Dynamic SBOM Docking Control for Secure Edge Capacity Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge computing architectures lack the ability to dynamically check whether edge capacities have acceptable compliance and security compared to the network/cloud computing system, exposing the network to security threats.

Innovation Solution

Implement a BOM enabled agent on edge capacities to generate a BOM data structure, perform a lookup operation in a BOM controls mapping data structure to identify applicable policies, and enforce compliance and security policies before docking with the cloud computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If edge capacities are added to expand cloud computing network capabilities, then the network's processing and storage capacity increases, but security threats and compliance risks increase

Engineering Contradiction:
Improvenetwork capacityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs security assessments and compliance checks before allowing edge capacities to dock with the cloud computing network. The BOM enabled agent evaluates security controls, policies, and configurations in advance, identifying and remediating vulnerabilities before the edge capacity becomes part of the network, thus preventing security threats from being introduced

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a BOM enabled agent as an intermediary between edge capacities and the cloud computing network. This agent acts as a security gateway that assesses, validates, and mediates the docking process, ensuring that only compliant and secure edge capacities are integrated into the network while maintaining network security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If diverse edge capacities with different configurations are allowed to connect, then system versatility improves, but compliance verification complexity increases

Engineering Contradiction:
Improveedge capacity diversityVSAvoidcompliance verification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal BOM data structure and standardized control framework that can accommodate diverse edge capacities with different hardware, software, and configuration variations. The same BOM enabled agent and assessment methodology work across all edge capacity types, providing a unified approach to compliance verification regardless of the specific edge device being evaluated

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent dynamically adjusts security controls and assessment parameters based on the specific BOM data returned from each edge capacity. The system modifies verification depth, control requirements, and policy enforcement levels according to the identified components, configurations, and risk profiles of individual edge capacities, optimizing compliance verification for each device type

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12476969B2Dynamic SBOM based secure docking of edge capacity to existing computing systems
Publication Date: 2025.11.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12476969B2 patent drawing
  • US12476969B2 patent drawing
  • US12476969B2 patent drawing

AI summary

Mechanisms are provided for controlling docking of an edge capacity with a cloud computing system. A bill of materials (BOM) enabled agent, executing on the edge capacity, sends a BOM data structure specifying components of a configuration of the edge capacity. A lookup operation of components of the BOM data structure is performed in a BOM controls mapping data structure to identify controls or policies applicable to the components of the BOM data structure. The identified controls/policies are transmitted to the BOM enabled agent for execution to determine if there are any violations. Results of the identified controls or policies are received which specify whether there are any violations of the controls/policies. In response to at least one violation being detected, docking of the edge capacity with the cloud computing system is denied. In response to no violations, the edge capacity docks with the cloud computing system.