Trust Controller Using Continuous Scores for Consistent Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Zero-trust networking systems face inefficiencies due to ad hoc adjustments in security checks, leading to inconsistencies and increased resource intensity, which can undermine network security and performance.

Innovation Solution

Implementing a trust controller that systematically determines and adjusts trust scores for network entities based on prerequisites, variable factors, and reputation, using a predictable methodology to reduce inconsistencies and optimize security checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ad hoc adjustments in security checks are performed, then network security can be strengthened, but resource intensity increases and inconsistencies arise

Engineering Contradiction:
Improvenetwork securityVSAvoidresource intensity
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system changes the parameter of trust assessment from binary (trusted/not trusted) to a continuous trust score based on multiple factors including distance, intervening entities, and entity attributes. This allows for more nuanced security decisions that are more efficient than ad hoc adjustments while maintaining or improving security reliability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary trust assessments and calculates trust scores before network operations occur. By pre-evaluating entity trustworthiness based on distance, intervening entities, and attributes, the system avoids the need for resource-intensive ad hoc security checks during actual network operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If ad hoc adjustments in security checks are performed, then network security can be strengthened, but inconsistencies arise

Engineering Contradiction:
Improvenetwork securityVSAvoidconsistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system implements a universal trust score calculation methodology that can be applied consistently across all network entities and operations. This single framework handles diverse security scenarios (different entity types, network paths, and operations) in a unified manner, eliminating inconsistencies that arise from ad hoc adjustments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By transforming security assessment into a standardized parameter (trust score) calculated from consistent factors, the system ensures stable and repeatable security decisions. The trust score methodology provides deterministic results based on entity attributes, distance, and intervening entities, rather than variable ad hoc judgments.

Inventive Principle:
Principle #35Parameter changes

3Stability of the object's composition

If trust scores are calculated and adjusted based on multiple factors, then security consistency is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidtrust controller complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The trust controller segments the trust assessment process into distinct components: distance calculation, intervening entity analysis, entity attribute evaluation, and trust score synthesis. This modular approach manages complexity by breaking down the overall function into smaller, independently manageable segments while maintaining security consistency.

Inventive Principle:
Principle #1Segmentation

4Use of energy by moving object

If systematic trust score determination is implemented, then resource intensity is reduced, but device complexity increases

Engineering Contradiction:
Improveresource intensityVSAvoidtrust controller complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The trust controller performs preliminary calculations of trust scores using pre-collected entity attributes, distance metrics, and intervening entity information. By preparing these assessments in advance rather than computing them on-demand during network operations, the system reduces real-time resource intensity while the computational complexity is managed as a one-time setup cost.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12375496B2Inferring trust in computer networks
Publication Date: 2025.07.29 JUNIPER NETWORKS INC
  • US12375496B2 patent drawing
  • US12375496B2 patent drawing
  • US12375496B2 patent drawing

AI summary

This disclosure describes techniques including assessing trust in a computer network. In one example, this disclosure describes a method that includes determining a level of trust that a first network entity has for a second network entity; determining a level of trust that the second network entity has for a third network entity; determining that the first network entity is separated from the third network entity by the second network entity; determining, based on the level of trust that the first network entity has for the second network entity and further based on the level of trust that the second network entity has for the third network entity, a level of trust that the first network entity has for the third network entity; and enabling, based on the level of trust that the first network entity has for the third network entity, the first network entity to perform an operation.