Software Provenance Tracking via External Marketplace Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective provenance tracking and incentivization for derivative software work, allowing unauthorized modifications and sales, which undermines original developer compensation in centralized marketplaces.
Innovation Solution
A developer toolkit with a provenance tracker that identifies and verifies ownership of software bundles through cryptographic and non-cryptographic methods, constructing a tree structure to track origins and ensure proper royalty payments, and includes a user interface for creating and modifying software bundles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If product codes are embedded in VM images to track ownership, then original developers can be identified and compensated, but privileged users with root access can change or remove the product codes
Solution Approach 1:
The patent introduces a marketplace infrastructure as an intermediary that hosts and verifies product codes externally. Instead of storing product codes within the VM images where they can be tampered with, the system uses the marketplace server as a trusted mediator to validate ownership. The VM images reference product codes stored on the marketplace infrastructure, which performs verification without requiring the codes to be embedded in the images themselves.
Solution Approach 2:
The patent replaces the mechanical/embedded approach (storing product codes directly in VM images) with a service-based verification system. The marketplace infrastructure provides a remote verification service that checks ownership claims without relying on embedded credentials that could be extracted or modified. This substitution moves the trust model from embedded authentication to service-based validation.
2Adaptability or versatility
If VM images are shared and modified by multiple developers, then collaboration and derivative works are enabled, but tracking provenance and ensuring proper compensation becomes complex
Solution Approach 1:
The patent implements preliminary action by requiring developers to declare the product codes of original VM images before creating derivative works. The marketplace infrastructure pre-records these relationships in a provenance database, establishing the ownership chain before any potential disputes arise. This proactive declaration system simplifies later verification and compensation calculations compared to attempting to track modifications retroactively.
Solution Approach 2:
The system implements feedback mechanisms where the marketplace infrastructure continuously monitors and verifies provenance relationships. When derivative works are submitted, the system automatically checks against the recorded provenance data and provides feedback on compensation requirements. This continuous verification loop ensures that provenance tracking remains accurate and that compensation can be automatically calculated based on the chain of derivative works.
3Measurement precision
If product codes are embedded in VM images, then ownership can be tracked, but the system becomes vulnerable to cheating and obfuscation attempts
Solution Approach 1:
The marketplace infrastructure acts as a trusted intermediary that performs ownership verification independently of the VM image contents. Instead of relying on embedded product codes that can be obscured or removed, the system uses the marketplace server to validate ownership claims against externally stored records. This intermediary approach maintains measurement precision while eliminating the vulnerability to embedding-related attacks.
Solution Approach 2:
The patent moves the product code storage from the VM image dimension to the marketplace infrastructure dimension. By externalizing the authentication data to a separate, controlled environment, the system creates a new dimension of security where verification occurs outside the potentially compromised VM image space. This dimensional separation prevents obfuscation attempts within the image from affecting ownership verification.
Data Source
AI summary
A system and method for tracking provenance for software use and development includes a developer toolkit program stored in memory and accessible by a software market place, the software marketplace providing a library of software bundles usable for software development and modification of the software bundles. The developer toolkit includes a user interface configured to enable software creation of original works and derivative works. The development toolkit further includes a provenance tracker configured to track provenance of the derivative works and original works wherein the provenance tracker makes the derivative work and the provenance of the derivative work available in the software market place. The provenance tracker includes a software bundle identification module configured to identify and verify ownership of the original works and derivative works by associating an owner of the derivative works and original works with features included in portions of the derivative works and original works.


