Enterprise Software Supply Chain Security via Blockchain SBOMs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing software supply chain security approaches lack transparency, traceability, and effective verification mechanisms, leading to potential security breaches and vulnerabilities due to complex ecosystems and cyberattacks.
Innovation Solution
A system leveraging blockchain and large language models (LLM) for a 'Know Your Software' (KYS) approach, which includes a metadata extractor, an enhanced software bill of materials generator, and a smart software supply chain contract to ensure secure and transparent software component management, verification, and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If blockchain technology is used to track software ownership and usage, then transparency and traceability are improved, but device complexity increases
Solution Approach 1:
The patent introduces a blockchain as an intermediary distributed ledger that mediates between software components and their metadata. The blockchain provides a transparent, immutable record of software ownership, usage, and provenance without requiring direct complex interactions between all system components. Smart contracts serve as automated intermediaries that enforce policies and manage permissions.
Solution Approach 2:
The patent creates digital copies of software metadata, provenance information, and usage records that are stored on the blockchain. These copies provide transparent access to information about software components, their origins, and their usage history, enabling traceability without requiring direct access to original software artifacts.
2Reliability
If metadata extraction and verification mechanisms are implemented, then software verification is improved, but processing time increases
Solution Approach 1:
The patent extracts and stores metadata about software components, their dependencies, and provenance information in advance during the software build and deployment processes. This preliminary action allows for rapid verification later, as the metadata is already prepared and indexed on the blockchain, eliminating the need for time-consuming analysis during verification operations.
Solution Approach 2:
The patent replaces manual verification processes with automated smart contracts and cryptographic verification mechanisms. These automated systems perform verification tasks that would otherwise require significant human time and computational resources, thereby improving verification accuracy while reducing processing time.
3Ease of operation
If dependency management complexity is reduced, then ease of operation is improved, but security vulnerabilities increase
Solution Approach 1:
The patent implements continuous feedback mechanisms where the blockchain records and verifies software dependencies, their versions, and provenance information. This feedback loop enables automated detection of vulnerable dependencies and ensures that only verified, secure components are deployed, maintaining security while simplifying dependency management through automated enforcement.
Solution Approach 2:
The patent changes the parameters of dependency management by introducing cryptographic hashes, digital signatures, and immutable records on the blockchain. These parameter changes enable automated verification and enforcement of dependency policies, reducing the operational complexity of managing dependencies while maintaining strong security controls.
Data Source
AI summary
A system and method for securing an enterprise's software supply chain includes an enterprise, a build artifact, and a metadata extractor. The metadata extractor is configured to extract metadata from the build artifact and send the metadata to an enhanced software bill of materials generator. The enhanced software bill of materials generator may generate a software bill of materials based on the metadata. A know your system large language model (“KYS LLM”) is also provided. The KYS LLM is configured to be trained by the metadata and to receive a query from an actor. An enterprise blockchain is provided and may receive the metadata and a query. The enterprise blockchain may include an application programming interface configured to initiate a download of dependencies from the enterprise blockchain. A pipeline may be provided to receive the download of the dependencies from enterprise blockchain and deploy information from the download.


