Trust Score Plan for Network Entity Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks operating with zero-trust architectures, there is a lack of systematic methodology for reducing authentication and security checks, leading to inconsistencies and potential security breaches and network outages due to ad hoc adjustments based on administrator experience and intuition.

Innovation Solution

A trust scoring system that calculates a trust score for network entities using customizable trust score plans, allowing for flexible and context-dependent evaluation of trust levels, which can modify network operations and improve security consistency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ad hoc adjustments to authentication and security checks are made based on administrator experience and intuition, then flexibility in network operation is improved, but consistency and reliability of security measures deteriorate

Engineering Contradiction:
Improveflexibility in network operationVSAvoidconsistency of security measures
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the parameter of trust assessment from subjective administrator judgment to objective quantified trust scores. Multiple trust factors (security posture, performance metrics, compliance status) are converted into numerical scores that can be consistently applied across different network entities and time periods, eliminating variability introduced by human intuition while maintaining operational flexibility through configurable trust thresholds.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical system of human administrator decision-making with an automated computational system. The trust scoring system automatically calculates trust levels based on predefined factors and algorithms, substituting human cognitive processes with machine-based calculations that provide consistent, reproducible results without being influenced by individual experience or intuition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple trust score plans are maintained for different contexts and purposes, then adaptability of trust assessment is improved, but system complexity deteriorates

Engineering Contradiction:
Improveadaptability of trust assessmentVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The trust assessment system is segmented into multiple independent trust score plans, each tailored for specific contexts (e.g., security-critical operations, performance-optimized operations, compliance-focused operations). Each plan contains customized weights and thresholds for different trust factors, allowing the system to adapt to various operational requirements without requiring a complete redesign for each context. This segmentation enables flexible adaptation while managing complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust scoring system is designed with universal components that can serve multiple functions across different contexts. The same core trust factor calculation engine and data collection mechanisms are reused across all trust score plans, with only the weighting and threshold parameters varying by context. This multi-functionality approach allows the system to adapt to different assessment purposes while avoiding the complexity of maintaining entirely separate systems for each use case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230300150A1Use of a trust score plan
Publication Date: 2023.09.21 JUNIPER NETWORKS INC
  • US20230300150A1 patent drawing
  • US20230300150A1 patent drawing
  • US20230300150A1 patent drawing

AI summary

This disclosure describes techniques that include assessing trust in a system, and in particular, assessing trust for entities based on a trust score plan. In one example, this disclosure describes a method that includes identifying, by the computing system, a selected trust score plan from a plurality of trust score plans associated with a network entity in a computer network; storing, by a computing system, information collected about the network entity in the computer network; determining, by the computing system and based on the identified trust score plan and the stored information, a trust score for the network entity; and modifying, by the computing system and based on the trust score for the network entity, operations within the computer network.