IP Library › Granted Patent US 12,541,741
Granted Patent B2
US 12,541,741 · App. 18/126,037 · Granted Feb 3, 2026

Storage and consumption of software bill of materials on public blockchain

Inventor: Nelson Paily Varghese (Hyderabad, IN)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06Q10/0875G06Q20/3827G06Q20/389
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,741
App. No.
18/126,037
Granted
Feb 3, 2026
Kind
B2
Abstract

Disclosed is a secure and distributed system for storing and consuming software bill of materials (SBOM). The system allows software publishers to create a software component and generate an SBOM that describes its dependencies. A web API then securely stores the SBOM on a distributed file system and publishes a hash of the SBOM to a public blockchain. When the software component is updated, a new SBOM is generated, and a signed hash of the new SBOM is stored in a new node on the blockchain. This preserves the history and auditability of the application's SBOMs. Third parties may query the web API to obtain the SBOM while ensuring the integrity and provenance of the information.

Claims (60)

1 . A method comprising:

obtaining a store web request that comprises a Software Bill Of Materials (SBOM) associated with a software component and a publisher identifier;

storing the SBOM in a distributed database;

determining an SBOM hash of the SBOM;

generating an SBOM identifier, wherein the SBOM identifier is randomly generated, and wherein the SBOM identifier is associated with a plurality of SBOMs that are associated with different versions of the software component;

invoking a store function of a smart contract on a blockchain, causing the store function to create a block on the blockchain that comprises the SBOM identifier, the SBOM hash, and the publisher identifier; and

returning the SBOM identifier in response to the store web request.

2 . The method of claim 1 , wherein the store web request includes an SBOM format type that indicates a format of the SBOM.

3 . The method of claim 1 , wherein the SBOM is for a first version of a software component, further comprising:

obtaining a second store web request that comprises a second SBOM for a second version of the software component and the SBOM identifier;

determining a second SBOM hash of the second SBOM; and

invoking the store function of the smart contract on the blockchain, causing the store function to create a second block on the blockchain that comprises the SBOM identifier, the second SBOM hash, and the publisher identifier, and wherein the second block on the blockchain refers to the block on the blockchain.

4 . The method of claim 1 , wherein the store web request is received from a computing device performing a build of a component, and wherein the SBOM describes dependencies of the component.

5 . The method of claim 1 , further comprising:

receiving an update web request that includes the SBOM identifier and an updated SBOM;

storing the updated SBOM in the distributed database;

determining a hash of the updated SBOM; and

invoking the store function of the smart contract to store the updated SBOM on the blockchain.

6 . The method of claim 1 , further comprising:

receiving a retrieve web request that includes the SBOM identifier;

mapping the SBOM identifier to a contract address;

invoking a retrieve function of the smart contract with a publisher address, the contract address, and a SBOM type.

7 . A computer-readable storage medium having computer-executable instructions stored thereupon that, when executed by a processor, cause the processor to:

obtain a store web request including a first Software Bill Of Materials (SBOM) associated with a first version of a software component and a publisher identifier;

store the first SBOM in a distributed database;

obtain a first SBOM hash of the first SBOM generated by the distributed database;

generate an SBOM identifier, wherein the SBOM identifier is associated with a plurality of SBOMs that are associated with different versions of the software component;

invoke a store function of a smart contract on a blockchain, causing the store function to create a block on the blockchain that comprises the SBOM identifier, the first SBOM hash, and the publisher identifier;

return the SBOM identifier in response to the store web request;

obtain a second store web request that comprises a second SBOM, the SBOM identifier, and the publisher identifier, wherein the second SBOM is associated with a second version of the software component; and

invoke the store function of the smart contract, causing the store function to create another block on the blockchain that comprises the SBOM identifier, the publisher identifier, and a second SBOM hash of the second SBOM.

8 . The computer-readable storage medium of claim 7 , wherein the store function takes a contract address as a parameter, and wherein the contract address identifies the smart contract on the blockchain.

9 . The computer-readable storage medium of claim 7 , wherein the block stores a timestamp indicating when the store function was invoked.

10 . The computer-readable storage medium of claim 7 , wherein the computer-executable instructions further cause the processing-system to:

receive a delete web request that includes a publisher address, a SBOM type, and the SBOM identifier; and

invoke a delete function of the smart contract, causing the delete function to mark a block associated with the SBOM identifier as deleted.

11 . The computer-readable storage medium of claim 10 , wherein the computer-executable instructions further cause the processing-system to:

delete from the distributed database SBOMs associated with the SBOM identifier.

12 . A processing system, comprising:

a processor; and

a computer-readable storage medium having computer-executable instructions stored thereupon that, when executed by the processing system, cause the processing system to:

receive a store web request including a first Software Bill Of Materials (SBOM) associated with a first version of a software component, an SBOM type, an SBOM format, and a publisher identifier;

store the first SBOM in a distributed database;

obtain a first SBOM hash of the first SBOM generated by the distributed database;

generate a random SBOM identifier, wherein the random SBOM identifier is associated with a plurality of SBOMs that are associated with different versions of the software component;

invoke a store function of a smart contract on a blockchain, wherein the store function takes a contract address as a parameter, and wherein the contract address identifies the smart contract on the blockchain, causing the store function to create a block on the blockchain that includes the SBOM identifier, the SBOM type, the first SBOM hash, a timestamp indicating when the store function was invoked, and the publisher identifier

return the SBOM identifier in response to the store web request;

obtain a second store web request that comprises a second SBOM, the SBOM identifier, and the publisher identifier, wherein the second SBOM is associated with a second version of the software component; and

invoke the store function of the smart contract, causing the store function to create another block on the blockchain that comprises the SBOM identifier, the publisher identifier, and a second SBOM hash of the second SBOM.

13 . The processing system of claim 12 , wherein the computer-executable instructions further cause the processing system to:

receive a request to register the smart contract.

14 . The processing system of claim 13 , wherein the computer-executable instructions further cause the processing system to:

provide the contract address in response to the request to register the smart contract, wherein the contract address uniquely identifies the smart contract on the blockchain.

15 . The processing system of claim 14 , wherein the store function is identified based on the contract address.

16 . The processing system of claim 12 , wherein the store web request is received as an HTTP POST request.

17 . The processing system of claim 12 , wherein the SBOM defines dependencies of the software component.

18 . The processing system of claim 17 , wherein the computer-executable instructions further cause the processing system to:

receive an update web request, wherein the update web request was sent by a computing device in response to generating another version of the software component, and wherein the update web request includes an SBOM of the other version of the software component.

19 . The processing system of claim 18 , wherein the computer-executable instructions further cause the processing system to:

invoke an update function on the blockchain with a hash of the SBOM of the other version of the software component, causing the update function to add another block to the blockchain that supersedes the block.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2023
From: VARGHESE, NELSON PAILY
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063094/0729 →
Continuity (1)
Related Publication 20240320624A1 · Sep 26, 2024
References Cited (23)
US 11150888B2 · Beard · 2021 [cited by examiner]
US 11809575B1 · Reddy · 2023 [cited by examiner]
US 20180287800A1 · Chapman · 2018 [cited by examiner]
US 20190303541A1 · Reddy et al. · 2019 [cited by applicant]
US 20200201620A1 · Beard · 2020 [cited by applicant]
US 20200327137A1 · Farver et al. · 2020 [cited by applicant]
US 20210097528A1 · Wang · 2021 [cited by examiner]
US 20210311926A1 · Ponceleon et al. · 2021 [cited by applicant]
US 20220166626A1 · Madisetti et al. · 2022 [cited by applicant]
US 20230072264A1 · Coccia · 2023 [cited by examiner]
US 20230073608A1 · Awasthy · 2023 [cited by examiner]
US 20240086549A1 · Rapowitz · 2024 [cited by examiner]
US 20240126530A1 · Kairali · 2024 [cited by examiner]
US 20240152625A1 · Bar · 2024 [cited by examiner]
Iain Barclay et. al., “Towards Traceability in Data Ecosystems using a Bill of Materials Model”, Jun. 12, 2019 (Year: 2019). [cited by examiner]
“CVE Binary Tool quick start / README”, Retrieved from: https://web.archive.org/web/20221208020950/https://cve-bin-tool.readthedocs.io/en/latest/README.html, Dec. 8, 2022, 9 Pages. [cited by applicant]
“National Telecommunications and Information Administration”, Retrieved from: https://www.ntia.doc.gov/, Retrieved Date: Jun. 3, 2022, 4 Pages. [cited by applicant]
“SBOM FAQ”, In Journal of NTIA Multistakeholder Process on Software Component Transparency, Nov. 16, 2020, pp. 1-12. [cited by applicant]
“Software Bill of Materials”, Retrieved from: https://www.ntia.doc.gov/SBOM, Retrieved Date: Jun. 3, 2022, 6 Pages. [cited by applicant]
“Survey of Existing SBOM Formats and Standards”, Retrieved from: https://www.ntia.gov/files/ntia/publications/ntia_sbom_formats_and_standards_whitepaper_-_version_20191025.pdf, Oct. 24, 2019, pp. 1-31. [cited by applicant]
Muiri, Eamonn O., “Framing Software Component Transparency”, In Journal of NTIA Multistakeholder Process on Software Component Transparency, Sep. 3, 2019, pp. 1-24. [cited by applicant]
Rispens, Sybe Izaak, “Why the World Needs a Software Bill of Materials Now”, Retrieved from: https://drrispens.medium.com/why-the-world-needs-a-software-bill-of-materials-now-5a565df65dff, Mar. 14, 2021, 16 Pages. [cited by applicant]
Shea, Georgianna, “A Software Bill of Materials Is Critical for Comprehensive Risk Management”, In TCIL Technical Note, Sep. 29, 2021, pp. 1-18. [cited by applicant]