System and method of decentralized trust verification of network nodes

The decentralized trust verification system addresses latency and failure points in centralized systems by using PUF-generated tokens and collective trust scoring to ensure secure and transparent network operations.

WO2026032508A1PCT designated stage Publication Date: 2026-02-12SIEMENS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/072518
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-08
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Centralized trust management systems in computer networks suffer from latency issues in updating trust scores, are prone to single points of failure, and compromise network security and robustness.

Method used

A decentralized trust verification system where nodes in a computer network, such as IoT networks, request tokens from a root-of-trust device using PUFs, determine trust scores based on multiple node interactions, and maintain a trust table using Bayesian inference and consensus algorithms to validate node authenticity and integrity.

Benefits of technology

Enhances network security and reliability by reducing latency, eliminating single points of failure, and promoting transparency and fairness through collective trust management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024072518_12022026_PF_FP_ABST
    Figure EP2024072518_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method and system for decentralized trust verification in a computer network (106) comprising a plurality of nodes (102A-N). The method involves obtaining a token from a root-of-trust device (104) for a first node (102A), determining trust scores for at least a second node (102B) and third node (102C), and obtaining additional trust scores from other nodes within the network (102A-N). These trust scores are used to generate a trust table, which is then broadcasted to the plurality of nodes (102A-N). The trust table is validated and used to verify at least a fourth node (102D) through the application of consensus algorithms. The system includes a root-of-trust device (104) and a first node (102A) equipped with a processing unit (202) capable of performing the aforementioned steps.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD OF DECENTRALIZED TRUST VERIFICATION OF NETWORK NODES

[0002] DESCRIPTION

[0003] The present invention relates generally to the field of computer network security, and more specifically, to methods and systems for decentralized trust verification in a computer network comprising a plurality of nodes.

[0004] In modern computer networks, trust management is a critical component for ensuring secure communication and interaction among nodes. Traditional trust management systems predominantly rely on a centrahzed verifier to assess and propagate trust scores or credentials. While centralized systems provide a straightforward approach to trust management, they come with several significant drawbacks.

[0005] One of the primary issues with centralized trust management systems is the inherent delay associated with the propagation of trust-related updates. In a centralized model, all trust-related data must be sent to a central verifier, processed, and then redistributed to the relevant nodes in the network. This process can introduce significant latency, especially in large-scale or highly dynamic networks where trust scores need to be frequently updated and disseminated.

[0006] Furthermore, the centralized nature of these systems creates a single point of failure. If the central verifier becomes compromised or unavailable due to network issues or malicious attacks, the entire trust management system can become unreliable or non-functional. This poses a significant risk to the overall security and robustness of the network.

[0007] Further limitations and disadvantages of conventional and traditional approaches will become apparent to one of skill in the art, through comparison of described systems with some aspects of the present disclosure, as set forth in the remainder of the present application and with reference to the drawings. In light of the above, there is a need for a method and system for decentralized trust verification of network nodes in a computer network.

[0008] Therefore, it is an object of the present disclosure to provide a system and method of decentralized trust verification of network nodes as substantially as shown in, and / or described in connection with, at least one of the figures, as set forth more completely in the claims. This object is solved by a system and method of decentralized trust verification of network nodes.

[0009] The object of the present disclosure is achieved through a system and method of decentralized trust verification of network nodes.

[0010] The object of the present disclosure is achieved through a method for decentralized trust verification in a computer network. The computer network comprises a plurality of nodes. The method is executed in a first node of the plurality of nodes. The plurality of nodes is a plurality of interconnected devices that share resources and communicate with each other using either wired or wireless technologies. In one example, the computer network is an Internet of Things (loT) network configured to streamline production processes in an industrial plant. The loT networks include devices such as sensors that monitor machine health, actuators that control robotic arms, and controllers that manage assembly lines. In this scenario, a node is any device that can send, receive, or forward information within the computer network. Examples of the plurality of nodes include industrial computers that manage data analytics, mobile devices like tablets used by technicians for remote monitoring, and specialized devices such as pressure sensors and robotic actuators. In one example, the plurality of nodes are sensors which collect real-time data on machine performance while one or more nodes are actuators which execute precise tasks based on automated commands.

[0011] The method comprises requesting, by a first node of the plurality of nodes, a token from a root-of-trust device. The root-of-trust device typically comprises a dedicated hardware module, which is configured to generate a trust token for the plurality of nodes in the computer network. The trust token is a cryptographic entity used to establish and verify an identity and integrity of each node of the plurality of nodes within the computer network. In one example, the trust token is a digital certificate or credential that authenticates each node of the plurality of nodes. The trust token ensures that a node is a legitimate and trusted participant in the computer network. The trust token ensures that each node is uniquely and securely identified within the computer network. The trust token is generated by use of a physically unclonable function (PUF). The physically unclonable function leverages inherent physical variations in a manufacturing process of the root-of-trust device to create a unique cryptographic key which cannot be duplicated or cloned.

[0012] The method further comprises obtaining, by the first node, the token from the root-of-trust device. The first node further receives a plurality of trust parameters from the root-of-trust device. The plurality of trust parameters comprises information related to security policies, authentication credentials, encryption keys, and integrity verification measures. The plurality of trust parameters is utilized by the first node to establish a secure communication channel with other nodes in the network. By leveraging the plurality of trust parameters, the first node is enabled to validate an authenticity of other nodes of the plurality of nodes, ensure data integrity, and protect against potential security threats. Advantageously an overall reliability and security of the computer network is enhanced, enabling secure data exchange and collaboration among interconnected nodes of the plurality of nodes.

[0013] The plurality of trust parameters provides comprehensive information about the token. The plurality of trust parameters comprises a validity parameter associated with the token, a current Trust Level (TL) of the computer network, and a Trust Information (delta-Trustlnfo) associated with the computer network. The validity parameter associated with the token includes information about a lifespan of the token. The information about the lifespan of the token comprises at least an issuance date and an expiration date. The information in the validation parameter ensures that outdated or potentially compromised tokens are not used to authenticate devices within the computer network. For instance, in a smart home network, a smart thermostat receives a trust token with a validity parameter indicating that the trust token is valid for one year from a date of issuance of the trust token. The validity parameter ensures that after one year, the smart thermostat has to renew the trust token to continue participating in the computer network securely.

[0014] The validity parameter further comprises metadata associated with the trust token such as an identifier of the first node, a type of device of the first node, and one or more cryptographic algorithms used in generating the token. The current Trust Level (TL) of the computer network is a parameter which reflects an overall security posture and integrity of the computer network at any given time. In one example, the current trust level is measured as a number between 1 and 9. The current trust level of the computer network, is a dynamic parameter which changes based on real-time assessments of a security status of the computer network.

[0015] The Trust Information, often referred to as delta-Trustlnfo, provides granular details about any changes or updates to a trust status of the plurality of nodes within the computer network. The trust information includes recent trust events, such as issuance or revocation of trust tokens, changes in device status, or detected security incidents. For instance, in a factory automation system, the delta-Trustlnfo might indicate that a new robotic arm has been added to the computer network and has successfully authenticated itself, or that a sensor has been temporarily removed from the computer network due to suspicious activity. The trust information allows the plurality of nodes and a central control system to maintain a robust and adaptive security posture.

[0016] The method further comprises determining, by the first node, a trust score for at least a second and a third node within the computer network. The trust score is a numerical representation of reliability, credibility, and trustworthiness of at least the second node and the third node within the computer network. The trust score associated with a node, is calculated based on a plurality of trust indicators, including a past behavior of the node, a quality of interactions of the node with other nodes in the plurality of nodes, and any available security credentials or certifications possessed by the node. The plurality of trust indicators are specific metrics or criteria used to evaluate and quantify a trustworthiness of a node within the computer network. A collective assessment of the plurality of trust indicators contributes to an overall trust score assigned to the node, which reflects a reliability and a credibility of the node within the network.

[0017] For example, to determine the trust score, the first node first gathers data from interactions of the first node with at least the second node and third nodes, as well as from experiences and reports of other nodes of the plurality of nodes. The first node further applies one or more algorithms which are configured to analyze patterns, detect anomalies, on the plurality of trust indicators. Examples of the one or more algorithms include a Bayesian inference algorithm, which updates trust scores based on new interactions and feedback; an EigenTrust algorithm, which aggregates local trust values into a global trust score; a fuzzy logic systems based algorithm, which handle uncertainty and combine multiple trust indicators into a single score; and machine learning algorithms like Random Forest and Support Vector Machines, which predict trust scores based on historical data and learned patterns. The determined trust score helps the first node decide whether to engage in transactions or share sensitive information with at least the second and third nodes, thereby enhancing the overall security and efficiency of the computer network.

[0018] The method further comprises obtaining, by the first node, a plurality of trust scores from at least the second node and the third node of the computer network. The received plurality of trust scores comprises one or more trust scores which are determined by at least the second node and the third node, for a fourth node of the plurality of nodes. The one or more trust scores are indicative of a trust evaluated for the fourth node by at least the second node and the third node. The second node and the third node determine the one or more trust scores based on interaction of the second node and the third node, with the fourth node. So, in other words, the method comprises obtaining, by the first node, the one or more trust scores from at least the second node and the third node.

[0019] Obtaining the one or more trust scores from at least the second node and the third node provides several advantages to the first node. By collecting trust evaluations from multiple sources, the first node is enabled to cross-verify a reliability and a trustworthiness of the fourth node. The cross -verification process enhances an accuracy of a trust assessment, as the cross -verification process mitigates a risk of biased or erroneous evaluations from individual nodes. Additionally, aggregation of trust scores from diverse nodes helps the first node to build a more comprehensive and nuanced understanding of a behavior of the fourth node and interactions within the computer network. The cross -verification process enables the first node to make informed decisions about engaging in transactions or sharing sensitive information with the fourth node, thereby enhancing an overall security and efficiency of the computer network. By leveraging a collective intelligence of the computer network, the first node is enabled to identify patterns and detect anomalies that might indicate potential security threats, ensuring a robust and adaptive trust management system.

[0020] In one example, the plurality of trust scores is collected from the plurality of nodes, where each node of the plurality of nodes contributes its evaluation of other nodes based on interactions and experiences of the node with other nodes. Advantageously, by aggregating the plurality of trust scores, the first node is enabled to mitigate influence of any biased or malicious evaluations, leading to a more accurate and reliable trust determination.

[0021] The method further comprises obtaining, by the first node, a plurality of tokens from at least the second node and the third node. The obtained plurality of tokens comprises the one or more tokens which are received by the second node and the third node, from the root-of-trust device. Each token in the one or more tokens is originally received from the root-of-trust device by at least the second node and the third node.

[0022] Receiving the one or more tokens from at least the second node and the third node offers several advantages to the first node. By obtaining the tokens, the first node can validate an authenticity and trustworthiness of the second node and the third node, as each token serves as a certified credential issued by the root-of- trust device. This validation process enhances the overall security of the computer network by ensuring that only legitimate nodes participate in network activities. The first node can also cross-reference the received tokens with the trust scores, thereby corroborating the trust assessments provided by the second node and the third node. A risk of accepting trust evaluations from compromised or malicious nodes is thus, reduced, leading to more reliable and accurate trust determinations .

[0023] Furthermore, receipt of the one or more tokens allows the first node to build a comprehensive trust table that includes verified credentials and trust scores for various nodes within the computer network. By maintaining a repository of authenticated tokens, the first node can quickly and efficiently assess trustworthiness of other nodes, facilitating secure and seamless interactions within the network. The presence of tokens also enables the first node to detect any discrepancies or anomalies in the trust data, prompting timely corrective actions to maintain network integrity.

[0024] In one example, the first node is configured to receive the plurality of tokens from at least one node of the plurality of nodes. Each token in the plurality of tokens is originally received from the root-of-trust device by a specific node within the computer network and is uniquely associated with that particular node. Thus, each node in the computer network has a specific token issued by the root-of- trust device, serving as a certified credential that verifies authenticity and trustworthiness of the specific node. By collecting the plurality of tokens, the first node can gather evidence of trustworthiness from multiple nodes across the computer network, thereby enhancing robustness and reliability of the decentralized trust verification process. The plurality of tokens enables the first node to cross-reference and validate the trust scores and trust relationships among different nodes, contributing to the overall security and integrity of the computer network.

[0025] For example, if a node, of the plurality of nodes, consistently provides inflated trust scores due to collusion or error, then an impact of the node is diluted by more numerous and diverse evaluations from other nodes of the plurality of nodes. Thus, a risk of single points of failure is reduced. Furthermore, a robustness of a trust evaluation process of the first node is increased. Additionally, the first node benefits from leveraging a collective intelligence of the computer network, as different nodes have access to different subsets of information, leading to a richer and more complete dataset for the trust evaluation process. Furthermore, an aggregation of trust scores from the plurality of nodes allows the first node to detect and respond to anomalies more effectively. For example, if a drop in trust scores from the plurality of nodes, is indicative of a potential security threat or mahcious behavior, hence enabling the first node to intervene timely. Advantageously, the trust evaluation mechanism not only enhances security but also promotes fairness and transparency within the computer network.

[0026] The method further comprises generating, in the first node, a trust table comprising at least one trust score associated with the fourth node of the plurality of nodes. The at least one trust score is an indicator of an amount of trust that the first node has, towards the fourth node. The trust table is generated based on the trust score determined for at least the second node and the third node and the plurality of trust scores obtained from at least the second node and the third node, and further based on the one or more tokens received from at least the second node and the third node.

[0027] Thus, the at least one trust score is determined without having to use any token which is provided by the fourth node. Determining the at least one trust score without receiving any tokens from the fourth node offers several advantages. Firstly, this approach allows the first node to evaluate the trustworthiness of the fourth node based on observations and interactions from other nodes in the network, rather than relying on potentially biased or fraudulent tokens that the fourth node might provide. This external validation ensures a more objective and accurate assessment of the fourth node's behavior and reliability.

[0028] Using the trust score determined for at least the second node and the third node, along with the one or more trust scores obtained from at least the second node and the third node, and further based on the one or more tokens received from at least the second node and the third node, causes better trust evaluation for the fourth node in several ways. By incorporating multiple trust scores and tokens into the trust table, the first node ensures a more comprehensive and holistic assessment of the fourth node’s trustworthiness. Integration of trust scores from different nodes provides a balanced perspective on the fourth node's behavior and reliability within the network.

[0029] Additionally, inclusion of the one or more tokens received from the root-of-trust device adds a layer of authentication to the one or more trust scores. The one or more tokens serve as verified credentials that confirm a legitimacy of trust evaluations of at least the second node and the third node, thereby increasing an accuracy and a reliability of the fourth node. By cross-referencing the one or more trust scores with the one or more tokens, the first node is enabled to validate a credibility of trust data, ensuring that evaluations are based on secure and verified information.

[0030] The method also allows the first node to detect and address any anomalies or inconsistencies in the trust data. By continuously updating and monitoring the trust table, the first node can identify patterns or trends that may indicate potential security threats or changes in the behavior of the fourth node. Thus, trust management enhances an overall security and integrity of the computer network, ensuring that only trustworthy nodes are allowed to participate.

[0031] The trust table is a structured data repository that stores trust scores for various nodes within the computer network. The trust table functions as a reference guide for the first node, allowing the first node to quickly access and evaluate trustworthiness of other nodes. Each node of the plurality of nodes has a specific trust table stored within the node.

[0032] In one example, to generate the trust table, the first node processes both the trust score determined by the first node and the plurality of trust scores obtained by the first node from the plurality of nodes. The plurality of trust scores is then organized into a tabular format, where each row corresponds to a node of the plurality of nodes and each column contains relevant trust metrics, such as a trust score, historical interactions, and any anomalies detected. The trust table is periodically updated to reflect the latest trust scores and to incorporate new nodes as they join the network. In one example, the trust table is generated by application of one or more trust evaluation algorithms to the trust score determined by the first node, the one or more trust scores and the one or more tokens. The one or more trust evaluation algorithms may be machine learning algorithms such as a Bayesian inference algorithm, an eigen trust algorithm, a fuzzy logic system-based algorithm, or machine learning algorithms like random forest and support vector machine based algorithms. The Bayesian Inference algorithm is configured to update trust scores periodically based on new interactions and evidence. The EigenTrust Algorithm aggregates local trust values into a global score, reflecting a consensus view and mitigating the influence of malicious nodes. Fuzzy Logic Systems combine multiple trust indicators into a single score, accommodating uncertainty and providing nuanced evaluations. Machine learning models like Random Forest and Support Vector Machines predict trust scores based on historical data and learned patterns. These models adapt and improve over time, providing robust trust assessments. By applying these algorithms, the first node generates a reliable trust table that serves as a central repository for trust information. This enables informed decision-making, enhances network security, and promotes transparency and cooperation among nodes.

[0033] One of the primary advantages of generating the trust table is an ability to efficiently manage and reference trust information. By maintaining a decentralized repository of trust scores, the first node can make rapid and informed decisions regarding which nodes to interact with and to what extent. Thus, the decentralized repository of trust scores is particularly useful in large networks where manually assessing the trustworthiness of every node would be impractical and time-consuming.

[0034] Another advantage of the trust table is in enhancing security and reliability within the computer network. By aggregating trust scores from multiple sources and continuously updating the table, the first node can detect patterns and trends that may indicate potential threats or changes in node behavior. For instance, if a previously trustworthy node begins to receive lower trust scores from multiple sources, this can serve as an early warning signal for possible compromised security. Additionally, the trust table supports transparency and accountability within the computer network. Nodes can periodically review and audit the trust scores recorded in the trust table, ensuring that trust evaluation process remains fair and unbiased. Thus, the transparency builds confidence among the plurality of nodes, fostering a cooperative and secure network environment.

[0035] The method further comprises broadcasting the generated token and the generated trust table to the plurality of nodes. By broadcasting the generated token and the generated trust table, all nodes in the computer network receive the same information, promoting consistency and transparency across the computer network. By distributing the generated token and trust table, each node in the network is equipped with the necessary data to assess the trustworthiness of other nodes, including the first node.

[0036] Each of the plurality of nodes stores one or more trust tables that are updated based on the received token and the received trust table. A continuous updating ensures that the trust data remains current and accurate, reflecting the latest trust assessments from across the network. The decentralized approach is implemented through this mechanism, enabling each node to contribute to the collective trust verification process.

[0037] Broadcasting the generated token and the generated trust table enhances the overall security and reliability of the network. Each node independently verifies the authenticity and trustworthiness of other nodes, thereby reducing the risk of single points of failure. The decentralized approach also mitigates the influence of biased or erroneous evaluations by relying on a diverse set of observations from multiple nodes.

[0038] Similarly, the first node receives a set of tokens and a set of trust tables from all other nodes periodically. The periodic reception ensures that the first node is continuously informed about latest trust evaluations and cryptographic validations conducted by other nodes in the computer network. Upon receiving the set of tokens and the set of trust tables, the first node updates the generated trust table accordingly. By integrating the newly received data, the trust table becomes a comprehensive and up-to-date repository of trust scores and cryptographic tokens. Thus, the trust evaluations are reflective of most current state of the computer network.

[0039] A decentralized approach is reinforced through this mechanism, as the trust data is continuously aggregated and vahdated by multiple nodes. This collective updating process distributes the responsibility of trust verification across the network, preventing any single node from having undue influence or becoming a point of failure. Each node's periodic contribution to the trust data ensures a balanced and diversified evaluation, enhancing the robustness and reliability of the trust verification system. By maintaining an updated and comprehensive trust table, the network can adapt to changes and potential threats dynamically, ensuring consistent and secure operations. This decentralized method fosters a resilient and cooperative network environment, where trust is collectively managed and continuously validated by all participating nodes.

[0040] As a result, the plurality of nodes is thus, enabled to perform trust verification of the first node. Each node can independently evaluate the token and trust table to determine whether the first node can be trusted based on the collective trust scores and authenticated credentials. Advantageously, decentralized approach to trust verification eliminates the need for a central authority, enhancing the resilience and scalability of the network.

[0041] Moreover, the dissemination of the trust table allows nodes to cross erify the plurality of trust scores and the plurality of tokens of other nodes in the plurality of nodes, fostering a collaborative environment where trust relationships are continuously monitored and updated. Additionally, broadcasting the token and trust table can facilitate the detection of anomalies or inconsistencies in the trust data, prompting further investigation and corrective actions if necessary.

[0042] The trust score generated by the first node is periodically updated based on realtime data received from the computer network. Thus, each node of the plurality of nodes receives the trust table generated by the first node. Furthermore, each node of the plurality of nodes generates a trust table for the node. Thus, each node of the plurality of nodes has one trust table received from the first node and one trust table generated by the node. The method further comprises verifying a fourth node by applying a consensus algorithm to the trust table produced by the first node. Examples of consensus algorithms includes Practical Byzantine Fault Tolerance (PBFT) and Raft. PBFT ensures that the trust scores are agreed upon even in the presence of faulty or malicious nodes, offering robustness and reliability. Raft simplifies the consensus process by electing a leader to manage the trust scores, providing ease of implementation and high fault tolerance. Applying the consensus algorithms ensures that the trust scores are collectively validated by multiple nodes, leading to a more accurate verification of the fourth node. Thus, the first node mitigates the risk of single points of failure and reduces the influence of biased or erroneous evaluations. The consensus-based verification is particularly advantageous in an loT network, where numerous devices with varying levels of reliability interact. Thus, the first node ensures that only trustworthy devices can participate, enhancing the overall security and integrity of the loT ecosystem. By leveraging the distributed nature of loT networks, this method promotes cooperative decision-making and resilience against attacks. Additionally, the trust table is periodically updated to reflect real-time changes, ensuring continuous and adaptive trust management. The fourth node is verified by the first node in a periodical manner. In one example, each node of the plurality of node is verified by the first node by application of the consensus algorithm to the trust table generated by the first node.

[0043] The method further comprises generating a validation response based on a successful validation of the fourth node by the first node. Furthermore, the method further comprises initiating data communication with the fourth node based on the success of a validation process.

[0044] The object of the present disclosure is achieved through a system for decentralized trust verification in a computer network. The computer network comprises a plurality of nodes which comprises a first node, a second node, a third node, and a fourth node.

[0045] The system comprises a root-of-trust device configured to generate a token for a first node of the plurality of nodes and one or more tokens for at least the second node, and a third node. The root-of-trust device typically comprises a dedicated hardware module, which is configured to generate a trust token for the plurality of nodes in the computer network. The trust token is a cryptographic entity used to estabhsh and verify an identity and integrity of each node of the plurality of nodes within the computer network. In one example, the trust token is a digital certificate or credential that authenticates each node of the plurality of nodes. The trust token ensures that a node is a legitimate and trusted participant in the computer network. The trust token ensures that each node is uniquely and securely identified within the computer network. The trust token is generated by use of a physically unclonable function (PUF). The physically unclonable function leverages inherent physical variations in a manufacturing process of the root-of- trust device to create a unique cryptographic key which cannot be duplicated or cloned.

[0046] The system further comprises a first node of the plurality of nodes. The first node comprises a processing unit configured to determine a trust score for at least a second node and a third node of the plurality of nodes. The processing unit is further configured to receive a plurality of trust parameters from the root-of-trust device. The plurality of trust parameters comprises information related to the security policies, authentication credentials, encryption keys, and integrity verification measures. The plurality of trust parameters is utilized by the first node to establish a secure communication channel with other nodes in the network. By leveraging these trust parameters, the first node can validate the authenticity of other nodes, ensure data integrity, and protect against potential security threats. Advantageously, an overall reliability and security of the computer network is enhanced, enabling secure data exchange and collaboration among interconnected nodes of the plurality of nodes.

[0047] The processing unit is further configured to determine a trust score for at least a second and a third node within the computer network. The trust score is a numerical representation of the reliability, credibility, and trustworthiness of at least the second node and the third node within the computer network. The trust score associated with a node is calculated based on a plurality of trust indicators, including a past behavior of the node, a quality of interactions of the node with other nodes in the plurality of nodes, and any available security credentials or certifications possessed by the node. The plurality of trust indicators are specific metrics or criteria used to evaluate and quantify a trustworthiness of a node within the computer network. A collective assessment of the plurality of trust indicators contributes to an overall trust score assigned to the node, which reflects a reliability and a credibility of the node within the computer network.

[0048] For example, to determine the trust score, the processing unit is configured to gather data from interactions of the first node with at least the second node and third nodes, as well as from experiences and reports of other nodes of the plurality of nodes. The processing unit further applies one or more algorithms which are configured to analyze patterns, detect anomalies, on the plurality of trust indicators.

[0049] The processing unit is further configured to obtain one or more trust scores determined by the second node and the third node for the fourth node. In one example, the one or more trust scores are collected from the plurality of nodes, where each node of the plurality of nodes contributes an evaluation of other nodes based on interactions and experiences of the node with other nodes. Advantageously, by aggregating the one to more trust scores, the processing unit is enabled to mitigate influence of any biased or malicious evaluations, leading to a more accurate and reliable trust determination. For example, if a node, of the plurality of nodes, consistently provides inflated trust scores due to collusion or error, then the impact of the node is diluted by more numerous and diverse evaluations from other nodes of the plurality of nodes. Thus, a risk of single points of failure is reduced. Furthermore, a robustness of a trust evaluation process of the processing unit is increased. Additionally, the processing unit benefits from leveraging a collective intelligence of the computer network, as different nodes have access to different subsets of information, leading to a richer and more complete dataset for the trust evaluation process.

[0050] Furthermore, an aggregation of trust scores from the plurality of nodes allows the processing unit to detect and respond to anomalies more effectively. For example, if a drop in trust scores from the plurality of nodes is indicative of a potential security threat or malicious behavior, hence enabling the processing unit to intervene timely. Advantageously, the trust evaluation mechanism not only enhances security but also promotes fairness and transparency within the computer network.

[0051] The processing unit is further configured to generate a trust table comprising at least one trust score associated with the fourth node. The trust table is generated based on the trust score determined for at least the second node and the third node, the one or more trust scores obtained from at least the second node and the third node, and further based on the one or more tokens obtained from at least the second node and the third node. The trust table is a structured data repository that stores trust scores for various nodes within the computer network. The trust table functions as a reference guide for the processing unit, allowing the processing unit to quickly access and evaluate trustworthiness of other nodes. Each node of the plurality of nodes has a specific trust table stored within the node.

[0052] The trust table is generated by application of a trust evaluation algorithm to the trust score determined by the processing unit, the obtained one or more trust scores and the obtained one or more tokens. Examples of the one or more algorithms comprise a Bayesian inference algorithm, an EigenTrust algorithm, a fuzzy logic system-based algorithm, or machine learning algorithms like Random Forest and Support Vector Machine based algorithms. The Bayesian Inference algorithm is configured to update trust scores periodically based on new interactions and evidence. The EigenTrust Algorithm aggregates local trust values into a global score, reflecting a consensus view and mitigating the influence of malicious nodes. Fuzzy Logic Systems combine multiple trust indicators into a single score, accommodating uncertainty and providing nuanced evaluations. Machine learning models like Random Forest and Support Vector Machines predict trust scores based on historical data and learned patterns. These models adapt and improve over time, providing robust trust assessments. By applying these algorithms, the processing unit generates a reliable trust table that serves as a central repository for trust information. This enables informed decision-making, enhances network security, and promotes transparency and cooperation among nodes. One of the primary advantages of generating a trust table is the ability to efficiently manage and reference trust information. By maintaining a decentralized repository of trust scores, the processing unit can make rapid and informed decisions regarding which nodes to interact with and to what extent. Thus, the decentralized repository of trust scores is particularly useful in large networks where manually assessing the trustworthiness of every node would be impractical and time-consuming.

[0053] Another advantage of the trust table is its role in enhancing security and reliability within the network. By aggregating trust scores from multiple sources and continuously updating the table, the processing unit can detect patterns and trends that may indicate potential threats or changes in node behavior. For instance, if a previously trustworthy node begins to receive lower trust scores from multiple sources, this can serve as an early warning signal for possible compromised security.

[0054] Additionally, the trust table supports transparency and accountability within the computer network. Nodes can periodically review and audit the trust scores recorded in the table, ensuring that the trust evaluation process remains fair and unbiased. Thus, the transparency builds confidence among the plurality of nodes, fostering a cooperative and secure network environment.

[0055] The system further comprises a broadcasting module configured to broadcast the generated trust table to the plurality of nodes. The trust score generated by the processing unit is periodically updated based on real-time data received from the computer network. The system further comprises verifying a fourth node by applying a consensus algorithm to the trust table produced by the processing unit. Examples of consensus algorithms include Practical Byzantine Fault Tolerance (PBFT) and Raft. PBFT ensures that the trust scores are agreed upon even in the presence of faulty or malicious nodes, offering robustness and reliability. Raft simplifies the consensus process by electing a leader to manage the trust scores, providing ease of implementation and high fault tolerance. Applying the consensus algorithms ensures that the trust scores are collectively validated by multiple nodes, leading to a more accurate verification of the fourth node. Thus, the processing unit mitigates the risk of single points of failure and reduces the influence of biased or erroneous evaluations. The consensus-based verification is particularly advantageous in an loT network, where numerous devices with varying levels of reliability interact. Thus, the processing unit ensures that only trustworthy devices can participate, enhancing the overall security and integrity of the loT ecosystem. By leveraging the distributed nature of loT networks, this system promotes cooperative decision-making and resilience against attacks. Additionally, the trust table is periodically updated to reflect real-time changes, ensuring continuous and adaptive trust management.

[0056] The object of the present disclosure is achieved through a first node comprising a processing unit which is configured to determine a trust score for at least a second node and a third node of the plurality of nodes The processing unit is further configured to obtain one or more trust scores and one or more tokens from at least the second node and the third node. The one or more trust scores are determined, for the fourth node, by at least the second node and the third node. The processing unit is further configured to generate a trust table comprising the trust score associated with the fourth node. The trust table is generated by application of a trust evaluation algorithm on the obtained one or more tokens, the determined trust score and the obtained one or more trust scores. The processing unit is further configured to verify the fourth node of the plurality of nodes by application of a consensus algorithm on the generated trust table.

[0057] The above-mentioned and other features of the invention will now be addressed with reference to the accompanying drawings of the present invention. The illustrated embodiments are intended to illustrate, but not limit the invention.

[0058] The present invention is further described hereinafter with reference to illustrated embodiments shown in the accompanying drawings, in which:

[0059] FIG 1 is a block diagram of a system configured to execute decentralized trust verification of network nodes in a computer network, according to an embodiment of the present invention!

[0060] FIG 2 is a block diagram of a network node, such as those shown in FIG. 1, in which an embodiment of the present invention can be implemented! FIG 3 is a block diagram of a trust verification module, such as those shown in FIG 2, in which an embodiment of the present invention can be implemented; and

[0061] FIG 4 is a process flowchart illustrating an exemplary method of decentralized trust verification of network nodes in a computer network, according to an embodiment of the present invention.

[0062] Various embodiments are described with reference to the drawings, wherein like reference numerals are used to refer the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following description, for the purpose of explanation, numerous specific details are set forth in order to provide thorough understanding of one or more embodiments. It may be evident that such embodiments may be practiced without these specific details.

[0063] FIG 1 is a block diagram of a system 100 configured to execute decentralized trust verification of network nodes in a computer network 106, according to an embodiment of the present invention. The system 100 comprises a plurality of nodes 102A-N, a root-of-trust device 104, and the computer network 106.

[0064] The plurality of nodes 102A-N is a collection of interconnected devices which share resources and communicate with each other using either wired or wireless technologies, via the computer network 106. The plurality of nodes 102A-N is implemented in various ways, depending on the specific requirements of the computer network 106. For instance, in one example, the plurality of nodes 102 A- N are sensors that monitor environmental conditions, machine health, or other parameters. In such a scenario, examples of the plurality of nodes 102A-N include temperature sensors, humidity sensors, pressure sensors, and vibration sensors. The plurality of nodes are also actuators that perform actions based on commands received from other nodes or a central controller. Further examples of the plurality of nodes 102A-N include robotic arms, motors, and valves. Additionally, in another example, the plurality of nodes 102A-N are controllers that manage and coordinate activities of other nodes in the computer network 106. Examples include programmable logic controllers (PLCs) and industrial computers. Furthermore, examples of the plurality of nodes 102A-N further comprises edge devices that process data locally before sending it to the cloud or a central server. Examples include edge gateways and edge servers. Moreover, the plurality of nodes 102A-N further comprises mobile devices used by technicians or operators for remote monitoring and control. Examples include tablets, smartphones, and wearable devices. In some implementations, the plurality of nodes 102A-N further comprises specialized devices such as smart meters, smart thermostats, and other smart appliances that contribute to the overall functionality and efficiency of the computer network 106.

[0065] The root-of-trust device 104 typically comprises a dedicated hardware module, which is configured to generate a trust token for the plurality of nodes 102A-N in the computer network 106. The trust token is a cryptographic entity used to establish and verify an identity and integrity of each node of the plurality of nodes 102A-N within the computer network 106. In one example, the trust token is a digital certificate or credential that authenticates each node of the plurality of nodes 102A-N. The trust token ensures that a node is a legitimate and trusted participant in the computer network 106. The trust token ensures that each node is uniquely and securely identified within the computer network 106. The trust token is generated by use of a physically unclonable function (PUF). The physically unclonable function leverages inherent physical variations in a manufacturing process of the root-of-trust device 104 to create a unique cryptographic key which cannot be duplicated or cloned.

[0066] Examples of the root-of-trust device 104 include Trusted Platform Modules (TPMs), which are specialized hardware chips designed to secure hardware through integrated cryptographic keys. Another example is Hardware Security Modules (HSMs), which are physical devices that manage digital keys and provide cryptographic processing. Secure Elements (SEs) are also used as root-of- trust devices! these are tamper-resistant chips used in mobile devices and smart cards to securely store sensitive information and perform cryptographic operations. The computer network 106 is a collection of interconnected devices that communicate with each other to share resources, data, and apphcations. The computer network 106 can vary in size and complexity, ranging from small local area networks (LANs) within a single building to expansive wide area networks (WANs) that span multiple geographic locations. In one example, the computer network 106 is an Internet of Things (loT) network configured to streamline production processes in an industrial plant. The loT networks include devices such as sensors that monitor machine health, actuators that control robotic arms, and controllers that manage assembly lines. Possible implementations of the computer network 106 include smart manufacturing systems, where loT networks automate and optimize production lines by continuously monitoring equipment status with sensors and adjusting operations in real-time with actuators to enhance efficiency and reduce downtime. Another implementation is energy management systems, which deploy loT devices to monitor and control energy consumption within industrial plants, ensuring optimal use of resources and reducing operational costs. Predictive maintenance is another critical application, where a network of sensors gathers data on machinery health, enabling predictive analytics to forecast potential failures and schedule maintenance proactively, thereby minimizing unexpected breakdowns.

[0067] In the illustrated system 100, each node 102A-N communicates with the root-of- trust device 104. When a node, such as 102A, joins the network, it requests a trust token from the root-of-trust device 104. The root-of-trust device 104 generates this token, often utilizing a physically unclonable function (PUF) to create a unique cryptographic key that cannot be duplicated or cloned.

[0068] FIG 2 is a block diagram of a network node such as a first node 102A, such as those shown in FIG 1, in which an embodiment of the present invention can be implemented. In FIG 2, the first node 102A includes a processing unit 202, an accessible memory 204, a storage unit 206, a communication interface 208, an input-output unit 210, a network interface 212 and a bus 214.

[0069] The processing unit 202, as used herein, means any type of computational circuit, such as, but not limited to, a microprocessor unit, microcontroller, complex instruction set computing microprocessor unit, reduced instruction set computing microprocessor unit, very long instruction word microprocessor unit, explicitly parallel instruction computing microprocessor unit, graphics processing unit, digital signal processing unit, or any other type of processing circuit. The processing unit 202 may also include embedded controllers, such as generic or programmable logic devices or arrays, application specific integrated circuits, single-chip computers, and the like.

[0070] The memory 204 may be non-transitory volatile memory and non-volatile memory. The memory 204 may be coupled for communication with the processing unit 202, such as being a computer-readable storage medium. The processing unit 202 may execute machine-readable instructions and / or source code stored in the memory 204. A variety of machine-readable instructions may be stored in and accessed from the memory 204. The memory 204 may include any suitable elements for storing data and machine-readable instructions, such as read only memory, random access memory, erasable programmable read only memory, electrically erasable programmable read only memory, a hard drive, a removable media drive for handling compact disks, digital video disks, diskettes, magnetic tape cartridges, memory cards, and the like. In the present embodiment, the memory 204 includes a network module 216. The network module 216 includes the trust verification module 112 stored in the form of machine-readable instructions on any of the above-mentioned storage media and may be in communication with and executed by the processor(s) 202.

[0071] When executed by the processing unit 202, the trust verification module 112 causes the processing unit 202 to request a token from a root-of-trust device 104. The trust verification module 112 causes the processing unit 202 to obtain, by the first node 102A, the token from the root-of-trust device 104. The first node 102A further receives a plurality of trust parameters from the root-of-trust device 104. The plurality of trust parameters comprises information related to a security policy, an authentication credential, an encryption key, and integrity verification measures. The plurality of trust parameters is utilized by the first node 102A to establish a secure communication channel with other nodes in the network.

[0072] By leveraging the plurality of trust parameters, the first node 102A is enabled to validate an authenticity of other nodes of the plurality of nodes 102A-N, ensure data integrity, and protect against potential security threats. Advantageously, an overall reliability and security of the computer network 106 is enhanced, enabling secure data exchange and collaboration among interconnected nodes of the plurality of nodes 102A-N. The plurality of trust parameters provides comprehensive information about the token. The plurality of trust parameters comprises a validity parameter associated with the token, a current Trust Level (TL) of the computer network 106, and a Trust Information (delta-Trustlnfo) associated with the computer network 106. The validity parameter associated with the token includes information about a lifespan of the token. The information about the lifespan of the token comprises at least an issuance date and an expiration date. The information in the validation parameter ensures that outdated or potentially compromised tokens are not used to authenticate devices within the computer network 106. For instance, in a smart home network, a smart thermostat receives a trust token with a validity parameter indicating that the trust token is valid for one year from a date of issuance of the trust token. The validity parameter ensures that after one year, the smart thermostat has to renew the trust token to continue participating in the computer network 106 securely. The validity parameter further comprises metadata associated with the trust token such as an identifier of the first node 102A, a type of device of the first node 102A, and one or more cryptographic algorithms used in generating the token.

[0073] The current Trust Level (TL) of the computer network 106 is a parameter which reflects an overall security posture and integrity of the computer network 106 at any given time. In one example, the current trust level is measured as a number between 1 and 9. The current trust level of the computer network 106 is a dynamic parameter which changes based on real-time assessments of a security status of the computer network 106.

[0074] The Trust Information, often referred to as delta-Trustlnfo, provides granular details about any changes or updates to a trust status of the plurality of nodes 102A-N within the computer network 106. The trust information includes recent trust events, such as issuance or revocation of trust tokens, changes in device status, or detected security incidents. For instance, in a factory automation system, the delta-Trustlnfo might indicate that a new robotic arm has been added to the computer network 106 and has successfully authenticated itself, or that a sensor has been temporarily removed from the computer network 106 due to suspicious activity. The trust information allows the plurality of nodes 102A-N and a central control system to maintain a robust and adaptive security posture.

[0075] The trust verification module 112 causes the processing unit 202 to determine a trust score for at least a second node 102B and a third node 102C within the computer network 106. In one example, the second node 102B and the third node 102C are neighboring nodes of the first node 102A. The trust score is a numerical representation of the reliability, credibility, and trustworthiness of at least the second node 102B and the third node 102C within the computer network 106. The trust score associated with a node is calculated based on a plurality of trust indicators, including a past behavior of the node, a quality of interactions of the node with other nodes in the plurality of nodes 102A-N, and any available security credentials or certifications possessed by the node. The plurality of trust indicators are specific metrics or criteria used to evaluate and quantify a trustworthiness of a node within the computer network 106. A collective assessment of the plurality of trust indicators contributes to an overall trust score assigned to the node, which reflects a reliability and a credibility of the node within the network.

[0076] For example, to determine the trust score, the first node 102A first gathers the plurality of trust indicators from interactions of the first node 102A with at least the second node 102B and third node 102C, as well as from experiences and reports of other nodes of the plurality of nodes 102A-N. The first node 102A further applies one or more algorithms which are configured to analyze patterns, detect anomalies, on the plurality of trust indicators. Examples of the one or more algorithms include a Bayesian inference algorithm, which updates trust scores based on new interactions and feedback; an EigenTrust algorithm, which aggregates local trust values into a global trust score; a fuzzy logic systems-based algorithm, which handles uncertainty and combines multiple trust indicators into a single score; and machine learning algorithms like Random Forest and Support Vector Machines, which predict trust scores based on historical data and learned patterns. The determined trust score enables the first node 102A to decide whether to engage in transactions or share sensitive information with at least the second node 102B and third node 102C, thereby enhancing the overall security and efficiency of the computer network 106.

[0077] The first node 102A is configured to select the one or more algorithms for trust score calculation based on a specific requirement of the network. For instance, the Bayesian inference algorithms are used in smaller networks where interactions are frequent, and data is continuously updated. The EigenTrust algorithms are preferred in larger networks to aggregate local trust values into a global score. The Fuzzy logic systems are employed in environments with high uncertainty, while the machine learning algorithms like the Random Forest and the Support Vector Machines are used for predictive trust scoring based on historical data.

[0078] The trust verification module 112 causes the processing unit 202 to obtain, by the first node 102A, a plurality of trust scores determined by at least one of the plurality of nodes 102A-N of the computer network 106. In one example, the obtained plurality of trust scores comprises one or more trust scores obtained from at least the second node (102B) and the third node (102C). The one or more trust scores are determined, for the fourth node (102D), by at least the second node (102B) and the third node (102C).

[0079] The plurality of trust scores is collected from the plurality of nodes 102A-N, where each node of the plurality of nodes 102A-N contributes its evaluation of other nodes based on interactions and experiences of the node with other nodes.

[0080] The processing unit 202 is further configured to receive a plurality of tokens from at least one node of the plurality of nodes 102A-N. In one example, the obtained plurality of tokens comprises one or more tokens obtained from at least the second node (102B) and the third node (102C). The one or more tokens are originally obtained by at least the second node (102B) and the third node (102C) from the root-of-trust device 104.

[0081] Each token in the plurality of tokens is originally received from the root-of-trust device 104 by a specific node within the computer network 106 and is uniquely associated with that particular node. Thus, each node in the computer network 106 has a specific token issued by the root-of-trust device 104, serving as a certified credential that verifies authenticity and trustworthiness of the specific node. By collecting the plurality of tokens, the first node 102A can gather evidence of trustworthiness from multiple nodes across the computer network 106, thereby enhancing robustness and reliability of the decentralized trust verification process. The plurality of tokens enables the first node to crossreference and validate the trust scores and trust relationships among different nodes, contributing to the overall security and integrity of the computer network 106.

[0082] Advantageously, by aggregating the plurality of trust scores, the first node 102A is enabled to mitigate the influence of any biased or malicious evaluations, leading to a more accurate and reliable trust determination. For example, if a node of the plurality of nodes 102A-N consistently provides inflated trust scores due to collusion or error, then the impact of the node is diluted by more numerous and diverse evaluations from other nodes of the plurality of nodes 102A-N. Thus, a risk of single points of failure is reduced. Furthermore, a robustness of a trust evaluation process of the first node 102A is increased. Additionally, the first node 102A benefits from leveraging a collective intelligence of the computer network 106, as different nodes have access to different subsets of information, leading to a richer and more complete dataset for the trust evaluation process.

[0083] Furthermore, an aggregation of trust scores from the plurality of nodes 102A-N allows the first node 102A to detect and respond to anomalies more effectively. For example, if a drop in trust scores from the plurality of nodes 102 A-N is indicative of a potential security threat or malicious behavior, hence enabling the first node 102A to intervene timely. Advantageously, the trust evaluation mechanism not only enhances security but also promotes fairness and transparency within the computer network 106. The trust verification module 112 causes the processing unit 202 to generate, in the first node 102A, a trust table comprising at least one trust score associated with the fourth node 102D.

[0084] The trust table is generated based on the trust score determined for at least the second node 102B and the third node 102C, the one or more trust scores obtained from at least the second node 102B and the third node 102C, and further based on the one or more tokens received from at least the second node 102B and the third node 102C. By incorporating the one or more tokens, the trust table has an additional layer of validation, ensuring that the plurality of trust scores is backed by authenticated and credible sources. The trust table is a structured data repository that stores trust scores for various nodes within the computer network 106. The trust table functions as a reference guide for the first node 102A, allowing the first node 102A to quickly access and evaluate trustworthiness of other nodes.

[0085] In one example, the trust table comprises at least one trust score associated with the fourth node (102D) of the plurality of nodes (102A-N). The at least one trust score is an indicator of an amount of trust that the first node (102A) has, towards the fourth node (102D). It is noted that the trust table is generated based on the trust score determined for at least the second node and the third node and the plurality of trust scores obtained from at least the second node and the third node, and further based on the one or more tokens received from at least the second node and the third node.

[0086] Thus, the at least one trust score for the fourth node 102D is determined by the first node 102A without having to use any token which is provided by the fourth node 102D. Determining the at least one trust score without receiving any tokens from the fourth node offers several advantages. Firstly, the first node 102A is enabled to evaluate a trustworthiness of the fourth node 102D based on observations and interactions from other nodes in the computer network 106, rather than relying on potentially biased or fraudulent tokens that the fourth node 102D might provide. This external validation ensures a more objective and accurate assessment of the fourth node's behavior and reliability.

[0087] Using the trust score determined for at least the second node 102B and the third node 102C, along with the one or more trust scores obtained from at least the second node 102B and the third node 102C, and further based on the one or more tokens received from at least the second node 102B and the third node 102C, causes better trust evaluation for the fourth node in several ways. By incorporating multiple trust scores and tokens into the trust table, the first node 102A ensures a more comprehensive and holistic assessment of trustworthiness of the fourth node 102D. Integration of trust scores from different nodes provides a balanced perspective on a behavior of the fourth node 102D and reliability within the computer network 106.

[0088] Additionally, inclusion of the one or more tokens received from the root-of-trust device 104 adds a layer of authentication to the one or more trust scores. The one or more tokens serve as verified credentials that confirm a legitimacy of trust evaluations of at least the second node 102B and the third node 102C, thereby increasing an accuracy and a reliability of the fourth node 102D. By crossreferencing the one or more trust scores with the one or more tokens, the first node 102A is enabled to validate a credibility of trust data, ensuring that evaluations are based on secure and verified information.

[0089] Each node of the plurality of nodes 102A-N has a specific trust table stored within the node. To generate the trust table, the first node 102A processes both the trust score determined by the first node 102A and the plurality of trust scores obtained by the first node 102A from the plurality of nodes 102A-N. The plurality of trust scores is then organized into a tabular format, where each row corresponds to a node of the plurality of nodes 102A-N and each column contains relevant trust metrics, such as a trust score, historical interactions, and any anomalies detected. The trust table is periodically updated to reflect the latest trust scores and to incorporate new nodes as they join the network.

[0090] The trust table is generated by application of a trust evaluation algorithm to both the trust score determined by the first node 102A and the one or more trust scores obtained from the second node (102B) and the third node (102C), and the one or more tokens. Examples of the trust evaluation algorithm comprise a Bayesian inference algorithm, an EigenTrust algorithm, a fuzzy logic systembased algorithm, or machine learning algorithms like Random Forest and Support Vector Machine-based algorithms. The Bayesian Inference algorithm is configured to update trust scores periodically based on new interactions and evidence. The EigenTrust Algorithm aggregates local trust values into a global score, reflecting a consensus view and mitigating the influence of malicious nodes. Fuzzy Logic Systems combine multiple trust indicators into a single score, accommodating uncertainty and providing nuanced evaluations. Machine learning models like Random Forest and Support Vector Machines predict trust scores based on historical data and learned patterns. The machine learning models adapt and improve over time, providing robust trust assessments. By applying these algorithms, the first node 102A generates a reliable trust table that serves as a central repository for trust information.

[0091] Thus, informed decision-making, an enhancement of network security, and a promotion of transparency and cooperation among the plurality of nodes 102A-N is obtained. Advantageously, the trust table enables the first node 102A to efficiently manage and reference trust information. By maintaining a decentralized repository of trust scores, the first node 102A is enabled to make rapid and informed decisions regarding which nodes to interact with and to what extent. Thus, the decentralized repository of trust scores is particularly useful in large networks where manually assessing the trustworthiness of every node would be impractical and time-consuming. Another advantage of the trust table is its role in enhancing security and reliability within the network. By aggregating trust scores from multiple sources and continuously updating the table, the first node 102A is enabled to detect patterns and trends that may indicate potential threats or changes in node behavior. For instance, if a previously trustworthy node begins to receive lower trust scores from multiple sources, this can serve as an early warning signal for possible compromised security. Additionally, the trust table supports transparency and accountability within the computer network 106. Nodes can periodically review and audit the trust scores recorded in the table, ensuring that the trust evaluation process remains fair and unbiased. Thus, the transparency builds confidence among the plurality of nodes 102A-N, fostering a cooperative and secure network environment.

[0092] The trust verification module 112 causes the processing unit 202 to broadcast the obtained token and the generated trust table to the plurality of nodes 102A-N. By broadcasting the generated token and the generated trust table, all nodes in the computer network 106 receive same information, promoting consistency and transparency across the computer network 106. By distributing the generated token and trust table, each node in the computer network 106 is equipped with the necessary data to assess the trustworthiness of other nodes, including the first node 102A.

[0093] As a result, the plurality of nodes 102A-N is thus, enabled to perform trust verification of the first node 102A. Each node can independently evaluate the token and the trust table to determine whether the first node 102A can be trusted based on the collective trust scores and authenticated credentials. Advantageously, decentralized approach to trust verification eliminates the need for a central authority, enhancing the resilience and scalability of the computer network 106.

[0094] Moreover, the dissemination of the trust table allows nodes to cross erify the plurality of trust scores and the plurality of tokens of other nodes in the plurality of nodes 102A-N, fostering a collaborative environment where trust relationships are continuously monitored and updated. Additionally, broadcasting the token and the trust table can facilitate the detection of anomalies or inconsistencies in the trust data, prompting further investigation and corrective actions if necessary.

[0095] Additionally, each node receives a trust table broadcasted by the first node 102A. The trust table generated by the node and the trust table received from the first node 102A are merged by each node by using a predefined algorithm that prioritizes recent and highly reliable data. Thus, merging process ensures that each node has a comprehensive and up-to-date view of a trust landscape of the computer network 106, thereby enhancing an accuracy and a reliability of trust evaluations.

[0096] The trust score generated by the first node 102A is periodically updated based on real-time data received from the computer network 106. The trust verification module 112 causes the processing unit 202 to verify a fourth node 102D by applying a consensus algorithm to the trust table produced by the first node 102A. A verification of the fourth node 102D is performed at regular intervals, typically ranging from daily to weekly, depending on security requirements of the computer network 106. The verification is triggered by predefined criteria such as significant changes in trust scores, detection of suspicious activity, or periodic schedules. During verification, each node of the plurality of nodes 102A-N, applies consensus algorithms to validate trust scores and ensure that only trustworthy nodes participate in the computer network 106. Nodes that fail verification are flagged for further investigation and may be temporarily or permanently excluded from the computer network 106.

[0097] Examples of consensus algorithms include Practical Byzantine F ault Tolerance (PBFT) and Raft. PBFT ensures that the trust scores are agreed upon even in the presence of faulty or malicious nodes, offering robustness and reliability. Raft simplifies the consensus process by electing a leader to manage the trust scores, providing ease of implementation and high fault tolerance. Applying the consensus algorithm ensures that the trust scores are collectively validated by multiple nodes, leading to a more accurate verification of the fourth node 102D. Thus, the first node 102A mitigates the risk of single points of failure and reduces the influence of biased or erroneous evaluations. The consensus-based verification is particularly advantageous in an loT network, where numerous devices with varying levels of reliability interact. Thus, the first node 102A ensures that only trustworthy devices can participate, enhancing the overall security and integrity of the loT ecosystem. By leveraging the distributed nature of loT networks, cooperative decision-making and resilience against attacks are obtained. Additionally, the trust table is periodically updated to reflect real-time changes, ensuring continuous and adaptive trust management.

[0098] The trust verification module 112 causes the processing unit 202 to generate a validation response based on a successful validation of the fourth node (102D) by the first node (102A). The generation of a validation response provides several advantages. Firstly, the validation response acts as a confirmation signal that the fourth node (102D) has successfully passed the trust verification process, ensuring that only legitimate and trustworthy nodes participate in the computer network 106. Thus, the confirmation signal enhances an overall security and trustworthiness of the computer network 106 by preventing unauthorized or compromised nodes from gaining access.

[0099] Examples of the validation response include a digital certificate or a cryptographic token that can be used by the fourth node 102D to prove an authenticity of the fourth node 102D to other nodes in the computer network 106. The validation response may also include metadata such as a timestamp of vahdation, an identity of validating node (the first node 102A), and any relevant security attributes. By providing detailed information, the validation response facilitates transparent and verifiable trust relationships among the nodes.

[0100] The trust verification module 112 causes the processing unit 202 to initiate data communication with the fourth node based on a success of the validation process. Initiating data communication only after successful validation offers significant advantages. Firstly, this approach ensures that sensitive information is exchanged exclusively with verified and trusted nodes, thereby minimizing risk of data breaches and unauthorized access. Thus, selective communication enhances overall integrity and confidentiality of data being transmitted within the computer network 106.

[0101] Moreover, initiating communication only after validation fosters a secure and reliable network environment, where nodes can confidently interact without concerns about potential security threats. This selective interaction based on vahdation reinforces the computer network 106 resilience against malicious attacks and improves the efficiency of data exchanges. The validation process thus, serves as a critical gatekeeper, allowing only authenticated and trustworthy nodes to participate in network activities, thereby upholding the security and robustness of the computer network 106.

[0102] One of a primary advantage of being able to assess the at least one trust score of the fourth node 102D based on the one or more trust scores and the one or more tokens obtained from at least the second node 102B and the third node 102C is the enhanced security and reliability of the computer network 106. By not relying on any token provided directly by the fourth node 102D, the first node 102A mitigates a risk of accepting potentially fraudulent or compromised tokens, thus, ensuring a more objective and accurate assessment of trustworthiness. Thus, overall security posture of the computer network 106 is increased by preventing malicious nodes from infiltrating the computer network 106 with counterfeit credentials. Additionally, the present invention offers considerable convenience as the first node 102A is enabled to leverage existing trust relationships and evaluations from other nodes, streamlining the trust verification process and reducing a computational overhead typically associated with generating and verifying tokens for every individual node. From a financial perspective, this decentralized approach can lead to substantial cost savings. By minimizing the need for extensive token issuance and validation processes for each node, it reduces the operational expenses associated with trust management infrastructure. Furthermore, by ensuring that only trustworthy nodes participate in the network, it can prevent costly security breaches and data compromises, thereby saving money in the long run.

[0103] Each node in the plurality of nodes 102A-N is configured to perform all functions attributed to the first node 102A. Each node determines trust scores for other nodes, obtains trust scores and tokens from neighboring nodes, generates a trust table, and applies consensus algorithms on other nodes for verification. When multiple nodes in the plurality of nodes execute these steps concurrently, it collectively results in decentralized trust verification across the computer network 106. This distributed approach ensures that every node contributes to the overall trust assessment, leveraging the collective intelligence and observations of the network to maintain robust and adaptive security measures.

[0104] The storage unit 206 may be a non-transitory storage medium configured for storing a database (such as database 118).

[0105] The communication interface 208 is configured for establishing communication sessions between the one or more network nodes 102A-N.

[0106] The input-output unit 210 may include input devices a keypad, touch-sensitive display, camera (such as a camera receiving gesture-based inputs), etc. capable of receiving one or more input signals, such as user commands. The bus 214 acts as interconnect between the processing unit 202, the memory 204, and the inputoutput unit 210.

[0107] The network interface 212 is configured to handle network connectivity, bandwidth and network traffic between the plurality of nodes 102A-N. Those of ordinary skilled in the art will appreciate that the hardware depicted in FIG 2 may vary for particular implementations. For example, other peripheral devices such as an optical disk drive and the like, Local Area Network (LAN), Wide Area Network (WAN), Wireless (e.g., Wi-Fi) adapter, graphics adapter, disk controller, input / output (I / O) adapter also may be used in addition or in place of the hardware depicted. The depicted example is provided for the purpose of explanation only and is not meant to imply architectural limitations with respect to the present disclosure.

[0108] Those skilled in the art will recognize that, for simplicity and clarity, the full structure and operation of all data processing systems suitable for use with the present disclosure is not being depicted or described herein. Instead, only so much of an engineering system 102 as is unique to the present disclosure or necessary for an understanding of the present disclosure is depicted and described.

[0109] FIG 3 is a block diagram of a trust verification module 112, such as those shown in FIG 2, in which an embodiment of the present invention can be implemented. In FIG 3, the trust verification module 112 comprises a request handler module 302, a trust score determination module 304, an analysis module 306, a trust table generation module 308, an broadcast module 310, a validation module 312 and a verification module 314. FIG. 3 is explained in conjunction with FIG. 1 and FIG. 2.

[0110] The request handler module 302 is configured for receiving the request to perform decentralized trust verification of one or more nodes in the plurality of nodes 102A-N. The request handler module acts as the initial point of contact, ensuring that all incoming requests for trust verification are properly logged and processed.

[0111] The trust score determination module 304 is configured to determine trust scores for one or more nodes in the plurality of nodes 102A-N. The trust score determination module 304 evaluates various trust indicators, such as past behavior and security credentials, to calculate a numerical trust score for each node. The analysis module 306 is configured for analyzing the plurahty of trust scores received from the plurality of nodes 102A-N. The analysis module 306 aggregates and examines the trust scores to identify patterns, detect anomalies, and ensure the reliability of the trust evaluation process.

[0112] The trust table generation module 308 is configured to generate the trust table for the first node 102A. The trust table generation module 308 organizes the determined trust scores into a structured data repository, allowing the first node 102A to quickly access and evaluate the trustworthiness of other nodes.

[0113] The broadcast module 310 is configured to broadcast the trust table to the plurality of nodes 102 A-N. The broadcast module 310 ensures that the generated trust table is disseminated across the network, enabling all nodes to access the updated trust information.

[0114] The validation module 312 is configured to validate the trust table generated by the trust table generation module 308. The validation module 312 checks the integrity and accuracy of the trust table, ensuring that it meets predefined security and reliability standards.

[0115] The verification module 314 is configured to use a consensus algorithm to validate at least one node of the plurahty of nodes 102A-N. The verification module 314 employs algorithms like Practical Byzantine Fault Tolerance (PBFT) or Raft to achieve consensus among nodes, ensuring that the trust scores are collectively validated and reliable.

[0116] FIG 4 is a process flowchart illustrating an exemplary method 400 of decentralized trust verification of network nodes in the computer network 106, according to an embodiment of the present invention. FIG 4 is described in conjunction with FIG 1, FIG 2, and FIG 3.

[0117] At step 402, the trust verification module 112 causes the processing unit 202 to determine a trust score for at least a second node 102B and a third node 102C of the plurality of nodes 102A-N. The trust score is a numerical representation of the reliability, credibility, and trustworthiness of the second node 102B and the third node 102C.

[0118] At step 404, the trust verification module 112 causes the processing unit 202 to obtain one or more trust scores and one or more tokens from at least the second node 102B and the third node 102C. The one or more trust scores are indicative of the trustworthiness of at least a fourth node 102D, as determined by the second node 102B and the third node 102C.

[0119] At step 406, the trust verification module 112 causes the processing unit 202 to generate a trust table comprising at least one trust score associated with the fourth node 102D. The trust table is generated by applying a trust evaluation algorithm to the obtained one or more tokens, the determined trust score, and the obtained one or more trust scores. This organized data repository allows for quick access and evaluation of the fourth node's trustworthiness.

[0120] At step 408, the trust verification module 112 causes the processing unit 202 to verify at least the fourth node 102D of the plurality of nodes 102A-N by applying a consensus algorithm to the generated trust table. This verification process ensures that the fourth node 102D is a trustworthy participant within the computer network 106, thereby executing decentralized trust verification.

[0121] At step 410, the trust verification module 112 causes the processing unit 202 to generate a validation response based on a successful validation of at least the fourth node 102D.

[0122] The present invention can take a form of a computer program product comprising program modules accessible from computer-usable or computer-readable medium storing program code for use by or in connection with one or more computers, processors, or instruction execution system. For the purpose of this description, a computer-usable or computer-readable medium can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The medium can be electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device) or a propagation mediums in and of themselves as signal carriers are not included in the definition of physical computer-readable medium include a semiconductor or solid state memory, magnetic tape, a removable computer diskette, random access memory (RAM), a read only memory (ROM), a rigid magnetic disk and optical disk such as compact disk read-only memory (CD-ROM), compact disk read / write, and DVD. Both processors and program code for implementing each aspect of the technology can be centralized or distributed (or a combination thereof) as known to those skilled in the art.

[0123] While the present invention has been described in detail with reference to certain embodiments, it should be appreciated that the present invention is not limited to those embodiments. In view of the present disclosure, many modifications and variations would be present themselves, to those skilled in the art without departing from the scope of the various embodiments of the present invention, as described herein. The scope of the present invention is, therefore, indicated by the following claims rather than by the foregoing description. All changes, modifications, and variations coming within the meaning and range of equivalency of the claims are to be considered within their scope. All advantageous embodiments claimed in method claims may also be apply to system / apparatus claims.

[0124] Independent of the grammatical term usage, individuals with male, female or other gender identities are included within the term.

[0125] List of Reference Numerals:

[0126] 1. System and Network Components: o 100: System for decentralized trust verification o 102A-N: Plurality of nodes o 102A: First node o 102B: Second node o 102C: Third node o 102D: Fourth node o 104: Root-of-trust device o 106: Computer network

[0127] 2. Components of First Node (102A):

[0128] 202: Processing unit

[0129] 204 Memory o 206 Storage unit o 208: Communication interface o 210 Input-output unit o 212: Network interface

[0130] 214: Bus o 216: Network module

[0131] 3. Trust Verification Module (112) Components:

[0132] 302 Request handler module o 304 Trust score determination module o 306 Analysis module o 308 Trust table generation module o 310 Broadcast module o 312 Validation module

[0133] 314: Verification module

[0134] 4. Process Steps (FIG 4): o 402: Determine a trust score for at least the second and third nodes o 404: Obtain one or more trust scores and tokens from at least the second and third nodes o 406: Generate a trust table comprising at least one trust score associated with at least the fourth node 408- Verify at least the fourth node by applying a consensus algorithm to the generated trust table 410: Generate a validation response based on a successful validation of the fourth node

Claims

AMENDED CLAIMS received by the International Bureau on 28 November 2025 (28.11 .2025)1. A method (400) of decentralized trust verification in a computer network (106) comprising a plurality of nodes (102A-N), the method comprising: in a first node (102A) of the plurahty of nodes (102A-N) of the computer network (106), wherein the plurahty of nodes (102A-N) comprises a second node (102B), a third node (102C), and a fourth node (102D): determining a trust score for at least the second node (102B) and the third node (102C); obtaining one or more trust scores and one or more tokens from at least the second node (102B) and the third node (102C), wherein the one or more trust scores are determined for the fourth node (102D), by at least the second node (102B) and the third node (102C); generating a trust table comprising at least one trust score associated with at least the fourth node (102D), wherein the trust table is generated by application of a trust evaluation algorithm on the obtained one or more tokens, the determined trust score and the obtained one or more trust scores! and verifying at least the fourth node (102D) of the plurality of nodes (102A-N) by application of a consensus algorithm on the generated trust table, thereby executing a decentralized trust verification of at least the fourth node (102D) of the plurality of nodes (102A-N), wherein the one or more tokens, of the at least the second node (102B) and the third node (102C), is generated by a root-of-trust device (104) by application of a physically unclonable function.

2. The method (400) of claim 1, wherein the trust score for at least the second node (102B) and the third node (102C) is determined based on a plurality of trust indicators between the first node (102A), at least the second node (102B), and at least the third node (102C).

3. The method (400) of claim 2, wherein the trust score is determined by application of one or more machine learning algorithms on the plurahty of trust indicators.

4. The method (400) of any of claims 1 to 2, further comprising:(102A); broadcasting the obtained token and the trust table to the plurality of nodes (102A-N) in the computer network (106).

5. The method (400) of any of claims 1 to 4, wherein the trust score, generated by the first node (102A), is periodically updated based on real-time data received from the plurality of nodes (102A-N).

6. The method (400) of any of claims 1 to 5, wherein the verification of the fourth node (102D) is performed by application of a consensus algorithm on the trust table generated by the first node (102A).

7. A system (100) for decentralized trust verification in a computer network (106) comprising a plurality of nodes (102A-N), the system comprising: a plurality of nodes (102A-N) comprising a first node (102A), a second node (102B), a third node (102C), and a fourth node (102D); and a root-of-trust device (104) configured to generate one or more tokens for at least a second node (102B) and a third node (102C) of the plurality of nodes (102A-N), wherein the first node (102A) comprises: a processing unit (202) configured to: determine a trust score for at least the second node (102B) and the third node (102C) of the plurality of nodes (102A-N); obtain one or more trust scores and the one or more tokens from at least the second node (102B) and the third node (102C), wherein the one or more trust scores is indicative of a trustworthiness of at least the fourth node (102D) as determined by at least the second node (102B) and the third node (102C); generate a trust table comprising at least one trust score associated with the fourth node (102D), wherein the trust table is generated by application of a trust evaluation algorithm on the obtained one or more tokens, the determined trust score and the obtained one or more trust scores! and verify the fourth node (102D) of the plurality of nodes (102A-N) by application of a consensus algorithm on the generated trust table, wherein the root-of-trust device (104) is configured to generate the token by application of a physically unclonable function.

8. The system (100) of claim 7, wherein the processing unit (202) is configured to determine the trust score for at least the second node (102B) and the third node (102C) based on a plurality of trust indicators between the first node (102A), the second node (102B), and the third node (102C).

9. The system (100) of any of claims 7 to 8, wherein the processing unit (202) is configured to determine the trust score by application of one or more machine learning algorithms on the plurality of trust indicators.

10. The system (100) of any of claims 7 to 9, further comprising a broadcasting module configured to broadcast the generated token and the generated trust table to the plurality of nodes (102A-N) in the computer network (106).

11. The system (100) of any of claims 7 to 10, further comprising a revocation module configured to revoke the token of the first node (102A) upon detection of malicious activity.

12. The system (100) of any of claims 7 to 11, wherein the processing unit (202) is configured to perform the trust verification in a distributed ledger environment.

13. A first node (102A) of a plurality of nodes (102A-N), the first node comprising: a processing unit (202) configured to: determine a trust score for at least a second node (102B) and a third node (102C) of the plurality of nodes (102A-N); obtain one or more trust scores and one or more tokens from at least the second node (102B) and the third node (102C), wherein the one or more trust scores are determined, for the fourth node (102D), by at least the second node (102B) and the third node (102C); generate a trust table comprising the trust score associated with the fourth node (102D), wherein the trust table is generated by application of a trust evaluation algorithm on the obtained one or more tokens, the determined trust score and the obtained one or more trust scores! andapplication of a consensus algorithm on the generated trust table, wherein the one or more tokens, of the at least the second node (102B) and the third node (102C), is generated by a root-of-trust device (104) by application of a physically unclonable function.

Citation Information

Patent Citations

  • Method for validating a node

    US20210036868A1

  • Methods and systems for a distributed certificate authority

    US20220158855A1