Augmented SBOM Analysis for Automated Software Supply Chain Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods are inefficient and error-prone for integrators/consumers to verify adherence of software code to software development standards, particularly in detecting security risks from software supply chain attacks, as they rely on manual verification of supplier-provided artifacts.

Innovation Solution

Augmenting the Software Bill of Materials (SBOM) with information about software development standards, processes, and activities to automatically assess compliance and identify potential security risks, including vulnerabilities and licensing issues, using a SBOM analyzer to generate a risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual verification of supplier-provided artifacts is used to verify adherence to software development standards, then verification can be performed, but the process is inefficient and error-prone

Engineering Contradiction:
Improveverification accuracyVSAvoidverification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual verification processes with automated computational analysis. The SBOM analyzer automatically processes software component information, vulnerability data, and license information to generate risk assessments, eliminating the need for manual review of supplier artifacts while improving both accuracy and efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables automatic self-verification of software compliance and security. The SBOM analyzer independently evaluates software components against security criteria and generates risk assessments without requiring manual intervention, allowing the system to verify its own compliance status automatically.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual verification methods are used to detect security risks from software supply chain attacks, then risk detection can be performed, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvesecurity risk detection accuracyVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security analysis by automatically evaluating software components, vulnerabilities, and licenses before deployment. The SBOM analyzer continuously monitors and assesses risk factors in advance, enabling early detection of security issues without requiring time-consuming manual verification later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Manual security verification is replaced with automated computational analysis that rapidly processes vulnerability databases, license information, and software component data to detect security risks, significantly reducing the time required for security assessment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive software component information is collected for risk assessment, then detection accuracy improves, but data processing complexity increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata processing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the risk assessment process into distinct automated analysis modules within the SBOM analyzer. Each module handles specific aspects such as vulnerability scanning, license verification, and component validation independently, managing complex data processing through structured segmentation while maintaining high assessment accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4273726B1Risk assessment based on augmented software bill of materials
Publication Date: 2025.10.01 BLACKBERRY LTD
  • EP4273726B1 patent drawingFigure 1
  • EP4273726B1 patent drawingFigure 2
  • EP4273726B1 patent drawingFigure 3

AI summary

Systems, methods, and software can be used to identify security risks in software code based on Software Bill of Materials (SBOM). In some aspects, a method includes: obtaining, by a server, software code and a SBOM corresponding to the software code; identifying, by the server and based on the SBOM, a library used by the software code; and generating, by the server, a risk assessment based on at least one metric corresponding to the library, where the at least one metric is associated with one or more maintainers of the library.