Software Provenance Patents: Leaders, Trends & White Space 2026
A data-led look at software artifact provenance verification patents: filing trends 2017-2024, assignee concentration across 129 records, IPC composition, and where claim space remains open.
Filing growth = 2021 (21 records) → 2024 (11); 2024 is the last year we treat as complete. Top-5 share = the 5 largest assignees ÷ all 129 records in scope (CR5), not the ranked leaders only.
A young, still-fragmenting claim space
Software artifact provenance verification sits at the intersection of two long-standing patent traditions: remote attestation architectures built for distributed systems security, and package or container distribution mechanisms built for software delivery. The 129 records in scope trace a field that borrowed heavily from decade-old attestation patents before SLSA and in-toto gave the practice a name in industry, and claim language still reflects that lineage — signature verification, integrity checks and attestation-by-proxy recur across both the oldest and newest filings.
Filing activity peaked in 2021 and has genuinely declined through 2024, though the most recent two years remain incomplete under normal publication lag. Ownership is concentrated among a handful of leading filers but far from settled: over half of the 129 records sit outside the ten leading filers, and IPC composition shows the field's centre of gravity still sitting on classical data-processing and network-transmission claims rather than on the AI-model or business-process branches where deployment is now heaviest.
Filing activity, technology mix and where records are published
The 129 records in scope span 2015 through the 2026 cut-off, filed across six major receiving offices and clustered heavily in two IPC subclasses. The figures below use consistent denominators throughout, so shares can be compared directly across sections.
Filing trend: a 2021 peak followed by a real but partial decline
Filings rose to a peak of 21 in 2021, then fell to 11 by 2024 — a decline of 48% over that three-year span, the last span the data can treat as complete. Publication lags filing by roughly 18 months, so 2025 and 2026 figures are still filling in and should not be read as a continued fall.
Publication lags filing by roughly 18 months, so 2025 onwards are still filling in. Growth rates on this page therefore end at 2024; running them to the last bar would understate the field.
Technology composition: two dominant classes, several thin ones
G06F (electronic data processing) appears on 72.9% of the 129 records and H04L (digital transmission) on 48.1%, confirming that most claims combine a data-integrity mechanism with a network or distribution step. Business-process (G06Q), AI-model (G06N) and pictorial-communication (H04N) classes each sit under 10%, and a handful of records extend into agricultural and pharmaceutical subclasses where similar provenance language is reused for physical goods.
Shares are the percentage of the 129 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Software Supply-Chain Security: Software Artifact Provenance Verification Patent Landscape with Eureka
This page is one run against one query. Ask Eureka your own question about software supply-chain security: software artifact provenance verification patent landscape and every answer comes back with the patent numbers behind it.
Try EurekaA recent filing that shows where claim language is heading
Cryptographic enforcement of jurisdiction, purpose, and consent in device, telecom, and network systems
Discloses a Virtual Identity instantiated in a secure enclave and bound to Compliance Jurisdiction Tokens, permitting communication only when jurisdiction, purpose and consent all validate inline — extending token-based compliance beyond payment or aliasing use cases into multi-purpose, multi-jurisdiction gating for GDPR, DPDPA, HIPAA and PSD2-style regimes.Adjacent to, but not overlapping, core artifact-signing and build-attestation claims — its enclave-bound token architecture is a compliance layer rather than a package or container verification mechanism.
View full filing| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US20200162432A1 | Systems and methods for proxying encrypted traffic to protect origin servers from internet threats | 220 |
| 2 | US5214700A | Method for obtaining a securitized cleartext attestation in a distributed data processing system environment | 116 |
| 3 | US8543998B2 | System and method for building virtual appliances using a repository metadata server and a dependency resolut… | 40 |
| 4 | US20160253664A1 | Attestation by proxy | 39 |
| 5 | US8327441B2 | System and method for application attestation | 39 |
| 6 | US20090055817A1 | Software update syndication | 25 |
| 7 | US20220391541A1 | Software provenance validation | 22 |
| 8 | US20200218811A1 | Full server recovery architecture for cloud bare metal instances | 21 |
| 9 | US11055428B1 | Systems and methods for encrypted container image management, deployment, and execution | 19 |
| 10 | US20180054314A1 | Instantiating Containers | 19 |
Citation counts reflect influence within this searched corpus and favour older records; they are not a measure of current commercial relevance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the filing pattern tells a technical or legal reader
Three signals recur across the dataset: a real but incomplete decline from a 2021 peak, a concentration that stops well short of a monopoly, and a technology mix still anchored in two classical IPC classes.
A peak followed by a partial pullback
Filings climbed from 7 in 2017 to 21 in 2021, then fell to 11 by 2024. That three-year decline is real, but 2025-2026 counts are still incomplete under the roughly 18-month publication lag, so the field should not be described as continuing to slow.
Concentrated, but not locked down
The leading filer holds 9 records against a ranked field of 60 companies. Even the ten leading filers together hold only 45.7% of all 129 records, leaving over half the field to smaller and single-filing entrants — a structure that favours new entrants over incumbents with defensive filing strategies.
Two classical IPC classes still dominate
G06F (data processing) and H04L (digital transmission) together anchor most claims, typically pairing a signature or attestation mechanism with a network or distribution step. Newer adjacent classes like G06N (AI models) remain under 5% of records, signalling where claim density has not yet caught up with deployment reality.
Old attestation architectures still anchor the field
The most-cited records date back to proxy-based traffic protection and distributed attestation mechanisms, some over a decade old. High citation counts here reflect influence within a mature searched corpus, not that these mechanisms remain the best current design.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to software supply-chain security: software artifact provenance verification patent landscape, with the prior art for and against each one.
| Assignee | Co-assignee | Shared families |
|---|---|---|
| MOMPER ERIC ALLEN | MAI NHAN HUU | 8 |
| MOMPER ERIC ALLEN | LOPEZ DAVID JOSE | 8 |
| MOMPER ERIC ALLEN | KAUL JASON TODD | 8 |
| MAI NHAN HUU | LOPEZ DAVID JOSE | 8 |
| MAI NHAN HUU | KAUL JASON TODD | 8 |
| LOPEZ DAVID JOSE | KAUL JASON TODD | 8 |
| MOMPER ERIC ALLEN | HINNERSHITZ SCOTT EDWIN | 6 |
| MAI NHAN HUU | HINNERSHITZ SCOTT EDWIN | 6 |
The strongest co-assignee pairing in the dataset recurs across three separate pairings built around the same lead inventor, each appearing on 8 shared records — a pattern consistent with one inventor-led team filing a coordinated portfolio rather than isolated one-off applications.
Where to take this analysis
The trends above point to specific next questions for R&D, IP counsel and competitive-intelligence teams working in this space.
Check freedom-to-operate against the densest claim clusters
With G06F and H04L carrying the bulk of claim density, any new filing around artifact signing or attestation needs a clearance check against the most-cited prior art before drafting.
Run a clearance search in EurekaTrack the inventor-led filing cluster
The strongest co-assignee pairings in this dataset all centre on one lead inventor filing across multiple related applications — worth monitoring for portfolio strategy signals.
Monitor filer activity in EurekaScope a claim in the under-filed AI-model branch
G06N sits at just 4.7% of records despite heavy production dependence on signed model artifacts — a narrower, well-drafted claim here faces less prior art than the core package-signing space.
Explore white space in EurekaCommon questions about this patent landscape
In this dataset it is a filing whose claims tie a software artifact — a package, binary, container image, or similar — to a provenance record such as a signature, attestation, or signed metadata, and then verify, validate or authenticate that record before the artifact is trusted or used. The search covers both title/abstract mentions of provenance verification and claim-level language combining artifact terms with verification mechanisms like SLSA or in-toto. It excludes filings that only discuss general software security without a provenance or origin-verification step.
The ranking covers 60 companies across the 129 records in scope, with the leading filer holding 9 records and the fifth-place holder 6. The five leading filers together account for 28.7% of all 129 records, and the ten leading filers account for 45.7% — meaning roughly half of the field's filing activity sits outside the top ten. That leaves a substantial long tail of organisations with one or a few filings each, which is typical of a technology area still being actively defined rather than one with a single dominant architecture.
Filings rose from 7 in 2017 to a peak of 21 in 2021, then declined to 11 by 2024 — a 48% drop over that three-year window, which is the most recent period the data can treat as complete. Because publication typically lags actual filing by around 18 months, the 2025 and 2026 counts shown in any raw trend line are still incomplete and should not be read as evidence the field is cooling further. The honest read is a strong 2021 peak followed by a real pullback through 2024, with the most recent two years still an open question.
The United States leads with 55 filings, followed by the European Patent Office with 21 and the WIPO PCT route with 13. India (9), Israel (6) and Austria (5) each show smaller but notable filing counts, indicating that while the field is concentrated in US and European jurisdictions, provenance-verification claims are also being pursued through international PCT filings and in a handful of other national offices worth monitoring for regional strategy.
The IPC composition shows G06F and H04L dominating at 72.9% and 48.1% of the 129 records respectively, while AI-model computing (G06N) and pictorial communication (H04N) each sit at only 4.7%. That gap is notable because production machine-learning pipelines increasingly depend on signed model and dataset provenance, yet patent claims specifically targeting AI-model artifact verification are still thin. Filers looking for open claim space should look at model-checkpoint provenance chains and build-to-inference attestation rather than the heavily contested core package/container signing mechanisms.
Research Software Supply-Chain Security: Software Artifact Provenance Verification Patent Landscape in depth with Eureka
Go past this page: query the whole software supply-chain security: software artifact provenance verification patent landscape corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.