Blockchain Vulnerability Database Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software product providers face challenges in proving and documenting the state of third-party component vulnerabilities at the time of product release, as the software component vulnerability database is constantly evolving, and consumers may assume all risks have been mitigated, which is not always the case.

Innovation Solution

A verification stamp is published for each software product release, referencing specific blockchains that detail the component inventory and the state of the software component vulnerability database, ensuring transparency and accountability by using a cryptographic ledger to record changes to the database, allowing providers to prove which vulnerabilities were addressed and consumers to be aware of unaddressed risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional vulnerability database scanning process is used, then vulnerability detection is performed, but the ability to prove and document the state of vulnerabilities at the time of product release is lost due to database evolution

Engineering Contradiction:
Improveproof of vulnerability stateVSAvoidvulnerability database state information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by creating cryptographic snapshots of the vulnerability database state before product release. These snapshots capture the database contents at specific points in time, allowing later verification of what vulnerabilities existed when the product was released, even as the database continues to evolve.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating replicated copies of the vulnerability database state through cryptographic hashing. Instead of storing the entire database, it generates hash copies that represent the database state, enabling efficient verification and proof of the vulnerability landscape at release time.

Inventive Principle:
Principle #26Copying

2Reliability

If vulnerability mitigation is performed based on database scanning, then security risks are addressed, but transparency and accountability regarding which vulnerabilities were addressed versus unaddressed risks are reduced

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidtransparency of vulnerability status
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback by creating a verifiable record that links product releases to specific vulnerability database states. This feedback mechanism allows consumers and stakeholders to verify which vulnerabilities were present at release time and assess whether they were appropriately addressed, providing transparency and accountability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary cryptographic verification system that mediates between the vulnerability database, the product release process, and the consumers. This intermediary layer provides independent verification of the vulnerability state without requiring direct access to the evolving database contents.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the vulnerability database is continuously updated, then current security information is maintained, but the ability to reference historical vulnerability states for accountability is compromised

Engineering Contradiction:
Improvedatabase update efficiencyVSAvoidhistorical vulnerability state
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The patent applies segmentation by dividing the continuous vulnerability database into discrete, time-stamped snapshots. Each snapshot represents a stable state at a specific point in time, allowing the database to evolve continuously while preserving historical states for verification and accountability purposes.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11372980B2Blockchains for software component vulnerability databases
Publication Date: 2022.06.28 MICRO FOCUS LLC
  • US11372980B2 patent drawing
  • US11372980B2 patent drawing
  • US11372980B2 patent drawing

AI summary

A method includes, by a computer associated with a security reporter, updating a component vulnerability entry blockchain to represent a state of a component vulnerability entry of a software component vulnerability database. The method includes, by the computer, providing the updated component vulnerability entry blockchain to a management authority so that the management authority updates a master blockchain for the software component vulnerability database. The updated master blockchain includes a plurality of component vulnerability entry blockchains, which represent corresponding states of component vulnerability entries of the software component vulnerability database, including the updated component vulnerability entry.