Build Proxy Metadata Registration for Trusted SBOM Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in managing program components from diverse sources, leading to supply chain attacks and difficulties in generating accurate Software Bills of Materials (SBOMs, which complicates compliance with security regulations.

Innovation Solution

A program component management system automates the registration of program components with project metadata in a provenance repository, using a proxy to manage build commands and ensure secure retrieval from trusted repositories, generating accurate SBOMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If program components are retrieved from diverse sources to build deliverables, then the versatility and availability of components is improved, but the security and reliability of the supply chain deteriorates due to increased risk of tampering and unauthorized sources

Engineering Contradiction:
Improveavailability of program componentsVSAvoidsupply chain security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a proxy as an intermediary component that sits between the build tool and program component repositories. This proxy intercepts build commands, retrieves program components from diverse sources, and automatically registers them with a metadata management system. The proxy acts as a trusted mediator that maintains an audit trail of all component retrievals, thereby enabling versatile component sourcing while ensuring supply chain security through centralized control and provenance tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual tracking of program components is performed, then the accuracy of Software Bill of Materials (SBOM) can be improved, but the time and effort required for compliance management increases significantly

Engineering Contradiction:
Improveaccuracy of SBOMVSAvoidtime for compliance management
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements an automated system where the metadata management system self-updates with program component information through automatic registration triggered by the proxy during the build process. The system autonomously captures component metadata, maintains provenance records, and generates SBOMs without requiring manual intervention. This self-service approach ensures high accuracy in SBOM generation while eliminating the time-consuming manual tracking process.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated registration of program components with project metadata is implemented, then the productivity and efficiency of build processes is improved, but the device complexity and infrastructure requirements increase

Engineering Contradiction:
Improvebuild process efficiencyVSAvoidsystem infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent designs the proxy to perform multiple functions: it acts as a build command interceptor, a program component retriever, an automatic registrar with the metadata management system, and an SBOM generator. By consolidating these diverse functions into a single multi-functional proxy component, the system achieves high build process efficiency without proportionally increasing overall system complexity. The metadata management system also serves dual purposes by both storing component information and generating compliance artifacts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250362903A1Program components registration using project metadata
Publication Date: 2025.11.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250362903A1 patent drawing
  • US20250362903A1 patent drawing
  • US20250362903A1 patent drawing

AI summary

In some examples, a system receives, at a proxy, build command information from a build tool. Based on the build command information, the proxy obtains program components from one or more program repositories for building a deliverable with the build tool. The proxy associates project metadata with the build command information, the project metadata relating to a project associated with building the deliverable comprising the program components. The proxy initiates a registration of the program components with the project metadata in a provenance repository. The system generates, using the provenance repository, component information identifying the program components that are part of the deliverable.