Trust Score-Based Security Verification Function Allocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large network environments, zero-trust networking techniques face insufficient computing and communication resources for security verification, leading to inadequate verification accuracy and potential false positives.
Innovation Solution
A function allocation control device that calculates trust scores for entities based on verification results and resource information, dynamically allocating and controlling security verification functions to optimize resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security verification is performed for all entities in large network environments, then security verification coverage is improved, but resource consumption increases
Solution Approach 1:
The patent applies local quality by differentiating security verification intensity based on entity characteristics. High-value entities receive comprehensive verification while low-value entities receive minimal verification. This is achieved through value assessment modules that categorize entities and allocate verification resources accordingly, ensuring adequate security coverage while optimizing resource consumption.
Solution Approach 2:
The patent changes verification parameters dynamically based on entity value assessments. Verification frequency, depth, and resource allocation are adjusted as parameters according to entity characteristics. This allows the system to maintain security verification coverage across all entities while adapting resource consumption to match the actual security needs of each entity.
2Measurement precision
If comprehensive security verification is performed, then security accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent implements local quality by applying different verification accuracy levels to different entities based on their assessed value. High-value entities undergo comprehensive verification with high accuracy requirements, while low-value entities receive streamlined verification. This differential approach maintains overall security accuracy while significantly reducing total computing resource consumption.
Solution Approach 2:
The patent applies partial action by performing only the necessary portion of security verification for each entity. Instead of uniform comprehensive verification, the system performs verification to the extent needed for each entity's security requirements, avoiding excessive verification of low-risk entities and thereby reducing resource consumption while maintaining adequate accuracy.
3Reliability
If security verification is performed frequently, then security monitoring effectiveness is improved, but resource consumption increases
Solution Approach 1:
The patent implements periodic action by scheduling security verification at different frequencies for different entities based on their assessed value and risk profiles. High-value entities undergo frequent periodic verification, while low-value entities are verified less frequently. This approach maintains effective security monitoring for critical entities while improving overall resource efficiency through reduced verification frequency for non-critical entities.
Solution Approach 2:
The patent applies dynamics by making verification frequency adaptive rather than static. Verification intervals are dynamically adjusted based on entity value assessments, risk levels, and historical security performance. This dynamic approach allows the system to optimize the balance between monitoring effectiveness and resource efficiency, increasing verification frequency when risks elevate and reducing it when entities maintain low risk profiles.
Data Source
AI summary
A function allocation control device for controlling a security verification system that executes a security verification function allocated to a target entity, the function allocation control device including: a trust score calculation unit configured to calculate a trust score indicating a security level of each entity on the basis of verification result information indicating a result of verifying security of each entity; a security verification function allocation unit configured to allocate a security verification function to each entity on the basis of the calculated trust score and resource information indicating a resource used for achieving the security verification function allocated to each entity; and a security verification function control unit configured to control the security verification system so as to execute the allocated security verification function.


