Method, apparatus, and computer program (legitimizing trust in peer network using artificial intelligence)
Artificial intelligence-based trust scoring and bot nodes in peer networks address the vulnerability of new members by ensuring alignment with network objectives and preventing malicious activities.
Patent Information
- Application Number
- JP2025063351
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-26
- Filing Date
- 2025-04-07
- Publication Date
- 2025-11-07
AI Technical Summary
Existing peer networks lack the ability to prove trustworthiness of new members on a user-to-user basis, leaving them vulnerable to malicious actors who pass initial vetting processes.
Implementing artificial intelligence to calculate trust scores for untrusted nodes based on their activity within the network, restricting their participation until they demonstrate adherence to network goals, and using bot nodes to counter potential hijacking attempts.
Ensures that network activities align with objectives by promoting trustworthiness through activity monitoring and restricting participation of untrusted nodes, preventing malicious behavior and network takeover.
Smart Images

Figure 2025168267000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to methods, apparatus, and products for justifying trust in a peer network using artificial intelligence. Peer networks may be used in a variety of systems to enable multiple entities to engage in coordinated and / or distributed activities. Trust among members of a peer network is essential in ensuring that members of the peer network do not engage in activities that are contrary to the goals or objectives of the peer network. Various approaches address the vetting of new members to a peer network, but lack the ability to prove the trust of new members on a user-to-user basis. Summary of the Invention [Problem to be solved by the invention]
[0002] Various approaches address the vetting of new members to a peer network, but lack the ability to prove the trustworthiness of new members on a user-to-user basis. [Means for solving the problem]
[0003] According to embodiments of the present disclosure, various methods, apparatuses, and products are described herein for justifying trust in a peer network using artificial intelligence. In some aspects, justifying trust in a peer network using artificial intelligence comprises calculating, by a monitor, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the activity of the untrusted node in the peer network; and restricting the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted. This provides the advantage of using a monitor to ensure that activity in the peer network meets the goals and objectives of the peer network. In some aspects, an apparatus may comprise a processing device; and a memory operably coupled to the processing device, the memory storing computer program instructions that, when executed, cause the processing device to perform the method. In some aspects, a computer program product comprising a computer-readable storage medium may store computer program instructions that, when executed, perform the method.
[0004] In some aspects, the method may comprise designating the untrusted node as a trusted node in response to the trustworthiness score exceeding a threshold, thereby providing the advantage that previously untrusted nodes may be re-designated as trusted if their activity over time indicates adherence to peer network goals.
[0005] In some aspects, the method may comprise, in response to a request to add a node to the peer network, adding the node as an untrusted node, which provides the advantage of having a newly added node start out as an untrusted node, reducing the risk posed by a newly added node to a peer network.
[0006] In some aspects, the method may comprise adding a bot node to the peer network in response to the request to add the node to the peer network, thereby allowing voting activity for new, untrusted nodes to be countered by bots to prevent hijacking of voting activity by an influx of new nodes in the peer network.
[0007] In some aspects, calculating the trustworthiness score of the untrusted node comprises calculating the trustworthiness score of the untrusted node based on the trustworthiness of one or more other nodes with which the untrusted node has interacted, thereby providing the advantage of having a trustworthiness score that reflects not only the activity of a given node, but also the trustworthiness of those nodes with which the given node has interacted. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 illustrates an exemplary computing environment for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0009] [Figure 2] 1 is a flowchart of an example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0010] [Figure 3] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0011] [Figure 4] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0012] [Figure 5] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0013] [Figure 6] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0014] [Figure 7] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure.
[0015] [Figure 8] 1 is a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0016] Peer networks may be used in a variety of systems to enable multiple entities to engage in coordinated and / or distributed activities. Trust among members of a peer network is essential in ensuring that members of a peer network do not engage in activities that are contrary to the goals or objectives of the peer network. Various approaches address the vetting of new members to a peer network, but lack the ability to prove the trust of new members on a user-to-user basis. Moreover, these approaches do not address the activities or trustworthiness of members after they are admitted to the peer network, leaving such networks vulnerable to malicious actors who pass the initial vetting process.
[0017] 1, an exemplary computing environment according to aspects of the present disclosure is shown. Computing environment 100 includes an example environment for execution of at least some of the computer code involved in performing the various methods described herein, such as peer network module 107. In addition to block 107, computing environment 100 includes, for example, computer 101, wide area network (WAN) 102, end user device (EUD) 103, remote server 104, public cloud 105, and private cloud 106. In this embodiment, computer 101 includes a set of processors 110 (including processing circuitry 120 and cache 121), a communications fabric 111, volatile memory 112, persistent storage 113 (including operating system 122 and block 107 as identified above), a set of peripheral devices 114 (including a set of user interface (UI) devices 123, storage 124, and a set of Internet of Things (IoT) sensors 125), and a network module 115. The remote server 104 includes a remote database 130. The public cloud 105 includes a gateway 140, a cloud orchestration module 141, a set of host physical machines 142, a set of virtual machines 143, and a set of containers 144.
[0018] Computer 101 may take the form of a desktop computer, a laptop computer, a tablet computer, a smartphone, a smartwatch or other wearable computer, a mainframe computer, a quantum computer, or any other form of computer or mobile device now known or later developed that is capable of executing programs, accessing a network, or querying a database, such as remote database 130. As is well understood in the art of computer technology, and depending on the technology, execution of a computer-implemented method may be distributed among multiple computers and / or among multiple locations. While in this representation of computing environment 100, to keep the presentation as concise as possible, the detailed discussion focuses on a single computer, specifically computer 101. Although computer 101 is not depicted in the cloud of FIG. 1 , it may be located in a cloud. However, computer 101 is not required to reside within a cloud except to any extent that may be expressly indicated.
[0019] Processor set 110 includes one or more computer processors of any type now known or later developed. Processing circuitry 120 may be distributed across multiple packages, e.g., multiple coordinated integrated circuit chips. Processing circuitry 120 may implement multiple processor threads and / or multiple processor cores. Cache 121 is memory located within the processor chip package and is typically used for data or code that should be available for fast access by threads or cores executing on processor set 110. Cache memory is typically organized into multiple levels depending on relative proximity to the processing circuitry. Alternatively, some or all caches for a processor set may be located “off-chip.” In some computing environments, processor set 110 may be designed to operate with qubits and perform quantum computing.
[0020] Computer-readable program instructions are typically loaded onto computer 101 to cause processor set 110 of computer 101 to perform a series of operational steps, thereby realizing a computer-implemented method, whereby the instructions so executed instantiate the method specified in the computer-implemented method flowcharts and / or descriptions contained herein. These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 121 and other storage media discussed below. The program instructions and associated data are accessed by processor set 110 to control and direct the execution of the computer-implemented method. In computing environment 100, at least some of the instructions for executing the computer-implemented method may be stored in block 107 in persistent storage 113.
[0021] Communications fabric 111 is the signal-conducting pathway that allows various components of computer 101 to communicate with one another. Typically, this fabric is made up of switches and conductive pathways, such as those that make up buses, bridges, physical input / output ports, and the like. Other types of signal communication pathways may be used, such as fiber optic and / or wireless communication pathways.
[0022] Volatile memory 112 may be any type of volatile memory now known or later developed. Examples include dynamic type random access memory (RAM) or static type RAM. Typically, volatile memory 112 is characterized by random access, although this is not required unless expressly indicated. In computer 101, volatile memory 112 is located in a single package and is internal to computer 101; however, alternatively or additionally, volatile memory may be distributed across multiple packages and / or located external to computer 101.
[0023] Persistent storage 113 is any form of non-volatile storage for a computer, now known or later developed. The non-volatility of this storage means that stored data remains regardless of whether power is supplied to computer 101 and / or to persistent storage 113 directly. Persistent storage 113 may be read-only memory (ROM), but typically at least a portion of persistent storage allows data to be written, data to be deleted, and data to be rewritten. Some well-known forms of persistent storage include magnetic disks and solid-state storage devices. Operating system 122 may take several forms, such as various known proprietary operating systems or open-source Portable Operating System Interface-type operating systems that employ a kernel. The code included in block 107 typically includes at least a portion of the computer code involved in performing the computer-implemented methods described herein.
[0024] The peripheral device set 114 includes a set of peripheral devices of the computer 101. Data communication connections between the peripheral devices and other components of the computer 101 may be implemented in various ways, such as Bluetooth® connections, Near-Field Communication (NFC) connections, connections made by cable (such as a universal serial bus (USB)-type cable), insertion-type connections (e.g., a secure digital (SD) card), connections made over a local area communication network, and even connections made over a wide area network such as the Internet. In various embodiments, the UI device set 123 may include components such as a display screen, speakers, microphones, wearable devices (such as goggles and smartwatches), keyboards, mice, printers, touchpads, game controllers, and haptic devices. The storage 124 may be external storage, such as an external hard drive, or insertable storage, such as an SD card. The storage 124 may be persistent and / or volatile. In some embodiments, storage 124 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where computer 101 is required to have a large amount of storage (e.g., computer 101 stores and manages large databases locally), this storage may be provided by a peripheral storage device designed to store very large amounts of data, such as a storage area network (SAN) shared by multiple geographically distributed computers. IoT sensor set 125 consists of sensors that can be used in Internet of Things applications. For example, one sensor may be a thermometer and another sensor may be a motion detector.
[0025] Network module 115 is a collection of computer software, hardware, and firmware that enables computer 101 to communicate with other computers over WAN 102. Network module 115 may include hardware such as a modem or Wi-Fi® signal transceiver, software for packetizing and / or depacketizing data for communication network transmission, and / or web browser software for communicating data over the Internet. In some embodiments, the network control and network forwarding functions of network module 115 are performed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing software-defined networking (SDN)), the control and forwarding functions of network module 115 are performed on physically separate devices, such that the control function manages several different network hardware devices. Computer-readable program instructions for executing computer-implemented methods can typically be downloaded to computer 101 from an external computer or external storage device through a network adapter card or network interface included in network module 115.
[0026] WAN 102 is any wide area network (e.g., the Internet) capable of communicating computer data over non-local distances by any now known or later developed technology for communicating computer data. In some embodiments, WAN 102 may be replaced and / or supplemented by a local area network (LAN) designed to communicate data between devices located in a local area, such as a Wi-Fi network. WANs and / or LANs typically include copper transmission cables, optical fiber transmissions, wireless transmissions, and computer hardware such as routers, firewalls, switches, gateway computers, and edge servers.
[0027] End-user device (EUD) 103 is any computer system used and controlled by an end user (e.g., a customer of the enterprise operating computer 101) and may take any of the forms discussed above in connection with computer 101. EUD 103 typically receives useful and useful data from the operation of computer 101. For example, in the hypothetical case where computer 101 is designed to provide recommendations to the end user, the recommendations would typically be communicated from network module 115 of computer 101 over WAN 102 to EUD 103. In this manner, EUD 103 can display or otherwise present the recommendations to the end user. In some embodiments, EUD 103 may be a client device such as a thin client, a heavy client, a mainframe computer, a desktop computer, etc.
[0028] Remote server 104 is any computer system that provides at least some data and / or functionality to computer 101. Remote server 104 may be controlled and used by the same entity that operates computer 101. Remote server 104 represents a machine that collects and stores useful and useful data for use by other computers, such as computer 101. For example, in the hypothetical case where computer 101 is designed and programmed to provide recommendations based on historical data, then this historical data may be provided to computer 101 from remote database 130 of remote server 104.
[0029] Public cloud 105 is any computer system available for use by multiple entities that provides on-demand availability of computer system resources and / or other computer functionality, particularly data storage (cloud storage) and computing power, without direct active management by users. Cloud computing typically leverages resource sharing to achieve coherence and economies of scale. Direct active management of public cloud 105's computing resources is performed by computer hardware and / or software in cloud orchestration module 141. The computing resources provided by public cloud 105 are typically implemented by virtual computing environments (VCEs) running on various computers that comprise host physical machine set 142, the universe of physical computers in and / or available to public cloud 105. Virtual computing environments (VCEs) typically take the form of virtual machines from virtual machine set 143 and / or containers from container set 144. It is understood that these VCEs may be stored as images and can be transferred among and between various physical machine hosts, either as images or after instantiation of the VCEs. Cloud orchestration module 141 manages the transfer and storage of images, deploys new instantiations of VCE, and manages active instantiations of VCE deployments. Gateway 140 is a collection of computer software, hardware, and firmware that enables public cloud 105 to communicate over WAN 102.
[0030] Some further description of a virtualized computing environment (VCE) is now provided. A VCE can be stored as an "image." A new, active instance of a VCE can be instantiated from the image. Two well-known types of VCE are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature where the kernel allows for the existence of multiple isolated user space instances called containers. These isolated user space instances typically behave as actual computers from the perspective of programs running in them. A computer program running on a normal operating system can utilize all of the computer's resources, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, a program running inside a container can only use the contents of the container and of the devices assigned to the container; this feature is known as containerization.
[0031] A private cloud 106 is similar to a public cloud 105, except that the computing resources are available only for use by a single enterprise. While the private cloud 106 is shown as communicating with the WAN 102, in other embodiments, the private cloud may be completely disconnected from the Internet and accessible only through a local / private network. A hybrid cloud is a composite of multiple clouds of different types (e.g., private, community, or public cloud types), often each implemented by a different vendor. While each of the multiple clouds remains a separate, discrete entity, the larger hybrid cloud architecture is bound together by standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the constituent clouds. In this embodiment, both the public cloud 105 and the private cloud 106 are part of a larger hybrid cloud.
[0032] For further explanation, FIG. 2 sets forth a flowchart of an example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of FIG. 2 may be performed, for example, by the peer network module 107 of FIG. 1. The method of FIG. 2 includes calculating 202, by a watcher, a trust score for an untrusted node in a peer network including multiple nodes, where the trust score is based on the untrusted node's activity in the peer network. The peer network includes multiple intercommunicating entities (e.g., "nodes"), which may include one or more nodes that created or established the peer network (e.g., "ancestors") and, potentially, one or more nodes added after the creation of the peer network. An ancestor may have certain privileges that differ from other members of the peer network, including other trusted nodes described below. For example, an ancestor may have permission to add or remove nodes from the peer network. As another example, an ancestor may have permission to create mandates, update watchers, and the like. As a further example, an ancestor may have permission to modify the designation of a node as trusted or untrusted.
[0033] A peer network may include a variety of peer networks, as may be understood, including permissioned or open-ended peer networks. For example, in some embodiments, a peer network may include a distributed ledger technology (DLT) platform. As another example, in some embodiments, a peer network may include a network of nodes that control the operation of a mainframe or other computing system by proposing and voting for particular actions to be implemented in the mainframe or system. As a further example, in some embodiments, a peer network may include a network of developers or other users of a code repository, whereby users can submit actions to be performed on the code repository (e.g., pull requests or code commits), which may then be voted on for approval by other members of the peer network before being implemented. Other types of peer networks are also contemplated within the scope of this disclosure.
[0034] In particular, a peer network may include a network of nodes, whereby certain actions by and / or for a particular node may be voted on by member nodes. Member nodes of a peer network may include both trusted and untrusted nodes. In other words, each node in a peer network may be flagged as trusted or untrusted. As described in more detail below, participation in the peer network may be restricted for untrusted nodes until they are promoted to trusted status. Accordingly, a peer network may include a set of trusted nodes (e.g., a “syndicate”) that may trigger the creation of a watcher instance. A peer network may include a “consortium” that includes all trusted and untrusted nodes, including any bot nodes, which will be described in more detail below.
[0035] A guardian is a program executed by one or more of the nodes in a peer network that functions to maintain the goals or objectives of the peer network. A guardian may include, for example, a trained neural network, e.g., a feedforward neural network, another machine learning model, or another program or module as may be understood. In some embodiments, the specific algorithms used by the authority may be defined and / or agreed upon by ancestors as part of creating the peer network. To maintain the goals or objectives of the peer network, the guardian maintains one or more authorities that define these goals or objectives. In some embodiments, one or more authorities may include one or more rules, sets of actions, sequences of actions, and the like that are deemed permissible or impermissible by the guardian. As one example, one or more authorities may define a threshold amount of time after which a pull request may be approved or voted for approval. As another example, one or more authorities may define certain actions in a mainframe or computing system that are deemed disruptive and therefore may be subject to a vote before being implemented. As a further example, one or more authorities may define a voting threshold (e.g., other than a majority threshold), such as when implementing a DLT network. Other authorities are also contemplated within the scope of this disclosure.
[0036] In some embodiments, for example, when a watcher is implemented as a trained model, one or more authorities may be based on trends or other activity reflected in historical voting data. For example, in some embodiments, a watcher may be trained using historical voting data to identify optimal voting activity for a particular user that will meet the goals or objectives of the peer network. Accordingly, when an election takes place in the peer network, the watcher may be trained to generate votes for that election based on the historical voting data. Vote(s) generated by the watcher, which may or may not be included in the overall vote total for the election, may function as an authority. Thus, any vote that contradicts a watcher's vote may be deemed to contradict or violate that authority.
[0037] In some embodiments, the watcher may be executed by any node in the peer network. In some embodiments, instances of the watcher may be executed in the peer network by distributing and executing compiled binaries of the watcher to prevent tampering with the underlying code. In some embodiments, the compiled binaries may have a known checksum that is used to validate instances of the watcher in the peer network, further ensuring the integrity of the watcher. The reader will understand that in some embodiments, as the goals of the peer network change or operational demands change, the watcher may be updated (e.g., by updating the underlying algorithms and / or permissions) and distributed across the peer network as needed, thereby deprecating previous versions of the watcher.
[0038] As described above, the watcher calculates 202 trustworthiness scores for untrusted nodes in the peer network. The trustworthiness score for a given node in the peer network is a quantitative assessment of the extent to which the given node should be considered trusted or untrusted. In some embodiments, the trustworthiness score for a given node may be based on the voting patterns of the given node as reflected in the monitored activity of the given node. In other words, the trustworthiness score for an untrusted node may be calculated 202 as a function of the voting activity described in the activity of the untrusted node. For example, the trustworthiness score for a given node may be based on the extent to which the voting activity of the given node deviates from the voting activity of trusted nodes in the peer network. Thus, a node that tends to vote consistently with trusted nodes in the peer network may be assigned a higher trustworthiness score over time, while a node whose voting deviates from trusted nodes in the peer network may be assigned a lower trustworthiness score over time. The reader will understand that the trustworthiness score for a given node reflects some aggregation of activity in the peer network over time. Accordingly, the trustworthiness score for a given node may fluctuate over time as voting or other activity occurs. For example, in some embodiments, more recent activity may affect a given node's trustworthiness score more significantly than older activity, thereby causing the trustworthiness score to more accurately reflect the given node's current trustworthiness. As another example, the trustworthiness score for a given node may be based on a sliding time window of activity.
[0039] In some embodiments, the trustworthiness score for a given node may be calculated using activities other than, or in addition to, voting activity. For example, a given node's activity may be compared to one or more authorities enforced by a guardian. If a given node's activity violates or contradicts a given authority, this may result in a lower trustworthiness score for the given node. As another example, if a given node's activity complies with some authority, this may result in a higher trustworthiness score for the given node.
[0040] The monitor then calculates 202 a trustworthiness score for the untrusted node. In some embodiments, the monitor may calculate trustworthiness scores for multiple untrusted nodes, including the untrusted node. In some embodiments, the monitor may calculate a trustworthiness score for one or more of the trusted nodes. As described in more detail below, an untrusted node may be designated as a trusted node if its trustworthiness score exceeds some threshold.
[0041] The method of FIG. 2 also includes restricting 204 participation of an untrusted node in the peer network based on the untrusted node being flagged as untrusted. In some embodiments, the peer network may be restricted by an access control or regulatory system that may, for example, require a node to be trusted to perform some actions. In other words, participation in the peer network may differ between trusted and untrusted nodes. For example, in some embodiments, actions proposed or requested by an untrusted node may be automatically denied. As another example, the actions that may be proposed or requested by an untrusted node may be limited to a particular subset of actions. As described in more detail below, in some embodiments, votes of untrusted nodes may be automatically contested when voting is performed in the peer network. In other words, participation of an untrusted node in the peer network may be restricted by restricting the actions that may be requested or proposed by an untrusted node, restricting voting activity by an untrusted node, or a combination thereof.
[0042] The techniques described above enable a monitor, such as an artificial intelligence (AI)-enabled monitor, to enforce objectives in a peer network and prevent malicious or damaging activity that may be counter to the goals of the network. Additionally, the techniques described above provide activity restrictions for untrusted nodes, preventing potentially malicious nodes added to the network from damaging or taking over the peer network.
[0043] For further explanation, Figure 3 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 3 is similar to Figure 2 in that it also includes calculating 202, by a watchdog, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0044] The method of FIG. 3 differs from FIG. 2 in that the method of FIG. 3 also includes designating 302 an untrusted node as a trusted node in response to the trust score exceeding a threshold. In some embodiments, the threshold may be defined in one or more authorities of the watcher. In some embodiments, the threshold may be otherwise predefined. In some embodiments, the threshold may be dynamically calculated or variable based on the trust scores of each of the other nodes in the peer network. In some embodiments, an untrusted node may be designated as trusted in response to the trust score exceeding the threshold after some amount of time. In some embodiments, as described in more detail below, watcher instances and / or bot nodes added to the peer network in response to a previously untrusted node being added to the peer network may be removed once the previously untrusted node is designated as trusted.
[0045] By designating 302 an untrusted node as a trusted node, the untrusted node may be promoted to trusted if its voting and / or other activities are shown to be in harmony with other trusted nodes on the network. This prevents the untrusted node from fully participating in the peer network until it has proven itself trusted. Accordingly, after being designated 302 as untrusted, restrictions that previously applied to the untrusted node will no longer apply to the newly trusted node.
[0046] For further explanation, Figure 4 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 4 is similar to Figure 2 in that it also includes calculating 202, by a watchdog, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0047] The method of FIG. 4 differs from FIG. 2 in that the method of FIG. 4 also includes adding 402 a node as an untrusted node in response to a request to add the node to the peer network. Notably, in some embodiments, any newly added node to the peer network is automatically added as an untrusted node and is thereby subject to various activity restrictions. Moreover, in some embodiments, adding 402 a node as an untrusted node may include distributing and / or running watcher instances to monitor newly added untrusted nodes. This prevents a sudden influx of newly added nodes from damaging the peer network. As these newly added nodes prove themselves trustworthy over time due to their voting activity, they may subsequently be promoted to trusted nodes.
[0048] In some embodiments, a newly added, untrusted node may be assigned some default trust score. In such embodiments, this default trust score may be modified as the untrusted node's activities occur in the peer network. Thus, the trust score may be periodically updated until it reaches some threshold (e.g., higher than the default trust score) so that the newly added node can be designated a trusted node.
[0049] For further explanation, Figure 5 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 5 is similar to Figure 4 in that the method of Figure 5 also includes adding 402 a node as an untrusted node in response to a request to add the node to the peer network; calculating 202 a trust score for an untrusted node of a peer network including multiple nodes by a watchdog, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0050] The method of FIG. 5 differs from FIG. 4 in that the method of FIG. 5 also includes adding 502 a bot node to the peer network in response to a request to add the node to the peer network. In other words, in some embodiments, for each newly added untrusted node, a corresponding bot node may be executed. A bot node is a node that may participate in the peer network, but whose actions are automatically controlled or defined. For example, in some embodiments, restricting 204 an untrusted node of a plurality of nodes from participating in the peer network based on the untrusted node being flagged as untrusted may include countering 504, by the bot node, voting activity performed by the untrusted node.
[0051] In some embodiments, if an untrusted node requests or proposes an action in the peer network, countering 504 the voting activity performed by the untrusted node may include automatically voting against the proposed action. In some embodiments, if an untrusted node issues a vote in an election in the peer network, countering 504 the voting activity performed by the untrusted node may include automatically casting a vote against the vote of the untrusted node, effectively canceling the vote of the untrusted node. In some embodiments, if a given untrusted node is subsequently designated as trusted, the corresponding bot node may be removed from the peer network.
[0052] The techniques described above particularly address concerns related to attacks that may be enabled by a sudden influx of a large number of cooperative, untrusted nodes in a network, especially cooperative nodes. In some existing peer networks, a sufficiently large influx of newly added nodes into the peer network can capture a majority of the votes in the peer network, effectively allowing these newly added nodes to seize control of the peer network (e.g., in a 51 percent attack). Here, each of these newly added nodes will be added to the peer network as an untrusted node along with a corresponding bot node. Even if these newly added nodes constitute more than 50 percent of the total non-bot nodes and decide to vote cooperatively, they will not achieve a majority of the votes on their own due to their votes being cancelled out by the newly added bot nodes.
[0053] For further explanation, Figure 6 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 6 is similar to Figure 2 in that it also includes calculating 202, by a watchdog, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0054] The method of FIG. 6 differs from FIG. 2 in that calculating 202, by the watcher, a trustworthiness score for an untrusted node based on the activity of the untrusted node in the peer network also includes calculating 602, by the watcher, a trustworthiness score for the untrusted node based on the trustworthiness of one or more other nodes with which the untrusted node has interacted. A given node may be considered to have interacted with another node, where both nodes are involved in the same action or activity. As an example, in the context of a code repository, if a given node issues a pull request and another node approves the pull request, the nodes may be considered to have interacted. As another example, if a given node creates some task to be completed and another node accepts the task for completion, the nodes may be considered to have interacted. Various interactions between nodes may be embodied as a graph or “approval tree,” which may be directed, undirected, cyclic, or acyclic.
[0055] In this example, the trustworthiness score of a given node (e.g., an untrusted node) may be affected by the trustworthiness of another node when they interact. As an example, assuming a given node interacts with another node, in some embodiments, the trustworthiness score of the given node may be calculated as a function of the trustworthiness score of the other node. As another example, the trustworthiness score of a given node may be calculated as a function of whether the other node is flagged as a trusted node or an untrusted node.
[0056] In some embodiments, the trustworthiness score of a given node may be based on the degree to which the given node interacts with another node. For example, if a given node has a high degree of interaction with an untrusted node, this may have a more negative impact on the trustworthiness score of the given node compared to having a low degree of interaction. As another example, if a given node has a low degree of interaction with a trusted node, this may have a less positive impact on the trustworthiness score of the given node compared to having a high degree of interaction.
[0057] The techniques described herein allow the activities of associated nodes to affect the trustworthiness of associated nodes. For example, suppose a given node has low trustworthiness due to a history of submitting poor-quality code to a code base. Furthermore, suppose another node has repeatedly approved that code from the given node. Although the other node has not itself submitted poor-quality code, its trustworthiness score may be negatively affected due to its approval.
[0058] For further explanation, Figure 7 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 7 is similar to Figure 2 in that it also includes calculating 202, by a watchdog, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0059] The method of Figure 7 differs from Figure 2 in that the method of Figure 7 also includes generating 702 an alert in response to detecting, by a watcher, a consensus of activity in the peer network that is inconsistent with one or more authorities. In some embodiments, the consensus may include votes from a consortium of peer networks that are inconsistent with one or more authorities. For example, in some embodiments, the consensus may include votes approving some action that violates rules defined in one or more authorities.
[0060] In some embodiments, if the watcher is a trained model, such trained model may be trained using historical voting activity. Accordingly, the authority may include the vote determined by the watcher for a given election. Such vote reflects the goals and objectives of the peer network as determined by the watcher. Accordingly, if the consortium votes inconsistently with the vote determined by the watcher, this may be considered a conflict of authority.
[0061] In some embodiments, the alert may include a notification or message sent to one or more members of the peer network. As one example, the alert may be sent to an ancestor of the peer network, a syndicate (e.g., a trusted node) of the peer network, or other members of the peer network as may be understood. This may be used for a variety of purposes. For example, it may serve to indicate to members of the peer network that the monitor may not accurately reflect the current objectives and goals of the peer network and may need to be updated. As another example, it may serve only to notify those members that an action has been taken inconsistently with the authority of the monitor. The alert may also facilitate or initiate other actions as may be understood.
[0062] For further explanation, Figure 8 sets forth a flowchart of another example method for justifying trust in a peer network using artificial intelligence, according to some embodiments of the present disclosure. The method of Figure 8 is similar to Figure 2 in that it also includes calculating 202, by a watchdog, a trust score for an untrusted node of a peer network including a plurality of nodes, where the trust score is based on the untrusted node's activity in the peer network; and restricting 204 the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted by the watchdog.
[0063] The method of Figure 8 differs from Figure 2 in that the method of Figure 8 also includes detecting 802 drift in the activity of trusted nodes of the peer network from a consensus of activity in the peer network over time. Drift in the activity of trusted nodes indicates a tendency for voting activity by the trusted nodes to deviate from the consensus reached by the syndicate (e.g., the trusted nodes) and / or the peer network as a whole. For example, a trusted node may repeatedly vote inconsistently with other trusted nodes in the syndicate over time. Drift may be detected 802 when the voting trend for a trusted node deviates by some amount (e.g., having a deviation exceeding some threshold).
[0064] Various remedial actions may be taken in response to detecting 802 a drift in the activity of a trusted node. For example, in some embodiments, bots may be deployed to counter the voting activity of the trusted node or further monitor and / or restrict the activity of the trusted node. As another example, in some embodiments, a notification indicating that the activity of the trusted node has drifted may be sent to ancestors of the peer network, and it is up to the ancestors how to handle the trusted node. In some embodiments, a trustworthiness score may be calculated or recalculated for a trusted node that, if it falls below some threshold, may cause the trusted node to be designated as an untrusted node and / or removed from the peer network altogether.
[0065] The techniques described above protect the peer network from trusted nodes that may shift their activity to a state that is inconsistent with the peer network, thereby preventing attacks against the peer network, for example, by gaining status as a trusted node and abusing that status to perform potentially malicious activity.
[0066] Various aspects of the present disclosure are described through text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in computer program product (CPP) embodiments. For any flowchart, depending on the technology involved, operations may be performed in an order different from that shown in a given flowchart. For example, again depending on the technology involved, two operations shown in successive flowchart blocks may be performed in reverse order, as a single integrated step, simultaneously, or in an at least partially overlapping manner.
[0067] A computer program product embodiment ("CPP embodiment" or "CPP") is a term used in this disclosure to describe any set of one or more storage media (also referred to as "media") collectively included in a set of one or more storage devices that collectively contain machine-readable code corresponding to instructions and / or data for performing the computer operations specified in a given CPP claim. A "storage device" is any tangible device that can hold and store instructions for use by a computer processor. The computer-readable storage medium may be, but is not limited to, an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these media include diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded devices (such as punch cards or pits / lands formed on a major surface of a disk), or any suitable combination of the foregoing. Computer-readable storage media, as the term is used in this disclosure, is not to be construed as storage in the form of a transitory signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, light pulses passing through fiber optic cables, electrical signals communicated through wires, and / or other transmission media.As will be appreciated by those skilled in the art, data is typically moved at some infrequent time during the normal operation of a storage device, such as during access, defragmentation, or garbage collection, but the above does not make the storage device temporary, as the data is not temporary while it is stored.
[0068] The description of various embodiments of the present disclosure has been presented for illustrative purposes, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been selected to best explain the principles, practical applications, or technical improvements of the embodiments over technologies found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. calculating, by a watcher, a trustworthiness score for an untrusted node of a peer network including a plurality of nodes, wherein the trustworthiness score is based on the activity of the untrusted node in the peer network; and restricting the untrusted node from participating in the peer network based on the untrusted node being flagged as untrusted. A method comprising:
2. The method of claim 1 , wherein the trustworthiness score is further based on one or more authorities of the peer network.
3. The method of claim 1 or 2, further comprising designating the untrusted node as a trusted node in response to the reliability score exceeding a threshold.
4. The method of claim 1 or 2, further comprising adding a node as the untrusted node in response to a request to add the node to the peer network.
5. The method of claim 4 , further comprising adding a bot node to the peer network in response to the request to add the node to the peer network.
6. 6. The method of claim 5, wherein restricting participation of the untrusted nodes in the peer network comprises countering voting activity performed by the untrusted nodes by the bot nodes.
7. 3. The method of claim 1, wherein the trustworthiness score of the untrusted node is based at least on the degree of deviation between the activity and other activities performed by trusted nodes in the peer network.
8. 3. The method of claim 1, wherein calculating the trustworthiness score of the untrusted node comprises calculating the trustworthiness score of the untrusted node based on the trustworthiness of one or more other nodes with which the untrusted node has interacted.
9. 3. The method of claim 1 or 2, further comprising generating an alert in response to detecting, by the monitor, a consensus of activity in the peer network that is inconsistent with one or more authorities of the peer network.
10. The method of claim 1 or 2, further comprising detecting drift of activity of trusted nodes of the peer network from a consensus of activity in the peer network over time.
11. a processing device; and a memory operatively coupled to the processing device; the memory, when executed, causes the processing device to calculating, by a watcher, a trustworthiness score for an untrusted node in a peer network including a plurality of nodes, wherein the trustworthiness score is based on the activity of the untrusted node in the peer network; and restricting participation of the untrusted node in the peer network based on the untrusted node being flagged as untrusted. A device that stores computer program instructions that cause the device to perform the following:
12. The apparatus of claim 11 , wherein the trustworthiness score is further based on one or more authorities of the peer network.
13. 13. The apparatus of claim 11 or 12, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure of designating the untrusted node as a trusted node in response to the reliability score exceeding a threshold.
14. 13. The apparatus of claim 11 or 12, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure of adding a node as the untrusted node in response to a request to add the node to the peer network.
15. 15. The apparatus of claim 14, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure of adding a bot node to the peer network in response to the request to add the node to the peer network.
16. 16. The apparatus of claim 15, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure for countering, by the bot node, voting activity performed by the untrusted node, to restrict participation in the peer network by the untrusted node.
17. 13. The apparatus of claim 11 or 12, wherein the trustworthiness score of the untrusted node is based at least on the degree of deviation between the activity and other activities performed by trusted nodes in the peer network.
18. 13. The apparatus of claim 11 or 12, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure for calculating the trustworthiness score of the untrusted node based on the trustworthiness of one or more other nodes with which the untrusted node has interacted, in order to calculate the trustworthiness score of the untrusted node.
19. 13. The apparatus of claim 11 or 12, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure of generating an alert in response to detecting, by the monitor, a consensus of activity in the peer network that is inconsistent with one or more authorities of the peer network.
20. 13. The apparatus of claim 11 or 12, wherein the computer program instructions, when executed, further cause the processing device to perform a procedure of detecting drift of activity of trusted nodes of the peer network from a consensus of activity in the peer network over time.
21. On the computer, calculating, by a watcher, a trustworthiness score for an untrusted node in a peer network including a plurality of nodes, wherein the trustworthiness score is based on the activity of the untrusted node in the peer network; and restricting participation of the untrusted node in the peer network based on the untrusted node being flagged as untrusted. A computer program for executing
22. 22. The computer program product of claim 21, wherein the trustworthiness score is further based on one or more authorities of the peer network.
23. The computer, designating the untrusted node as a trusted node in response to the trust score exceeding a threshold.
23. A computer program according to claim 21 or 22, further comprising:
24. The computer, adding a node as the untrusted node in response to a request to add the node to the peer network.
23. A computer program according to claim 21 or 22, further comprising:
25. The computer, adding a bot node to the peer network in response to the request to add the node to the peer network.
25. The computer program of claim 24, further comprising: