Distributed Security Framework Using Reputation-Based Validation Hierarchy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed systems face challenges in efficiently managing security, particularly in reducing resource costs and limiting the impact of compromises on the system.

Innovation Solution

A security framework is implemented that distributes authority for validating entities across the distributed system using a hierarchy based on weighted reputation scores, which helps in identifying and remedying compromised systems efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized security authority is used to validate all entities in the distributed system, then security validation can be performed uniformly, but the resource cost increases and the impact of compromises spreads across the entire system

Engineering Contradiction:
Improvesecurity validationVSAvoidresource cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the centralized security authority into multiple distributed validation providers arranged in a hierarchical structure. Each provider validates entities within its designated scope rather than a single authority validating all entities, thereby distributing the computational resource cost while maintaining security validation reliability through the hierarchical arrangement where higher-level providers can override lower-level decisions.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a centralized security authority is used to validate all entities in the distributed system, then security validation can be performed uniformly, but the impact of compromises affects the entire system

Engineering Contradiction:
Improvesecurity validationVSAvoidimpact of compromises
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security validation function across multiple distributed providers in a hierarchy, so that a compromise at one level affects only that provider and its direct descendants in the hierarchy, not the entire system. Higher-level providers can override compromised lower-level providers, containing the harmful impact locally rather than system-wide.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security validation is performed across the entire distributed system, then all entities can be validated, but computing resources are not efficiently utilized

Engineering Contradiction:
Improveentity validationVSAvoidcomputing resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent assigns different validation responsibilities to different providers in the hierarchy based on their capabilities and scope. Each provider performs validation locally within its designated entity scope rather than all providers validating all entities, improving computing resource efficiency while maintaining comprehensive entity validation through the hierarchical structure.

Inventive Principle:
Principle #3Local quality

4Reliability

If a hierarchy based on weighted reputation scores is implemented, then the impact of compromises is limited, but the system complexity increases

Engineering Contradiction:
Improvecompromise containmentVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent pre-establishes a hierarchical structure with weighted reputation scores for each validation provider before security validation begins. This preliminary arrangement of authorities and their relative trust weights allows the system to automatically contain compromise impacts by following the pre-defined hierarchy, reducing the need for complex real-time decision-making while maintaining reliable compromise containment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12301584B2System and method for security management in distributed systems
Publication Date: 2025.05.13 DELL PROD LP
  • US12301584B2 patent drawing
  • US12301584B2 patent drawing
  • US12301584B2 patent drawing

AI summary

Methods and systems for securing distributed systems are disclosed. The distributed systems may include data processing systems subject to compromise by malicious entities. If compromised, the data processing systems may impair the services provided by the distributed system. To secure the distributed systems, the data processing systems may implement a security framework. The security framework may utilize a hierarchy that defines authority for validating trusted entities. The hierarchy may vest authority across the distributed system, and may be based on a reputation (e.g., weighted reputation) of each of the data processing systems within the distributed system. Consequently, the impact of compromise of a data processing system may be limited by the distributed authority.