Trust Controller System for Dynamic Network Security Check Intensity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Zero-trust networking architectures in computer networks face performance issues due to resource-intensive authentication and security checks, leading to inconsistencies and potential security breaches when administrators reduce check intensity based on experience rather than systematic methodologies.

Innovation Solution

A trust controller system determines trust scores for network entities based on prerequisites, variable factors, and reputation, allowing for consistent and predictable adjustments to security checks, thereby reducing inconsistencies and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If administrators reduce check intensity based on experience, then network performance improves, but security reliability deteriorates

Engineering Contradiction:
Improvenetwork performanceVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically changes the intensity parameter of security checks based on computed trust scores. Trust scores are calculated by analyzing multiple factors including entity behavior patterns, historical security incidents, and compliance with security policies. When trust scores exceed thresholds, check intensity is reduced to improve performance; when scores fall below thresholds, intensity increases to maintain security reliability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements continuous feedback loops where security check results and network behavior data are fed back into the trust score calculation engine. This feedback mechanism allows the system to adaptively adjust check intensity based on real-time security conditions and entity performance, resolving the contradiction between performance optimization and security maintenance.

Inventive Principle:
Principle #23Feedback

2Reliability

If routine identity and integrity checks are performed on all entities, then security reliability improves, but network performance deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of security check intensity to different network entities based on their individual trust scores. High-trust entities receive reduced or expedited checks, while low-trust entities undergo more rigorous verification. This localized approach maintains security reliability for critical entities while improving overall network performance by reducing redundant checks on trusted entities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial security checks on high-trust entities rather than complete verification, reducing overhead while maintaining adequate security. Trust scores determine the extent of verification required, allowing the system to apply only the necessary level of security scrutiny for each entity based on its risk profile and historical behavior.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11683331B2Trust scoring of network entities in networks
Publication Date: 2023.06.20 JUNIPER NETWORKS INC
  • US11683331B2 patent drawing
  • US11683331B2 patent drawing
  • US11683331B2 patent drawing

AI summary

A method to determine, by a computing system, a trust score for a network entity in a computer network, the trust score for the network entity indicating a level of trust in the network entity; and modifying, by the computing system, a traffic pattern of the computer network based on the trust score for the network entity.