Loading…
May 21, 2026 | Minneapolis, Minnesota, USA
Learn More and Register To Attend
Schedule is subject to change.

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day NA 2026. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.












Thursday May 21, 2026 3:10pm - 3:25pm CDT
Software Bills of Materials are central to improving transparency and trust in modern software supply chains. However, organizations often hesitate to share complete SBOMs due to intellectual property or security concerns. This challenge is amplified in multi-tier supply chains, where SBOMs are routinely redistributed across vendors.
We present Petra, a system that enables confidential and policy-bounded SBOM exchange without sacrificing verifiability.
Petra allows producers to selectively encrypt sensitive SBOM metadata while preserving structural integrity and enabling authorized consumers to search redacted SBOMs for answers to specific security questions without revealing information they are not authorized to access. Importantly, Petra supports controlled redistribution: SBOMs can be shared across organizational boundaries while cryptographically enforcing downstream access restrictions.
We discuss selective disclosure for real-world SPDX and CycloneDX SBOMs, cryptographically verifiable redactions, and practical deployment considerations. Through a demo, attendees will see how Petra enables secure SBOM sharing that supports transparency and compliance without oversharing.
Speakers
avatar for Marcela Melara

Marcela Melara

Research Scientist, Intel Corporation
Marcela Melara is a research scientist at Intel making distributed and cloud systems more trustworthy. Her current work focuses on developing solutions for high-integrity software and AI supply chains. She leads a number of internal, academic and open-source projects on supply chain... Read More →
avatar for Eman Abu Ishgair

Eman Abu Ishgair

Graduate Research Assistant, Purdue University
PhD candidate in ECE @ Purdue, working on software supply chain security
Thursday May 21, 2026 3:10pm - 3:25pm CDT
101E

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link