OSS Compliance Analysis System for Software Products

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing open source software (OSS) compliance in software products is exacerbated by the large number of OSS components (over 1.2 million) and diverse license types (over 2000), making it challenging to ensure technical and legal compliance during software development, packaging, and delivery.

Innovation Solution

A processor-implemented method and system that compares OSS components in a product with a public database, categorizes them based on license types (strong copyleft, permissive, weak copyleft), identifies usage types, and generates comprehensive reports on compliance, using adaptive learning to update a database with OSS component information and pre-defined rules for compliance analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of OSS components is performed, then compliance accuracy can be maintained, but the analysis time and resource consumption increase significantly due to the large volume of components

Engineering Contradiction:
Improvecompliance analysis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the OSS component analysis process into multiple stages: initial database matching for quick identification, attribute-based filtering for detailed verification, and rule-based compliance checking. This multi-level segmentation enables automated processing of large volumes of components while maintaining compliance accuracy through progressive refinement at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary database system that stores pre-analyzed OSS component information, attributes, and license data. This intermediary database acts as a mediator between the raw OSS components and the compliance analysis engine, enabling rapid automated matching and reducing the time required for manual analysis while maintaining accuracy through structured data comparison.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive attribute verification is performed on all OSS components, then compliance reliability is improved, but the complexity of the analysis system increases

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by verifying attributes selectively based on the specific OSS component type, license category, and usage context. Different verification depths are applied to different components: critical components undergo full attribute verification, while less critical components receive streamlined checking. This targeted approach maintains compliance reliability for high-risk areas while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial verification by focusing compliance checks on the most critical attributes and components first. The system performs essential verification on all components (partial action) and applies more exhaustive verification only when initial checks indicate potential compliance issues. This approach ensures reliability for critical compliance requirements without requiring full verification of every attribute for every component.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If automated matching algorithms are used to identify OSS components, then analysis productivity increases, but the precision of component identification may decrease due to false matches

Engineering Contradiction:
Improveanalysis productivityVSAvoidcomponent identification precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the automated matching algorithm continuously refines its results based on verification outcomes. Initial automated matches are followed by attribute-based verification that feeds back into the matching process, allowing the system to learn from false positives and improve identification precision while maintaining high productivity through automated iteration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary automated matching to quickly identify potential OSS components, then applies subsequent verification steps to confirm accuracy. This preliminary action enables the system to process large volumes of code rapidly while maintaining precision through follow-up verification, effectively separating the high-productivity matching phase from the high-precision verification phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240020293A1Systems and methods for analysing software products
Publication Date: 2024.01.18 TATA CONSULTANCY SERVICES LTD
  • US20240020293A1 patent drawing
  • US20240020293A1 patent drawing
  • US20240020293A1 patent drawing

AI summary

Considering the number of OSS components and the number of OSS license types available today, the number of license attributes to be considered for analyzing a product at a granular level is a challenge to perform manually, prudently considering legal implications of non-compliance and contamination and also within the limited time available today before going to market in the software industry. Systems and methods of the present disclosure intelligently facilitates a matrix which is able to identify OSS components in a software product and also facilitates the product owner to identify proprietary IP that can be suitably protected and licensed without contamination by the accompanying OSS components and generated components in the software product under consideration. License attributes of the OSS components are mapped suitably, and a final attribute is derived for each OSS component embedded in the product under consideration.