<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.nobuo-scitt-protected-object-binding" target="https://datatracker.ietf.org/doc/html/draft-nobuo-scitt-protected-object-binding-00">
   <front>
      <title>SCITT Statement Relationship and Protected Object Binding</title>
      <author initials="N." surname="Aoki" fullname="Nobuo Aoki">
         <organization>The Graduate University for Advanced Studies (SOKENDAI)</organization>
      </author>
      <date month="July" day="6" year="2026" />
      <abstract>
	 <t>   This document defines a small common model for relating Supply Chain
   Integrity, Transparency, and Trust (SCITT) Signed Statements to the
   supply-chain objects that those statements describe, measure,
   authorize, revoke, or audit.  The model can be used for software
   artifacts, firmware artifacts, hardware components, device instances,
   cloud compute resources, and other objects that appear in supply-
   chain evidence.

   The document also defines a relationship vocabulary and an optional
   Statement Graph Manifest.  These parts help verifiers connect
   heterogeneous SCITT statements without requiring SCITT to define the
   payload formats of those statements.  This document does not define
   SBOM, HBOM, CBOM, attestation, audit, vulnerability, or regulatory
   payload formats.  It only defines a common binding and graph layer
   around SCITT statements and receipts.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-nobuo-scitt-protected-object-binding-00" />
   
</reference>
