Automated Software Package Verification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Verifying that software packages developed at remote sites meet specific requirements and detect unauthorized code injections is time-consuming and inefficient, especially when access to servers and user systems is limited.
Innovation Solution
A verification system that communicatively couples package development, verification, and user systems via data networks, using modules like the communication module, manifest repository, package repository, package verification, and distribution modules to compare manifest data with developed software packages for code injections, requirements compliance, and timestamp validation, with customizable comparison combinations based on risk levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual verification of software packages is performed, then verification thoroughness is improved, but verification time and labor effort increase significantly
Solution Approach 1:
The verification system performs self-service by automatically comparing software packages against manifest data without requiring manual intervention. The system autonomously checks for code injections, validates requirements compliance, and verifies timestamps, eliminating the need for manual verification while maintaining thoroughness.
Solution Approach 2:
The patent replaces manual mechanical verification processes with an automated computer-based verification system. The system uses software modules to automatically compare package contents against manifest data, substituting human manual checking with automated computational comparison to reduce time while maintaining reliability.
2Reliability
If comprehensive verification checks are implemented, then package security is improved, but system complexity increases
Solution Approach 1:
The verification system is segmented into distinct functional modules: a communication module for data exchange, a manifest repository for storing reference data, a package verification module for execution, and a distribution module for delivering results. This segmentation allows comprehensive security checks to be performed through organized, manageable functional components rather than a monolithic complex system.
Solution Approach 2:
The verification system achieves multi-functionality by integrating multiple verification capabilities within a single system framework. The same system performs code injection detection, requirements compliance validation, and timestamp verification, eliminating the need for separate specialized systems and reducing overall complexity while maintaining comprehensive security.
3Adaptability or versatility
If verification access to servers and user systems is expanded, then verification capability is improved, but access control complexity and security risks increase
Solution Approach 1:
The verification system acts as an intermediary between package development systems and user systems. Rather than requiring direct access to servers and user systems, the verification system receives packages from development systems, performs verification using manifest data from a repository, and distributes results to user systems. This intermediary role enables comprehensive verification capability while simplifying access control through a centralized verification function.
Data Source
AI summary
The system and method may include identifying manifest data associated with a package to be developed on a package development system, receiving the package from the package development system via a first network, comparing the manifest data to the package to determine whether a code injection exists in the package, and distributing the package to a plurality of user systems via a second network based on a determination that the code injection does not exist in the package.


