Skip to content
Conference

SMT: SBOM and Merkle Tree Based Integrity Verification for Serverless Environments

Jul 2026 · International Conference on Ubiquitous and Future Networks · pp. 1182-1187 · 0 citations · 12 references

Abstract

Serverless computing environments are vulnerable to software supply chain attacks due to their heavy reliance on external libraries. However, existing integrity verification methods are centered on runtime execution logs, which limits their ability to directly detect tampering with function code and dependencies. In this paper, we propose an integrity verification framework that combines a Software Bill of Materials (SBOM) with a Merkle Tree, hereafter referred to as an SMT scheme. By utilizing SBOMs within the CI/CD (Continuous Integration/Continuous Delivery) pipeline, the SMT scheme establishes a trusted baseline at deployment time. Furthermore, it verifies both code and runtime integrity by correlating runtime execution logs with corresponding SBOM hash values. Experimental results demonstrate that the SMT scheme effectively detects code and dependency tampering attacks while incurring only a modest overhead of approximately 5–10% relative to existing method.

View source

Similar papers

Preprint Sep 2026

TPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux

TPM-Attest is presented, a hardware-rooted remote attestation framework that uses the Trusted Platform Module (TPM) 2.0 and the Linux Integrity Measurement Architecture (IMA) to prove, cryptographically, that a client booted cleanly and ran only authorised software -- without any kernel driver, without proprietary code...

Anudeep Gedela, A. Technology, Gitam University et al. · 0 citations
Preprint Aug 2026

Securing Filesystems for Confidential Computing

Evaluation with standard filesystem benchmarks and real-world workloads shows that ShieldZFS provides strong integrity and freshness guarantees with performance comparable to state-of-the-art filesystems.

Dimitra Giantsidi, A. Delignat-Lavaud, C. Fournet et al. · 0 citations
Preprint Sep 2026

Session Attestation for Unmodified TLS Services in Confidential Virtual Machines

Confidential cloud services aim to protect sensitive requests from the infrastructure that executes them. However, running a service inside a trusted execution environment does not ensure that users'plaintext appears only within the protected environment. We formulate Endpoint-Substitution Relay (ESR), a common attack...

Qi Gu, Wen-Mao Liu, Wei-Jing You et al. · 0 citations
#small language model Book Oct 2026

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Wen-Yu Xu, Anders Møller · 0 citations
Preprint Sep 2026

SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)

Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalid...

Shi-Xin Song, Davide Davoli, Elias Storme et al. · 0 citations
Review Sep 2026

Scaling Verification of Cryptographic Software with Aeneas, Rust, and Lean

This work develops a new methodology for verifying cryptographic software and extends SymCrypt with experimental optimizations and implementations of algorithms such as FrodoKEM, ML-DSA, and HPKE to explore the scalability of writing, adapting, and verifying cryptographic code.

Ho Son, C. Fournet, Jonathan Protzenko et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.