IP Library › Granted Patent US 12,481,498
Granted Patent B2
US 12,481,498 · App. 17/940,452 · Granted Nov 25, 2025

Software code verification using software code identifier comparison

Inventors: Daniel Toralles Avila (Porto Alegre, BR); Vicente Eliseu da Rosa (Imbé, BR); Sakthivel Govindasamy (Frisco, TX)
Assignee: Dell Products L.P.
G06F8/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,498
App. No.
17/940,452
Granted
Nov 25, 2025
Kind
B2
Abstract

Techniques are provided for software code verification using a comparison of software code identifiers. One method comprises obtaining a first software code identifier for a first version of software code, wherein the first software code identifier is obtained by applying a function to the first version of the software code; comparing a second software code identifier to the first software code identifier, wherein the second software code identifier is obtained by applying the function to a second version of the software code; and performing an automated action based on a result of the comparison. The comparison may detect a difference between the first and second versions of the software code. The first version of the software code may comprise software code associated with a first stage of a software development cycle and the second version of the software code may comprise software code associated with a different stage.

Claims (32)

1 . A method, comprising:

obtaining a first software code identifier value for a first version of software code of an application, wherein the first software code identifier value is automatically generated, in response to a validation of a software testing stage of a software deployment pipeline, by applying a function to the first version of the software code;

comparing a second software code identifier value to the first software code identifier value, wherein the second software code identifier value is automatically generated, in response to a second version of the software code of the application being deployed to a production environment during a software deployment stage of the software deployment pipeline, by applying the function to the second version of the software code of the application, wherein the comparison comprises: (i) detecting that the first version of the software code of the application is a same version of the software code as and the second version of the software code of the application and (ii) verifying that the second version of the software code of the application being deployed to the production environment is a same version of the software code as the first version of the software code of the application tested in the software testing stage; and

performing one or more automated actions based at least in part on a result of the comparison;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2 . The method of claim 1 , wherein the first version of the software code comprises software code associated with a first stage of a software development cycle and wherein the second version of the software code comprises software code associated with a different stage of the software development cycle.

3 . The method of claim 2 , further comprising generating the first software code identifier value at a first time associated with a completion of the first stage and generating the second software code identifier value at a second time associated with a completion of the different stage.

4 . The method of claim 1 , wherein the applying the function to the first version of the software code is performed at a first time and wherein the applying the function to the second version of the software code is performed at a different time.

5 . The method of claim 1 , wherein the applying the function to the first version of the software code and the applying the function to the second version of the software code comprise (i) extracting information from the respective version, wherein the extracted information comprises one or more of text and binary information, and (ii) applying the function to the extracted information from the respective version.

6 . The method of claim 1 , wherein the function comprises a secure hash algorithm.

7 . The method of claim 1 , wherein the one or more automated actions comprise one or more of: generating a validation of the software code; generating an alert; and generating supporting documentation for a compliance evaluation.

8 . The method of claim 1 , wherein the function generates a substantially unique value for an applied input.

9 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining a first software code identifier value for a first version of software code of an application, wherein the first software code identifier value is automatically generated, in response to a validation of a software testing stage of a software deployment pipeline, by applying a function to the first version of the software code;

comparing a second software code identifier value to the first software code identifier value, wherein the second software code identifier value is automatically generated, in response to a second version of the software code of the application being deployed to a production environment during a software deployment stage of the software deployment pipeline, by applying the function to the second version of the software code of the application, wherein the comparison comprises: (i) detecting that the first version of the software code of the application is a same version of the software code as and the second version of the software code of the application and (ii) verifying that the second version of the software code of the application being deployed to the production environment is a same version of the software code as the first version of the software code of the application tested in the software testing stage; and

performing one or more automated actions based at least in part on a result of the comparison.

10 . The apparatus of claim 9 , wherein the first version of the software code comprises software code associated with a first stage of a software development cycle and wherein the second version of the software code comprises software code associated with a different stage of the software development cycle.

11 . The apparatus of claim 9 , wherein the applying the function to the first version of the software code is performed at a first time and wherein the applying the function to the second version of the software code is performed at a different time.

12 . The apparatus of claim 9 , wherein the applying the function to the first version of the software code and the applying the function to the second version of the software code comprise (i) extracting information from the respective version, wherein the extracted information comprises one or more of text and binary information, and (ii) applying the function to the extracted information from the respective version.

13 . The apparatus of claim 9 , wherein the one or more automated actions comprise one or more of: generating a validation of the software code; generating an alert; and generating supporting documentation for a compliance evaluation.

14 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining a first software code identifier value for a first version of software code of an application, wherein the first software code identifier value is automatically generated, in response to a validation of a software testing stage of a software deployment pipeline, by applying a function to the first version of the software code;

comparing a second software code identifier value to the first software code identifier value, wherein the second software code identifier value is automatically generated, in response to a second version of the software code of the application being deployed to a production environment during a software deployment stage of the software deployment pipeline, by applying the function to the second version of the software code of the application, wherein the comparison comprises: (i) detecting that the first version of the software code of the application is a same version of the software code as and the second version of the software code of the application and (ii) verifying that the second version of the software code of the application being deployed to the production environment is a same version of the software code as the first version of the software code of the application tested in the software testing stage; and

performing one or more automated actions based at least in part on a result of the comparison.

15 . The non-transitory processor-readable storage medium of claim 14 , wherein the first version of the software code comprises software code associated with a first stage of a software development cycle and wherein the second version of the software code comprises software code associated with a different stage of the software development cycle.

16 . The non-transitory processor-readable storage medium of claim 14 , wherein the applying the function to the first version of the software code is performed at a first time and wherein the applying the function to the second version of the software code is performed at a different time.

17 . The non-transitory processor-readable storage medium of claim 14 , wherein the applying the function to the first version of the software code and the applying the function to the second version of the software code comprise (i) extracting information from the respective version, wherein the extracted information comprises one or more of text and binary information, and (ii) applying the function to the extracted information from the respective version.

18 . The method of claim 2 , wherein the software development cycle transitions to a next stage in response to detecting that the first software code identifier value and the second software code identifier value are the same value.

19 . The method of claim 1 , wherein the at least one processing device is implemented in a software development system that processes software code in a plurality of stages of a software deployment pipeline.

20 . The method of claim 1 , wherein one or more of: (i) a new first software code identifier value is automatically generated in response to an update of the first version of the software code of the application following the validation of the software testing stage and (ii) a new second software code identifier value is automatically generated in response to an update of the second version of the software code of the application following the deployment of the software code of the application to the production environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2022
From: AVILA, DANIEL TORALLES; ROSA, VICENTE ELISEU DA; GOVINDASAMY, SAKTHIVEL
To: DELL PRODUCTS L.P.
Reel/Frame 061026/0933 →
Continuity (1)
Related Publication 20240086183A1 · Mar 14, 2024
References Cited (55)
US 8768962B2 · Laron · 2014 [cited by examiner]
US 9386037B1 · Hunt · 2016 [cited by examiner]
US 11119754B1 · Sun · 2021 [cited by examiner]
US 11222091B2 · Liu · 2022 [cited by examiner]
US 11327744B2 · Rodrigues Rosa Junior · 2022 [cited by examiner]
US 11443047B2 · Sekhar · 2022 [cited by examiner]
US 11586433B2 · Hoenzsch · 2023 [cited by examiner]
US 11797639B2 · Liu · 2023 [cited by examiner]
US 20040210885A1 · Wang · 2004 [cited by examiner]
US 20050257205A1 · Costea · 2005 [cited by examiner]
US 20080068153A1 · Doan et al. · 2008 [cited by applicant]
US 20080269938A1 · Meaney et al. · 2008 [cited by applicant]
US 20120324435A1 · Somani · 2012 [cited by examiner]
US 20130055231A1 · Hyndman · 2013 [cited by examiner]
US 20130066901A1 · Marcelais · 2013 [cited by examiner]
US 20130173530A1 · Laron · 2013 [cited by examiner]
US 20140089185A1 · Desai · 2014 [cited by examiner]
US 20140282400A1 · Moorthi · 2014 [cited by examiner]
US 20150113638A1 · Valasek et al. · 2015 [cited by applicant]
US 20150324178A1 · Arnold · 2015 [cited by examiner]
US 20160034267A1 · Wetzold · 2016 [cited by examiner]
US 20170003958A1 · Okubo · 2017 [cited by examiner]
US 20170286544A1 · Hunt · 2017 [cited by examiner]
US 20180004953A1 · Smith, II · 2018 [cited by examiner]
US 20180189690A1 · Chan · 2018 [cited by examiner]
US 20180191764A1 · Chawla · 2018 [cited by examiner]
US 20180205560A1 · Park et al. · 2018 [cited by applicant]
US 20190155598A1 · Bainville · 2019 [cited by examiner]
US 20190303623A1 · Reddy · 2019 [cited by examiner]
US 20190305959A1 · Reddy · 2019 [cited by examiner]
US 20190306173A1 · Reddy · 2019 [cited by examiner]
US 20190394050A1 · Goeringer et al. · 2019 [cited by applicant]
US 20200379752A1 · Rodrigues Rosa Junior · 2020 [cited by examiner]
US 20200394235A1 · Liu · 2020 [cited by examiner]
US 20210021428A1 · Landman · 2021 [cited by examiner]
US 20210021633A1 · Landman · 2021 [cited by examiner]
US 20210326454A1 · Sekhar · 2021 [cited by examiner]
US 20220092137A1 · Liu · 2022 [cited by examiner]
US 20220164452A1 · Landman · 2022 [cited by examiner]
US 20220171840A1 · Balin et al. · 2022 [cited by applicant]
US 20220283801A1 · Hoenzsch · 2022 [cited by examiner]
US 20230014438A1 · Jones · 2023 [cited by examiner]
US 20230325080A1 · Huo · 2023 [cited by examiner]
US 20230376603A1 · Yaron · 2023 [cited by examiner]
US 20240086183A1 · Avila · 2024 [cited by examiner]
Knittl-Frank, Daniel. “Analysis and comparison of distributed version control systems.” Bachelorarbeit, University of Applied Sciences, Upper Austria (2010). (Year: 2010). [cited by examiner]
“Sga256sum(1)—Linux man page”; https://linux.die.net/man/1/sha256sum, downloaded Aug. 30, 2022. [cited by applicant]
“How toSHA256SUM”; https://help.ubuntu.com/community/HowToSHA256SUM, downloaded Aug. 30, 2022. [cited by applicant]
“What is Secure Hashing Algorithm? What is SHA Used for?” https://www.encryptionconsulting.com/education-center/what-is-sha/#:˜:text=SHA%20stands%20for%20secure%20hashing,modular%20additions%2C%20and%20compression%20fun… [cited by applicant]
U.S. Appl. No. 17/210,799 entitled “System Protection Using Verification of Software Digital Identity Values”, filed Mar. 24, 2021. [cited by applicant]
Cooper, David et al. “BIOS Protection Guidelines” https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-147.pdf; downloaded on Sep. 6, 2022. [cited by applicant]
Hoffman, Chris; “How to Secure Your Computer with a BIOS or UEFI Password”; Updated Jul. 12, 2017; https://www.howtogeek.com/186235/how-to-secure-your-computer-with-a-bios-or-uefi-password/; downloaded on Sep. 6, 2022. [cited by applicant]
Lewis, Nick; How to Bolster Security to Prevent BIOS Attacks; published Nov. 2011; https://searchsecurity.techtarget.com/answer/How-to-bolster-BIOS-security-to-prevent-BIOS-attacks; downloaded on Sep. 6, 2022. [cited by applicant]
Rashid, Fahmida Y.; “Dell BIOS Verification Extents Security Focus”; Feb. 5, 2016; https://www.infoworld.com/article/3029728/dell-bios-verification-extends-security-focus.html; downloaded on Sep. 6, 2022. [cited by applicant]
Rajdeep; “Hardware Verification Using Software Analyzers”; http://www.kroening.com/papers/ISVLSI2015-1.pdf; downloaded on Nov. 24, 2020. [cited by applicant]