Open Source Software Compliance Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The large volume of open source software (OSS) components and diverse license types pose challenges in analyzing and ensuring compliance during software development, packaging, and delivery, as existing systems struggle to categorize and manage OSS components effectively.

Innovation Solution

A processor-implemented method and system that compares OSS components in a product with a public database, categorizes them based on license types (strong copyleft, permissive, or weak copyleft), identifies usage types, and generates compliance reports, while updating a database to ensure ongoing compliance analysis and adaptation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of OSS components is performed, then compliance accuracy can be ensured, but the analysis time and resources required increase significantly due to the large volume of components

Engineering Contradiction:
Improvecompliance analysis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the OSS analysis process into distinct phases: fingerprint extraction from binary files, database matching against known OSS components, license type classification, and compliance rule evaluation. This segmentation enables automated parallel processing of multiple components while maintaining thorough analysis of each component's compliance attributes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary database containing pre-stored OSS component information, fingerprints, and license details. This intermediary database acts as a reference repository that enables rapid automated matching and comparison, eliminating the need for manual analysis while preserving compliance accuracy through systematic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive database of OSS components is maintained, then matching accuracy improves, but database management and updates become more complex

Engineering Contradiction:
Improvecomponent matching accuracyVSAvoiddatabase management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-computing and storing OSS component fingerprints, license information, and compatibility rules in the database before actual compliance checking occurs. This pre-processing enables rapid automated matching during product analysis without requiring complex real-time computations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where compliance analysis results and newly discovered OSS components are fed back into the database for continuous updates. This feedback loop maintains database accuracy and completeness automatically, reducing manual management complexity while improving matching precision over time

Inventive Principle:
Principle #23Feedback

3Reliability

If detailed compliance rules are enforced for all OSS components, then legal compliance is ensured, but the complexity of compliance checking increases

Engineering Contradiction:
Improvelegal compliance assuranceVSAvoidcompliance checking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by tailoring the depth and type of compliance checking to each specific OSS component based on its license classification. Different license types (GPL, LGPL, Apache, MIT) receive appropriately differentiated compliance evaluations, focusing detailed analysis only where legally required rather than uniformly applying complex rules to all components

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11816190B2Systems and methods to analyze open source components in software products
Publication Date: 2023.11.14 TATA CONSULTANCY SERVICES LTD
  • US11816190B2 patent drawing
  • US11816190B2 patent drawing
  • US11816190B2 patent drawing

AI summary

Considering the number of OSS components and the number of OSS license types available today, the number of license attributes to be considered for analyzing a product at a granular level is a challenge to perform manually, prudently considering legal implications of non-compliance and contamination and also within the limited time available today before go to market in the software industry. Systems and methods of the present disclosure intelligently facilitates a matrix which is able to identify OSS components in a deliverable and also facilitates the product owner to identify proprietary IP that can be suitably protected and licensed without contamination by the accompanying OSS components in the product under consideration. License attributes of the OSS components are mapped suitably and a final attribute is derived for each OSS component embedded in the product under consideration.