IP Library › Granted Patent US 12,547,400
Granted Patent B2
US 12,547,400 · App. 17/946,752 · Granted Feb 10, 2026

Catalog for managing modular code

Inventors: Anthony Thomas Rowlands (Moore, OK); Michael Joseph Fraser (Incline Village, NV)
Assignee: Sophos Limited
G06F9/06G06F8/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,400
App. No.
17/946,752
Filed
Sep 16, 2022
Granted
Feb 10, 2026
Kind
B2
Examiner
THAI, HANH B
Art Unit
2163
USPC
707/798
Abstract

A catalog of pipelines for modular coding integrates resources for consistent use and verification of individual pipeline components. The platform may incorporate tools and metadata for version control, verification, and licensing in order to support a user when creating and deploying applications using resources from the catalog.

Claims (44)

1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

storing a catalog of pipelines for performing security functions, wherein the catalog of pipelines includes one or more local data stores or remote data stores;

storing a description of a pipeline in the catalog of pipelines, wherein:

the description includes an identifier, a version, and a definition,

the definition includes one or more inputs to the pipeline, one or more outputs of the pipeline, one or more steps executable by a computing device to perform the security functions, and a graph of other pipelines from the catalog that contain code segments used in the pipeline, and

the graph characterizes a location for accessing the code segments for each other one of the pipelines and a functional location of the code segments for each of the other pipelines in the pipeline;

traversing one or more other graphs for each other pipeline in the definition including any sub-graphs until all source code modules for the pipeline have been identified;

adding graph data from the one or more other graphs to the graph of other pipelines, thereby providing an integrated graph for all of the code segments used in the pipeline;

adding security compliance data for each of the code segments in the integrated graph to the description of the pipeline;

storing the integrated graph and the security compliance data in the description of the pipeline;

evaluating a compliance of the pipeline with a security policy for an enterprise based on the description of the pipeline, the description including the security compliance data for each of the code segments in the integrated graph; and

in response to the compliance of the pipeline with the security policy meeting a predetermined criterion, publishing the pipeline for use in the enterprise along with a second security compliance data for the pipeline derived from the security compliance data for each of the code segments in the integrated graph of the description of the pipeline.

2 . The computer program product of claim 1 , wherein the catalog is distributed among two or more different data centers.

3 . The computer program product of claim 1 , wherein the catalog is stored in a central data repository accessible to registered users of the catalog.

4 . The computer program product of claim 1 , further comprising computer executable code that, when executing on one or more computing devices, causes the one or more computing devices to perform the step of: synchronizing the catalog using a plurality of pipelines stored in two or more remote repositories of pipelines.

5 . The computer program product of claim 4 , wherein synchronizing includes retrieving one or more of the plurality of pipelines from one or more of the remote repositories of pipelines to the catalog.

6 . The computer program product of claim 1 , wherein the description includes at least one of a digital signature for verifying a source of the pipeline, a second digital signature for verifying a second source of the other pipelines in the graph of other pipelines from the catalog, and a third digital signature for verifying a third source of one of the code segments used in the pipeline.

7 . A method comprising:

storing a catalog of pipelines for performing security functions;

storing a description of a pipeline in the catalog of pipelines, wherein:

the description includes an identifier, a version, and a definition, and

the definition includes one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph that characterizes a location for accessing resources for each other one or more pipelines in the catalog of pipelines and a functional location of the resources for each of the one or more other pipelines in the pipeline;

verifying security compliance data for each of the one or more other pipelines from the catalog containing resources used in the pipeline, thereby providing a verification of a compliance for the pipeline with a security policy; and

in response to the verification of the compliance for the pipeline with the security policy, publishing the pipeline for use along with a second security compliance data for the pipeline derived from the security compliance data for the each of the one or more other pipelines from the catalog containing resources used in the pipeline in the description of the pipeline.

8 . The method of claim 7 , wherein verifying the security compliance data for the each of the one or more other pipelines from the catalog containing resources used in the pipeline includes verifying an operation on one or more corresponding resources for at least one of the other pipelines.

9 . The method of claim 7 , wherein verifying the security compliance data for the each of the one or more other pipelines from the catalog containing resources used in the pipeline includes verifying a digital signature for at least one of the other pipelines.

10 . The method of claim 7 , wherein verifying the security compliance data for the each of the one or more other pipelines from the catalog containing resources used in the pipeline includes verifying a programmatic interface between at least two of the other pipelines associated by the graph.

11 . The method of claim 7 , wherein verifying the security compliance data for the each of the one or more other pipelines from the catalog containing resources used in the pipeline includes verifying a source of at least one of the other pipelines.

12 . The method of claim 7 , wherein verifying the security compliance data for the each of one or more other pipelines from the catalog containing resources used in the pipeline includes receiving one or more licensing requirements for at least one of the other pipelines and explicitly accepting the one or more licensing requirements for use of the at least one of the other pipelines.

13 . The method of claim 12 , further comprising automatically securing an acceptance of the one or more licensing requirements by a user requesting the pipeline from the catalog.

14 . The method of claim 7 , further comprising storing a result of the verification in the description of the pipeline.

15 . The method of claim 7 , wherein publishing the pipeline in the catalog includes conditionally publishing the pipeline when the verification satisfies a predetermined condition.

16 . A system comprising:

a data repository storing a catalog of pipelines for performing security functions;

a description of a pipeline stored in the catalog of pipelines, the description including:

an identifier,

a version, and

a definition including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing resources used in the pipeline,

wherein the graph characterizes a location for accessing the resources for each other one of the pipelines, a functional location of the resources for each of the other pipelines in the pipeline, one or more compatible versions of at least one of the other pipelines identified in the graph, and security compliance data for each of the other pipelines in the pipeline, the security compliance data providing a compliance of a corresponding one of the other pipelines with a security policy; and

a search interface for searching the catalog for pipelines of interest, wherein the search interface in response to the compliance of the corresponding one of the other pipelines with the security policy publishes the pipeline to users along with a second security compliance data for the pipeline derived from the security compliance data for the each of the other pipelines in pipeline in the graph in the description of the pipeline.

17 . The system of claim 16 , further comprising an integrated development environment for creating and deploying an application using the catalog of pipelines, the integrated development environment including a user interface for selecting and arranging pipelines from the catalog into the application.

18 . The system of claim 16 , further comprising a version identifier specifying, for the pipeline stored in the catalog, a compatibility with one or more prior versions of the pipeline.

19 . The system of claim 16 , wherein the data repository is a cloud-based data repository.

20 . The system of claim 16 , wherein the data repository is a federated data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2023
From: ROWLANDS, ANTHONY THOMAS; FRASER, MICHAEL JOSEPH
To: SOPHOS LIMITED
Reel/Frame 062369/0879 →
Continuity (1)
Related Publication 20240095029A1 · Mar 21, 2024
References Cited (77)
US 8141162B2 · Myles · 2012 [cited by examiner]
US 8151282B2 · Carnahan · 2012 [cited by examiner]
US 10534983B1 · Tung · 2020 [cited by examiner]
US 10902046B2 · Carrier · 2021 [cited by examiner]
US 11221831B1 · Al Khafaji · 2022 [cited by examiner]
US 11281673B2 · Nanda · 2022 [cited by examiner]
US 11403094B2 · Mirantes · 2022 [cited by examiner]
US 11431785B2 · Spaven · 2022 [cited by examiner]
US 11461672B2 · Filoti · 2022 [cited by examiner]
US 11500895B2 · Fan · 2022 [cited by examiner]
US 11775898B1 · Thompson · 2023 [cited by examiner]
US 11823073B2 · Doan Huu · 2023 [cited by examiner]
US 11983189B2 · Fan · 2024 [cited by examiner]
US 20040017395A1 · Cook · 2004 [cited by examiner]
US 20060229896A1 · Rosen · 2006 [cited by examiner]
US 20070011437A1 · Carnahan · 2007 [cited by examiner]
US 20090113553A1 · Myles · 2009 [cited by examiner]
US 20110029549A1 · Pandya · 2011 [cited by examiner]
US 20140108321A1 · Buchanan · 2014 [cited by examiner]
US 20140359119A1 · Spaven · 2014 [cited by examiner]
US 20140365575A1 · Spaven · 2014 [cited by examiner]
US 20160004973A1 · Trenkov · 2016 [cited by examiner]
US 20180342324A1 · Cha · 2018 [cited by examiner]
US 20190243836A1 · Nanda · 2019 [cited by examiner]
US 20190303579A1 · Reddy · 2019 [cited by examiner]
US 20200021620A1 · Purathepparambil · 2020 [cited by examiner]
US 20200082223A1 · Tung · 2020 [cited by examiner]
US 20200151588A1 · Doan Huu · 2020 [cited by examiner]
US 20200175051A1 · Carrier · 2020 [cited by examiner]
US 20200257990A1 · Filoti · 2020 [cited by examiner]
US 20200394305A1 · Cosgrove et al. · 2020 [cited by applicant]
US 20210232388A1 · Mirantes · 2021 [cited by examiner]
US 20210292646A1 · Cha · 2021 [cited by examiner]
US 20210303584A1 · Fan · 2021 [cited by examiner]
US 20210303585A1 · Fan · 2021 [cited by examiner]
US 20210334254A1 · Thompson · 2021 [cited by examiner]
US 20210377146A1 · Sommers · 2021 [cited by examiner]
US 20220121479A1 · Chivukula · 2022 [cited by examiner]
US 20220121480A1 · Chivukula · 2022 [cited by examiner]
US 20220374443A1 · Fan · 2022 [cited by examiner]
US 20230045235A1 · Pierscieniak · 2023 [cited by examiner]
US 20230092030A1 · Battaglia · 2023 [cited by examiner]
US 20230101551A1 · Jobanputra · 2023 [cited by examiner]
US 20230128753A1 · Bawa · 2023 [cited by examiner]
US 20230161945A1 · Vadapandeshwara · 2023 [cited by examiner]
US 20230259650A1 · Sepehri · 2023 [cited by examiner]
US 20230267483A1 · Joshi · 2023 [cited by examiner]
US 20230315534A1 · Asawa · 2023 [cited by examiner]
US 20230409585A1 · Dunning · 2023 [cited by examiner]
US 20240086190A1 · Kwatra · 2024 [cited by examiner]
US 20240095337A1 · Rowlands et al. · 2024 [cited by applicant]
REFACTR, “Building Pipelines”, Wiki materials published to refactr.it website on or about May 17, 2021 , 4 Pages. [cited by applicant]
REFACTR, “Building Pipelines Best Practices”, Wiki materials published to refactr.it website on or about Jan. 6, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Clone a GitHub Repository”, Wiki materials published to refactr.it website on or about Feb. 10, 2021 , 4 Pages. [cited by applicant]
REFACTR, “Clone a GitLab Project”, Wiki materials published to refactr.it website on or about Feb. 10, 2021 , 4 Pages. [cited by applicant]
REFACTR, “Core Concepts”, Wiki materials published to refactr.it website on or about Nov. 16, 2020 , 2 Pages. [cited by applicant]
REFACTR, “Credential Types”, Wiki materials published to refactr.it website on or about Dec. 22, 2020 , 2 Pages. [cited by applicant]
REFACTR, “Deprecation Schedule”, Wiki materials published to refactr.it website on or about Jul. 21, 2021 , 2 Pages. [cited by applicant]
REFACTR, “Expression Reference”, Wiki materials published to refactr.it website on or about May 17, 2021 , 8 Pages. [cited by applicant]
REFACTR, “Getting Started”, Wiki materials published to refactr.it website on or about Mar. 29, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Kubernetes on Google Cloud Platform”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Managing Teams”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 2 Pages. [cited by applicant]
REFACTR, “Read and Write Files”, Wiki materials published to refactr.it website on or about Nov. 10, 2020 , 3 Pages. [cited by applicant]
REFACTR, “Reference”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 1 Page. [cited by applicant]
REFACTR, “Release Notes”, Wiki materials published to refactr.it website on or about Jul. 21, 2021 , 8 Pages. [cited by applicant]
REFACTR, “Runners”, Wiki materials published to refactr.it website on or about Mar. 29, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Running Pipelines”, Wiki materials published to refactr.it website on or about May 17, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Send an HTTP Request”, Wiki materials published to refactr.it website on or about Nov. 1, 2020 , 4 Pages. [cited by applicant]
REFACTR, “Sharing Pipelines”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 3 Pages. [cited by applicant]
REFACTR, “Tutorials”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 1 Page. [cited by applicant]
REFACTR, “Using the API”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 2 Pages. [cited by applicant]
REFACTR, “Using the CLI”, Wiki materials published to refactr.it website on or about Mar. 9, 2021 , 4 Pages. [cited by applicant]
“U.S. Appl. No. 17/946,776 Non-Final Office Action mailed Aug. 12, 2024”, , 25 pages. [cited by applicant]
UKIPO, , “UK Application No. 2312859.8 Examination Report mailed Aug. 15, 2024”, 3 pages. [cited by applicant]
UKIPO, , “UK Application No. 2312859.8 Search and Examination Report mailed Feb. 23, 2024”, 8 pages. [cited by applicant]
“U.S. Appl. No. 17/946,776 Final Office Action mailed Mar. 24, 2025”, 26 pages. [cited by applicant]
UKIPO, , “UK Application No. 2312859.8 Examination Report mailed Mar. 12, 2025”, 3 pages. [cited by applicant]