IP Library › Granted Patent US 12,265,946
Granted Patent B2
US 12,265,946 · App. 17/736,428 · Granted Apr 1, 2025

Risk assessment based on augmented software bill of materials

Inventors: Neil David Jonathan Duggan (Basingstoke, GB); Adam John Boulton (Wirral, GB)
Assignee: BlackBerry Limited
G06Q10/0875G06Q10/0635G06Q10/0637
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,946
App. No.
17/736,428
Granted
Apr 1, 2025
Kind
B2
Abstract

Systems, methods, and software can be used to identify security risks in software code based on Software Bill of Materials (SBOM). In some aspects, a method includes: obtaining, by a server, software code and a SBOM corresponding to the software code; identifying, by the server and based on the SBOM, a library used by the software code; and generating, by the server, a risk assessment based on at least one metric corresponding to the library, where the at least one metric is associated with one or more maintainers of the library.

Claims (42)

1. A method, comprising:

obtaining, by a server, software code and a Software Bill of Materials (SBOM) corresponding to the software code, wherein the SBOM comprises information related to a software development standard;

determining, by the server and based on the information related to the software development standard in the SBOM, whether the software code comprises a risk, wherein the software code comprises a component, the component comprises a plurality of subcomponents, and the information in the SBOM comprises a Cybersecurity Assurance Level (CAL) rating of each of the plurality of subcomponents, and wherein determining whether the software code comprises a risk comprises:

determining, by the server, a CAL rating of the component based on the CAL rating of each of the plurality of subcomponents; and

based on determining whether the software code comprises a risk, generating, by the server, a risk assessment of the software code.

2. The method of claim 1 , wherein the information in the SBOM comprises information related to a development process specified in the software development standard, and wherein the method comprises:

determining, by the server and based on the development process, that the software code comprises the risk.

3. The method of claim 2 , wherein determining, by the server and based on the development process, that the software code comprises the risk comprises:

determining, by the server, that the information related to the development process is incomplete; and

in response to determining that the information related to the development process is incomplete, determining that the software code comprises the risk.

4. The method of claim 2 , wherein the development process comprises at least one of a secure software development process, a static application security testing process, a security design assessment, or a static analysis test.

5. The method of claim 1 , wherein the software development standard is a standard for automotive cybersecurity.

6. The method of claim 1 , comprising:

determining, based on the CAL rating, whether to initiate an analysis on the software code to determine whether the software code comprises an additional risk.

7. A computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:

obtaining, by a server, software code and a Software Bill of Materials (SBOM) corresponding to the software code, wherein the SBOM comprises information related to a software development standard;

determining, by the server and based on the information related to the software development standard in the SBOM, whether the software code comprises a risk, wherein the software code comprises a component, the component comprises a plurality of subcomponents, and the information in the SBOM comprises a Cybersecurity Assurance Level (CAL) rating of each of the plurality of subcomponents, and wherein determining whether the software code comprises a risk comprises:

determining, by the server, a CAL rating of the component based on the CAL rating of each of the plurality of subcomponents; and

based on determining whether the software code comprises a risk, generating, by the server, a risk assessment of the software code.

8. The computer-readable medium of claim 7 , wherein the information in the SBOM comprises information related to a development process specified in the software development standard, and wherein the operations comprise:

determining, by the server and based on the development process, that the software code comprises the risk.

9. The computer-readable medium of claim 8 , wherein determining, by the server and based on the development process, that the software code comprises the risk comprises:

determining, by the server, that the information related to the development process is incomplete; and

in response to determining that the information related to the development process is incomplete, determining that the software code comprises the risk.

10. The computer-readable medium of claim 8 , wherein the development process comprises at least one of a secure software development process, a static application security testing process, a security design assessment, or a static analysis test.

11. The computer-readable medium of claim 7 , wherein the software development standard is a standard for automotive cybersecurity.

12. The computer-readable medium of claim 7 , the operations comprising:

determining, based on the CAL rating, whether to initiate an analysis on the software code to determine whether the software code comprises an additional risk.

13. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

obtaining, by a server, software code and a Software Bill of Materials (SBOM) corresponding to the software code, wherein the SBOM comprises information related to a software development standard;

determining, by the server and based on the information related to the software development standard in the SBOM, whether the software code comprises a risk, wherein the software code comprises a component, the component comprises a plurality of subcomponents, and the information in the SBOM comprises a Cybersecurity Assurance Level (CAL) rating of each of the plurality of subcomponents, and wherein determining whether the software code comprises a risk comprises:

determining, by the server, a CAL rating of the component based on the CAL rating of each of the plurality of subcomponents; and

based on determining whether the software code comprises a risk, generating, by the server, a risk assessment of the software code.

14. The computer-implemented system of claim 13 , wherein the software development standard is a standard for automotive cybersecurity.

15. The computer-implemented system of claim 13 , wherein the information in the SBOM comprises information related to a development process specified in the software development standard, and wherein the operations comprise:

determining, by the server and based on the development process, that the software code comprises the risk.

16. The computer-implemented system of claim 15 , wherein determining, by the server and based on the development process, that the software code comprises the risk comprises:

determining, by the server, that the information related to the development process is incomplete; and

in response to determining that the information related to the development process is incomplete, determining that the software code comprises the risk.

17. The computer-implemented system of claim 15 , wherein the development process comprises at least one of a secure software development process, a static application security testing process, a security design assessment, or a static analysis test.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2022
From: BOULTON, ADAM JOHN
To: BLACKBERRY UK LIMITED
Reel/Frame 060822/0585 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2022
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 060604/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2022
From: DUGGAN, NEIL DAVID JONATHAN
To: BLACKBERRY UK LIMITED
Reel/Frame 059904/0816 →
Continuity (1)
Related Publication 20230359992A1 · Nov 9, 2023
References Cited (29)
US 9465942B1 · Kane Parry et al. · 2016 [cited by applicant]
US 20150268948A1 · Plate · 2015 [cited by applicant]
US 20170180346A1 · Saurez et al. · 2017 [cited by applicant]
US 20180239898A1 · Haerterich et al. · 2018 [cited by applicant]
US 20190050576A1 · Boulton · 2019 [cited by examiner]
US 20190220596A1 · Lie et al. · 2019 [cited by applicant]
US 20190227902A1 · Cheng et al. · 2019 [cited by applicant]
US 20190251251A1 · Carson · 2019 [cited by applicant]
US 20200167476A1 · Boulton · 2020 [cited by applicant]
US 20200201620A1 · Beard · 2020 [cited by applicant]
US 20210029151A1 · Brooks · 2021 [cited by examiner]
US 20220083652A1 · Ransford et al. · 2022 [cited by applicant]
US 20220337611A1 · Brazao · 2022 [cited by examiner]
US 20230367883A1 · Bussell · 2023 [cited by examiner]
EP 1376343 · 2004 [cited by applicant]
EP 3716113 · 2020 [cited by applicant]
WO WO2021231423 · 2021 [cited by applicant]
Extended European Search Report in European Appln. No. 23164627.4, mailed on Sep. 20, 2023, 6 pages. [cited by applicant]
Extended European Search Report in European Appln. No. 23164625.8, mailed on Sep. 15, 2023, 6 pages. [cited by applicant]
U.S. Appl. No. 17/736,433, filed May 4, 2022, Duggan et al. [cited by applicant]
Grammatech.com [online], “CodeSentry—Software Supply Chain Security Platform” Oct. 2020, [retrieved on Jul. 5, 2022], retrieved from : URL <https://www.grammatech.com/codesentry-sca>, 8 pages. [cited by applicant]
ISO/SAE “Road Vehicles—Cybersecurity Engineering” Final Draft, International Standard, ISO/SAE FDIS 21434, May 2021, 92 pages. [cited by applicant]
The United States Department of Commerce, “The Minimum Elements For a Software Bill of Materials (SBOM)” Pursuant to Executive Order 14028 on Improving the Nation's Cybersecurity, Jul. 12, 2021, 28 pages. [cited by applicant]
Whitehouse.gov [online], “Executive Order on Improving the Nation's Cybersecurity” May 12, 2021. [retrieved on Jul. 5, 2022], retrieved from : URL <https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/1… [cited by applicant]
Wikipedia.org [online], “Evaluation Assurance Level” created on Sep. 2004, [retrieved on Jul. 5, 2022], retrieved from : URL <https://en.wikipedia.org/wiki/Evaluation_Assurance_Level>, 6 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 17/736,433, mailed on Jun. 27, 2024, 12 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 17/736,420, mailed on Jul. 5, 2024, 34 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 17/736,433, mailed on Sep. 25, 2024, 9 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 17/736,433, mailed on Jul. 15, 2024, 10 pages. [cited by applicant]
Cited By (1)
US 12,748,678