Skip to content

Architecture

CBOM is a three-tier system: distributed Sensors discover cryptographic assets, a central API ingests and manages them, and a Web UI provides visualization and management.


CBOM System Architecture


Standalone Java applications deployed near the infrastructure they scan. Each sensor:

  • Runs as a background service (systemd on Linux, Windows Service on Windows)
  • Checks in with the central API on a configurable heartbeat interval
  • Receives scanner assignments dynamically (no local reconfiguration needed)
  • Executes scans according to schedule (hourly, daily, weekly, or custom)
  • Pushes discovered assets to the API via authenticated REST calls

A single sensor can run multiple scanner types simultaneously. Sensors require no inbound network access — they initiate all connections outward.

The API server handles:

FunctionDescription
IngestionReceives assets from sensors, deduplicates by fingerprint, stores in MongoDB
Quantum RiskClassifies every asset’s quantum vulnerability automatically
Relationship LinkingBuilds connections between assets (issuer chains, key pairs, keystore containment)
ComplianceEvaluates inventory against policy standards
ExportGenerates CycloneDX v1.6 CBOM with full spec compliance
SchedulingManages scan schedules and distributes assignments to sensors
AlertsEmail notifications for policy violations and certificate expiry

Single-page application served by the API in production (single-artifact deployment). Provides:

  • Real-time dashboard with quantum risk analytics and PQC readiness tracking
  • Searchable inventory with type-specific filters and saved searches
  • Sensor management with inline scanner assignment and configuration
  • Compliance assessment with rule-based policy evaluation
  • CycloneDX import/export and offline (air-gapped) import support

MongoDB stores all discovered assets in a single collection, indexed by fingerprint for content-based deduplication. No cryptographic key material is stored — only metadata and fingerprints.


CBOM Data Flow


CBOM deploys as a single Docker Compose stack:

Sensors → Nginx (HTTPS, port 443) → CBOM Application (API + UI) → MongoDB

The application serves the UI and API from a single process. Nginx handles TLS termination. Sensors connect outbound to the API — no inbound ports needed on sensor machines.

See Deployment Guide for full instructions.


CommunicationAuthentication
Sensor → APIAPI key (issued at registration, one per sensor)
UI → APIJWT token (24h expiration)
External → PlatformHTTPS via Nginx reverse proxy
  • Two user roles: Admin (full access) and Viewer (read-only)
  • No private key material stored in the database — only metadata and fingerprints
  • Secrets (JWT key, DB credentials, SMTP) managed via environment variables