Machine-Learned Code Evaluation for Security and Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing manual review processes for evaluating third-party software are time-consuming and expensive, posing risks to security, safety, privacy, and policy compliance of computing devices.

Innovation Solution

A machine-learned model is trained to evaluate computer-readable code and its corresponding code description, determining the level of agreement between descriptions and identifying prohibited features, allowing for efficient and automated approval of software on digital distribution platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review processes are used to evaluate third-party software, then security and compliance can be ensured, but the process becomes time-consuming and expensive

Engineering Contradiction:
ImprovesecurityVSAvoidreview time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an automated code analysis system as an intermediary between third-party software developers and the manual review process. This system uses static analysis, dynamic analysis, and machine learning models to evaluate code for security vulnerabilities, performance issues, and compliance with guidelines, thereby maintaining security assurance while dramatically reducing review time and costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual review process with an automated computational system. Instead of relying solely on human reviewers to manually examine code, the system employs automated tools including static analyzers, dynamic testers, and AI-based evaluation models to perform the assessment, thus eliminating the time and resource constraints of manual processes while maintaining or improving security evaluation quality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual review processes are used to evaluate third-party software, then security and compliance can be ensured, but the cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidevaluation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The automated code analysis system serves as an intermediary that performs preliminary security and compliance evaluations, reducing the need for expensive manual review processes. By filtering out clearly problematic code and providing detailed analysis reports, the system enables more efficient allocation of human review resources, thereby reducing overall evaluation costs while maintaining security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent substitutes expensive manual labor with automated computational tools. The system employs open-source and commercially-available analysis tools, along with machine learning models, to perform comprehensive code evaluations at a fraction of the cost of manual review, while maintaining or improving the quality of security and compliance assurance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated evaluation is used to assess third-party software, then review time is reduced, but the ability to ensure security and compliance may be compromised

Engineering Contradiction:
Improvereview efficiencyVSAvoidsecurity assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the security evaluation process into multiple independent analysis components: static code analysis, dynamic testing, vulnerability scanning, and machine learning-based assessment. Each component focuses on specific security aspects and can be performed automatically, with results aggregated to form a comprehensive security evaluation. This segmentation enables automated processing while maintaining thorough security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements multi-layered feedback mechanisms where automated analysis tools provide detailed findings that are reviewed and validated. The machine learning models are trained on historical security data and continuously improved based on feedback from actual security incidents and expert reviews, ensuring that automated evaluations maintain high reliability while achieving rapid assessment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250110850A1Evaluating Computer-Readable Code
Publication Date: 2025.04.03 GOOGLE LLC
  • US20250110850A1 patent drawing
  • US20250110850A1 patent drawing
  • US20250110850A1 patent drawing

AI summary

Techniques are described for evaluating computer-readable code. In example aspects, a machine-learned model is trained to evaluate computer-readable code and/or its corresponding code description. As part of the evaluation, the machine-learned model can determine a level of agreement between the code description and the computer-readable code. Additionally or alternatively, the machine-learned model can determine that a prohibited feature is absent from (or present in) the computer-readable code. If present, the prohibited feature can compromise a security of a device that executes the computer-readable code, a safety of a user operating the device, and/or the user's privacy. Additionally or alternatively, the prohibited feature can violate a policy of a manufacturer of the device. With this machine-learned model, the manufacturer can efficiently evaluate computer-readable code and code descriptions that are provided by a third-party developer and can determine whether to make the third-party software available to users via a digital distribution platform.