1. Mechanism
A device participating in the disclosed architecture carries a governance secure element and a software bill of materials that enumerates the software components installed on the device. The bill of materials is carried in the device's lineage and is verified by a software-bill-of-materials attestation verifier as part of system hardening. Verification chains the device-to-manufacturer attestation through the manufacturing-provenance chain evaluator, so that the bill of materials is bound to a credentialed source identification rather than reported as an unattested inventory.
The verified bill of materials is emitted as a governance-credentialed observation: a record carrying a credentialed source identification, the attested software composition, and the cryptographic attestation binding the observation to the emitting device. Downstream consumers admit this governance-credentialed observation into the five-property governance chain, where it is subject to evidential weighting in the shared observation store alongside other supply-chain-health observations.
The software bill of materials is carried in device lineage to enable per-component vulnerability tracking. When the software composition changes, the change is recorded through the supply-chain-health lineage recorder and re-enters the chain as a fresh governance-credentialed observation, so that downstream consumers can evaluate the changed composition against composite admissibility. The supply-chain-health lineage recorder composes with continuous firmware-integrity monitoring and with governance-credentialed firmware update, which admits firmware only with credentialed authority signatures validated against prior firmware-hash history.
Each governance-credentialed observation carries the authority credential, a temporal-scope specification of the credential's validity period, a device-binding attestation binding the credential to the emitting device, and a cryptographic attestation produced under a digital-signature, threshold-signature, zero-knowledge, post-quantum, or equivalent cryptographic mechanism. The authority-credential format is not limited to a single primitive; any equivalent cryptographic primitive capable of carrying the governance-chain attestation is within scope. Lineage-recorded provenance links each observation, evaluation, and action through deterministic lineage across the architecture, supporting per-device stream-level analysis by downstream consumers.
2. Operating Parameters
Per-component vulnerability tracking operates against the bill of materials carried in device lineage. The software composition recorded for each device supports matching against governance-credentialed advisory observations admitted through the chain, so that an affected component can be associated with the devices that carry it. Match results enter the chain as governance-credentialed observations subject to composite admissibility evaluation rather than as standalone alerts.
Credential revocation is treated structurally. A credentialing authority emits a revocation governed observation identifying a specific device, a specific credential, or a specific credential class as no longer authoritative. Each consuming device down-weights or invalidates previously-admitted governed mesh messages emitted under the revoked credential, in accordance with a governance-policy-defined retroactive-effect window that specifies the duration of past emissions subject to the revocation. A device whose credential has been revoked is ineligible to emit governed mesh messages under the revoked authority context. Revocation propagates to downstream consumers through the lineage-recorded provenance of the chain, so that prior decisions made under the now-revoked authority can be re-evaluated.
The bill-of-materials observation is admitted alongside other supply-chain-health observations and is weighted in the shared governed observation store by authority, sensing-modality reliability, and inter-source consistency. The disclosure does not fix a particular serialization, transport size, or storage budget; the format of the carried composition is governed by the architecture's technology-neutrality doctrine rather than by a hard-coded encoding.
Cryptographic parameters are governance-declared rather than hard-coded. The cryptographic attestation binding an observation to its emitting device may be produced under a digital-signature, threshold-signature, zero-knowledge, or post-quantum mechanism, and a quantum governance secure element provides post-quantum-cryptographic primitives for long-term assurance. The authority-credential lifecycle supports enrollment, rotation, and revocation of governance credentials, so that credential and authority transitions remain verifiable by relying parties across the transition.
Aggregation, when applied, is governed rather than ad hoc. Higher-authority observations are processed before lower-authority observations during admission-queue saturation through authority-weighted prioritization, and rate-limiting at the composite admissibility evaluator throttles contributors that exceed governance-policy-defined per-source rate envelopes. The per-device observation stream is preserved as a lineage-recorded record so that aggregated outputs reference the underlying per-device observations through the lineage property of the chain.
3. Alternative Embodiments
A constrained-device embodiment relies on a hardened device-to-manufacturer attestation chain verified through the manufacturing-provenance chain evaluator, with the bill of materials carried in lineage and firmware integrity tracked through continuous firmware-integrity monitoring rather than full process-set introspection. Per-component vulnerability tracking is performed off-device by a downstream consumer that holds the bill of materials on behalf of the constrained device.
A server-class embodiment integrates the bill-of-materials attestation verifier with continuous firmware-integrity monitoring and with hardware-attested secure enclaves, so that the verification path runs inside an attested isolated execution environment. Each change in software composition re-enters the chain as a governance-credentialed observation.
A federated embodiment composes per-device supply-chain-health observations into composite fleet-health observations. A downstream consumer aggregates the per-device observations through governance-policy-defined summary functions and admits the composite observation without exposing the underlying per-device telemetry. The architecture is agnostic to whether attestation happens on-device, in a gateway, or in a federated aggregator, provided the governance-credentialed-observation interface is honored at each layer.
A privacy-preserving embodiment uses zero-knowledge binding, wherein the bound pair is verifiable without revealing the underlying composition, so that the device can demonstrate that its bill of materials satisfies a relying party's admissibility predicate without revealing the component list itself. This embodiment supports regulated industries in which the operator must demonstrate compliance to an auditor while withholding inventory detail from competitive disclosure. The proof is itself a governance-credentialed observation, bound to the emitting device through the cryptographic attestation of the chain.
4. Composition With Five-Property Chain
The bill of materials enters the chain as an authority-credentialed observation carrying a credentialed source identification. It is subject to evidential weighting in the shared governed observation store, weighted by authority, sensing-modality reliability, and inter-source consistency; to composite admissibility evaluation across the dispositional, integrity, confidence, and capability fields before admission; and to lineage-recorded provenance that links the observation, its evaluation, and any resulting action through deterministic lineage. Where physical actuation is implicated, governed actuator execution requires composite admissibility approval. Credential revocation is honored through revocation governed observations propagated by the lineage property of the chain.
Bill-of-materials observations compose with other supply-chain-health observations. A device whose composition is current but whose tamper-evident seal observation is failing is admissible for fewer downstream decisions than one with both signals nominal; a device carrying a component associated with an admitted advisory observation may be subject to elevated thresholds until the composition changes and re-enters the chain. The architecture exposes these composition rules through governance-policy-defined admissibility evaluation rather than as hard-coded device behavior, so that the same device can serve different downstream consumers with different risk tolerances.
Composition with the manufacturing-provenance chain strengthens provenance. The bill-of-materials attestation verifier composes with the manufacturing-provenance chain evaluator that verifies the device-to-manufacturer attestation chain, so that the lineage captures provenance from manufacturer attestation through deployment to runtime supply-chain-health observation. Any compromise discovered at any layer can be propagated through credential revocation to all derived observations.
Composition with incident-response workflows exposes the bill of materials as a structured input to forensic analysis. The per-device supply-chain-health observation stream provides a lineage-recorded timeline of software state across the affected fleet; investigators query the stream to identify which devices carried a suspect component during the incident window. The same query infrastructure supports matching against advisory observations admitted through the governance-credentialed advisory path.
5. Distinction from Prior Art
The disclosed architecture is distinct from build-time bill-of-materials generation followed by static publication, in which the inventory is produced once, posted to a registry, and never re-evaluated against the running device. Static publication provides no structural guarantee that the device in the field corresponds to the published inventory and no propagation path for revocation. The disclosed architecture carries the bill of materials in device lineage as a governance-credentialed observation and treats credential revocation as a first-class governance event.
The architecture is also distinct from a conventional sensor-actuator system that senses, evaluates through a fixed algorithm, and actuates without authority credentials, evidential weighting, composite admissibility, and lineage provenance. Such a system offers no credentialed source identification for its reported composition and no governed path from observation to admissibility. The disclosed architecture admits the bill of materials only as an authority-credentialed observation evaluated through the five-property governance chain.
Finally, the architecture is distinct from inventory reporting that operates against unattested, externally-collected composition. Such reporting cannot distinguish a genuine inventory from one fabricated by a compromised host. The disclosed architecture binds the bill of materials to the emitting device through a cryptographic attestation and to the manufacturer through the manufacturing-provenance chain, providing a structural guarantee that unattested inventory reporting cannot match.
6. Disclosure Scope
This disclosure covers the software-bill-of-materials attestation verifier, the carriage of the bill of materials in device lineage for per-component vulnerability tracking, the governance-credentialed-observation format, the revocation governed observation, and the propagation of revocation through the lineage property of the five-property governance chain. The disclosure is not limited to a specific serialization of the carried composition. Likewise, the disclosure is not limited to a specific secure-element technology; the governance secure element, hardware-attested secure enclaves, and a quantum governance secure element providing post-quantum-cryptographic primitives are all admissible roots, consistent with the architecture's technology-neutrality doctrine.
This disclosure corresponds to U.S. Provisional Application No. 64/049,409. Defense, civilian critical infrastructure, regulated medical devices, financial systems, and consumer IoT all benefit from the disclosed architecture, and the architecture's technology-neutrality doctrine admits new supply-chain primitives without modification of the core mechanism.