UEFI Summit Spring 2022

Embassy Suites by Hilton Portland Hillsboro, Oregon 9355 NE Tanasbourne Dr., Hillsboro, OR, United States

We are pleased to announce the upcoming UEFI Summit is planned for the week of April 4th. The event will take place both in-person and virtually from the Embassy Suites by Hilton in Hillsboro, Oregon. In a shift from previous testing heavy Plugfest events, this event will focus primarily on educational/technical sessions, working group meetings and networking.

UEFI 2022 Virtual Summit – UEFI Support for Software Bill of Materials (SBOM)

BrightTalk

UEFI Support for Software Bill of Materials (SBOM) Sep 28 2022, 12:00pm EDT Duration: 45 mins Presented by Brian Mullen and Felix Polyudov, AMI About this talk Traditionally, capturing a Software Bill of Materials (SBOM) for UEFI firmware has been seen as challenging. Some technical challenges include immutable blobs in the image (e.g., Intel FSP and CPU microcode). Other roadblocks are due to a process where IHVs contribute binary DXE objects to the ODM. Finally, some challenges are due to commercial issues where code might be licensed from the IBV but modified by the ODM. This talk will focus on the following topics: How to include accurate SBOM metadata that is compliant with NTIA’s The Minimum Elements For a Software Bill of Materials (SBOM) guidelines in a UEFI firmware project? What edge conditions and use cases need to be considered when implementing SBOM? What approaches can enable extracting and consuming SBOM data from one supply chain partner to another? The talk plans to address several industry-wide items necessary for broader adoption of SBOM in the firmware ecosystem.