Enterprise Software Supply Chain Security via Blockchain SBOMs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing software supply chain security approaches lack transparency, traceability, and effective verification mechanisms, leading to potential security breaches and vulnerabilities due to complex ecosystems and cyberattacks.

Innovation Solution

A system leveraging blockchain and large language models (LLM) for a 'Know Your Software' (KYS) approach, which includes a metadata extractor, an enhanced software bill of materials generator, and a smart software supply chain contract to ensure secure and transparent software component management, verification, and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If blockchain technology is used to track software ownership and usage, then transparency and traceability are improved, but device complexity increases

Engineering Contradiction:
ImprovetransparencyVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain as an intermediary distributed ledger that mediates between software components and their metadata. The blockchain provides a transparent, immutable record of software ownership, usage, and provenance without requiring direct complex interactions between all system components. Smart contracts serve as automated intermediaries that enforce policies and manage permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates digital copies of software metadata, provenance information, and usage records that are stored on the blockchain. These copies provide transparent access to information about software components, their origins, and their usage history, enabling traceability without requiring direct access to original software artifacts.

Inventive Principle:
Principle #26Copying

2Reliability

If metadata extraction and verification mechanisms are implemented, then software verification is improved, but processing time increases

Engineering Contradiction:
Improveverification accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and stores metadata about software components, their dependencies, and provenance information in advance during the software build and deployment processes. This preliminary action allows for rapid verification later, as the metadata is already prepared and indexed on the blockchain, eliminating the need for time-consuming analysis during verification operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual verification processes with automated smart contracts and cryptographic verification mechanisms. These automated systems perform verification tasks that would otherwise require significant human time and computational resources, thereby improving verification accuracy while reducing processing time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If dependency management complexity is reduced, then ease of operation is improved, but security vulnerabilities increase

Engineering Contradiction:
Improvedependency managementVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback mechanisms where the blockchain records and verifies software dependencies, their versions, and provenance information. This feedback loop enables automated detection of vulnerable dependencies and ensures that only verified, secure components are deployed, maintaining security while simplifying dependency management through automated enforcement.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameters of dependency management by introducing cryptographic hashes, digital signatures, and immutable records on the blockchain. These parameter changes enable automated verification and enforcement of dependency policies, reducing the operational complexity of managing dependencies while maintaining strong security controls.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250217113A1System and method for enterprise software supply chain security
Publication Date: 2025.07.03 GUARDIAN LIFE INSURANCE COMPANY OF AMERICA
  • US20250217113A1 patent drawing
  • US20250217113A1 patent drawing
  • US20250217113A1 patent drawing

AI summary

A system and method for securing an enterprise's software supply chain includes an enterprise, a build artifact, and a metadata extractor. The metadata extractor is configured to extract metadata from the build artifact and send the metadata to an enhanced software bill of materials generator. The enhanced software bill of materials generator may generate a software bill of materials based on the metadata. A know your system large language model (“KYS LLM”) is also provided. The KYS LLM is configured to be trained by the metadata and to receive a query from an actor. An enterprise blockchain is provided and may receive the metadata and a query. The enterprise blockchain may include an application programming interface configured to initiate a download of dependencies from the enterprise blockchain. A pipeline may be provided to receive the download of the dependencies from enterprise blockchain and deploy information from the download.