Blockchain-Based Vulnerability Database Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized security vulnerabilities and exposures intelligence databases face delays in updating entries, restrict participation by security researchers, and result in significant coverage gaps due to centralized control, allowing malicious tactics to go undetected.

Innovation Solution

A distributed security vulnerabilities and exposures intelligence system using blockchain for decentralized storage, validation, and incentivization, where computing nodes maintain a secure chain of data blocks using Proof of Work and Proof of Stake algorithms, allowing for consensus-based updates and rewarding contributors with digital tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized systems are used for security vulnerability databases, then control and management are simplified, but update delays occur and participation is restricted

Engineering Contradiction:
Improvecontrol and management simplicityVSAvoidupdate speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The centralized database control is segmented into multiple distributed nodes, each maintaining a copy of the vulnerability database. This segmentation eliminates single-point bottlenecks and allows parallel processing of vulnerability entries across different nodes, significantly reducing update delays while maintaining operational simplicity through automated synchronization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service mechanisms where nodes automatically validate and synchronize vulnerability entries without requiring centralized approval. The distributed architecture enables nodes to autonomously update their local copies based on consensus protocols, eliminating manual intervention delays while maintaining data consistency across the network.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If centralized control is implemented, then system management is easier, but security researchers cannot effectively participate

Engineering Contradiction:
Improvesystem management easeVSAvoidresearcher participation
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

Management functions are segmented from data storage and validation functions. While a coordinating entity maintains overall system governance, individual security researchers can participate as distributed nodes to propose, validate, and update vulnerability entries independently, enabling effective researcher participation without compromising system management ease.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a consensus protocol as an intermediary mechanism between researchers and the centralized management layer. This intermediary enables researchers to contribute their findings through standardized submission and validation processes, translating diverse researcher inputs into unified database updates while maintaining manageable system governance.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If centralized entities control the database, then entry assignment is streamlined, but coverage gaps occur due to rejection of out-of-scope entries

Engineering Contradiction:
Improveentry assignment processVSAvoidcoverage gaps
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The entry assignment process is segmented into multiple independent validation streams across distributed nodes. Each node maintains its own assessment criteria and can independently validate entries against local scope definitions, reducing the likelihood of uniform rejection and minimizing coverage gaps while keeping the overall process manageable through automated coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts validation parameters and scope criteria at different nodes based on local requirements and threat landscapes. This parameter flexibility allows entries that might be rejected by rigid centralized criteria to be accepted by nodes with adapted parameters, reducing coverage gaps while maintaining streamlined processing through automated parameter application.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If decentralized distribution is implemented, then update speed increases and participation expands, but system complexity increases

Engineering Contradiction:
Improveupdate speedVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Instead of replicating the entire complex centralized management system at each node, the architecture uses selective copying where nodes maintain simplified local copies of the vulnerability database and apply consensus protocols only for critical validation functions. This reduces per-node complexity while enabling fast parallel updates across the distributed system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The consensus protocol serves as an intermediary layer that abstracts the complexity of distributed coordination from individual nodes. Nodes interact with a simplified interface through this intermediary, handling only essential validation tasks while the protocol manages the complexity of synchronization, consensus reaching, and conflict resolution centrally, thereby reducing perceived node complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11381589B2Systems and methods for distributed extended common vulnerabilities and exposures data management
Publication Date: 2022.07.05 SOPHOS INC
  • US11381589B2 patent drawing
  • US11381589B2 patent drawing
  • US11381589B2 patent drawing

AI summary

In one aspect, the present disclosure is directed to systems and methods for validating and securely storing security entry updates. The security entry update is received from a contributor, and broadcast to a plurality of computing nodes. It then is determined whether to validate the received security update at each computing node of the plurality of computing nodes. If the received security entry update is validated, information relating to the received security update is added as transaction information in a current block, the current block is included in a blockchain that is stored in a datastore of each computing node of the plurality of computing nodes. Other aspects also are described.