Software Supply-Chain Security Patents: Who Leads, Where the Gaps Are 2026
- One assignee dominates a small field. The leader holds 9 of the ranked records against a fifth-place entrant at 2 and a tenth-place entrant at just 1 — a steep drop-off rather than a broad, evenly spread field.
- Filing has not sustained its early pace. Filings ran 2 in 2021 down to 0 by 2024, a -100% swing over that span, even as 2025 alone recorded 11 publications working through the ~18-month publication lag.
- Claim activity is concentrated in one IPC subclass. G06F covers 75.9% of the 29 records in scope, while wireless-network claims under H04W appear in only 6.9% — a sign of where the crowded ground is and where it is not.
Filing growth compares 2021 (2 records) with 2024 (0) — a three-year span. 2024 is the most recent year we treat as complete: publication lags filing by roughly 18 months, so 2025 onwards are still filling in and any growth rate that ends there would understate the field.
What this landscape covers
This review covers 29 published records matching software supply-chain security search terms — component security, dependency vulnerability and provenance claims paired with authentication, encryption, threat detection or secure-communication elements — filed between 2015 and the 2026-08-31 data cut-off. Records are drawn overwhelmingly from United States filings (26 of the total), with a small number routed through the WIPO PCT system and one via India.
The field is small enough that a single well-resourced filer can shape most of the visible claim space, and the data bears that out: one assignee accounts for the bulk of the ranked records while the rest of the ranking thins out quickly into single-digit and single-filing entrants.
Let an AI agent run this analysis on your own technology
Pick a task. Every answer cites the patents behind it.
Filing trend and technology composition
Two views of the same 29-record dataset: publication activity by year, and the IPC subclasses those records fall under.
Filing trend, 2017–2026
Publications ran from zero in 2017 to a peak of 11 in 2025, with 2026 only partially represented at 2 so far. The three-year span from 2021 to 2024 shows a -100% swing as filings fell from 2 to 0; treat 2025 and 2026 as still filling in given the roughly 18-month gap between filing and publication, not as a resumption of growth.
IPC subclass composition
G06F (electric digital data processing) appears in 75.9% of the 29 records, far ahead of H04L (digital information transmission) at 24.1%, G06Q (business/commerce data processing) at 13.8%, and H04W (wireless communication networks) at 6.9%. Records can carry more than one class, so these shares sum above 100%.
Shares are the percentage of the 29 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Software Supply-Chain Security Patent Landscape with Eureka
This page is one run against one query. Ask Eureka your own question about software supply-chain security patent landscape and every answer comes back with the patent numbers behind it.
Try EurekaMost-cited prior art and a representative filing
System and method for providing security services with multi-function supply chain hardware integrity for electronics defense (shield)
A system and a method for a supply-chain hardware integrity for electronics defense (SHIELD) dielet embedded over a component of a device, a radio frequency identification (RFID) probe system coupled to the SHIELD dielet, and a secure server system communicating with the RFID probe system that can enable security services is provided. Embodiments include a multi-function SHIELD software defined, hardware enabled security system that provides hardware identity, anti-tamper, encryption key generation and management, trusted platform module services, and cryptographic software security services for a device.Filed by Northrop Grumman Systems Corporation, published 2021-06-17 as US20210182436A1.


| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US20140075567A1 | Service Processor Configurations for Enhancing or Augmenting System Software of a Mobile Communications Device | 417 |
| 2 | US20120072968A1 | Assessment and analysis of software security flaws in virtual machines | 281 |
| 3 | US20110173693A1 | Assessment and analysis of software security flaws | 159 |
| 4 | US8613080B2 | Assessment and analysis of software security flaws in virtual machines | 69 |
| 5 | US9069967B2 | Assessment and analysis of software security flaws | 23 |
| 6 | US20210182436A1 | System and method for providing security services with multi-function supply chain hardware integrity for ele… | 15 |
| 7 | US20190251267A1 | Assessment and analysis of software security flaws | 10 |
| 8 | US10275600B2 | Assessment and analysis of software security flaws | 10 |
| 9 | US20200364350A1 | Assessment and analysis of software security flaws | 5 |
| 10 | US20160098564A1 | Assessment and analysis of software security flaws | 4 |
Citation counts favour older filings simply because they have had longer to accumulate references; read them as a signal of influence within this corpus, not as a measure of current technical relevance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the numbers mean for strategy
Three patterns stand out once the ranking, the IPC composition and the filing trend are read together.
A steep drop from the top
The leading assignee holds 9 of the ranked records; by fifth place the count is down to 2, and the tenth-ranked entrant holds just 1. That is a short head and a long, thin tail rather than a broadly contested field.
Growth has not carried through to a complete year
Filings dropped from 2 in 2021 to 0 in 2024, the last year that can be read as complete. The 2025 spike to 11 records is real activity but sits inside the ~18-month publication lag window and should not yet be read as a trend reversal.
One IPC subclass absorbs most of the claim space
G06F (electric digital data processing) touches three in four records in scope. H04L, G06Q and H04W each appear far less often, which points to where filing pressure is lightest rather than where the technology is less capable.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to software supply-chain security patent landscape, with the prior art for and against each one.
Who is filing, and where the gaps sit
The ranked assignees split into one dominant filer, a cluster of named individuals tied to the same organisation, and a handful of large technology companies with a single record each.
One assignee sets the pace
The top-ranked assignee's 9 records dwarf the rest of the field. Named individuals appearing lower in the ranking co-file with each other and with the leader, suggesting a small, tightly connected inventor group behind much of the corpus.
A tight inventor network
Co-assignee pairs are few but repeat: the strongest pair appears together 4 times, with two further pairs appearing twice each. This points to a stable core team rather than a dispersed set of independent filers.
Big players hold single filings
Several large technology and defense organisations appear in the ranking with a single record apiece. That is a toehold, not a program — worth watching for follow-on filings rather than treating as established territory.
| Assignee | Recent year | YoY |
|---|---|---|
| WESTGATE DATA SCIENCE LLC | 0 | -100% |
| VERACODE INC | 0 | — |
| WYSOPAL CHRISTOPHER J | 0 | — |
| MOYNAHAN MATTHEW P | 0 | — |
| Northrop Grumman Systems Corporation | 0 | — |
| Amazon Technologies, Inc. | 0 | — |
| STEVENSON JON R | 0 | — |
| ENG CHRISTOPHER J | 0 | — |
Where to take this analysis
The dataset points to a narrow, concentrated field with room to move in adjacent claim territory.
Map the leader's claim boundaries
Before filing near the dominant assignee's 9 records, work through their independent claims to see exactly which combinations of component security, authentication and encryption elements are already occupied.
Explore claim scope in EurekaWatch the single-filing entrants
Large organisations holding one record each may be testing the water. A follow-on filing from any of them would be an early signal of a larger program forming.
Track assignee activity in EurekaPrioritise the under-claimed branches
Wireless-endpoint integrity and SBOM-linked scoring show thin coverage relative to the core G06F cluster. These are candidate areas for a defensible first claim.
Run a white-space search in EurekaCommon questions about this landscape
Within this dataset of 29 records, one assignee leads with 9 records, well ahead of the rest of the ranking, which includes 10 assignees total. The next several entrants hold much smaller counts, down to a single record at tenth place. That gap suggests the field has one clear front-runner rather than several evenly matched competitors, though the dataset is small enough that new entrants could shift the picture quickly.
Filings fell from 2 in 2021 to 0 in 2024, a -100% change over that span, and 2024 is the most recent year that can be treated as complete. The apparent jump to 11 records in 2025 reflects the roughly 18-month lag between filing and publication rather than a confirmed new wave of activity, so it should be read cautiously rather than as evidence of renewed growth.
This Northrop Grumman filing describes a SHIELD dielet embedded on a device component, paired with an RFID probe system and a secure server, delivering hardware identity, anti-tamper protection, encryption key generation and management, trusted platform module services and cryptographic software security. It combines hardware-level identity verification with software security services in a single claimed system, which makes it relevant to anyone building component-level authenticity checks into a supply chain.
G06F, covering electric digital data processing, appears in 75.9% of the 29 records in scope, making it by far the densest claim area. H04L (digital information transmission) follows at 24.1%, with G06Q and H04W trailing well behind. High density in G06F signals occupied claim territory rather than technical maturity, so new filings there face a more crowded prior-art landscape.
The IPC composition shows H04W, wireless communication networks, present in only 6.9% of records, well below the G06F cluster, which points to thinner coverage of wireless-endpoint component integrity. Sub-areas such as dependency graph provenance attestation, build-pipeline signing key rotation and SBOM-linked vulnerability scoring also show limited representation among the ranked assignees. These are reasonable starting points for a novelty search rather than guaranteed white space, since the ranking here covers only 10 assignees and the full prior-art universe is larger.
Research Software Supply-Chain Security Patent Landscape in depth with Eureka
Go past this page: query the whole software supply-chain security patent landscape corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.
Machine translation. Assignee and organisation names originally recorded in Chinese, Japanese or Korean have been rendered into English by an AI translation step so that the tables stay readable. These renderings are best-effort and may not match a company’s registered English name; the original name is what the underlying patent record carries, and it is what any Eureka query launched from this page uses.