5–7 Oct 2026
Europe/Prague timezone

From Manual Argument to Machine-Readable Graph: Toward a Safety SBOM for Linux

5 Oct 2026, 13:00
25m
"Club A" (Prague Congress Centre)

"Club A"

Prague Congress Centre

53
Safe Systems with Linux MC Safe Systems with Linux MC

Speaker

Nicole Pappler

Description

A safety case is the structured argument that a system is acceptably safe: claims, the evidence supporting them, and the assumptions under which the argument holds. Building and maintaining one is largely manual, and keeping it consistent as a design evolves is harder still.
SPDX 3.1's Functional Safety profile changes the starting point by giving the safety case a machine-readable form. It models requirements and their refinement, verification activities, pass/fail evaluations, evidence, and assumptions of use—the same structure safety practitioners already reason about, now expressed as a graph that tools can produce, exchange, and check.
This talk introduces the profile and its data model: what each element means, and how claims link to the evidence that supports them and the assumptions they depend on. We show how this representation can be used to generate a safety SBOM for Linux—a safety case generated and recomputed from project content rather than assembled by hand—building on the work of the ELISA Architecture working group and its current efforts on requirements. We argue this graph-based approach is the foundation for an automated handshake between upstream evidence and downstream safety arguments, enabling the kind of contract-style consumption of Linux components that safety-critical projects need.

Author

Presentation materials

There are no materials yet.