IP Library › Granted Patent US 12,327,112
Granted Patent B2
US 12,327,112 · App. 17/533,188 · Granted Jun 10, 2025

Compliance adaption plans and software component matchmaking

Inventors: Juliana Medeiros Destro (Indaiatuba, BR); Flavio Gilberto De Souza (Estiva Gerbi, BR); Diego Aparecido Wolfshorndl (Piracicaba, BR); Marco Aurelio Stelmar Netto (Sao Paulo, BR)
Assignee: International Business Machines Corporation
G06F8/73G06F21/60G06F40/242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,327,112
App. No.
17/533,188
Filed
Nov 23, 2021
Granted
Jun 10, 2025
Kind
B2
Examiner
VO, TED T
Art Unit
2191
USPC
717/123
Abstract

Aspects of the invention include correlating a context of a written data privacy requirement with a first code segment of a source code of a target computer system. A selection of a first candidate code segment is received to replace the first code segment. The selected first candidate code segment is determined to have replaced the first code segment and is integrated into the source code. A stimulation signal is transmitted to the target computer system, wherein the stimulation signal is directed toward the first candidate code segment integrated into the source code.

Claims (67)

1. A computer-implemented method comprising:

correlating, by a processor, a context of a written data privacy requirement with a first code segment of a source code of a target computer system;

receiving, by the processor, a selection of a first candidate code segment to replace the first code segment;

determining, by the processor, that the selected first candidate code segment has replaced the first code segment and is integrated into the source code;

transmitting, by the processor, a stimulation signal to the target computer system, wherein the stimulation signal is directed toward the first candidate code segment integrated into the source code; and

determining, by the processor, whether the source code with the first candidate code segment replacing the first code segment is in compliance with the written data privacy requirement based on an output to the stimulation signal.

2. The computer-implemented method of claim 1 , wherein the method further comprises generating a virtual machine to execute the source code with the candidate code segment replacing the first code segment.

3. The computer-implemented method of claim 1 , wherein the method further comprises:

analyzing, via natural language techniques, the written data privacy requirement to determine the context of the written data privacy requirement;

accessing a dictionary to correlate the context of the written data privacy requirement with a component of the target computer system; and

selecting the first candidate code segment based on the correlated component of the target computer system.

4. The computer-implemented method of claim 3 , wherein the method further comprises:

selecting a plurality of candidate code segments that are related to the correlated component of the target computer system;

accessing a dictionary to determine a correlation between the context of the written data privacy requirement with the plurality of candidate code segments; and

selecting the first candidate code segment based on the correlation.

5. The computer-implemented method of claim 1 , wherein the method further comprises:

generating a directed dependency graph comprising a plurality of nodes and edges, wherein each node of the plurality of nodes describes a code segment of the source code, and wherein each edge of the plurality of edges describes a dependency between two code segments of the source code; and

identifying a second code segment that is dependent from the first code segment based on the directed dependency graph.

6. The computer-implemented method of claim 1 , wherein the method further comprises:

receiving a selection of the first candidate code segment; and

provisioning computing resources of the target computer system, such as processors and memory to prepare for replacing the first code segment.

7. The computer-implemented method of claim 1 , wherein the method further comprises estimating a cost for replacing the first code segment with the first candidate code segment.

8. A system comprising:

a memory having computer readable instructions; and

one or more processors for executing the computer readable instructions, the computer readable instructions controlling the one or more processors to perform operations comprising:

correlating a context of a written data privacy requirement with a first code segment of a source code of a target computer system;

receiving a selection of a first candidate code segment to replace the first code segment;

determining that the selected first candidate code segment has replaced the first code segment and is integrated into the source code;

transmitting a stimulation signal to the target computer system, wherein the stimulation signal is directed toward the first candidate code segment integrated into the source code; and

determining whether the source code with the first candidate code segment replacing the first code segment is in compliance with the written data privacy requirement based on an output to the stimulation signal.

9. The system of claim 8 , wherein the operations further comprise generating a virtual machine to execute the source code with the first candidate code segment replacing the first code segment.

10. The system of claim 8 , wherein the operations further comprise:

analyzing, via natural language techniques, the written data privacy requirement to determine the context of the written data privacy requirement;

accessing a dictionary to correlate the context of the written data privacy requirement with a component of the target computer system; and

selecting the first candidate code segment based on the correlated component of the target computer system.

11. The system of claim 10 , wherein the operations further comprise:

selecting a plurality of candidate code segments that are related to the correlated component of the target computer system;

accessing a dictionary to determine a correlation between the context of the written data privacy requirement with the plurality of candidate code segments; and

selecting the first candidate code segment based on the correlation.

12. The system of claim 8 , wherein the operation further comprise:

generating a directed dependency graph comprising a plurality of nodes and edges, wherein each node of the plurality of nodes describes a first code segment of the source code, and wherein each edge of the plurality of edges describes a dependency between two code segments of the source code; and

identifying a second code segment that is dependent from the first code segment based on the directed dependency graph.

13. The system of claim 8 , wherein the operations further comprise:

receiving a selection of the first candidate code segment; and

provisioning computing resources of the target computer system, such as processors and memory to prepare for replacing the first code segment.

14. The system of claim 8 , wherein the operations further comprise estimating a cost for replacing the first code segment with the first candidate code segment.

15. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations comprising:

correlating a context of a written data privacy requirement with a first code segment of a source code of a target computer system;

receiving a selection of a first candidate code segment to replace the first code segment;

determining that the selected first candidate code segment has replaced the first code segment and is integrated into the source code;

transmitting a stimulation signal to the target computer system, wherein the stimulation signal is directed toward the first candidate code segment integrated into the source code; and

determining whether the source code with the first candidate code segment replacing the first code segment is in compliance with the written data privacy requirement based on an output to the stimulation signal.

16. The computer program product of claim 15 , wherein the operations further comprise generating a virtual machine to execute the source code with the first candidate code segment replacing the first code segment.

17. The computer program product of claim 15 , wherein the operations further comprise:

analyzing, via natural language techniques, the written data privacy requirement to determine the context of the written data privacy requirement;

accessing a dictionary to correlate the context of the written data privacy requirement with a component of the target computer system; and

selecting the first candidate code segment based on the correlated component of the target computer system.

18. The computer program product of claim 17 , wherein the operations further comprise:

selecting a plurality of candidate code segments that are related to the correlated component of the target computer system;

accessing a dictionary to determine a correlation between the context of the written data privacy requirement with the plurality of candidate code segments; and

selecting the first candidate code segment based on the correlation.

19. The computer program product of claim 15 , wherein the operations further comprise:

generating a directed dependency graph comprising a plurality of nodes and edges, wherein each node of the plurality of nodes describes a first code segment of the source code, and wherein each edge of the plurality of edges describes a dependency between two code segments of the source code; and

identifying a second code segment that is dependent from the first code segment based on the directed dependency graph.

20. The computer program product of claim 15 , wherein the operations further comprise:

receiving a selection of the first candidate code segment; and

provisioning computing resources of the target computer system, such as processors and memory to prepare for replacing the first code segment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2021
From: MEDEIROS DESTRO, JULIANA; GILBERTO DE SOUZA, FLAVIO; WOLFSHORNDL, DIEGO APARECIDO; STELMAR NETTO, MARCO AURELIO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058190/0765 →
Continuity (1)
Related Publication 20230161585A1 · May 25, 2023
References Cited (32)
US 8234641B2 · Fitzgerald · 2012 [cited by examiner]
US 9727751B2 · Oliver · 2017 [cited by examiner]
US 9729583B1 · Barday · 2017 [cited by examiner]
US 9892442B2 · Barday · 2018 [cited by applicant]
US 10043035B2 · Lafever et al. · 2018 [cited by applicant]
US 10102533B2 · Barday · 2018 [cited by applicant]
US 10127147B2 · Oberle · 2018 [cited by examiner]
US 10331898B2 · Nefedov · 2019 [cited by examiner]
US 10445513B2 · Biswas · 2019 [cited by examiner]
US 10567439B2 · Barday · 2020 [cited by applicant]
US 10572684B2 · Lafever et al. · 2020 [cited by applicant]
US 10839099B2 · Vogel et al. · 2020 [cited by applicant]
US 11024299B1 · Drake · 2021 [cited by examiner]
US 11481710B2 · Brannon · 2022 [cited by examiner]
US 20140282837A1 · Heise et al. · 2014 [cited by applicant]
US 20170270318A1 · Ritchie · 2017 [cited by applicant]
US 20210056219A1 · Sofer et al. · 2021 [cited by applicant]
CN 111831979A · 2020 [cited by applicant]
EP 1675047A1 · 2006 [cited by examiner]
WO 2017214602A1 · 2017 [cited by applicant]
WO 2017214608A1 · 2017 [cited by applicant]
Garcia-Galan et al., “Towards Adaptive Compliance”, 2016, ACM, pp. 108-114. (Year: 2016). [cited by examiner]
Zhang et al., “A Differential Privacy Support Vector Machine Classifier Based on Dual Variable Perturbation”, 2019, IEEE Access, pp. 98238-98251. (Year: 2019). [cited by examiner]
Ayala-Rivera, et al., “The Grace Period Has Ended: An Approach to Operationalize GDPR Requirements” IEEE 26th International Requirements Engineering Conference (2018): 11 pages. [cited by applicant]
“Automate Compliance with Brazil's General Data Protection Law”, Onetrust, retrieved from web https://www.onetrust.com/products/brazil-law-compliance/, dated Feb. 4, 2025, 8 pages. [cited by applicant]
“Python”, retrieved from https://www.sourcetrail.com/, dated Feb. 4, 2025, 3 pages. [cited by applicant]
“Review Assistant—Code Review Tool”, Marketplace, retrieved from web dated Feb. 4, 2025, 7 pages. [cited by applicant]
“The 5 Best GDPR Compliance Tools”, Exin, retrieved from https://www.exin.com/article/the-5-best-gdpr-compliance-tools/ dated Feb. 4, 2025, 5 pages. [cited by applicant]
Ferrara et al. “Static Analysis for GDPR Compliance”, Julia SRL, Verona, Italy, Nov. 2, 2019, 11 pages. [cited by applicant]
Grootendorst Maarten. “Keyword Extraction with Bert—A minimal method for extracting keywords and keyphrases”, Medium, Oct. 29, 2020, 8 pages. [cited by applicant]
Vanezi et al. “A Formal Modeling Scheme for Analyzing a Software System Design against the GDPR”, ENASE 2019: Proceedings of the 14th International Conference on Evaluation of Novel Approaches to Software Engineering, M… [cited by applicant]
Yang et al. “A Language for Automatically Enforcing Privacy Policies”, POPL '12: Proceedings of the 39th annual ACM SIGPLAN-SIGACT symposium on Principles of programming languages, Jan. 25, 2012, pp. 85-96. [cited by applicant]