Information processing device and information processing method

The system uses a blockchain infrastructure to store and verify software module information, addressing the authenticity and integrity issues in the software supply chain, ensuring reliable software delivery.

JP2025099662APending Publication Date: 2025-07-03TOYOTA JIDOSHA KK +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023216502
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing software supply chain systems struggle to ensure the authenticity and integrity of software modules, particularly in large-scale software products, where the relationships between modules are unclear, and tampering cannot be detected, leading to reliability issues.

Method used

A system utilizing a blockchain infrastructure to store module information in distributed ledgers, generating software information that includes dependency relationships and unique values, enabling verification of software modules' authenticity and integrity across the supply chain.

Benefits of technology

Enhances the reliability of the software supply chain by ensuring the legitimacy and integrity of software modules, allowing companies to verify the authenticity of received modules, thereby improving the overall trust and security of the software product.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025099662000001_ABST
    Figure 2025099662000001_ABST
Patent Text Reader

Abstract

To enhance reliability in a supply chain of software.SOLUTION: Module information about software modules constituting first software and produced by one or more first companies included in a supply chain of the first software is received from a terminal corresponding to the first companies. Different parts of the module information are stored in a storage device and a distributed ledger that uses a block chain platform. Software information including information about one or more software modules constituting the first software is generated based on one or more pieces of the module information stored in the storage device and the distributed ledger. The software information is transmitted to a terminal corresponding to a second company.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the software supply chain.

Background Art

[0002] Systems for detecting software vulnerabilities are known. In this regard, for example, Patent Document 1 discloses a system for managing software vulnerabilities using a database storing configuration information of software products.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of the present disclosure is to improve the reliability in the software supply chain.

Means for Solving the Problems

[0005] One aspect of an embodiment of the present disclosure is receiving module information regarding software modules that make up the first software from a terminal corresponding to one or more first companies included in the first software supply chain; a storage device; storing different parts of the module information in respective distributed ledgers using a blockchain infrastructure; generating software information including information regarding one or more software modules that make up the first software based on the one or more pieces of module information stored in the storage device and the distributed ledger; and transmitting the software information to a terminal corresponding to a second company, and an information processing apparatus having a control unit that executes the above.

[0006] One aspect of an embodiment of the present disclosure is One or more first devices corresponding to each of one or more enterprises included in a first software supply chain, and a second device that manages information regarding the first software, wherein the first device transmits module information regarding one or more software modules constituting the first software to the second device, and requests software information corresponding to the first software from the second device, and the second device stores different parts of the received module information in a storage device and a distributed ledger using a blockchain infrastructure respectively, and in response to the request, acquires the module information regarding one or more software modules constituting the first software from the storage device and the distributed ledger, and generates software information corresponding to the first software based on the acquired module information.

[0007] As another aspect, there is provided a program for causing a computer to execute the above method, or a computer-readable storage medium that non-temporarily stores the program.

Advantages of the Invention

[0008] According to the present disclosure, the reliability in a software supply chain can be improved.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Mode for Carrying Out the Invention

[0010] In recent years, the scale of embedded software in devices has been growing enormously. The software embedded in a device can be produced in module units by multiple companies. For example, another company located downstream creates a second software module using the first software module created by a company (supplier) located upstream in the supply chain. By repeating this, the final software product is made.

[0011] In such a system, when the scale of the software becomes large, there arises a problem that the relationship between multiple software modules becomes unclear. For example, a company located downstream in the supply chain may not be able to grasp which software modules are used upstream.

[0012] On the other hand, when vulnerabilities or defects occur in the software, it is required to identify the software modules that need to be addressed and update them promptly. Therefore, there is a technology for centrally managing information on a plurality of modules included in software. According to this technology, for example, the relationships between a plurality of software modules can be visualized by a tree diagram.

[0013] However, even if the information on software modules is centrally managed, in the case where the file body is tampered with due to unauthorized access, the prior art cannot detect this. In the software supply chain, a completed software module is delivered from one company to another company. Therefore, there is no mechanism to guarantee that the delivered software module is legitimate (for example, not tampered with). The information processing apparatus according to the present disclosure solves such a problem.

[0014] An information processing apparatus according to an aspect of the present disclosure receives module information regarding software modules that make up the first software and are produced by one or more first companies corresponding to terminals included in a first software supply chain; a storage device; stores different parts of the module information in respective distributed ledgers using a blockchain infrastructure; generates software information including information regarding one or more software modules that make up the first software based on the one or more pieces of module information stored in the storage device and the distributed ledger; and transmits the software information to a terminal corresponding to a second company.

[0015] The first software is software composed of a plurality of software modules. The first software may be software that is finally provided to consumers. Each software module can be produced by one or more enterprises that make up the supply chain. Each enterprise is also called a downstream enterprise or an upstream enterprise according to its position in the supply chain. A downstream enterprise uses the software modules produced by an upstream enterprise to produce new software modules.

[0016] Module information is information about the software modules produced by each enterprise. Module information can include, in addition to the basic information of each software module, information about the dependency relationships with other software modules, information about the unique values corresponding to the software module, and so on. For example, by collecting information about the dependency relationships of each software module, a tree diagram of the software modules that make up the first software can be generated.

[0017] The unique value corresponding to a software module is typically the unique value of the software module itself (e.g., a hash value). By using such a value, it is possible to detect the tampering of the software module. The unique value corresponding to a software module does not have to be the unique value of the software module itself as long as it is a value for verifying the authenticity of the software module. For example, the unique value corresponding to a software module may be the unique value of the Software Bill of Materials (SBOM) corresponding to the software module. When an SBOM is attached to a software module, by using the unique value of the SBOM, it is possible to detect the tampering of the SBOM itself.

[0018] Module information is stored in a storage device, and a part of it is stored in a distributed ledger using a blockchain infrastructure. This makes it difficult to falsify the module information. Among the module information, in particular, information for verifying the authenticity of software modules, such as unique values corresponding to software modules, is preferably stored in a distributed ledger using a blockchain infrastructure.

[0019] Based on the acquired module information, the control unit generates software information corresponding to the first software. The software information may include detailed information of a plurality of software modules constituting the first software, information regarding the dependency relationship between modules, and the like. The software information may include an image visualizing the dependency relationship of a plurality of software modules in a tree structure. In the following description, a tree diagram representing the dependency relationship between a plurality of software modules is referred to as a software tree.

[0020] The software information may include unique values corresponding to each software module. Thereby, for example, each company that has acquired the software information can confirm that the software modules supplied by other companies are genuine.

[0021] In the following description, software modules manufactured by each of a plurality of suppliers are simply referred to as "modules", and the final software product is referred to as the "final software product". In one example, the final software product can be supplied to consumers. Also, supplier companies and OEM companies included in the supply chain are simply referred to as "companies". Also, each of the plurality of tiers of the supply chain is referred to as a "Tier". In the following description, a specific tier in the supply chain is expressed in terms such as Tier N. N represents the tier in the supply chain, and the smaller the numerical value, the more downstream the position.

[0022] Hereinafter, specific embodiments of the present disclosure will be described with reference to the drawings. The hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure only to them unless otherwise specified.

[0023] (First Embodiment) The information processing system according to this embodiment is a system that provides information regarding software products supplied by a supply chain including a plurality of companies.

[0024] First, the structure of the supply chain will be described. FIG. 1 is a diagram for explaining an example of the supply chain according to this embodiment. The supply chain shown in FIG. 1 is composed of an OEM company and a plurality of companies that are suppliers. In the example of FIG. 1, for example, a supply chain for manufacturing software products is assumed. The OEM company is a company that manufactures the final software product. The plurality of companies (Companies A to C) that are suppliers supply the software modules they produced to the companies belonging to the adjacent Tier. Each of the plurality of companies that are suppliers manufactures one or more modules and supplies the modules to the companies located in the lower layer. The plurality of companies repeat this, and in the final process (that is, the OEM company), the final software product is configured.

[0025] In this embodiment, in each layer of the supply chain, the side that incorporates the module is referred to as the upstream side, and the side that manufactures a new module relying on the module is referred to as the downstream side. In this specification, a company located on the upstream side is referred to as an upstream company, and a company located on the downstream side is referred to as a downstream company. Also, the module manufactured by the upstream company is referred to as an upstream module, and the module manufactured by the downstream company is referred to as a downstream module. The upstream module is included in the downstream module. Also, in this embodiment, the layers included in the supply chain are referred to as Tier. Tier0 is the bottom layer that assembles the final software product (corresponding to the OEM company). It is a hierarchy of layers, and as it progresses to Tier1, 2, and 3, it transitions upstream. Depending on the layer of interest , a downstream company may become an upstream company. For example, Company B belonging to Tier2 is a downstream company in relation to Tier3, but is an upstream company in relation to Tier1. Thus, the definitions of "upstream" and "downstream" can vary for each layer. Note that other companies may exist between the upstream company and the downstream company, or other modules may exist between the upstream module and the downstream module.

[0026] Figure 2 is a diagram for explaining the relationship between modules supplied by a supply chain. Here, the supply relationship of a plurality of modules constituting the final software product X is represented by a tree diagram. In this example, the final software product X includes modules A1, B1, C1, D1,.... Module A1 is composed of modules A11, A12, A13,.... Thus, the relationship between a plurality of modules constituting the final software product can be represented by a tree diagram with individual modules as nodes. Hereinafter, a tree diagram regarding a specific final software product is referred to as a software tree.

[0027] The server device 1 according to the present embodiment collects information regarding modules (hereinafter referred to as module information) produced by each company from terminals (company terminals 2) corresponding to each company, and generates software information based on these. The software information may include a software tree. The module information includes information regarding the dependency relationship between modules, and the server device 1 can use this to generate a tree diagram.

[0028] As shown in FIG. 1, the information processing system according to the present embodiment includes a server device 1 and a plurality of company terminals 2. The company terminal 2 is a terminal corresponding to each of a plurality of companies constituting the supply chain . The number of terminals corresponding to each company may be arbitrary.

[0029] The server device 1 collects module information from each of a plurality of enterprise terminals 2, and generates software information including a software tree based on the collected module information. The software tree may include information about each module and information (hash value) for verifying the authenticity of each module. The server device 1 can transmit the generated software information to each enterprise terminal 2.

[0030] Next, with reference to FIG. 3, an outline of the process in which the server device 1 generates software information will be described. FIG. 3 is a diagram showing an outline of the process performed between the enterprise terminal 2 and the server device 1. In the example of FIG. 3, it is assumed that there are enterprise A, which is a downstream enterprise, and enterprise B, which is an upstream enterprise, between the Tiers indicated by reference numeral 201 in FIG. 2. It is assumed that enterprise B manufactures module A11 and supplies it to enterprise A, and enterprise A manufactures module A1 using module A11. That is, on the software tree, module A11 becomes a child node of module A1.

[0031] First, enterprise A requests the server device 1 to register a project. A project is a unit for managing module information. One module to be managed is included in the project. In this example, as shown in FIG. 2, the case where enterprise A manufactures module A1 using module A11 is considered. When enterprise A checks whether the delivered module A11 is genuine, information about module A11 (for example, a hash value) is required. In this case, enterprise A registers the range indicated by reference numeral 201 as a project. The project manages module A11. The enterprise that registers the project invites other enterprises related to the project to the system. In the case of this example, enterprise A invites enterprise B, which manufactures module A11, to the system.

[0032] Company B (enterprise terminal 2B) participating in the project transmits information about the modules it manufactures (module information) to the server device 1. In this example, the enterprise terminal 2B corresponding to Company B transmits module information about module A11 (referred to as module information A11) to the server device 1. The module information corresponds one-to-one with the project.

[0033] In addition to the basic information of the module, the module information includes information for verifying the authenticity of the module (hereinafter referred to as eigenvalue information). When the module is provided by one file (package), the eigenvalue information may be the hash value of the package (hereinafter referred to as the module package). Also, the eigenvalue information may be the hash value of the SBOM corresponding to module A11, etc.

[0034] Furthermore, the module information includes information indicating the dependency relationship between modules (hereinafter referred to as dependency relationship information). For example, when module A11 is configured using module A111 located further upstream, the module information of module A11 may include dependency relationship information indicating that "this module depends on module A111". The dependency relationship information may be represented by the relationship between modules or by the relationship between projects. For example, the module information of module A11 may include dependency relationship information indicating that "this project depends on project 202". The module information transmitted from the enterprise terminal 2 is stored in the server device 1.

[0035] When the collection of module information corresponding to the project is completed, the server device 1 registers the eigenvalue information (hash value in this embodiment) included in the module information in the distributed ledger (distributed database). The distributed database is a database using the blockchain infrastructure. It is a server. The distributed database may be constituted by a plurality of computers including a plurality of enterprise terminals 2. In the present embodiment, among the plurality of information included in the module information, the server device 1 stores those other than the eigenvalue information, and stores only the eigenvalue information in the distributed database.

[0036] Based on the module information collected in project units, the server device 1 can generate information (software information) regarding the final software product. The software information may include, for example, basic information of a plurality of modules included in the final software product and a tree (software tree) representing the dependency relationship between the plurality of modules. The server device 1 may generate, in response to a request from the enterprise terminal 2, a GUI for visualizing the software tree, for example, and provide it to the enterprise terminal 2.

[0037] Also, the server device 1 can provide the eigenvalue information of a plurality of modules to the enterprise terminal 2 as software information. The eigenvalue information of the module is acquired from the distributed database. For example, when an operator of the enterprise terminal 2 selects a specific module on the software tree, a corresponding eigenvalue (hash value) may be output. Thereby, the enterprises constituting the supply chain can confirm the correct hash value for the software module (module A11) supplied from the upstream enterprise. Also, based on this, the authenticity of the module can be verified.

[0038] [Hardware Configuration] Next, the hardware configuration of each device constituting the system will be described. FIG. 4 is a diagram schematically showing an example of the hardware configuration of the server device 1 according to the present embodiment. The server device 1 is configured as a computer having a control unit 11, a storage unit 12, a communication module 13, and an input / output device 14.

[0039] The server device 1 can be configured as a computer having a processor (such as a CPU or GPU), a main storage device (such as a RAM or ROM), and an auxiliary storage device (such as an EPROM, a hard disk drive, or a removable medium). The auxiliary storage device stores an operating system (OS), various programs, various tables, etc. By executing the programs stored therein, various functions (software modules) that meet a predetermined purpose, as described later, can be realized. However, some or all of the functions may be realized as hardware modules by a hardware circuit such as an ASIC or FPGA.

[0040] The control unit 11 is an arithmetic unit that realizes various functions of the server device 1 by executing a predetermined program. The control unit 11 can be realized by a hardware processor such as a CPU, for example. Also, the control unit 11 may be configured to include a RAM, a ROM (Read Only Memory), a cache memory, etc.

[0041] The storage unit 12 is a means for storing information and is composed of a storage medium such as a RAM, a magnetic disk, or a flash memory. The storage unit 12 stores the programs executed by the control unit 11, the data used by the programs, etc. Also, a database is constructed in the storage unit 12, and the database stores the module information collected from a plurality of enterprise terminals 2 and the account information for logging in from the enterprise terminals 2. Details will be described later.

[0042] The communication module 13 is a communication interface for connecting the server device 1 to a network. The communication module 13 may be configured to include, for example, a network interface board, a wireless communication interface for wireless communication, etc. The server device 1 can perform data communication with other computers (such as each enterprise terminal 2) via the communication module 13.

[0043] The input / output device 14 is a means for receiving input operations performed by the operator and presenting information to the operator. Specifically, the input / output device 14 includes devices for performing input such as a mouse and a keyboard, and devices for performing output such as a display and a speaker. The input / output device may be integrally configured by, for example, a touch panel display or the like.

[0044] Note that the specific hardware configuration of the server device 1 can be appropriately omitted, replaced, and added according to the embodiment. For example, the control unit 11 may include a plurality of hardware processors. The hardware processor may be composed of a microprocessor, an FPGA, a GPU, or the like. The input / output device 14 may be omitted, or an input / output device other than the exemplified one (for example, an optical drive or the like) may be added. Further, the server device 1 may be composed of a plurality of computers. In this case, the hardware configurations of the respective computers may or may not match.

[0045] FIG. 5 is a diagram schematically showing an example of the hardware configuration of the enterprise terminal 2 according to the present embodiment. The enterprise terminal 2 is configured as a computer having a control unit 21, a storage unit 22, a communication module 23, and an input / output device 24.

[0046] Similar to the server device 1, the enterprise terminal 2 can be configured as a computer having a processor (CPU, GPU, etc.), a main storage device (RAM, ROM, etc.), and an auxiliary storage device (EPROM, hard disk drive, removable media, etc.). However, some or all of the functions (software modules) may be realized as hardware modules by a hardware circuit such as an ASIC or an FPGA.

[0047] The control unit 21 is an arithmetic unit that realizes various functions (software modules) of the enterprise terminal 2 by executing a predetermined program. The control unit 11 can be realized by a hardware processor such as a CPU, for example. Also, the control unit 21 may be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0048] The storage unit 22 is a means for storing information and is composed of a storage medium such as a RAM, a magnetic disk, or a flash memory. In the storage unit 22, a program executed by the control unit 21, data used by the program, and the like are stored.

[0049] The communication module 23 is a communication interface for connecting the enterprise terminal 2 to a network. The communication module 23 may be configured to include, for example, a network interface board, a wireless communication interface for wireless communication, and the like. The enterprise terminal 2 can perform data communication with other computers (for example, the server device 1 and other enterprise terminals 2) via the communication module 23.

[0050] The input / output device 24 is a means for receiving an input operation performed by an operator and presenting information to the operator. Specifically, the input / output device 24 includes a device for performing input such as a mouse and a keyboard, and a device for performing output such as a display and a speaker. The input / output device may be integrally configured by, for example, a touch panel display.

[0051] Note that the specific hardware configuration of the enterprise terminal 2 can be appropriately omitted, replaced, and added with components according to the embodiment, similar to the server device 1.

[0052] [Software Configuration] Next, the software configuration of each device constituting the system will be described. FIG. 6 is a diagram schematically showing the software configuration of the server device 1 according to the present embodiment. In the present embodiment, the control unit 11 is configured to include two software modules: an information collection unit 111 and an information provision unit 112. Each software module may be realized by executing a program stored in the storage unit 12 by the control unit 11 (CPU). Note that the information processing executed by the following information collection unit 111 and information provision unit 112 is synonymous with the information processing executed by the control unit 11.

[0053] The information collection unit 111 is configured to execute a process of collecting module information from the enterprise terminal 2 and storing the module information in the storage unit 12. FIG. 7 is an example of module information collected by the information collection unit 111. One piece of module information corresponds to one project. The module information may be input via an operator of the enterprise terminal 2. In the present embodiment, the module information is configured to include three types of information: basic information, dependency information, and unique value information.

[0054] The basic information includes information about the module, such as an identifier of the company that manufactures the target module, the company name, an identifier of the project (identifier of the module), and the version.

[0055] The dependency information includes information about other projects on which the target project depends (in the example of FIG. 7, the "referenced project") and the version. For example, when module A is created by referring to module B, it can be said that the project corresponding to module A depends on the project corresponding to module B. The dependency information may include identifiers of other modules referred to by the target module and the connection relationship between the modules (for example, the connection relationship between nodes in a tree structure).

[0056] The eigenvalue information includes information for verifying the authenticity of the target module. When the target module is exchanged between enterprises by one file (hereinafter referred to as the module package), the eigenvalue information may be the hash value of the file. Also, when the target module is exchanged between enterprises together with the SBOM, the eigenvalue information may be the hash value of the SBOM attached to the target module, etc.

[0057] The information collection unit 111 provides an interface for the operator of the enterprise terminal 2 to input such information and obtains the module information. The information collection unit 111 may receive information indicating that the input of the module information has been completed from the enterprise terminal 2.

[0058] The module information collected by the server device 1 is stored in the database constructed in the storage unit 12. Also, at the timing when the collection of the module information included in the target project is completed, the information collection unit 111 copies the eigenvalue information included in the module information to the distributed database. By executing this process for a plurality of projects, the eigenvalue information reported by each enterprise can be stored in a distributed database using the blockchain infrastructure, that is, a database that is difficult to tamper with.

[0059] The information providing unit 112 generates software information regarding the final software product based on the module information stored in the storage unit 12 and the distributed database, and provides it to the enterprise terminal 2. In this embodiment, when the operator of the enterprise terminal 2 requests the server device 1 to provide software information the information providing unit 112 performs the process and provides information to the enterprise terminal 2.

[0060] The server device 1 generates software information including, for example, information representing the dependencies between a plurality of modules included in the final software product, detailed information (basic information and eigenvalue information) of each module, etc. The software information is converted into an image or the like by the enterprise terminal 2 and outputted.

[0061] The storage unit 12 stores the module information transmitted from the enterprise terminal 2 and the account information. In the present embodiment, an operator of each enterprise logs in to the server device 1 using the corresponding enterprise's account via the enterprise terminal 2, thereby enabling interaction between the server device 1 and the enterprise terminal 2. The account information is information regarding the accounts corresponding to each enterprise constituting the supply chain. However, the method of accessing the server device 1 need not be limited to such an example and may be appropriately selected according to the embodiment.

[0062] FIG. 8 is a diagram schematically showing the software configuration of the enterprise terminal 2 according to the present embodiment. In the present embodiment, the control unit 21 is configured to include three software modules: an information registration unit 211, a file sharing unit 212, and an information acquisition unit 213. Each software module may be realized by the control unit 21 (CPU) executing a program stored in the storage unit 22. Note that the information processing executed by the following information registration unit 211, file sharing unit 212, and information acquisition unit 213 is synonymous with the information processing executed by the control unit 21.

[0063] The information registration unit 211 is configured to generate information (module information) regarding the software module corresponding to the enterprise terminal 2. The module information may be input via the operator of the device. As described above with reference to FIG. 7, the module information is configured to include basic information, dependency information, and eigenvalue information.

[0064] The information registration unit 211 is configured to acquire such information via the operator of the enterprise terminal 2 and transmit it to the server device 1 at an arbitrary timing.

[0065] The file sharing unit 212 is configured to share files among enterprises. In this embodiment, a plurality of enterprise terminals 2 have a file sharing function and can transmit and receive files with each other among enterprises having a business relationship. For example, the enterprise terminal 2 corresponding to the upstream enterprise shares the module package to be delivered to the downstream enterprise, and the enterprise terminal 2 corresponding to the downstream enterprise acquires it. Note that the sharing target may be a module package (that is, the module body), or an SBOM or the like corresponding to the module.

[0066] The information acquisition unit 213 is configured to request the server device 1 to provide software information and output the software information transmitted from the server device 1. For example, the information acquisition unit 213 may generate a GUI (software tree) that visualizes the dependency relationships of a plurality of modules based on the software information transmitted from the server device 1.

[0067] FIG. 9 is an example of a software tree generated by the information acquisition unit 213. The information acquisition unit 213 may execute a process of generating a GUI as illustrated based on the software information received from the server device 1.

[0068] Further, the information acquisition unit 213 may be configured to output information about a specific module based on an operation of an operator of the enterprise terminal 2. For example, when an operator of the enterprise terminal 2 selects a specific module on the GUI, the basic information and unique value information of the module may be output.

[0069] The storage unit 22 stores the module information generated by the information registration unit 211 and the module package shared by the file sharing unit 212 (that is, the module package to be delivered to the downstream enterprise).

[0070] [Processing flow] Next, with reference to FIG. 10, the processes executed by each device constituting the system will be described. FIG. 10 is a sequence diagram showing a process in which a plurality of enterprise terminals 2 interact with the server device 1 to register a project.

[0071] In one example, the interaction between the server device 1 and the enterprise terminal 2 is started when an operator of each enterprise included in the supply chain logs in to the server device 1 using the account of the corresponding enterprise via the enterprise terminal 2. In this example, it is assumed that the operator of each enterprise logs in to the server device 1 using their own account. Also, in this example, the enterprise terminal corresponding to the downstream enterprise (referred to as enterprise A) in a certain Tier is the enterprise terminal 2A, and the enterprise terminal corresponding to the upstream enterprise (referred to as enterprise B) is the enterprise terminal 2B.

[0072] First, in step S11, the enterprise terminal 2A of the downstream enterprise accesses the server device 1 and registers a project. A project is a unit for managing module information, and in this example, it corresponds to the module produced by enterprise B.

[0073] In step S12, the server device 1 interacts with the enterprise terminal 2B and registers account information. As a result, the enterprise terminal 2B becomes able to log in to the server device 1.

[0074] In step S13, the enterprise terminal 2B obtains module information regarding the module produced by itself via the operator and transmits the module information to the server device 1. The module information transmitted to the server device 1 is received by the information collection unit 111 and stored in the storage unit 12 (step S14).

[0075] When all the input of module information is completed, the enterprise terminal 2B performs an operation to release the project to the server device 1 (step S15). When this operation is performed, the module information included in the project is determined.

[0076] When the project is released, the server device 1 copies, to the distributed database, the eigenvalue information among the received module information, in association with the identifier and version of the project (step S16).

[0077] By repeating the above-described process for a plurality of projects, the server device 1 can collect module information regarding a plurality of modules included in the final software product. Also, the eigenvalue information included in the module information can be stored in a distributed database where there is no risk of forgery.

[0078] FIG. 11 is a sequence diagram showing a process in which the server device 1 provides software information to the enterprise terminal 2 and the enterprise terminal 2 verifies a module using the software information. Here, an example is given in which enterprise A (enterprise terminal 2A), which is a downstream enterprise, acquires software information from the server device 1 and uses the software information to verify the authenticity of a module package delivered from an upstream enterprise.

[0079] First, in step S21, the enterprise terminal 2A requests the server device 1 to provide software information. The request may be for information on all the modules included in the final software product, or may be for information on some of the modules.

[0080] Upon receiving the request, the server device 1 generates software information in step S22. The software information includes information for generating a software tree as shown in FIG. 9. Also, the software information may have the basic information and eigenvalue information of each module included in the software tree associated therewith. Among these, the eigenvalue information is acquired from the distributed database.

[0081] The generated software information is transmitted to and output to the enterprise terminal 2A. The operator of enterprise A can view the software tree and the information associated with each module (step S23).

[0082] In parallel with this, Company A receives a module manufactured by Company B from Company B (step S24). In this step, the enterprise terminal 2A uses the file sharing function of the enterprise terminal 2B to obtain a module package from the enterprise terminal 2B.

[0083] In step S25, the operator of Company A refers to the eigenvalue information corresponding to the obtained module package. For example, when the eigenvalue information is the hash value of the module package, the enterprise terminal 2A calculates the hash value of the module package received from Company B and verifies whether it matches the eigenvalue information confirmed in step S23.

[0084] As described above, the server device 1 according to the present embodiment collects information on a plurality of software modules constituting the final software product and provides this to the enterprise terminal 2. The provided information includes eigenvalue information for each software module, and each enterprise can use this to confirm that the module package delivered from the upstream enterprise is genuine. In particular, since the eigenvalue information is stored not in the server device 1 but in a distributed database, the risk of the eigenvalue information itself being tampered with can be suppressed.

[0085] (Modification Example of the First Embodiment) In the first embodiment, when the enterprise terminal 2 requests software information, the server device 1 provides a software tree corresponding to the final software product. However, it may not be appropriate to disclose the entire software tree to a specific enterprise. Therefore, the server device 1 may set access rights for each enterprise and perform a process of non-disclosing the range without access rights from the enterprise when providing the software tree to the enterprise terminal 2 corresponding to a certain enterprise.

[0086] For example, there may be a case where a company included in a supply chain wants to keep its module information confidential from other companies. To enable this, access rights to module information may be permitted among companies. For example, each company may send a rule such as "Permit access to its own module information only to companies with which there is a trading relationship" to the server device 1, and the server device 1 may set access rights for each company according to the rule.

[0087] In this case, when generating software information, the information providing unit 112 may execute a process of concealing information about modules for which there is no access right based on the access rights set for each company. Regarding the modules for which the information has been concealed, they exist on the software tree, but detailed information may not be output even if they are selected.

[0088] (Modification example) The above embodiment is merely an example, and the present disclosure can be appropriately modified and implemented without departing from the gist thereof. For example, the processes and means described in the present disclosure can be freely combined and implemented as long as there is no technical contradiction.

[0089] Also, in the description of the embodiment, the server device 1 stores module information in a database, but the module information may be stored by means other than a database.

[0090] Also, in the description of the embodiment, a hash value is exemplified as the unique value of the module, but as long as the authenticity of the module (or SBOM) can be confirmed, information other than the hash value may be used. For example, a timestamp or the like can also be used.

[0091] In the description of the embodiment, an example was given in which companies with a business relationship confirm the authenticity of a module delivered from the other party using eigenvalue information. However, the target for authenticity confirmation is not limited to modules delivered from companies. For example, when manufacturing a module using open source software (OSS), eigenvalue information corresponding to the OSS may be registered and used for authenticity confirmation. In this case, the company using the OSS may register module information about the OSS in the server device 1. Alternatively, the server device 1 may manage a plurality of OSSs included in the final software product. The eigenvalue information corresponding to the OSS may be registered in a distributed database. Also, when the eigenvalue information of the OSS is registered in a reliable device, the server device 1 may acquire the eigenvalue information from the device and generate software information.

[0092] Also, the processing described as being performed by one device may be shared and executed by a plurality of devices. Alternatively, the processing described as being performed by different devices may be executed by one device. In a computer system, how each function is realized by what hardware configuration (server configuration) can be flexibly changed.

[0093] The present disclosure can also be realized by supplying a computer program that implements the functions described in the above embodiments to a computer and causing one or more processors included in the computer to read and execute the program. Such a computer program may be provided to the computer by a non-transitory computer-readable storage medium connectable to the system bus of the computer, or may be provided to the computer via a network. The non-transitory computer-readable storage medium includes, for example, any type of disk such as a magnetic disk (e.g., a floppy (registered trademark) disk, a hard disk drive (HDD), etc.), an optical disk (e.g., a CD-ROM, a DVD disk, a Blu-ray disk, etc.), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, and any type of medium suitable for storing electronic instructions.

Explanation of Signs

[0094] 1 ··· Server device 2 ··· Enterprise terminal 11, 21 ··· Control unit 12, 22 ··· Storage unit 13, 23 ··· Communication module 14, 24 ··· Input / output device

Claims

1. Receiving module information regarding software modules produced by one or more first enterprises included in a first software supply chain from a terminal corresponding to the one or more first enterprises, and configuring the first software; Storing different parts of the module information in a storage device and each of distributed ledgers using a blockchain infrastructure, respectively; Generating software information including information regarding one or more software modules constituting the first software based on the one or more pieces of module information stored in the storage device and the distributed ledger; Transmitting the software information to a terminal corresponding to a second enterprise; An information processing apparatus having a control unit that executes the above.

2. The module information includes first information representing a dependency relationship between software modules and second information representing an eigenvalue corresponding to a target software module, and the control unit stores the first information in the storage device and stores the second information in the distributed ledger. The information processing apparatus according to claim 1.

3. The eigenvalue corresponding to the target software module is an eigenvalue of the software module body or an eigenvalue of a software bill of materials corresponding to the software module. The information processing apparatus according to claim 2.

4. The control unit generates tree information indicating a dependency relationship between a plurality of software modules constituting the first software as the software information. The information processing apparatus according to claim 3.

5. The control unit generates tree information representing a dependency relationship between a plurality of software modules constituting the first software and eigenvalue information representing the eigenvalue corresponding to each software module as the software information. The information processing apparatus according to claim 3.

6. The control unit sets a reference right regarding one or more software modules constituting the first software for the second enterprise, and performs a predetermined confidentiality process on software modules among the one or more software modules constituting the first software for which the second enterprise does not have a reference right in the generation of the software information. The information processing apparatus according to any one of claims 1 to 5.

7. An information processing method executed by one or more first devices corresponding to each of one or more enterprises included in a supply chain of first software, and a second device that manages information related to the first software, wherein the first device transmits module information regarding one or more software modules constituting the first software to the second device; requests software information corresponding to the first software from the second device; and executes wherein the second device stores different parts of the received module information in a storage device and each of distributed ledgers using a blockchain infrastructure; in response to the request, acquires the module information regarding one or more software modules constituting the first software from the storage device and the distributed ledger, and generates software information corresponding to the first software based on the acquired module information; and executes the information processing method.

8. The module information includes first information representing a dependency relationship between software modules and second information representing a unique value corresponding to a target software module, and the second device stores the first information in the storage device and stores the second information in the distributed ledger. The information processing method according to claim 7.

9. The unique value corresponding to the target software module is a unique value of the software module body or a unique value of a software bill of materials corresponding to the software module. The information processing method according to claim 8.

10. The second device generates tree information indicating a dependency relationship between a plurality of software modules constituting the first software as the software information. The information processing method according to claim 9.

11. The second device generates tree information indicating a dependency relationship between a plurality of software modules constituting the first software and unique value information representing the unique values corresponding to the respective software modules as the software information. The information processing method according to claim 9.

12. For each of the one or more enterprises, the second device sets reference permissions for one or more software modules that make up the first software, and in generating the software information, among the one or more software modules that make up the first software, for software modules for which the enterprise that requested the software information does not have reference permissions, perform a predetermined confidentiality process. The information processing method according to any one of claims 7 to 11.

Citation Information

Patent Citations

  • Vulnerability management system and program

    JP2020021309A