Data Confidence Fabric Segmentation for Trusted Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing networks face challenges in determining the trustworthiness of data and ensuring security, as data transmission without a security strategy can expose the network to attacks and reduce confidence in the data.
Innovation Solution
A data confidence fabric (DCF) system that segments and isolates data based on confidence scores, using hardware-assisted trust insertion technologies to annotate data with confidence information, and applies security strategies like zero-trust and VLAN to enhance data trustworthiness and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is transmitted without a security strategy, then network openness and data accessibility are improved, but network security and data trustworthiness deteriorate
Solution Approach 1:
The patent segments the network into multiple confidence zones (high-confidence, medium-confidence, low-confidence networks) based on hardware confidence scores. This allows data to be accessible across different zones while maintaining security boundaries, resolving the contradiction between openness and trustworthiness.
Solution Approach 2:
Different security strategies and confidence requirements are applied to different parts of the network based on local hardware characteristics and data sensitivity. High-confidence hardware receives more trusted data while low-confidence hardware operates in restricted zones, enabling both accessibility and trustworthiness locally.
2Reliability
If hardware confidence scoring and security strategies are implemented, then data trustworthiness and network security are improved, but system complexity increases
Solution Approach 1:
The hardware confidence scoring mechanism serves multiple functions simultaneously: it evaluates hardware trustworthiness, determines network placement, controls data access permissions, and generates security policies. This multi-functionality reduces the need for separate security subsystems, managing complexity while improving trustworthiness.
Solution Approach 2:
Hardware devices automatically generate their own confidence scores based on their characteristics and self-manage their placement in appropriate confidence zones. This self-service approach reduces the need for manual security configuration and complex centralized management, lowering system complexity.
3Reliability
If fine-grained traffic segmentation is applied, then network security and data isolation are improved, but network performance and data flow efficiency may deteriorate
Solution Approach 1:
The network is segmented into confidence zones that act as semi-permeable membranes allowing efficient data flow within zones while providing security isolation between zones. This segmentation maintains productivity within high-confidence zones while ensuring security through inter-zone boundaries.
Solution Approach 2:
Hardware confidence scores and security policies are determined in advance during device onboarding, before data transmission begins. This preliminary classification enables efficient routing decisions without real-time security evaluations, maintaining data flow efficiency while ensuring security.
Data Source
AI summary
A data confidence fabric allows data to be associated with confidence scores that reflect how the data may be trusted. Sensors or other devices may generate data. Confidence scores for the sensors are determined and the data confidence fabric determines a security strategy for the data based on the confidence score of the sensor generating the data. Confidence information associated with the data may include an annotation reflecting the security strategy that was applied and which may impact the confidence score of the data.


