Blockchain Vulnerability Database Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software product providers face challenges in proving and documenting the state of third-party component vulnerabilities at the time of product release, as the software component vulnerability database is constantly evolving, and consumers may assume all risks have been mitigated, which is not always the case.
Innovation Solution
A verification stamp is published for each software product release, referencing specific blockchains that detail the component inventory and the state of the software component vulnerability database, ensuring transparency and accountability by using a cryptographic ledger to record changes to the database, allowing providers to prove which vulnerabilities were addressed and consumers to be aware of unaddressed risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional vulnerability database scanning process is used, then vulnerability detection is performed, but the ability to prove and document the state of vulnerabilities at the time of product release is lost due to database evolution
Solution Approach 1:
The patent applies preliminary action by creating cryptographic snapshots of the vulnerability database state before product release. These snapshots capture the database contents at specific points in time, allowing later verification of what vulnerabilities existed when the product was released, even as the database continues to evolve.
Solution Approach 2:
The patent uses copying by creating replicated copies of the vulnerability database state through cryptographic hashing. Instead of storing the entire database, it generates hash copies that represent the database state, enabling efficient verification and proof of the vulnerability landscape at release time.
2Reliability
If vulnerability mitigation is performed based on database scanning, then security risks are addressed, but transparency and accountability regarding which vulnerabilities were addressed versus unaddressed risks are reduced
Solution Approach 1:
The patent implements feedback by creating a verifiable record that links product releases to specific vulnerability database states. This feedback mechanism allows consumers and stakeholders to verify which vulnerabilities were present at release time and assess whether they were appropriately addressed, providing transparency and accountability.
Solution Approach 2:
The patent introduces an intermediary cryptographic verification system that mediates between the vulnerability database, the product release process, and the consumers. This intermediary layer provides independent verification of the vulnerability state without requiring direct access to the evolving database contents.
3Productivity
If the vulnerability database is continuously updated, then current security information is maintained, but the ability to reference historical vulnerability states for accountability is compromised
Solution Approach 1:
The patent applies segmentation by dividing the continuous vulnerability database into discrete, time-stamped snapshots. Each snapshot represents a stable state at a specific point in time, allowing the database to evolve continuously while preserving historical states for verification and accountability purposes.
Data Source
AI summary
A method includes, by a computer associated with a security reporter, updating a component vulnerability entry blockchain to represent a state of a component vulnerability entry of a software component vulnerability database. The method includes, by the computer, providing the updated component vulnerability entry blockchain to a management authority so that the management authority updates a master blockchain for the software component vulnerability database. The updated master blockchain includes a plurality of component vulnerability entry blockchains, which represent corresponding states of component vulnerability entries of the software component vulnerability database, including the updated component vulnerability entry.


