IP Library › Granted Patent US 12,518,014
Granted Patent B2
US 12,518,014 · App. 17/652,218 · Granted Jan 6, 2026

Data confidence and software development operations

Inventors: Nicole Reineke (Northborough, MA); Stephen J. Todd (North Andover, MA); Trevor Scott Conn (Leander, TX)
Assignee: Dell Products L.P.
G06F21/57G06F8/4452G06F8/447G06F2221/033G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,014
App. No.
17/652,218
Granted
Jan 6, 2026
Kind
B2
Abstract

A data confidence fabric for generating data confidence scores for a build pipeline is disclosed. Confidence scores are generated for data or jobs in a build pipeline. The scores may be combined into a final confidence score that reflects a confidence in the artifact generated by the pipeline and in the pipeline. A user or infrastructure may or may not perform the artifact based on the associated confidence score.

Claims (36)

1 . A method comprising:

for each stage of a pipeline that includes two or more of a development stage, a build stage, a test stage, and a deploy stage:

executing the stage of the pipeline for a code portion;

for each job performed on the code portion in the stage, generating job-specific confidence information, wherein the confidence information includes a plurality of annotations produced using two or more heterogeneous trust insertion technologies selected from static code analysis, dependency auditing, cryptographic signing, and runtime environment verification

cryptographically linking each instance of the confidence information to a unique identifier for the job and the code portion; and

storing the confidence information and corresponding metadata in an immutable blockchain-based ledger maintained by a data confidence fabric, wherein the data confidence fabric is integrated with each of the pipeline stages and configured to collect, timestamp, and store the confidence information in real time; and

generating a final confidence score for an artifact generated by the pipeline from the code portion, wherein:

the final confidence score includes job-specific confidence scores for each of the jobs performed on the code portion across the stages, and

the final confidence score is computed using a weighted function over the job-specific confidence scores and a validity check of the corresponding cryptographically linked provenance records.

2 . The method of claim 1 , wherein, for the development stage, the job includes one or more of receiving the code portion from a developer and storing the code portion in a repository, wherein generating job-specific confidence information includes generating confidence information for performing a security analysis on the code portion and generating confidence information related to storing the code portion in the repository.

3 . The method of claim 1 , wherein, for the build stage, the job includes one or more of retrieving the code portion from the repository, comparing the retrieved code portion to the code portion in the repository prior to compilation, and compiling the code portion, further comprising generating job-specific confidence information for retrieving the code portion, for comparing the code portion, and for compiling the code portion.

4 . The method of claim 1 , wherein, for the test stage, the job includes one or more of performing unit tests or testing the compiled code portion, further comprising generating job-specific confidence information for performing the unit tests and for testing the compiled code portion.

5 . The method of claim 1 , wherein, for the deploy stage, the job includes one or more of generating an artifact, signing the artifact, and publishing the artifact, further comprising generating job-specific confidence information for generating the artifact, generating confidence information for signing the artifact, and generating confidence information for publishing the artifact.

6 . The method of claim 1 , wherein the final confidence score includes job-specific confidence scores for multiple jobs performed on the code portion at multiple stages.

7 . The method of claim 1 , wherein the final confidence score is associated with annotations that describe trust insertions performed on the code portion.

8 . The method of claim 7 , further comprising determining whether to execute the artifact in an infrastructure based on the final confidence score and/or the annotations.

9 . The method of claim 8 , further comprising performing an audit of the pipeline.

10 . The method of claim 8 , wherein the artifact is at least one of an application, an image, an executable, a binary, or is packaged based on a programming language and/or an execution environment.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

for each stage of a pipeline that includes two or more of a development stage, a build stage, a test stage, and a deploy stage:

executing the stage of the pipeline for a code portion;

for each job performed on the code portion in the stage, generating job-specific confidence information, wherein the confidence information includes a plurality of annotations produced using two or more heterogeneous trust insertion technologies selected from static code analysis, dependency auditing, cryptographic signing, and runtime environment verification;

cryptographically linking each instance of the confidence information to a unique identifier for the job and the code portion; and

storing the confidence information and corresponding metadata in an immutable blockchain-based ledger maintained by a data confidence fabric wherein the data confidence fabric is integrated with each of the pipeline stages and configured to collect, timestamp, and store the confidence information in real time;

generating a final confidence score for an artifact generated by the pipeline from the code portion, wherein:

the final confidence score includes job-specific confidence scores for each of the jobs performed on the code portion across the stages, and

the final confidence score is computed using a weighted function over the job-specific confidence scores and a validity check of the corresponding cryptographically linked provenance records.

12 . The non-transitory storage medium of claim 11 , wherein, for the development stage, the job includes one or more of receiving the code portion from a developer and storing the code portion in a repository, wherein generating job-specific confidence information includes generating confidence information for performing a security analysis on the code portion and generating confidence information related to storing the code portion in the repository.

13 . The non-transitory storage medium of claim 11 , wherein, for the build stage, the job includes one or more of retrieving the code portion from the repository, comparing the retrieved code portion to the code portion in the repository prior to compilation, and compiling the code portion, further comprising generating job-specific confidence information for retrieving the code portion, for comparing the code portion, and for compiling the code portion.

14 . The non-transitory storage medium of claim 11 , wherein, for the test stage, the job includes one or more of performing unit tests or testing the compiled code portion, further comprising generating job-specific confidence information for performing the unit tests and for testing the compiled code portion.

15 . The non-transitory storage medium of claim 11 , wherein, for the deploy stage, the job includes one or more of generating an artifact, signing the artifact, and publishing the artifact, further comprising generating job-specific confidence information for generating the artifact, generating confidence information for signing the artifact, and generating confidence information for publishing the artifact.

16 . The non-transitory storage medium of claim 11 , wherein the final confidence score includes job-specific confidence scores for multiple jobs performed on the code portion at multiple stages.

17 . The non-transitory storage medium of claim 11 , wherein the final confidence score is associated with annotations that describe trust insertions performed on the code portion.

18 . The non-transitory storage medium of claim 17 , further comprising determining whether to execute the artifact in an infrastructure based on the final confidence score and/or the annotations.

19 . The non-transitory storage medium of claim 18 , further comprising performing an audit of the pipeline.

20 . The non-transitory storage medium of claim 18 , wherein the artifact is at least one of an application, an image, an executable, a binary, or is packaged based on a programming language and/or an execution environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2022
From: REINEKE, NICOLE; TODD, STEPHEN J.; CONN, TREVOR SCOTT
To: DELL PRODUCTS L.P.
Reel/Frame 059080/0255 →
Continuity (1)
Related Publication 20230267210A1 · Aug 24, 2023
References Cited (28)
US 11099835B1 · Wall · 2021 [cited by examiner]
US 11513772B1 · Gross · 2022 [cited by examiner]
US 20090196485A1 · Mueller et al. · 2009 [cited by applicant]
US 20160147875A1 · Adderly · 2016 [cited by examiner]
US 20170003948A1 · Iyer · 2017 [cited by examiner]
US 20180075194A1 · Allen · 2018 [cited by examiner]
US 20190103092A1 · Rusak et al. · 2019 [cited by applicant]
US 20190228262A1 · Gonzalez et al. · 2019 [cited by applicant]
US 20190265714A1 · Ball · 2019 [cited by examiner]
US 20190303579A1 · Reddy · 2019 [cited by examiner]
US 20200218623A1 · Zhang · 2020 [cited by examiner]
US 20200287919A1 · Ravindranath · 2020 [cited by examiner]
US 20210014127A1 · Iyengar et al. · 2021 [cited by applicant]
US 20210303296A1 · Ahuja · 2021 [cited by examiner]
US 20220043711A1 · Shemer et al. · 2022 [cited by applicant]
US 20220043721A1 · Shemer et al. · 2022 [cited by applicant]
US 20220100858A1 · Todd · 2022 [cited by examiner]
US 20220291921A1 · Balasubramanian · 2022 [cited by examiner]
US 20220335154A1 · Schuler et al. · 2022 [cited by applicant]
US 20220398308A1 · Zerah · 2022 [cited by examiner]
US 20230061701A1 · Shih et al. · 2023 [cited by applicant]
Lawton, The future of trust will be built on data transparency, pp. 1-10, Mar. 2021. [cited by applicant]
Perez, Alvarium, pp. 1-2 (Year: 2021). [cited by applicant]
Todd, Building the First Data Confidence Fabric, pp. 1-9 Oct. 2019. [cited by applicant]
Todd, Enterprise Trust Insertion and IoT, pp. 1-2, Aug. 5, 2019. [cited by applicant]
Todd, Information Playground: Edge Data and Trust Insertion, pp. 1-3, Sep. 18, 2019. [cited by applicant]
Todd, Information Playground: IoT Data Confidence Fabrics, pp. 1-3, May 30, 2019. [cited by applicant]
Todd, Project Alvarium: the Future of Edge Data, pp. 1-39 (Year: 2020). [cited by applicant]
Cited By (1)
US 12,705,629