Open Source Code Discovery and Enforcement System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for an efficient system to discover and analyze software distributed across an electronic network platform of an entity, particularly for managing free and open source software (FOSS) within a technology environment, to ensure proper governance and compliance with open source code rules.
Innovation Solution
A system comprising a processing device that continuously monitors hardware devices, initiates an open source code discovery engine to identify matching applications, and an approval and enforcement engine to determine user access and compliance, automatically populating a database and enforcing access restrictions or uninstallation of non-compliant applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual monitoring and management of software applications is used, then user control and security can be maintained, but the system complexity and time consumption increase significantly
Solution Approach 1:
The system is divided into distinct functional modules: a discovery engine for identifying FOSS applications, a database for storing compliance information, and an enforcement engine for accessing or blocking applications. This segmentation allows automated compliance management while keeping each module's complexity manageable and independently maintainable.
Solution Approach 2:
The patent introduces an intermediary system between users and software applications that automatically discovers, analyzes, and enforces compliance rules. This intermediary handles the complex automation tasks of monitoring application installations, comparing them against compliance databases, and enforcing access controls, thereby reducing the burden on users while maintaining security.
2Reliability
If comprehensive monitoring of all hardware devices is implemented, then complete FOSS compliance can be achieved, but the time and computational resources required increase
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and discovering FOSS applications on hardware devices, storing their information in advance in a database. Compliance rules are pre-established and stored, allowing the system to quickly evaluate new applications against known criteria without time-consuming analysis during access requests.
Solution Approach 2:
The discovery engine operates continuously to monitor hardware devices for new or updated applications, ensuring that compliance information is always current. This continuous operation maintains up-to-date compliance data without requiring periodic manual audits, thereby ensuring reliable compliance assurance while optimizing the use of computational resources through sustained automated monitoring.
3Reliability
If strict enforcement of open source code rules is applied, then compliance is ensured, but user accessibility and system flexibility decrease
Solution Approach 1:
The enforcement engine provides feedback to users about compliance status and access permissions. When a user attempts to access an application, the system checks compliance rules and either grants or denies access based on the evaluation. This automated feedback mechanism ensures compliance enforcement while maintaining ease of operation by providing clear, immediate decisions without requiring manual user intervention or complex user-side compliance checks.
Data Source
AI summary
Systems, computer program products, and methods are described herein for discovery and analysis of software distributed across an electronic network platform of an entity. The present invention is configured to continuously monitor one or more hardware devices associated with a technology environment; initiate an open source code discovery engine on the one or more hardware devices, wherein initiating further comprises automatically populating a first database with at least the portion of the one or more applications that match the attributes associated with open source code identifiers; and initiate an approval and enforcement engine on at least the portion of the one or more applications stored on the first database.

