebraic constraints and generates the final proofs. This decomposition allows us to isolate the role of each layer while also examining how they interact in real systems. To give readers a more direct understanding of how these design choices affect performance, scalability, and usability, we conduct a comprehensive experimental evaluation of representative zkVMs following this layered framework. Finally, we conclude the paper by summarizing the main observations from our analysis and outlining several potential directions for zkVM design and implementation.
Tatami puzzles are pencil puzzles with an objective to partition a rectangular grid into rectangular regions such that no four regions share a corner point, as well as satisfying other constraints. In this paper, we develop a physical card-based protocol called Tatami printer that can help verify solutions of Tatami puzzles. We then use the Tatami printer to construct zero-knowledge proof protocols for two such puzzles: Tatamibari and Square Jam. These protocols enable a prover to show a verifier the existence of the puzzles' solutions without revealing them.
Frances Liddell, Ella Tallyn, Evan Morgan, Kar Balan · 10 authors
In this work-in-progress, we present ORAgen, as ‘unfinished software’, materialised through a demonstrative web application that enables participants to engage with a novel approach to media tokenisation – the ORA framework. By presenting ORAgen in ‘think-aloud’ interviews with 17 professionals working in the creative and cultural industries, we explore potential values of media tokenisation in relation to existing challenges they face related to ownership, rights, and attribution. From our initial findings, we reflect specifically on the challenges of attribution and ongoing control of creative media, and examine how media tokenisation, and underpinning distributed ledger technologies can enable new approaches to designing attribution.
Through two experiments with volumetric and one experiment with edible Non-Fungible Tokens (NFTs) conducted between 2021 and 2022, we will discuss the limits of “assetization” and engagement with speculative future and value. Assetization is a process of claiming or generating “future” value that creates various (not only economic) expectations and incentives. To capture the novel aesthetic expectations and experiences beyond assetization, we will focus on the edge cases, such as edible NFTs and also NFTs related to large volumetric (mesh) data. How can fringe NFTs mitigate some of the negative effects of commodification and market speculation? Our use cases show that a major barrier for assetization and tokenization of alternative and novel values, impacts, and goals are the closed data and software silos, but also the user-unfriendly interfaces for interacting with the blockchain infrastructure. Instead of creating new markets and media ecosystems that generate new sources of income for the creators, NFTS still transform cultural artifacts into speculative investments with detrimental effects.
Open access
Additive Manufacturing and 3D Printing Technologies
Part of the recent developments in Ubiquitous Music (ubimus) research involve the proposal of the Internet of Musical Stuff (IoMuSt) as an expansion and complement to the Internet of Musical Things (IoMusT). The transition from IoMusT to IoMuSt entails a critique of blockchain and non-fungible tokens (NFTs) as technologies for allotment, disciplination and regimentation of formerly open and freely accessible artistic web content. In brief, the replacement of the operative concepts constructed around “things” with strategies based on “stuff ” highlights the underlying interconnected processes and factors that impact interaction and usage, pointing to resources that become disposable and valueless within an objectified and monetized musical internet. This conceptual and methodological turn allows us to deal with distributed-creativity phenomena in marginalized spaces, highlighting the role of resources that are widely reproducible, fluid and ever-changing. In this paper, we address IoMuSt-based responses to issues such as the artificial production of scarcity associated with the application of NFTs. The selected musical examples showcase the meshwork of dynamic relationships that characterizes ubimus research. In particular, we focus on a comprovisation project involving VOIP visual communication through Skype, Meet and Zoom, a ubimus experience involving a Telegram chatbot and a set of musical experiments enabled by an online tool for remote live patching.
Fahad Alam, Mohamed Elsherif, Bader AlQattan, Ahmed E. Salih · 8 authors
Although the manufacturing processes of contact lenses are well established, the use of additive manufacturing for their fabrication opens many new possibilities to explore. The current study demonstrates the fabrication of personalized smart contract lenses utilizing additive manufacturing. The study includes 3-dimensional (3D) modeling of contact lenses with the assistance of a computer aided designing tool based on standard commercial contact lens dimension, followed by the selection of the suitable materials and 3D printing of contact lenses. The 3D printing parameters were optimized to achieve the desired lens geometries, and a post processing treatment was performed to achieve a smooth surface finish. The study also presents functionalized contact lenses with built-in sensing abilities by utilizing microchannels at the contact lens edges. Tinted contact lenses were printed and nanopatterns were textured onto the contact lens surfaces through holographic laser ablation. 3D printed contact lenses have advantages over conventional contact lenses, offering customized ophthalmic devices and the capability to integrate with optical sensors for diagnostics.
Huaxin Wang, Joris S. M. Vergeest, Jan Miedema, Frank Meijer · 6 authors
Synthetic environment equipped with user interfaces intuitive for direct 3D shape modification by non-designer stake-holders was proposed as a collaboration tool for design concept communication in dynamic prototyping of product design in early stages of the design process. After a survey of 3D user interaction techniques for SE, a simple user interface with hierarchical visual menu was proposed and a proof-of-concept implementation of it was tested to be intuitive with experiment, which serves as a base for further study to verify the hypothetical benefits of SE aided dynamic prototyping in terms of communication efficiency and accuracy.
🥇 ProtectedPool ➤ Web3 Smart DeFi Wallet 🔐 . Your New DeFi Experience:: 🔐 Secure, Smart, Simple. Double Approvals. Add extra confirmation of any transaction with 2FA solutions including Google Authenticator or hardware security keys. Self-custodial Solutions. Protected Pool is built on smart contracts that interact with wallets, not persons or companies. A new wallet - a new smart-contract. Zero Trust Protocol. No one can be trusted unless verified. Your wallet is the only way to get access to your funds.