Method of determining trust in computer network, computing system and storage medium

By assessing the trust level of network entities through a trust controller, the network performance and security issues caused by reduced inspection strength in zero-trust networking are resolved, enabling more efficient and predictable security management.

CN121967069APending Publication Date: 2026-05-01JUNIPER NETWORKS INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JUNIPER NETWORKS INC
Filing Date
2022-01-14
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In zero-trust networking, existing technologies lack a systematic approach to reduce the intensity of identity and integrity checks on network entities, resulting in improved network performance but decreased security, as well as frequent configuration inconsistencies and security vulnerabilities.

Method used

By introducing a trust controller, the strength of inspections can be adjusted based on the trust score of network entities to achieve consistent and predictable security management.

Benefits of technology

It improves network performance while reducing inconsistencies and security vulnerabilities, enhancing overall network security and management predictability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967069A_ABST
    Figure CN121967069A_ABST
Patent Text Reader

Abstract

The invention relates to a method for determining trust in a computer network, a computing system and a storage medium. This disclosure describes techniques including evaluating trust in a computer network. In one example, the disclosure describes a method comprising: determining a trust level that a first network entity has for a second network entity; determining a trust level of the second network entity to the third network entity; determining that the first network entity is separated from the third network entity by the second network entity; determining a trust level of the first network entity to the third network entity based on the trust level of the first network entity to the second network entity and further based on the trust level of the second network entity to the third network entity; and enabling the first network entity to perform an operation with the third network entity based on the trust level of the first network entity to the third network entity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese patent application No. 202210044616.3. Technical Field

[0002] This disclosure relates to security in computer networks. Background Technology

[0003] Zero-trust networking is a network security approach in which network administrators assume that network entities should not be trusted by default, even if these entities are located in a private network or have been previously authenticated. Example types of network entities can include network nodes (e.g., endpoint devices, intermediate network devices, etc.), network services, or other types of real or virtual entities that can be identified on a computer network. Because network entities are not trusted by default in zero-trust networking, identity and integrity checks are performed on them as usual, even if these entities are part of a private computer network. Summary of the Invention

[0004] This disclosure describes techniques for assessing trust in a system, and more particularly, assessing the degree to which entities in a system can trust another entity in the system. As described herein, in the context of networking, a computing system can assess the degree to which a network entity or network device can trust another entity in a computer network. Making such a determination may involve determining the distance or separation between entities, wherein this distance or separation can be defined by the paths between network entities and / or the properties of intermediate network devices along those paths. In some cases, trust between two network entities can be inferred based on the distance or separation between them, and also based on the degree to which intermediate network entities are trusted.

[0005] As described in this article, a trust score or trust level can be calculated for network entities, and the trust score can be based at least in part on inferred trust. In some examples, a trust score can be calculated and then appropriately adjusted based on a set of trust inferences. A higher trust score is possible when the intermediary device between two network entities is trusted, and a lower trust score is possible when the intermediary device is not trusted.

[0006] Computing systems can use trust scores in various ways, including performing or enabling various actions based on trust scores of network devices or entities. For example, in some cases, a computing system can modify traffic patterns in a computer network based on trust scores and / or trust relationships.

[0007] While some examples in this document can be described based on entities taking the form of network devices, computing devices, and / or computing services (e.g., "network entities"), the techniques described herein can be applied to other types of entities. Such entities can be, for example, quantitative or qualitative entities.

[0008] In some examples, this disclosure describes operations performed by a controller or network device according to one or more aspects of this disclosure. In one specific example, this disclosure describes a method comprising: determining, by a computing system, a trust level of a first network entity to a second network entity; determining, by the computing system, a trust level of the second network entity to a third network entity; determining, by the computing system, that the first network entity and the third network entity are separated by the second network entity; determining, by the computing system, a trust level of the first network entity to the third network entity based on the trust level of the first network entity to the second network entity and further based on the trust level of the second network entity to the third network entity; and enabling the first network entity to perform operations with the third network entity based on the trust level of the first network entity to the third network entity.

[0009] In another example, this disclosure describes a system including a storage device and processing circuitry capable of accessing the storage device, wherein the processing circuitry is configured to: determine a trust level of a first network entity to a second network entity; determine a trust level of the second network entity to a third network entity; determine that the first network entity and the third network entity are separated by the second network entity; determine a trust level of the first network entity to the third network entity based on the trust level of the first network entity to the second network entity and further based on the trust level of the second network entity to the third network entity; and enable the first network entity to perform operations with the third network entity based on the trust level of the first network entity to the third network entity.

[0010] In another example, this disclosure describes a computer-readable storage medium including instructions that, when executed, configure processing circuitry of a computing system to: determine a level of trust that a first entity has with respect to a second entity; determine a level of trust that a first network entity has with respect to a second network entity; determine a level of trust that the second network entity has with respect to a third network entity; determine that the first network entity and the third network entity are separated by the second network entity; determine a level of trust that the first network entity has with respect to the third network entity based on the level of trust that the first network entity has with respect to the second network entity and further based on the level of trust that the second network entity has with respect to the third network entity; and enable the first network entity to perform operations with the third network entity based on the level of trust that the first network entity has with respect to the third network entity. Attached Figure Description

[0011] Figure 1A This is a block diagram illustrating an example computer network according to one or more aspects of this disclosure.

[0012] Figure 1B , Figure 1C and Figure 1D It is a conceptual diagram illustrating various types of entities embodied according to one or more aspects of this disclosure.

[0013] Figure 2 This is a block diagram illustrating an example component of a trust controller according to one or more aspects of this disclosure.

[0014] Figure 3 It is a graph showing how trust scores can change over time according to one or more aspects of this disclosure.

[0015] Figure 4A This is a conceptual diagram illustrating how trust can be inferred based on the properties of an entity that separates one entity from another, according to one or more aspects of this disclosure.

[0016] Figure 4B This is a conceptual diagram illustrating how a change in the level of trust between entities according to one or more aspects of this disclosure can affect the level of trust between other entities.

[0017] Figure 5A and Figure 5B This is a conceptual diagram illustrating trust inferences for two different entities based on one or more aspects of this disclosure.

[0018] Figure 6 This is a flowchart illustrating operations performed by an example trust controller according to one or more aspects of this disclosure. Detailed Implementation

[0019] Figure 1A This is a block diagram illustrating an example computer network 100 according to one or more aspects of this disclosure. Computer network 100 may include various types of computer networks, such as private networks (e.g., internal corporate or government networks, virtual private networks, residential networks, etc.) or public networks (e.g., cellular communication networks, Internet backbone networks, etc.).

[0020] exist Figure 1AIn the example, computer network 100 includes a set of network entities 102A to 102G, where "G" can be any number. This disclosure may collectively refer to network entities 102A to 102G as "network entity 102". Typically, each network entity 102 is individually addressable within computer network 100 and can send and receive data on computer network 100. One or more of network entities 102 may be computing nodes, such as real or virtual endpoint devices (e.g., personal computers, smartphones, tablets, server equipment, laptops, Internet of Things (IoT) devices, wearable devices, etc.) or real or virtual middleware devices (e.g., routers, switches, firewall equipment, virtualized appliances, etc.). In some examples, one or more of network entities 102 may be network services, such as web servers, certain application programming interfaces (APIs), media streaming services, etc. Other types of network entities may include components, controllers, and routes through computer network 100.

[0021] As described above, a computer network, such as computer network 100, may be designed to operate using a zero-trust networking architecture. When a computer network operates using a zero-trust networking architecture, numerous authentication and security checks are performed (e.g., whenever a service is requested from a network entity within the computer network). Performing such checks can be resource-intensive and may increase network latency. Therefore, to improve network performance in a computer network operating using a zero-trust networking architecture, network administrators may reduce the check strength for specific network entities on an ad hoc basis. While this may improve network performance, it compromises the overall security of the computer network because there is no systematic approach to reducing the check strength for individual network entities. Instead, this reduction in check strength may be based on the network administrator's experience and intuition. This can lead to inconsistencies and misconfigurations within the computer network, for example, because knowledge of reduced check strength may not be passed on among network administrators. Ultimately, this can lead to adverse consequences such as security vulnerabilities and network outages.

[0022] This disclosure describes techniques that can solve one or more of these problems. For example, such as Figure 1AAs illustrated in the examples, computer network 100 includes a trust controller 104. Trust controller 104 is a computing system that includes one or more computing devices, such as one or more server devices, personal computing devices, or other types of computing devices. In some examples described herein, trust controller 104 determines the trust level of network entities 102 within computer network 100. In some examples, the trust level may be represented as a number or a trust “score.” In other examples, the trust level may be represented as a class of trust values ​​indicating a continuum of more or less trust values ​​(e.g., “highly trusted,” “trusted,” “untrusted,” “trusted but not verified”), or as a category of trust values ​​for certain operations (“trusted for data transmission,” “trusted for testing”). In other examples, the trust level may be represented as a binary value (e.g., “trusted” or “untrusted”).

[0023] While many examples in this disclosure are described in the context of calculating a “trust score,” these examples can also be implemented alternatively using a “trust level.” Similarly, examples described according to a “trust level” can also be implemented using a trust score. Therefore, in this sense, the terms “trust score” and “trust level” are used interchangeably herein, depending on the context.

[0024] Additionally, trust controller 104 can use the trust score of network entity 102 to perform various actions regarding computer network 100. In some examples, one or more computing systems other than trust controller 104 may determine the trust score and / or use the trust score of network entity 102 to perform actions regarding computer network 100. However, for ease of explanation, at least some examples herein describe trust controller 104 as calculating the trust score and performing actions. In such examples, because trust controller 104 determines the trust score in a predictable and reproducible manner, the trust score can be consistently applied across all network entities of computer network 100. Therefore, inconsistencies associated with adhoc adjustments to checks can be reduced, and less documentation is needed to transfer knowledge of security procedures among network administrators. Trust controller 104 can be implemented as a single trust controller, or as a system of two or more trust controllers (e.g., a hierarchy), or implemented within a system of two or more trust controllers. In an example where the trust controller 104 is implemented as a system trust controller, the trust controller of the trust controller 104 may correspond to a specific category of network entities, different network entities in a subnetwork of computer network 100, or other groups of network entities.

[0025] Trust controller 104 can determine the trust score of network entity 102. The trust score of a network entity indicates the level of trust within the network entity. Generally, a higher level of trust exists if a network entity has previously acted in a manner expected by the administrator of computer network 100. Conversely, a lower level of trust exists if a network entity has not acted in a manner expected by the administrator of computer network 100. For example, a trust score may indicate low trust if the network entity is known to be compromised by malware, if it is known to generate corrupted data, if it is known to have frequent service outages, or if it has known unpatched security vulnerabilities.

[0026] A contribution category is a category of information that contributes to the trust score of a network entity. In some examples, a contribution category includes one or more of the following: a set of prerequisites for the network entity, a set of variable factors for the network entity, and / or a set of reputation factors for the network entity.

[0027] In some examples, separate sub-scores may exist for each contribution category. For example, there may be a first sub-score for the prerequisites of a network entity, a second sub-score for the variable factors of the network entity, and a third sub-score for the reputation factor of the network entity. In some examples, the sub-scores for a contribution category are expressed as a percentage of the highest possible sub-score for that contribution category. In other examples, the sub-scores for a contribution category are expressed in other ways. Trust controller 104 can use the sub-scores for the contribution categories of a network entity (e.g., the first, second, and third sub-scores) to determine the trust score of the network entity. Therefore, the trust score of a network entity may be the result of mathematical calculations based on one or more of the network entity's prerequisites, variable factors, and / or reputation factor.

[0028] Typically, each prerequisite for a network entity is a condition that must be met for the network entity to have a trust score greater than a minimum value (e.g., 0). In this disclosure, a network entity's trust score with a minimum value means that the lowest trust level (e.g., no trust) is given to that network entity. In some examples, the minimum value may be equal to 0. However, values ​​other than 0 can be used to represent a trust score indicating no trust.

[0029] The variable factors of a network entity correspond to the current characteristics of the network entity. Example characteristics of a network entity may include its current configuration, version, and activity characteristics. Variable factors can be weighted so that some contribute more to the variable factor sub-scores than others.

[0030] Each reputation factor of a network entity can be a function of a specified historical event relating to that network entity. For example, trust controller 104 modifies the value of a network entity's reputation factor based on the network entity's behavior over time. For instance, trust controller 104 may modify the value of a reputation factor based on the number of times a network entity has spontaneously restarted. In another example, trust controller 104 may modify the value of a reputation factor based on the number of times a network entity has been reconfigured.

[0031] Trust controller 104 can determine the trust score of a network entity based on several factors. For example, trust controller 104 can determine the trust score of a network entity based on one or more contribution categories and / or by inferring trust based on other known trust relationships in the network. Trust controller 104 can also consider the attributes of entities that separate one entity from another. For example, if network entity 102A trusts network entity 102C, and network entity 102C trusts network entity 102E, then network entity 102A can trust network entity 102E to some extent because network entity 102A trusts entities that also trust network entity 102E. In such an example, the trust score of network entity 102E can be increased for operations that network entity 102A can perform with network entity 102E (e.g., data transfer). Network entity 102A may not have any direct interaction with network entity 102E, but network entity 102A may be able to infer a trust relationship with network entity 102E based on the trust that network entity 102A has with an intermediate entity (e.g., network entity 102C).

[0032] On the other hand, if network entity 102A trusts network entity 102C, but network entity 102C does not trust network entity 102E, then network entity 102A may not trust network entity 102E because network entity 102C (an entity trusted by network entity 102A) does not trust network entity 102E. In this example, actions taken by network entity 102A can lower the trust score of network entity 102E. Therefore, network entity 102A can determine its trust inference about network entity 102E based on its trust level with network entity 102C and the trust level between network entity 102C and network entity 102E.

[0033] Further details regarding trust scoring, particularly in the context of computer networks, are available in U.S. Patent Application No. 16 / 949,996 (Attorney General’s No. 2014-270US01), filed November 23, 2020, entitled “Trust Scoring of Network Entities in Networks,” the entire contents of which are incorporated herein by reference.

[0034] Figure 1B , Figure 1C and Figure 1D This is a conceptual diagram illustrating various types of entities embodied according to one or more aspects of this disclosure. For example, Figure 1B The diagram shows that entities can take the form of functional entities, such as one or more routers 121 or one or more switches 122. Additionally, as... Figure 1B As shown, an entity can take the form of an equipment entity or a network entity, and represents an aggregation of equipment (e.g., a specific type of equipment, such as a set of reconfigurable optical add-drop multiplexers or "ROADM") or networks (e.g., subnets or subnetworks). Figure 1B The type of entity shown can usually correspond to the combination. Figure 1A The type of entity being described.

[0035] Although Figure 1A This is described based on an entity taking the form of network entity 102 (e.g., network device, computing device, computing service, etc.), but in other examples, the term "entity" can include a broader concept. For example, Figure 1C and Figure 1D Other types of entities, or at least entities of different categories, are shown, such as quantitative entity 160 and qualitative entity 170. Quantitative entity 160 may include user 161, service 162, power attribute 163, and cooling attribute 164. Qualitative entity 170 may include other types of entities, possibly non-physical entities. Figure 1D In the example, qualitative entity 170 includes one or more instances of supplier support 171, contractor experience 172, and / or contractor skill set 173. The techniques described herein can be applied simultaneously to both quantitative entity 160 and qualitative entity 170 with trust scores, and the components of the trust scores can be spatial in nature. Such trust scores can be defined to some extent based on the level of trust between adjacent entities in a graph, chart, table, or other data arrangement.

[0036] Figure 2 This is a block diagram illustrating an example component of a trust controller 104 according to one or more aspects of this disclosure. Figure 2 A specific example of a trust controller 104 is shown, and this disclosure covers any other appropriate configuration of the trust controller 104.

[0037] like Figure 2As shown in the example, the trust controller 104 includes one or more processors 202, one or more communication units 204, one or more input devices 208, one or more output devices 210, zero or more displays 212, one or more power supplies 214, one or more storage devices 216, and one or more communication channels 218. The trust controller 104 may include other components. For example, the trust controller 104 may include physical buttons, microphones, speakers, communication ports, etc. The communication channels 218 may (physically, communicatively, and / or operatively) interconnect each of components 202, 204, 208, 210, 212, and 216 for inter-component communication. In some examples, the communication channels 218 may include a system bus, network connection, inter-process communication data structures, or any other method for transmitting data. The power supply 214 may provide power to components 202, 204, 208, 210, 212, and 216.

[0038] Storage device 216 can store information needed during the operation of trust controller 104. In some examples, the primary purpose of storage device 216 is as a short-term, non-long-term computer-readable storage medium. Storage device 216 may include volatile memory, and therefore the stored contents may not be retained in the event of a power outage. In some examples, storage device 216 includes non-volatile memory configured for long-term storage of information and for retaining information after a power-on / power-off cycle. In some examples, the processor 202 of trust controller 104 can read and execute instructions stored by storage device 216.

[0039] Trust controller 104 may include one or more input devices 208 for receiving user input. Examples of user input include haptic, audio, and video user input. Input device 208 may include presence-sensitive screen, touch-sensitive screen, mouse, keyboard, voice response system, microphone, motion sensor capable of detecting gestures, or other types of devices for detecting input from a person or machine.

[0040] Communication unit 204 enables trust controller 104 to send data to and receive data from one or more other computing devices (e.g., via a computer network such as a local area network or the Internet). For example, communication unit 204 may be configured to receive data from network entity 102. In some examples, communication unit 204 may include a wireless transmitter and receiver that enable trust controller 104 to communicate wirelessly with other computing devices. Examples of communication unit 204 may include a network interface card, Ethernet card, optical transceiver, radio frequency transceiver, or other types of devices capable of sending and receiving information. Other examples of such a communication unit may include BLUETOOTH™, 3G, 4G, 5G, and Wi-Fi™ wireless devices, Universal Serial Bus (USB) interfaces, etc. Furthermore, trust controller 104 can use communication unit 204 to communicate with one or more other devices.

[0041] Output device 210 can generate output. Examples of output include haptic, audio, and video output. Output device 210 may include a presence-sensitive screen, sound card, video graphics adapter card, speaker, liquid crystal display (LCD), light-emitting diode (LED) display, or other types of devices used to generate output. Output device 210 may include display screen 212. In some examples, output device 210 may include a virtual reality, augmented reality, or mixed reality display device.

[0042] Processor 202 may include processing circuitry configured to perform various actions. Processor 202 may be configured to read instructions from storage device 216 and execute instructions stored by storage device 216. Execution of instructions by processor 202 may configure or cause trust controller 104 to provide at least some of the functions attributable to trust controller 104 or its components (e.g., processor 202) in this disclosure. Figure 2 As shown in the example, storage device 216 includes computer-readable instructions associated with data collection system 220, scoring system 222, action system 224, and tracking system 226. Figure 2 In the example, storage device 216 may also include source data 228 and scoring data 230. Furthermore, as... Figure 2 As illustrated in the examples, computer-readable instructions associated with the scoring system 222 may include computer-readable instructions associated with the prerequisite system 232, the variable factor system 234, the reputation system 236, and the computing system 238. In other examples, the storage device 216 may include computer-readable instructions associated with other systems or modules.

[0043] Data collection system 220 is configured to collect data about network entity 102. For example, data collection system 220 may query log data of the network entity as part of the data collection process for network entity 102. In some examples, data collection system 220 may be configured to collect configuration and performance data about the network entity. Configuration and performance data may include snapshots of configuration data, snapshots of alarm data, and logs. Data collection system 220 may also collect information about the network topology, enabling the determination of which network entities 102 are neighbors (i.e., adjacent to each other in the network topology), and also enabling the collection and storage of other information about the network (e.g., network paths and routes through the network). Source data 228 may include data collected by data collection system 220.

[0044] The scoring system 222 can use source data 228 to determine the trust score of network entity 102. Scoring data 230 may include the trust score determined by the scoring system 222 for network entity 102. Figure 2 In the example, prerequisite system 232 can determine the prerequisite sub-score of network entity 102. Variable factor system 234 can determine the variable factor sub-score of network entity 102. Reputation system 236 can determine the reputation sub-score of network entity 102. Calculation system 238 can use one or more of the network entity's prerequisite sub-score, variable factor sub-score, or reputation sub-score to determine the network entity's trust score.

[0045] The prerequisite system 232 can determine the prerequisite sub-score of network entity 102. That is, the prerequisite system 232 can determine the trust score of the network entity based on one or more prerequisites. Each prerequisite is a condition that the network entity's trust score must meet to have a minimum value. The prerequisite system 232 can evaluate the conditions to determine the prerequisite sub-score of the network entity. The prerequisite system 232 can store the prerequisite sub-score of network entity 102 as score data 230. Example conditions may include whether the network entity is using a certified software version, whether the network entity is using a certified hardware version, etc. Other prerequisites may include that the network entity does not use a known vulnerable software version, that the network entity only uses supported software or hardware versions, that the network entity has the correct network time settings, that the network entity has the correct certificate loaded for Transport Layer Security (TLS), etc. Conditions can be user-defined.

[0046] Furthermore, the variable factor system 234 can determine the variable factor sub-scores of network entity 102. Each of one or more variable factors of the network entity corresponds to the current characteristic of the network entity. The variable factor system 234 can store the variable factor sub-scores of network entity 102 as score data 230. Characteristics can be user-defined. Examples of characteristics may include: Only use approved applications on network entities.

[0047] Only use signed applications on network entities.

[0048] Is the released version of the network entity a known good version?

[0049] The status or configuration of network entities, such as whether the recommended configuration is applied.

[0050] Whether the software release version of the network entity's software application is within the given release quantity of the current version of the software application.

[0051] Rate limiting of requests to be processed by the router's routing engine.

[0052] Limits on the rate of possible network management interactions for each time period.

[0053] Password strength requirements.

[0054] The number and type of the open network port.

[0055] Does the frequency of encryption key updates exceed the threshold time limit?

[0056] The variable factor system 234 can apply different weights to different characteristics to determine the variable factor sub-score of a network entity. Therefore, a particular characteristic can contribute more to the variable factor sub-score than other characteristics. Table 1 below shows example contributions of specific choices (possible values) for a particular characteristic of a network entity. As shown in the examples in Table 1, software applications (apps) can be categorized into multiple categories (e.g., category 1, category 2, category 3, etc.). Different categories of apps can correspond to different risk levels. For example, category 1 applications can be restricted to applications approved by the system vendor, signed applications, applications with security audits, etc.; category 2 applications can be restricted to applications approved by the vendor, unsigned applications, applications with regular security updates, etc.; and category 3 applications can be unapproved applications, etc. In Table 1, the contribution column represents the score that will be contributed when the corresponding choice in the "Choice" column is applied. In other examples, one or more choices can be associated with negative values, but the final variable factor sub-score can be limited to a minimum value of 0 or other predetermined minimum values. In Table 1, the "Sample Score" column provides examples of how the variable factor sub-score can be calculated for a particular network entity. Therefore, in the example in Table 1, if a network entity uses only Category 1 applications and has software versions within the last 3 versions of the software, but the software is not a known good version, then the variable factor system 234 can determine the variable factor sub-score as 60 (i.e., 50 + 10).

[0057] Table 1

[0058] Reputation system 236 can determine the reputation sub-scores of network entity 102. The reputation sub-scores of a network entity can be based on one or more reputation factors of the network entity. Each reputation factor of the network entity is a function relating to a specified historical event of the network entity. The reputation factors of the network entity can be user-defined. Historical events can be defined as those events that occurred within a specific time period (e.g., 5 weeks, 10 weeks, 6 months, etc.). Reputation system 236 can store the reputation sub-scores of network entity 102 as rating data 230. Example types of reputation factors can include: Multiple time intervals (e.g., weeks, days, etc.) for network entity reset.

[0059] Multiple time intervals (e.g., weeks, days, etc.) for the restart of network entities.

[0060] Number of failed login attempts.

[0061] Login frequency.

[0062] Configure frequency.

[0063] Protocol timeout count or other runtime data.

[0064] Table 2 below illustrates examples of how reputation system 236 can determine the reputation sub-score of a network entity. For example, in Table 2, reputation system 236 may increase the reputation sub-score of a network entity by 5 for each month in which the network entity has not experienced a reset. Furthermore, in Table 2, reputation system 236 may increase the reputation sub-score of a network entity by 15 for each month in which the network entity has not experienced a restart. Since the time period considered is 5 months, the maximum reputation sub-score in this example is 100.

[0065] Table 2

[0066] The calculation system 238 can determine a network entity's trust score using one or more of the network entity's prerequisite sub-scores, variable factor sub-scores, or reputation sub-scores. When calculating a network entity's trust score, if one or more prerequisites are not met (e.g., if the prerequisite sub-score has a minimum value (e.g., 0)), the calculation system 238 can determine that the network entity's trust score indicates no trust. In some examples, the calculation system 238 determines the network entity's trust score as the sum of the variable factor sub-score and the reputation sub-score. In some examples, the calculation system 238 determines the network entity's trust score as a weighted sum of the variable factor sub-score and the reputation sub-score. For example, the calculation system 238 may apply 60% weight to the variable factor sub-score and 40% weight to the reputation sub-score. In some examples, the weights applied to the variable factor sub-score and the reputation sub-score are user-defined. Therefore, since the weights applied to the variable factor sub-score and the reputation sub-score are user-defined, the final trust score can depend on the user's priorities and preferences. In some examples, the calculation system 238 may multiply the resulting sum (or weighted sum) by the prerequisite sub-score to determine the trust score of the network entity. In some examples, if no prerequisites are met, the calculation system 238 may simply set the trust score of the network entity to a minimum value (e.g., 0) instead of calculating the prerequisite sub-score through the trust controller 104. The calculation system 238 may store the trust score of the network entity 102 in the scoring data 230.

[0067] In some examples, the scoring system 222 may aggregate the trust scores of two or more network entities 102 to determine the trust score of a higher-order network entity. Examples of higher-order network entities may include networks, services, routes, and / or other sets of one or more network entities. The scoring system 222 may aggregate trust scores in one of a variety of ways. For example, the scoring system 222 may aggregate the trust scores of two or more network entities 102 to determine the trust score of the higher-order network entity by using the lowest trust score among the two or more network entities as the trust score of the higher-order network entity. In another example, the scoring system 222 may aggregate the trust scores of two or more network entities 102 to determine the trust score of the higher-order network entity as the average or sum of the trust scores of the two or more network entities.

[0068] Action system 224 can perform one or more actions based on a trust score determined by scoring system 222 for network entity 102. For example, action system 224 can modify the traffic pattern of computer network 100 based on the network entity's trust score. For instance, in this example, based on the network entity's trust score, action system 224 can change the traffic pattern in computer network 100 to redirect network traffic away from or to the network entity. For example, if the network entity's trust score is below a certain threshold, action system 224 can change the traffic pattern in computer network 100 to redirect network traffic away from the network entity. In some examples, if the network entity's trust score is above a certain threshold, action system 224 can change the traffic pattern in computer network 100 to direct network traffic to the network entity. In another example, based on the network entity's trust score being greater than a certain threshold, action system 224 can send an instruction to one or more routers in computer network 100, causing the routers to change the routing in computer network 100 so that packets are not directed along routes to or through the network entity.

[0069] In another example, action system 224 can determine that conflicting information exists between two sensors (e.g., in the context of an aircraft, the angle of attack sensor and the nose pitch sensor). In this example, action system 224 can, in response to determining such a conflict, perform one or more actions based on the trust scores of the sensors (i.e., network entities). For example, action system 224 can generate a notification to the operator recommending the use of information from the sensor with the higher trust score. In another example, action system 224 can disable a sensor with a lower trust score. In some examples, action system 224 can recommend probing or acquiring a combination of other sensor data to determine which of the two sensors is more likely to generate accurate data. In an example where the network entities include multiple clock sources (e.g., Precision Time Protocol (PTP) clock sources), action system 224 can change the primary clock source from the current clock source to the backup clock source because the backup clock source has a higher trust score than the current clock source. In some examples, action system 224 can identify routes through network 100 based on the trust scores of network entities in network 100. Therefore, the action system 224 can configure the router to route network traffic along routes through network entities with high trust scores.

[0070] Tracking system 226 can track changes in trust scores and / or sub-scores and reassess the trust level associated with one or more entities. Tracking system 226 can collect information from source data 228 and determine changes in trust scores and / or sub-scores associated with one or more network entities 102. Tracking system 226 can determine which network entities 102 require services, such as upgrades, audits, reviews, testing, or other assessments, based on historical information about the trust scores of each network entity 102. In some examples, tracking system 226 can identify one or more network entities 102 with consistently high trust scores and track trends of using such network entities 102 for high-priority, high-importance, or mission-critical tasks.

[0071] Inference system 221 can perform functions related to inferring a trust score for a given entity based on the entity's distance, separation, or location from another entity's perspective. Inference system 221 can apply this inferred trust as a component or degree of trust. In some examples, inference system 221 can be used to adjust (and thereby improve) the trust score determined by rating system 222. In such examples, inference system 221 can apply an adjustment to an entity's trust score based on the separation between the entity and another entity being evaluated, where the degree of separation corresponds to distance, the count of intermediate entities, or the location associated with the entity being evaluated.

[0072] For example, in Figure 1AIn this context, if network entity 102E has a trust score of 70, then network entity 102C, which is adjacent to network entity 102E, can be considered to have a trust score of 70. If network entity 102C has a trust score of 80, then network entity 102A, which is adjacent to network entity 102C, can be considered to have a trust score of 80. However, the trust score associated with network entity 102A and network entity 102E can be a function of the trust scores of network entities 102C and 102E, as well as the number of intermediate network entities between network entities 102A and 102E. Trust score of 102A = f (trust score of 102C, trust score of 102E, count of intermediate entities between 102A and 102E) A high count of intermediate entities can lower the trust score. Conversely, a low count can result in a higher trust score.

[0073] In other examples, the inference system 221 can be integrated into the scoring system 222, so that the calculation system 238 calculates a trust score by considering inferences about trust between network entities 102.

[0074] In an example where inference system 221 or aspects thereof are integrated into scoring system 222, both variable factor system 234 and reputation system 236 can use trust inference or information derived from trust inference to perform variable and reputation assessments, respectively. For example, as a new entity is added and a new trust inference is determined, variable factor system 234 can recalculate the trust score. Reputation system 236 can assess whether trust inferences between entities improve or deteriorate over time. In such an example, Tables 1 and 2 above can be modified as follows: Table 1'

[0075] Table 2'

[0076] The scoring system 222 can supplement existing metrics with trust inferences or information derived from such trust inferences, thereby improving the accuracy of the scoring system 222. Typically, the inference system 221 can receive and output information from one or more other systems or modules within the storage device 216, and can otherwise interact with and / or operate in conjunction with one or more other systems and / or modules of the trust controller 104.

[0077] Figure 2The various systems shown (e.g., data collection system 220, inference system 221, scoring system 222, action system 224, tracking system 226, prerequisite system 232, variable factor system 234, reputation system 236, computing system 238) can be implemented as modules or other logic. In such examples, such modules shown or described elsewhere in this disclosure can perform the described operations using software, hardware, firmware, or a mixture of hardware, software, and firmware residing in and / or executing on one or more computing devices. For example, a computing device can execute one or more such modules using multiple processors or multiple devices. A computing device can execute one or more such modules as a virtual machine executing on the underlying hardware. One or more of such modules can execute as one or more services of an operating system or computing platform. One or more of such modules can execute as one or more executable programs at the application layer of a computing platform. In other examples, the functionality provided by the modules can be implemented by dedicated hardware devices.

[0078] Although certain modules, data stores, components, programs, executables, data items, functional units, and / or other items contained in one or more storage devices may be shown individually, one or more of these items may be combined and operate as a single module, component, program, executable, data item, or functional unit. For example, one or more modules or data stores may be combined or partially combined such that they operate or provide functionality as a single module. Furthermore, one or more modules may interact with each other and / or operate in combination with each other, such that, for example, one module serves or extends another module. Additionally, each module, data store, component, program, executable, data item, functional unit, or other item shown in the storage device may include multiple components, subcomponents, modules, submodules, data stores, and / or other components or modules or data stores not shown.

[0079] Furthermore, each module, data store, component, program, executable, data item, functional unit, or other item shown in the storage device can be implemented in various ways. For example, each module, data store, component, program, executable, data item, functional unit, or other item shown in the storage device can be implemented as a downloadable or pre-installable application or "app". In other examples, each module, data store, component, program, executable, data item, functional unit, or other item shown in the storage device can be implemented as part of an operating system that executes on a computing device.

[0080] Figure 3This is a graph illustrating how trust scores can change over time according to one or more aspects of this disclosure. In some examples, the tracking system 226 of trust controller 104 can track changes in trust scores and / or sub-scores and reassess the trust level associated with one or more entities. Trust controller 104 can use information about changes in trust scores and / or sub-scores for a variety of purposes. For example, trust controller 104 can use historical information about the trust scores of network entities to determine which network entities require attention (e.g., require escalation, auditing, review, testing, etc.). In other examples, trust controller 104 can use such historical information to identify network entities with consistently high trust scores and configure network 100 to use the identified network entities for high-priority tasks (such as for emergency communications during emergency situations).

[0081] exist Figure 3 In the example, "good initial setup" might mean that all prerequisites are met, and that variable and reputation factors result in a "good" initial score. "Behavior" can refer to actions that change the trust score over time. Behavior can be considered "good" if trust or the trust score does not deteriorate or decrease. Behavior might be considered "bad" if the trust score does deteriorate.

[0082] Figure 4A This is a conceptual diagram illustrating how trust can be inferred based on the properties of entities that separate one entity from another, according to one or more aspects of this disclosure. Figure 4A In the network 400, there are typically networks corresponding to Figure 1A Network entity 102 is a network entity. Bidirectional connections are shown between adjacent or connected entities. Figure 4A In this context, network entities 102A and 102C are adjacent entities, or close to each other, because network entities can send data directly to another network entity, for example, without first sending network data through other network entities. However, network entity 102A is "separated" from network entity 102E because data transmitted from network entity 102A to network entity 102E will traverse at least one other network entity (e.g., network entity 102C). Network entities 102A and 102E can be considered separated by another network entity because the shortest path between the two network entities involves another network entity. The separation attribute between the two network entities ("separation attribute") may include the number of other network entities separating the network entities (e.g., "separation degree" or "entity count," which would have a value of 1 for network entities 102A and 102E), the type of entities separating the network entities, information about the path between the network entities, or other information.

[0083] In addition Figure 4AIn the diagram, network entity 102 is shown as shaded to varying degrees, where the shade indicates the trust level from the perspective of network entity 102A (note that 102A is drawn with a dashed line). From the perspective of network entity 102A, shaded network entity 102 is considered untrusted; from the perspective of network entity 102A, network entity 102 with little or no shade is considered trusted. In some examples, binary trust relationships may apply, allowing neighbors to be simply classified as trusted or untrusted. However, in at least some of the illustrations shown herein (including...) Figure 4A A trust continuum can be applied, so that network entity 102, which is more shadowed than other network entities 102, is considered less trusted.

[0084] Trust controller 104 can determine the trust score of one or more network entities 102 within network 400. For example, trust controller 104 can combine the above... Figure 2 The described method applies the scoring system 222 to the attributes of each of network entities 102 to calculate a trust score for one or more of network entities 102A to 102G. However, in another example, the trust controller 104 may use an alternative method for determining the trust score.

[0085] In the application of Trust Controller 104, such as in combination Figure 2 In the example of the described rating system 222, the trust controller 104 can apply the prerequisite system 232, the variable factor system 234, the reputation system 236, and the calculation system 238 to obtain trust scores for at least some network entities 102. For example, in Figure 4A China and reference Figure 2 The trust controller 104 has a prerequisite system 232 that evaluates the prerequisites for each of network entities 102A to 102G. The prerequisite system 232 identifies which network entities 102 meet and do not meet the required prerequisites. Those network entities 102 that do not meet the prerequisites are marked as untrusted.

[0086] For those network entities 102 that meet the prerequisites, the variable factor system 234 of the trust controller 104 determines a variable factor sub-score for each such network entity 102. For example, as in combination Figure 2 As described, the variable factor system 234 can apply appropriate weights to different characteristics to determine the variable factor sub-scores for each network entity 102 (or at least those network entities 102 that meet the prerequisites). The variable factor system 234 stores the variable factor sub-scores of the network entities 102 as score data 230.

[0087] Furthermore, for those network entities 102 that do indeed meet the prerequisites, the reputation system 236 of the trust controller 104 determines a reputation sub-score for each such network entity 102. For example, similarly as in combination Figure 2 As described, reputation system 236 can apply weights to various factors, attributes, or characteristics of each network entity 102 to evaluate reputation sub-scores. Reputation system 236 can also evaluate historical data over a specific time period. Reputation system 236 calculates reputation sub-scores for each network entity 102 (or at least for network entities 102 that meet prerequisites). Reputation system 236 stores the reputation sub-scores of network entities 102 as rating data 230.

[0088] The calculation system 238 can use variable factor sub-scores and reputation sub-scores to calculate a trust score. For example, refer again... Figure 2 and Figure 4A The calculation system 238 accesses scoring data 230, which includes sub-scores stored by the variable factor system 234 and the reputation system 236. The calculation system 238 uses the accessed sub-scores to determine a trust score for each network entity 102. In one example, the calculation system 238 sums the sub-scores to obtain a trust score. In some examples, the calculation system 238 may multiply the resulting sum (or weighted sum) by the prerequisite sub-scores to determine the corresponding trust score for each network entity 102. The calculation system 238 stores the trust score for each network entity 102 as scoring data 230. Such scores may be calculated only for those network entities 102 that meet the prerequisites evaluated by the prerequisite system 232. If the prerequisite system 232 determines that one or more network entities 102 do not meet one or more prerequisites, the calculation system 238 may determine that for any such network entity 102 that does not meet the prerequisites, the trust score is zero.

[0089] Trust controller 104 can also determine about Figure 4A Information about the level of trust between neighbors or connected entities. For example, in reference... Figure 4A In the example described, trust controller 104 (see...) Figure 1A For each of network entities 102A to 102G, a set of trust inferences is determined, wherein, from the perspective of a particular network entity 102, such trust inferences indicate the degree of trust between that particular network entity 102 and other network entities 102. Figure 4A Trust inference is illustrated from the perspective of network entity 102A, and network entity 102A is drawn with dashed lines to indicate this. Figure 4AThe trust inference shown is from the perspective of network entity 102A. As mentioned above, from the perspective of network entity 102A, other network entities 102 that are not shaded are considered trusted. From the perspective of network entity 102A, shaded network entities 102 are considered untrusted. exist Figure 4A In the example shown, trust controller 104 can use trust calculations for each network entity 102 to determine the extent to which network entity 102A can trust other network entities 102. For example, in Figure 4A In this context, the trust controller 104 determines whether network entity 102A can trust another entity by evaluating whether a certain entity that network entity 102A already trusts trusts those other entities. For example, in... Figure 4A In this context, network entity 102A trusts network entity 102C (network entity 102C is shown as unshadowed or trusted from the perspective of network entity 102A), but network entity 102A does not trust network entity 102B (network entity 102B is shown as shadowed, indicating a lack of trust from the perspective of network entity 102A). Furthermore, based on the analysis performed by trust controller 104, trust controller 104 has determined that network entity 102C trusts network entity 102E, but network entity 102C does not trust network entity 102D. Additionally, trust controller 104 has determined that network entity 102E trusts network entity 102F, but does not trust network entity 102G.

[0090] By using this information, the trust controller 104 determines that, from the perspective of network entity 102A, network entity 102E has a certain degree of positive trust (i.e., is trusted by network entity 102A to some extent). Specifically, the inference system 221 of the trust controller 104 (see...) Figure 2 The system accesses the network topology information in source data 228 and determines that network entity 102C is adjacent to network entity 102A (i.e., it is its neighbor). The inference system 221 also determines based on the topology that network entity 102E is not adjacent to network entity 102A (not its "neighbor"), but rather that network entity 102E is adjacent to network entity 102C.

[0091] Inference system 221 uses this information to determine that network entity 102E is trusted from the perspective of network entity 102A because network entity 102C trusts its neighboring network entity 102E, and network entity 102A trusts network entity 102C, which is a neighbor of network entity 102A. Based on these attributes, trust controller 104 determines that network entity 102E is trusted by network entity 102A. And although inference system 221 can determine that network entity 102E is trusted from the perspective of 102A, inference system 221 can also determine that network entity 102E is not trusted by network entity 102A as much as network entity 102C is trusted by network entity 102A. Inference system 221 can make this determination at least because network entity 102E is farther from network entity 102A (i.e., network entity 102E has a higher degree of separation from network entity 102A than network entity 102C, for example, a higher-count intermediate device or entity).

[0092] Trust controller 104 can also determine that network entity 102F is trusted from the perspective of network entity 102A, or at least has a certain degree of positive trust. Trust controller 104's inference system 221 makes this determination based on network topology and information indicating that network entity 102E trusts network entity 102F and network entity 102A trusts network entity 102E (i.e., network entity 102F can be trusted by network entity 102A). However, based on the additional degree of separation between network entity 102F and network entity 102E, network entity 102A may trust network entity 102E less than network entity 102A trusts network entity 102F.

[0093] From the perspective of network entity 102A, trust controller 104 can also identify one or more untrusted network entities 102. For example, the inference system 221 of trust controller 104 can determine that network entity 102D is not trusted from the perspective of network entity 102A because, as mentioned above, network entity 102D is not trusted by network entity 102C. Similarly, inference system 221 can determine that network entity 102G is not trusted from the perspective of network entity 102A because, also as mentioned above, network entity 102G is not trusted by network entity 102E.

[0094] Trust controller 104 can enable network entity 102A to perform operations with network entity 102E based on the trust level that network entity 102A has for network entity 102E. For example, in Figure 4A In the examples and references Figure 2Action system 224 can determine that network entity 102A trusts network entity 102E, so action system 224 can place network entity 102E on an access control list, or can use trust to influence decisions about whether to place one or more network entities on an access control list.

[0095] In another example, if network entity 102A trusts network entity 102E, action system 224 can route traffic along a path that includes network entity 102E. However, in an example where action system 224 determines that network entity 102A does not trust network entity 102E, the action center can choose to route traffic along a path that does not include network entity 102E. In some examples, action system 224 can proactively block traffic from passing through network entity 102E by identifying network traffic queuing to cross network entity 102E and adjusting network flow so that at least some network traffic does not cross network entity 102E.

[0096] When the trust level is represented by a continuous value (e.g., a trust "score," where a higher value indicates more trust than a lower value), if the trust level between network 102A and network entity 102E exceeds a threshold, action system 224 can determine that network 102A trusts network entity 102E. In this case, action system 224 can enable network entity 102A to perform one or more operations with network entity 102E. If the trust level does not exceed the threshold, action system 224 may disallow network entity 102A from performing one or more operations with network entity 102E.

[0097] exist Figure 4A In one example, trust controller 104 is described as evaluating trust relationships, assigning trust scores, and performing trust inference operations. However, in other examples, such operations can be performed individually by one or more network entities 102, thereby enabling distributed evaluation of trust scores and / or trust relationships. In such examples, information about trust scores and / or trust relationships can be stored locally in each network entity 102. In other examples, this information can be evaluated in a distributed manner, but still stored in a single location accessible to each network entity 102. For entities that include processors or entities and have sufficient computing power to evaluate trust based on data they collect or data collected by another entity or computing device, information about trust scores and / or trust relationships can be calculated or determined by individual network entities 102 rather than by trust controller 104. In such examples, data sharing mechanisms can be set up to enable data sharing, even between entities that do not trust each other. Trust inference data can be presented through an application programming interface or shared between entities and / or computing systems using protocols.

[0098] Figure 4B This illustrates one or more aspects of this disclosure. Figure 4A A conceptual diagram showing how changes in the trust level between entities can affect the trust level between other entities. Figure 4B It shows the relationship with Figure 4A The same network 400 is shown, except in Figure 4B In the above, the trust level between network entity 102C and network entity 102D has changed, and the trust level between network entity 102C and network entity 102E has also changed. Specifically, the level of trust between network entity 102C and network entity 102D has increased, so that network entity 102C now trusts network entity 102D to some extent (previously, in...). Figure 4A In this context, network entity 102C does not trust network entity 102D. The increase in trust is due to… Figure 4B The "+++" instruction is shown. Furthermore, in... Figure 4B In this context, the level of trust between network entity 102C and network entity 102E has decreased, resulting in network entity 102C now trusting network entity 102E less than network entity 102C trusts network entity 102E in the past. Figure 4A Trust in (see) Figure 4B (The "- - -" symbol in the text).

[0099] Trust controller 104 can determine the extent to which a change in trust may affect one or more trust inferences of network entity 102A. For example, refer to Figure 4B and Figure 2 The router 121 of the trust controller 104 detects input from the tracking system 226. The inference system 221 determines that the input corresponds to information about changes in trust between network entities 102. For example, the inference system 221 determines that network entity 102C has updated its software to a more recent and / or more reliable version. The inference system 221 may also determine, for example, that network entity 102E requires one or more additional reboot operations to resolve performance issues. Therefore, based on this information, the inference system 221 determines that network entity 102C trusts network entity 102D to an increased degree, and network entity 102C trusts network entity 102E to a decreased degree. Where trust levels are expressed as trust scores, the inference system may increase the score associated with the trust network entity 102C has in trusting network entity 102D, but decrease the score associated with the trust network entity 102C has in trusting network entity 102E. When trust levels are expressed as categories, the inference system 221 can subsequently classify network entity 102D as a category with higher trust, and can subsequently classify network entity 102E as a category with lower trust.

[0100] Inference system 221 determines a change in trust among network entities 102 relative to a set of trust inferences affecting network entity 102A, even if the degree of separation between network entity 102A and other network entities 102 (e.g., the number of network entities) has not changed. As described, inference system 221 modifies the trust inference of network entity 102A so that network entity 102A now trusts network entity 102D to some extent (whereas previously, network entity 102A did not trust network entity 102D). To reflect this change, network entity 102D is now... Figure 4B There is no in Figure 4A It's so dark. Furthermore, the inference system 221 modifies the trust inference so that network entity 102A now trusts network entity 102E less than it did before detecting the trust change between network entities 102 (note, Figure 4B The shadows in network entity 102E are increased.

[0101] In some examples, the inference system 221 can also determine that changes in trust between network entities 102C and 102D, as well as network entity 102E, may affect network entity 102A's trust in network entity 102F. Note, for example, that both network entities 102D and 102E are on the path from network entity 102A to network entity 102F. In such examples, the trust level of network entity 102A in network entity 102F may decrease, such as... Figure 4B As shown.

[0102] Figure 5A and Figure 5B This is a conceptual diagram illustrating trust inferences for two different entities based on one or more aspects of this disclosure. Figure 5A A set of trust inferences is presented from the perspective of network entity 102C (note that network entity 102C is in...). Figure 5A (shown by dashed lines). Figure 5B A set of trust inferences is presented from the perspective of network entity 102F (note that network entity 102F is in...). Figure 5B (shown by dashed lines).

[0103] exist Figure 5A As shown in the shaded area of ​​network entity 102 in the figure, network entity 102C trusts network entities 102A and 102E, and has a lower level of trust in network entities 102D and 102F. However, network entity 102C does not trust network entities 102B or 102G.

[0104] exist Figure 5B In, and as Figure 5BAs shown by the shaded area of ​​network entity 102 in the diagram, network entity 102F has a certain level of trust in network entity 102D, but does not trust any other network entity 102. In summary, Figure 5A and Figure 5B The diagram illustrates that network entity 102C trusts network entity 102F to some extent, but network entity 102F does not trust network entity 102C. Therefore, this emphasizes that the degree of trust between entities is not reciprocal, at least in some examples. In such examples, the degree of trust should not be assumed to be reciprocal.

[0105] Figure 6 This is a flowchart illustrating operations performed by an example trust controller 104 according to one or more aspects of this disclosure. The following is... Figure 1A Described in the context of network 100 and trust controller 104 Figure 6 In other examples, Figure 6 The operations described herein can be performed by one or more other components, modules, systems, or devices. Furthermore, in other examples, in conjunction with... Figure 6 The described operations may be combined, performed in a different order, omitted, or may cover additional operations not specifically shown or described.

[0106] exist Figure 6 In the process shown, and according to one or more aspects of this disclosure, the trust controller 104 can determine the trust level (601) that the first network entity has over the second network entity. For example, in Figure 1A In this context, the trust controller 104 can determine the degree to which network entity 102A (the first entity) trusts network entity 102C (the second entity). The trust controller 104 can make this determination by applying a prerequisite scoring system, a variable factor scoring system, and / or a reputation scoring system to obtain a trust score for network entity 102C.

[0107] Trust controller 104 can determine the level of trust that the second network entity has in relation to the third network entity (602). For example, in Figure 1A In this context, the trust controller 104 can determine the degree to which network entity 102C (the second entity) trusts network entity 102E (the third entity). The trust controller 104 can make this determination by reapplying the prerequisite scoring system, the variable factor scoring system, and / or the reputation scoring system, this time to obtain the trust score of network entity 102E.

[0108] Trust controller 104 can determine the trust level of the first network entity to the third network entity based on the trust level of the first network entity to the second network entity and further based on the trust level of the second network entity to the third network entity (603). For example, trust controller 104 can determine that network entity 102A (the first entity) does not directly interact with or connect to network entity 102E (the third entity). However, trust controller 104 can determine that it can base its trust level on the entity located between network entity 102A and network entity 102E (i.e., Figure 1A The trust controller 104 infers the trust relationship between network entity 102A and network entity 102E based on the trust relationship between network entity 102A and network entity 102C (which separates network entity 102A from network entity 102E). The trust controller 104 infers the trust level of network entity 102A to network entity 102E based on at least two trust relationships: the trust level between network entity 102A and network entity 102C, and the trust level between network entity 102C and network entity 102E. If network entity 102A trusts network entity 102C and network entity 102C trusts network entity 102E, the trust controller 104 can infer that network entity 102A trusts network entity 102E. However, if network entity 102A does not trust network entity 102C and / or network entity 102C does not trust network entity 102E, the trust controller 104 can infer that network entity 102A does not trust or should not trust network entity 102E.

[0109] Trust controller 104 can enable the first network entity to perform operations with the third network entity based on the trust level the first network entity has towards the third network entity (605). For example, if trust controller 104 determines from the perspective of network entity 102A that network entity 102E is trusted (from the YES path of 604), then trust controller 104 can allow network entity 102A to interact with network entity 102E (e.g., transfer data). However, if trust controller 104 determines that network entity 102E should not be trusted (from the NO path of 604), then trust controller 104 can at least in some way prevent network entity 102A from interacting with network entity 102E.

[0110] For the processes, apparatuses, and other examples or illustrations described herein (included in any flowchart or diagram), certain operations, actions, steps, or events included in any of the techniques described herein may be performed in a different order, may be added, combined, or omitted entirely (e.g., not all described actions or events are necessary for practicing the described techniques). Furthermore, in some examples, operations, actions, steps, or events may be performed concurrently rather than sequentially, for example, through multithreaded processing, interrupt handling, or multiple processors. Additionally, certain operations, actions, steps, or events may be performed automatically, even if not specifically identified as automatically. Moreover, certain operations, actions, steps, or events described as automatically performed may alternatively not be automatically performed, but rather, in some examples, such operations, actions, steps, or events may be performed in response to input or another event.

[0111] All publications, patents, and patent applications mentioned herein are incorporated herein by reference in their entirety. In the event of any conflict between any such publications incorporated herein by reference and this disclosure, this disclosure shall prevail.

[0112] For ease of illustration, only a limited number of devices (e.g., network entity 102, trust controller 104, entity 110, quantitative entity 160, qualitative entity 170, and other devices) are shown in the figures and / or other illustrations referenced herein. However, the techniques according to one or more aspects of this disclosure can be implemented with many such systems, components, devices, modules, and / or other items, and collective references to such systems, components, devices, modules, and / or other items may refer to any number of such systems, components, devices, modules, and / or other items.

[0113] The accompanying drawings included herein illustrate at least one exemplary embodiment of one aspect of this disclosure. However, the scope of this disclosure is not limited to such embodiments. Therefore, other examples or alternative embodiments of the systems, methods, or techniques described herein may be appropriate in other examples besides those shown in the drawings. Such embodiments may include a subset of the devices and / or components included in the drawings, and / or may include additional devices and / or components not shown in the drawings.

[0114] The detailed description above is intended as a description of various configurations, and not as representing only the configurations in which the concepts described herein can be practiced. This detailed description includes specific details to provide a full understanding of the various concepts. However, these concepts can be practiced without these specific details. In some cases, well-known structures and components are shown in block diagram form in the cited figures to avoid obscuring these concepts.

[0115] Therefore, while one or more embodiments of various systems, devices, and / or components may be described with reference to specific accompanying drawings, these systems, devices, and / or components may be implemented in a variety of different ways. For example, in the accompanying drawings (e.g., Figure 1A and / or Figure 2 One or more devices shown as separate devices in the accompanying drawings may alternatively be implemented as a single device; one or more components shown as separate components may alternatively be implemented as a single component. Furthermore, in some examples, one or more devices shown as a single device in the accompanying drawings may alternatively be implemented as multiple devices; one or more components shown as a single component may alternatively be implemented as multiple components. Each of such multiple devices and / or components may be directly coupled via wired or wireless communication and / or remotely coupled via one or more networks. Additionally, one or more devices or components that may be shown in the various accompanying drawings may alternatively be implemented as part of another device or component not shown in these drawings. In this and other ways, some of the functions described herein can be performed by distributed processing of two or more devices or components.

[0116] Furthermore, certain operations, techniques, features, and / or functions may be described herein as being performed by a specific component, device, and / or module. In other examples, such operations, techniques, features, and / or functions may be performed by different components, devices, or modules. Therefore, in other examples, some operations, techniques, features, and / or functions that may be described herein as belonging to one or more components, devices, or modules may belong to other components, devices, and / or modules, even if not specifically described in this way herein.

[0117] While specific advantages have been identified in conjunction with the description of some examples, various other examples may include, exclude, or include all of the listed advantages. Other technical or other advantages will be apparent to those skilled in the art from this disclosure. Furthermore, although specific examples have been disclosed herein, any number of techniques (whether currently known or not) may be used to implement aspects of this disclosure, and accordingly, this disclosure should not be limited to the examples specifically described and / or illustrated herein.

[0118] In one or more examples, the described functionality may be implemented using hardware, software, firmware, or any combination thereof. If implemented in software, the functionality may be stored as one or more instructions or code on and / or transmitted via a computer-readable medium and executed by a hardware-based processing unit. A computer-readable medium may include a computer-readable storage medium, corresponding to a tangible medium such as a data storage medium, or a communication medium that includes any medium facilitating the transfer of a computer program from one place to another (e.g., according to a communication protocol). In this manner, a computer-readable medium may generally correspond to (1) a tangible computer-readable storage medium that is non-transitory, or (2) a communication medium such as a signal or carrier wave. A data storage medium may be any available medium accessible by one or more computers or one or more processors to retrieve instructions, code, and / or data structures for implementing the techniques described in this disclosure. A computer program product may include a computer-readable medium.

[0119] By way of example and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, or optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, flash memory, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Furthermore, any connection may be appropriately referred to as a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using a wired (e.g., coaxial cable, fiber optic cable, twisted pair) or wireless (e.g., infrared, radio, and microwave) connection, then a wired or wireless connection is included in the definition of medium. However, it should be understood that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but rather refer to non-transient, tangible storage media.

[0120] Instructions can be executed by one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Therefore, the terms "processor" or "processing circuit" as used herein may each refer to any of the foregoing structures or any other structure suitable for implementing the described techniques. Furthermore, in some examples, the described functionality may be provided within dedicated hardware and / or software modules. Moreover, the techniques may be implemented entirely within one or more circuit or logic elements.

[0121] The techniques disclosed herein can be implemented in a wide variety of devices or apparatuses, including wireless handheld devices, mobile or non-mobile computing devices, wearable or non-wearable computing devices, integrated circuits (ICs), or a set of ICs (e.g., chipsets). Various components, modules, or units are described in this disclosure to emphasize functional aspects of a device configured to perform the disclosed techniques, but they do not necessarily need to be implemented by different hardware units. Rather, as described above, various units can be combined in a hardware unit or provided by a collection of interoperable hardware units including one or more processors as described above, along with appropriate software and / or firmware.

Claims

1. A system comprising processing circuitry and a storage medium, wherein, The processing circuit is capable of accessing the storage medium and is configured to: Determine the first trust level that the first network device has for the second network device; Determine the second trust level that the second network device has for the third network device; It is determined that the first network device and the third network device are separated by the second network device; Based on the first trust level and the second trust level, identify the inferred trust level that the first network device has for the third network device; Based on the inferred trust level, one of a limited number of trust categories is assigned to the inferred trust level; The output uses one of the assigned finite number of trust categories to represent the inferred trust level in the user interface; as well as Based on the inferred trust level, the first network device is enabled to perform operations with the third network device.

2. The system according to claim 1, wherein, In order to assign one of the finite number of trust categories to the inferred trust level, the processing circuit is further configured to: Assign one of the two trust categories to the inferred trust level.

3. The system according to claim 2, wherein, In order to assign one of the two trust categories, the processing circuit is further configured to: Assign the category of trust to the inferred trust level.

4. The system according to claim 2, wherein, In order to assign one of the two trust categories, the processing circuit is further configured to: Assign the category of distrust to the inferred trust level.

5. The system according to claim 1, wherein, In order to assign one of the finite number of trust categories to the inferred trust level, the processing circuit is further configured to: Assign one of the four trust categories to the inferred trust level.

6. The system according to claim 1, wherein, In order to assign one of the finite number of trust categories to the inferred trust level, the processing circuit is further configured to: Assign trust categories for specific types of operations.

7. The system according to claim 6, wherein, The specific type of operation is a data transfer operation.

8. The system according to claim 6, wherein, The specific type of operation is a test operation.

9. The system according to any one of claims 1 to 8, wherein, The processing circuit is further configured as follows: Detect changes to the first trust level; and Based on the change in the first trust level, the inferred trust level of the first network device towards the third network device is adjusted.

10. The system according to claim 9, wherein, The processing circuit is further configured as follows: Based on the adjusted inferred trust level, one of the different trust categories from the finite number of trust categories is assigned to the adjusted inferred trust level; as well as The output is a user interface that uses one of the different trust categories from the finite number of trust categories to represent the updated inferred trust level.

11. The system according to any one of claims 1 to 8, wherein, The processing circuit is further configured as follows: Detect changes to the second trust level; Based on the change in the second trust level, the inferred trust level of the first network device towards the third network device is adjusted; Based on the adjusted inferred trust level, one of the different trust categories from the finite number of trust categories is assigned to the adjusted inferred trust level; as well as The output is a user interface that uses one of the different trust categories from the finite number of trust categories to represent the updated inferred trust level.

12. The system according to any one of claims 1 to 8, wherein, In order for the first network device to perform operations with the third network device, the processing circuit is further configured to: This enables data to be transmitted between the first network device and the third network device.

13. The system according to any one of claims 1 to 8, wherein, In order for the first network device to perform operations with the third network device, the processing circuit is further configured to: Enables the test operation to be executed.

14. A method for determining trust, comprising: The computing system determines the first trust level that the first network device has for the second network device; The computing system determines the second trust level that the second network device has for the third network device; The computing system determines that the first network device and the third network device are separated by the second network device; The computing system identifies the inferred trust level of the first network device to the third network device based on the first trust level and the second trust level. The computing system assigns one of a finite number of trust categories to the inferred trust level based on the inferred trust level; The computing system outputs a user interface that uses one of the assigned finite number of trust categories to represent the inferred trust level; as well as The computing system, based on the inferred trust level, enables the first network device to perform operations with the third network device.

15. The method according to claim 14, wherein, Assigning one of the finite number of trust categories to the inferred trust level includes: Assign one of the two trust categories to the inferred trust level.

16. The method according to claim 15, wherein, Assigning one of the two trust categories includes: Assign the category of trust to the inferred trust level.

17. The method according to claim 15, wherein, Assigning one of the two trust categories includes: Assign the category of distrust to the inferred trust level.

18. The method according to claim 14, wherein, Assigning one of the finite number of trust categories to the inferred trust level includes: Assign one of the four trust categories to the inferred trust level.

19. The method of claim 14, wherein, Assigning one of the finite number of trust categories to the inferred trust level includes: Assign trust categories for specific types of operations.

20. The method according to claim 19, wherein, The specific type of operation is a data transfer operation.

21. The method according to claim 19, wherein, The specific type of operation is a test operation.

22. The method according to any one of claims 14 to 21, further comprising: The change in the first trust level is detected by the computing system; as well as The computing system adjusts the inferred trust level of the first network device towards the third network device based on the change in the first trust level.

23. The method of claim 22, further comprising: The computing system assigns one of the finite number of trust categories to the adjusted inferred trust level based on the adjusted inferred trust level. as well as The computing system outputs an updated user interface that uses one of the finite number of trust categories to represent the adjusted inferred trust level.

24. The method according to any one of claims 14 to 21, further comprising: The change in the second trust level is detected by the computing system; The computing system adjusts the inferred trust level of the first network device towards the third network device based on the change in the second trust level. The computing system assigns one of the finite number of trust categories to the adjusted inferred trust level based on the adjusted inferred trust level. as well as The computing system outputs an updated user interface that uses one of the finite number of trust categories to represent the adjusted inferred trust level.

25. The method according to any one of claims 14 to 21, wherein, Enabling the first network device to perform operations with the third network device includes: This enables data to be transmitted between the first network device and the third network device.

26. The method according to any one of claims 14 to 21, wherein, Enabling the first network device to perform operations with the third network device includes: Enables the test operation to be executed.

27. A non-transitory computer-readable medium comprising instructions that, when executed, cause processing circuitry of a computing system to: Determine the first trust level that the first network device has for the second network device; Determine the second trust level that the second network device has for the third network device; It is determined that the first network device and the third network device are separated by the second network device; Based on the first trust level and the second trust level, identify the inferred trust level that the first network device has for the third network device; Based on the inferred trust level, one of a limited number of trust categories is assigned to the inferred trust level; The output uses one of the assigned finite number of trust categories to represent the inferred trust level in the user interface; as well as Based on the inferred trust level, the first network device is enabled to perform operations with the third network device.

28. The non-transitory computer-readable medium according to claim 27, wherein, The instruction that causes the processing circuit to assign one of the finite number of trust categories to the inferred trust level further includes: the instruction, when executed, causing the processing circuit to: Assign one of the two trust categories to the inferred trust level.

29. The non-transitory computer-readable medium according to claim 28, wherein, The instruction that causes the processing circuit to assign one of the two trust categories further includes, when executed, the instruction causing the processing circuit to: Assign the category of trust to the inferred trust level.

30. The non-transitory computer-readable medium according to claim 28, wherein, The instruction that causes the processing circuit to assign one of the two trust categories further includes, when executed, the instruction causing the processing circuit to: Assign the category of distrust to the inferred trust level.

31. The non-transitory computer-readable medium according to claim 27, wherein, The instruction that causes the processing circuit to assign one of the finite number of trust categories to the inferred trust level further includes: the instruction, when executed, causing the processing circuit to: Assign one of the four trust categories to the inferred trust level.

32. The non-transitory computer-readable medium according to claim 27, wherein, The instruction that causes the processing circuit to assign one of the finite number of trust categories to the inferred trust level further includes: the instruction, when executed, causing the processing circuit to: Assign trust categories for specific types of operations.

33. The non-transitory computer-readable medium according to claim 32, wherein, The specific type of operation is a data transfer operation.

34. The non-transitory computer-readable medium according to claim 32, wherein, The specific type of operation is a test operation.

35. The non-transitory computer-readable medium according to any one of claims 27 to 34, wherein, The instruction further causes the processing circuit to: Detect changes to the first trust level; and Based on the change in the first trust level, the inferred trust level of the first network device towards the third network device is adjusted.

36. The non-transitory computer-readable medium according to claim 35, wherein, The instruction further causes the processing circuit to: Based on the adjusted inferred trust level, one of the different trust categories from the finite number of trust categories is assigned to the adjusted inferred trust level; as well as The output is a user interface that uses one of the different trust categories from the finite number of trust categories to represent the updated inferred trust level.

37. The non-transitory computer-readable medium according to any one of claims 27 to 34, wherein, The instruction further causes the processing circuit to: Detect changes to the second trust level; Based on the change in the second trust level, the inferred trust level of the first network device towards the third network device is adjusted; Based on the adjusted inferred trust level, one of the different trust categories from the finite number of trust categories is assigned to the adjusted inferred trust level; as well as The output is a user interface that uses one of the different trust categories from the finite number of trust categories to represent the updated inferred trust level.

38. The non-transitory computer-readable medium according to any one of claims 27 to 34, wherein, The instructions that enable the processing circuit to perform operations on the first network device and the third network device further include: when the instructions are executed, the processing circuit: This enables data to be transmitted between the first network device and the third network device.

39. The non-transitory computer-readable medium according to any one of claims 27 to 34, wherein, The instructions that enable the processing circuit to perform operations on the first network device and the third network device further include: when the instructions are executed, the processing circuit: Enables the test operation to be executed.

Citation Information

Patent Citations

  • Trust scoring of network entities in networks

    US20220166788A1