IP Library Granted Patent US 12,737,448
Granted Patent B2
US 12,737,448 · App. 17/946,776 · Granted Sep 15, 2026

Security compliance for modular code

Inventors: Anthony Thomas Rowlands (Moore, OK); Michael Joseph Fraser (Incline Village, NV)
Assignee: Sophos Limited
G06F21/52G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,448
App. No.
17/946,776
Granted
Sep 15, 2026
Kind
B2
Abstract

A catalog of pipelines for modular coding integrates resources for security compliance. The platform may incorporate tools and metadata for selecting suitable compliance standards and verifying security compliance for existing pipelines within the catalog as well as new pipelines created from existing pipelines.

Claims (50)

1 . A computer program product comprising a non-transitory computer readable medium storing computer executable code that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

storing a catalog of pipelines, each of the pipelines executable on computing resources of an enterprise for performing security functions;

storing a description of a pipeline in the catalog of pipelines, the description including:

an identifier for the pipeline,

a version for the pipeline, and

a definition of the pipeline including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing code segments used in the pipeline, the graph characterizing a location for accessing the code segments for each other one of the pipelines, a component security compliance of each other one of the pipelines, and a functional location of the code segments for each of the other pipelines in the pipeline;

evaluating a security compliance of the pipeline for execution in the enterprise based on security compliances for each of the other pipelines identified in the graph of the definition for the pipeline by performing the steps of:

traversing the graph for the pipeline to identify the component security compliance of each other one of the pipelines,

evaluating the component security compliance of each of the other pipelines identified in the graph based on a security compliance framework for the enterprise, thereby providing one or more evaluations of the component security compliance of each of the other pipelines identified in the graph, and

evaluating the security compliance of the pipeline based on the one or more evaluations of the component security compliance of each of the other pipelines identified in the graph; and

storing the security compliance in the description of the pipeline.

2 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying an operation of at least one of the code segments used in the at least one of the other pipelines.

3 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying a source of the at least one of the other pipelines from the catalog.

4 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying a source of at least one of the code segments used in the at least one of the other pipelines.

5 . The computer program product of claim 1 , wherein the component security compliance is based on an industry standard compliance framework.

6 . The computer program product of claim 1 , further comprising, when the security compliance of the pipeline fails to meet a predetermined condition, evaluating the security compliance independently from the component security compliance of each of the other pipelines.

7 . A method comprising:

storing a catalog of pipelines, each of the pipelines executable on computing resources of an enterprise for performing security functions;

storing a description of a pipeline in the catalog of pipelines, the description including:

an identifier,

a version, and

a definition including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing resources used in the pipeline, the graph characterizing a location for accessing the resources for each other one of the pipelines, a component security compliance of each other one of the pipelines, one or more evaluations of the component security compliance of each other one of the pipelines in the definition, and a functional location of the resources for each of the other pipelines in the pipeline;

evaluating a security compliance of the pipeline for execution in the enterprise based on security compliances for each of the other pipelines identified in the graph of the definition for the pipeline by performing the steps of:

traversing the graph for the pipeline to identify the one or more evaluations of the component security compliance of each other one of the pipelines, and

evaluating the security compliance of the pipeline relative to a security compliance framework based on the one or more evaluations of the component security compliance of each of the other pipelines identified in the graph; and

storing the security compliance in the description of the pipeline.

8 . The method of claim 7 , wherein evaluating the security compliance includes verifying an operation of at least one of the resources used in the pipeline.

9 . The method of claim 7 , wherein evaluating the security compliance includes verifying a source of at least one of the other pipelines from the catalog containing resources used in the pipeline.

10 . The method of claim 7 , wherein evaluating the security compliance includes verifying a source of at least one of the resources used in the pipeline.

11 . The method of claim 7 , wherein the security compliance framework for the enterprise includes an industry standard compliance framework.

12 . The method of claim 7 , wherein the security compliance framework for the enterprise includes at least one security policy specified by an end user.

13 . The method of claim 7 , further comprising:

evaluating the component security compliance of each of the other pipelines in the pipeline based on the security compliance framework for the enterprise; and

evaluating the security compliance of the pipeline based on the component security compliance of each of the other pipelines.

14 . The method of claim 7 , further comprising verifying the security compliance of the pipeline independently from the component security compliance of each of the other pipelines.

15 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for a source of the pipeline.

16 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for a source of at least one of the other pipelines in the graph of other pipelines from the catalog.

17 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for at least one of the resources used in the pipeline.

18 . A system comprising:

a data repository in a non-transitory physical memory, the data repository storing a catalog of pipelines for performing security functions;

a description of a pipeline stored as non-transitory information in the catalog of pipelines in the non-transitory physical memory of the data repository, each of the pipelines executable on computing resources of an enterprise, the description including:

an identifier for the pipeline,

a version for the pipeline,

a definition including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing resources used in the pipeline, the graph characterizing a location for accessing the resources for each other one of the pipelines, a component security compliance of each other one of the pipelines, one or more evaluations of the component security compliance of each other one of the pipelines used in the pipeline, and a functional location of the resources for each of the other pipelines in the pipeline, and

a security compliance of the pipeline for execution in the enterprise based on the component security compliance for each of the other pipelines identified in the graph of the definition for the pipeline, wherein the security compliance of the pipeline is determined by performing the steps of:

evaluating the component security compliance of each other one of the pipelines in the definition based on a security compliance framework for the enterprise, and

evaluating the component security compliance of each of the other pipelines in the definition to a compliance framework for a user of the data repository; and

an integrated development environment executing on one or more processors, the integrated development environment configured by non-transitory computer executable code executing on the one or more processors to create and deploy an application using the catalog of pipelines, the integrated development environment including a user interface for selecting and arranging pipelines from the catalog into the application.

19 . The system of claim 18 , further comprising a search interface to the data repository, the search interface configured to support searches of the catalog for pipelines of interest.

20 . The system of claim 18 , wherein the data repository includes at least one of a cloud-based data repository and a federated data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2022
From: ROWLANDS, ANTHONY THOMAS; FRASER, MICHAEL JOSEPH
To: SOPHOS LIMITED
Reel/Frame 061562/0858 →
Continuity (1)
Related Publication 20240095337A1 · Mar 21, 2024
References Cited (79)
US 8141162B2 · Myles · 2012 [cited by applicant]
US 8151282B2 · Carnahan · 2012 [cited by applicant]
US 10534983B1 · Tung et al. · 2020 [cited by applicant]
US 10902046B2 · Carrier et al. · 2021 [cited by applicant]
US 11221831B1 · Al Khafaji et al. · 2022 [cited by applicant]
US 11281673B2 · Nanda et al. · 2022 [cited by applicant]
US 11403094B2 · Mirantes et al. · 2022 [cited by applicant]
US 11431785B2 · Spaven et al. · 2022 [cited by applicant]
US 11461672B2 · Filoti et al. · 2022 [cited by applicant]
US 11500895B2 · Fan et al. · 2022 [cited by applicant]
US 11775898B1 · Thompson et al. · 2023 [cited by applicant]
US 11823073B2 · Doan Huu · 2023 [cited by applicant]
US 11983189B2 · Fan et al. · 2024 [cited by applicant]
US 20040017395A1 · Cook · 2004 [cited by applicant]
US 20060229896A1 · Rosen et al. · 2006 [cited by applicant]
US 20070011437A1 · Carnahan · 2007 [cited by applicant]
US 20090113553A1 · Myles · 2009 [cited by applicant]
US 20110029549A1 · Pandya · 2011 [cited by applicant]
US 20140108321A1 · Buchanan et al. · 2014 [cited by applicant]
US 20140359119A1 · Spaven et al. · 2014 [cited by applicant]
US 20140365575A1 · Spaven et al. · 2014 [cited by applicant]
US 20160004973A1 · Trenkov et al. · 2016 [cited by applicant]
US 20180342324A1 · Cha et al. · 2018 [cited by applicant]
US 20190243836A1 · Nanda et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20200021620A1 · Purathepparambil et al. · 2020 [cited by applicant]
US 20200082223A1 · Tung et al. · 2020 [cited by applicant]
US 20200151588A1 · Doan Huu · 2020 [cited by applicant]
US 20200175051A1 · Carrier et al. · 2020 [cited by applicant]
US 20200257990A1 · Filoti et al. · 2020 [cited by applicant]
US 20200394305A1 · Cosgrove · 2020 [cited by examiner]
US 20210232388A1 · Mirantes · 2021 [cited by examiner]
US 20210292646A1 · Cha et al. · 2021 [cited by applicant]
US 20210303584A1 · Fan et al. · 2021 [cited by applicant]
US 20210303585A1 · Fan et al. · 2021 [cited by applicant]
US 20210334254A1 · Thompson et al. · 2021 [cited by applicant]
US 20210377146A1 · Sommers · 2021 [cited by applicant]
US 20220121479A1 · Chivukula et al. · 2022 [cited by applicant]
US 20220121480A1 · Chivukula et al. · 2022 [cited by applicant]
US 20220374443A1 · Fan et al. · 2022 [cited by applicant]
US 20230045235A1 · Pierscieniak et al. · 2023 [cited by applicant]
US 20230092030A1 · Battaglia et al. · 2023 [cited by applicant]
US 20230101551A1 · Jobanputra et al. · 2023 [cited by applicant]
US 20230128753A1 · Bawa et al. · 2023 [cited by applicant]
US 20230161945A1 · Vadapandeshwara et al. · 2023 [cited by applicant]
US 20230259650A1 · Sepehri · 2023 [cited by examiner]
US 20230267483A1 · Joshi et al. · 2023 [cited by applicant]
US 20230315534A1 · Asawa et al. · 2023 [cited by applicant]
US 20230409585A1 · Dunning et al. · 2023 [cited by applicant]
US 20240086190A1 · Kwatra · 2024 [cited by examiner]
US 20240095029A1 · Rowlands et al. · 2024 [cited by applicant]
UKIPO, “UK Application No. 2312859.8 Search and Examination Report mailed Feb. 23, 2024”, 8 pages. [cited by applicant]
Refactr, “Building Pipelines”, Wiki materials published to refactr.it website on or about May 17, 2021 , 4 Pages. [cited by applicant]
Refactr, “Building Pipelines Best Practices”, Wiki materials published to refactr.it website on or about Jan. 6, 2021 , 3 Pages. [cited by applicant]
Refactr, “Clone a GitHub Repository”, Wiki materials published to refactr.it website on or about Feb. 10, 2021 , 4 Pages. [cited by applicant]
Refactr, “Clone a GitLab Project”, Wiki materials published to refactr.it website on or about Feb. 10, 2021 , 4 Pages. [cited by applicant]
Refactr, “Core Concepts”, Wiki materials published to refactr.it website on or about Nov. 16, 2020 , 2 Pages. [cited by applicant]
Refactr, “Credential Types”, Wiki materials published to refactr.it website on or about Dec. 22, 2020 , 2 Pages. [cited by applicant]
Refactr, “Deprecation Schedule”, Wiki materials published to refactr.it website on or about Jul. 21, 2021 , 2 Pages. [cited by applicant]
Refactr, “Expression Reference”, Wiki materials published to refactr.it website on or about May 17, 2021 , 8 Pages. [cited by applicant]
Refactr, “Getting Started”, Wiki materials published to refactr.it website on or about Mar. 29, 2021 , 3 Pages. [cited by applicant]
Refactr, “Kubernetes on Google Cloud Platform”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 3 Pages. [cited by applicant]
Refactr, “Managing Teams”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 2 Pages. [cited by applicant]
Refactr, “Read and Write Files”, Wiki materials published to refactr.it website on or about Nov. 10, 2020 , 3 Pages. [cited by applicant]
Refactr, “Reference”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 1 Page. [cited by applicant]
Refactr, “Release Notes”, Wiki materials published to refactr.it website on or about Jul. 21, 2021 , 8 Pages. [cited by applicant]
Refactr, “Runners”, Wiki materials published to refactr.it website on or about Mar. 29, 2021 , 3 Pages. [cited by applicant]
Refactr, “Running Pipelines”, Wiki materials published to refactr.it website on or about May 17, 2021 , 3 Pages. [cited by applicant]
Refactr, “Send an HTTP Request”, Wiki materials published to refactr.it website on or about Nov. 1, 2020 , 4 Pages. [cited by applicant]
Refactr, “Sharing Pipelines”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 3 Pages. [cited by applicant]
Refactr, “Tutorials”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 1 Page. [cited by applicant]
Refactr, “Using the API”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 2 Pages. [cited by applicant]
Refactr, “Using the CLI”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 4 Pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/946,752 Non-Final Office Action mailed Jun. 18, 2024”, , 31 pages. [cited by applicant]
UKIPO, “UK Application No. 2312859.8 Examination Report mailed Aug. 15, 2024”, 3 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/946,752 Final Office Action mailed Apr. 28, 2025”, 37 pages. [cited by applicant]
UKIPO, , “UK Application No. 2312859.8 Examination Report mailed Mar. 12, 2025”, 3 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/946,752 Non-Final Office Action mailed Jul. 30, 2025”, 17 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/946,752 Notice of Allowance mailed Nov. 6, 2025”, 14 pages. [cited by applicant]