Software Management with Distributed-Ledger Verification Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software development processes face challenges in ensuring secure and trusted software products due to manual verification and testing inefficiencies, difficulty in mapping test results to software components, and vulnerabilities in the software supply chain, leading to potential cyber-attacks and compliance issues.
Innovation Solution
A software management system utilizing a distributed ledger to automate verification and testing processes, store results securely, and provide transparent and tamper-proof records of software component interactions, including metadata and timestamps, to ensure compliance and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual verification and testing of each software component is performed, then security verification thoroughness is improved, but time consumption and operational complexity increase significantly
Solution Approach 1:
The system enables software components to self-verify through automated execution of verification rules and policies. The verification system automatically executes verification rules against software components, eliminating the need for manual verification while maintaining thorough security checking. This self-service approach allows the system to perform comprehensive security verification without proportionally increasing time consumption.
Solution Approach 2:
The system performs verification and testing actions in advance before software components are deployed or transmitted. By conducting security verification upfront and storing results in the distributed ledger, the system ensures that components are pre-validated, reducing the need for repeated manual verification later and decreasing overall time consumption.
2Reliability
If manual verification and testing of each software component is performed, then security verification thoroughness is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The verification system automatically executes verification rules and policies against software components without requiring manual intervention. This automation reduces operational complexity by eliminating manual steps while maintaining thorough security verification through systematic automated checking of all components.
Solution Approach 2:
The system divides the verification process into discrete, manageable verification rules and policies that can be independently executed and tracked. Each software component is verified against specific rules, and results are segmented and stored in the distributed ledger, making the complex verification process more manageable and less operationally difficult.
3Ease of operation
If test results are shared via non-centralised means such as emails or chat messages, then communication flexibility is improved, but compliance verification and traceability deteriorate
Solution Approach 1:
The system merges communication flexibility with compliance traceability by storing test results and verification data in a centralized distributed ledger that is accessible to all authorized parties. This unified approach maintains the ease of sharing results while ensuring that all communications and results are recorded and traceable for compliance verification.
Solution Approach 2:
The distributed ledger acts as an intermediary that receives and stores test results from the verification system, providing a centralized, tamper-proof record that maintains communication efficiency while ensuring compliance traceability. The ledger mediates between the verification process and compliance requirements, preserving both flexibility and accountability.
4Ease of operation
If software components are transmitted to and stored on a server for distribution, then accessibility and utility are improved, but vulnerability to malicious code injection increases
Solution Approach 1:
The system performs verification and security checking of software components before they are transmitted to the server for distribution. By pre-validating components and recording their verification status in the distributed ledger, the system ensures that only verified components are made accessible, reducing the risk of malicious code injection while maintaining accessibility.
Solution Approach 2:
The system uses the distributed ledger to provide feedback on the verification status of software components. This feedback mechanism allows the system to track and control which components are transmitted and distributed, enabling continuous monitoring and reducing vulnerability to malicious code by maintaining an auditable record of all transmitted components.
5Measurement precision
If mapping of test results to software components requires significant human input, then verification accuracy is improved, but productivity and efficiency deteriorate
Solution Approach 1:
The system automatically maps test results to software components through automated execution of verification rules and policies. The verification system independently correlates test results with the corresponding software components and stores these mappings in the distributed ledger, eliminating the need for significant human input while maintaining verification accuracy through systematic automated processes.
Solution Approach 2:
The system performs automated mapping of test results to software components as part of the preliminary verification process. By automatically establishing these mappings before distribution, the system ensures accurate tracking and verification while significantly improving productivity compared to manual mapping processes.
Data Source
AI summary
A software management system comprising: a controller; a distributed ledger in communication with the controller, the distributed ledger comprising one or more records; and a set of software tools configured to be executed by the controller; wherein the controller is configured to: receive a software component; execute one or more software verification tools of the set of software tools, thereby producing a result; and store the result on a record of the distributed ledger.


