[论文解读] A Survey on Mapping Digital Systems with Bill of Materials: Development, Practices, and Challenges
本综述对软件、硬件、AI、数据和加密资产的物料清单(BOM)发展进行了跨领域的综述,总结了演变、实践、用途和研究差距。
Modern digital ecosystems, spanning software, hardware, learning models, datasets, and cryptographic products, continue to grow in complexity, making it difficult for organizations to understand and manage component dependencies. Bills of Materials (BOMs) have emerged as a structured way to document product components, their interrelationships, and key metadata, improving visibility and security across digital supply chains. This survey provides the first comprehensive cross-domain review of BOM developments and practices. We start by examining the evolution of BOM frameworks in three stages (i.e., pre-development, initial, and accelerated) and summarizing their core principles, key stakeholders, and standardization efforts for hardware, software, artificial intelligence (AI) models, datasets, and cryptographic assets. We then review industry practices for generating BOM data, evaluating its quality, and securely sharing it. Next, we review practical downstream uses of BOM data, including dependency modeling, compliance verification, operational risk assessment, and vulnerability tracking. We also discuss academic efforts to address limitations in current BOM frameworks through refinements, extensions, or new models tailored to emerging domains such as data ecosystems and AI supply chains. Finally, we identify four key gaps that limit the usability and reliability of today's BOM frameworks, motivating future research directions.
研究动机与目标
- 追溯BOM概念自硬件到数字生态系统的历史与现状演变。
- 概括软件、硬件、AI、数据与加密资产领域的BOM实践、标准及采用情况。
- 分析BOM数据的生成、质量与共享实践。
- 识别当前BOM框架的局限性和差距,以推动未来研究方向。
提出的方法
- 对Google Scholar、ACM DL、IEEE Xplore与arXiv进行系统性文献检索,目标为SBOM、CBOM、AIBOM、HBOM和SaaSBOM。
- 提供自2020年以来跨领域的BOM发展、标准与行业采用的综合性要点。
- 描述BOM演进的三阶段(开发前、初始、加速),并绘制领域特定的标准与框架映射。
- 总结在安全、合规与风险评估中的实用BOM数据生成、管理与使用情况。
- 讨论学术界为在AI、数据生态系统和物联等新兴领域改进或扩展BOM模型的努力。
实验结果
研究问题
- RQ1BOM框架在软件、硬件、AI模型与数据集、加密资产以及SaaS等领域的历史与现状发展是什么?
- RQ2行业实践如何生成、验证和共享BOM数据,哪些因素影响数据质量与可用性?
- RQ3BOM数据在依赖建模、合规、风险评估和漏洞跟踪中的实际用途有哪些?
- RQ4当前BOM框架存在哪些差距,未来方向如何应对新兴领域与挑战?
主要发现
- BOM框架已从以硬件为中心发展为覆盖SBOM、CBOM、AIBOM、HBOM和SaaSBOM的跨领域方案。
- 在2021年后,监管与标准化活动加速,SBOM(如SPDX、CycloneDX)及对AI、硬件、SaaS和密码学的领域扩展逐步形式化。
- 行业实践强调数据质量、共享与可用性,同时凸显跨工具与生态系统的完整性与一致性问题。
- 四个关键差距限制当前BOM的可用性与可靠性:对AI和数据生态系统的覆盖、标准化的数据共享、运行时与来源追溯、以及对动态环境的可扩展性。
- 学术界提出扩展模型、增强元数据以及运行时/构建时追踪以克服元数据的局限性。
- 目前正在探索在不访问源代码的前提下生成BOM数据的工作,以及通过域特定字段(隐私、安全、密码学、来源可追溯性)来增强BOM。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。