IP Library Granted Patent US 11,316,851
Granted Patent B2
US 11,316,851 · App. 16/446,278 · Granted Apr 26, 2022

Security for network environment using trust scoring based on power consumption of devices within network

Inventors: Mohamed Sohail (Sheikh Zayed, EG); Said Tabet (Sherborn, MA)
Assignee: EMC IP Holding Company LLC
H04L63/0876G06F1/28G06N20/00H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,316,851
App. No.
16/446,278
Granted
Apr 26, 2022
Kind
B2
Abstract

Systems, methods, and articles of manufacture comprising processor-readable storage media are provided for implementing security mechanisms for network environments. For example, a method includes collecting power consumption data of a plurality of devices operating within a network and determining trust scores for the plurality of devices based, at least in part, on the collected power consumption data. The trust score for a device provides a measure of trustworthiness of the device exhibiting normal operating behavior within the network. Each device is assigned to one of a plurality of trust tiers based on the determined trust scores, wherein each trust tier specifies an authentication level for devices assigned to the trust tier. One or more authentication procedures are applied to authenticate a given device operating within the network based on the authentication level specified by the trust tier to which the given device is assigned.

Claims (53)

1. A method, comprising:

collecting power consumption data of a plurality of devices operating within a network;

determining trust scores for the plurality of devices based, at least in part, on the collected power consumption data, wherein the trust score for a device provides a measure of trustworthiness of the device exhibiting normal operating behavior within the network;

assigning each of the plurality of devices into one of a plurality of trust tiers based on the determined trust scores, wherein each trust tier specifies an authentication level for devices assigned to the trust tier; and

applying one or more authentication procedures to authenticate a given device of the plurality of devices operating within the network based on the authentication level specified by the trust tier to which the given device is assigned.

2. The method of claim 1 , wherein each trust tier is allocated to a predefined range of trust scores, and wherein each device of the plurality of devices is assigned to a trust tier by determining which trust tier of the plurality of trust tiers has a predefined range of trust scores which includes the determined trust score of the device.

3. The method of claim 1 , further comprising:

assigning a default trust score to a newly provisioned device operating within the network; and

assigning the newly provisioned device to one of the plurality of trust tiers based on the default trust score.

4. The method of claim 1 , wherein determining trust scores for the plurality of devices further comprises:

determining device interaction patterns between the devices operating within the network; and

determining a trust score for each of the devices based, at least in part, on the determined device interaction patterns.

5. The method of claim 4 , wherein the trust score is determined using a trust scoring machine learning model which is trained to determine trust scores using a training dataset comprising features corresponding to device interaction patterns.

6. The method of claim 5 , wherein the features corresponding to device interaction patterns are based on device pairs and at least one feature associated with sets of neighbor nodes associated with the device pairs.

7. The method of claim 6 , wherein the at least one feature associated with sets of neighbor nodes comprises a number of neighbor nodes of each device of a given device pair.

8. The method of claim 6 , wherein the at least one feature associated with sets of neighbor nodes comprises a sum and difference between the number of neighbor nodes of each device of a given device pair.

9. The method of claim 6 , wherein the at least one feature associated with sets of neighbor nodes comprises a number of common neighbor nodes between the devices of a given device pair.

10. The method of claim 6 , wherein the at least one feature associated with sets of neighbor nodes comprises a value indicative of an intersection of the neighbor nodes of the devices of a given device pair divided by a union of the neighbor nodes of the devices of the given device pair.

11. The method of claim 1 , wherein the devices comprise sensor devices operating in a wireless sensor network of an Internet of Things network environment.

12. An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code is executable by one or more processors to implement a method comprising:

collecting power consumption data of a plurality of devices operating within a network;

determining trust scores for the plurality of devices based, at least in part, on the collected power consumption data, wherein the trust score for a device provides a measure of trustworthiness of the device exhibiting normal operating behavior within the network;

assigning each of the plurality of devices into one of a plurality of trust tiers based on the determined trust scores, wherein each trust tier specifies an authentication level for devices assigned to the trust tier; and

applying one or more authentication procedures to authenticate a given device of the plurality of devices operating within the network based on the authentication level specified by the trust tier to which the given device is assigned.

13. The article of manufacture of claim 12 , wherein each trust tier is allocated to a predefined range of trust scores, and wherein each device of the plurality of devices is assigned to a trust tier by determining which trust tier of the plurality of trust tiers has a predefined range of trust scores which includes the determined trust score of the device.

14. The article of manufacture of claim 12 , further comprising program code which is executable by the one or more processors to implement a method comprising:

assigning a default trust score to a newly provisioned device operating within the network; and

assigning the newly provisioned device to one of the plurality of trust tiers based on the default trust score.

15. The article of manufacture of claim 12 , wherein determining trust scores for the plurality of devices further comprises:

determining device interaction patterns between the devices operating within the network; and

determining a trust score for each of the devices based, at least in part, on the determined device interaction patterns.

16. The article of manufacture of claim 15 , wherein the trust score is determined using a trust scoring machine learning model which is trained to determine trust scores using a training dataset comprising features corresponding to device interaction patterns, wherein the features corresponding to device interaction patterns are based on device pairs and features associated with sets of neighbor nodes associated with the device pairs.

17. The article of manufacture of claim 16 , wherein the features associated with sets of neighbor nodes comprise:

a first feature comprising a number of neighbor nodes of each device of a given device pair;

a second feature comprising a sum and difference between the number of neighbor nodes of each device of the given device pair;

a third feature comprising a number of common neighbor nodes between the devices of the given device pair; and

a fourth feature comprising a value indicative of an intersection of the neighbor nodes of the devices of the given device pair divided by a union of the neighbor nodes of the devices of the given device pair.

18. A server node, comprising:

at least one processor; and

system memory configured to store program code, wherein the program code is executable by the at least one processor to perform a process which comprises:

collecting power consumption data of a plurality of devices operating within a network;

determining trust scores for the plurality of devices based, at least in part on, the collected power consumption data, wherein the trust score for a device provides a measure of trustworthiness of the device exhibiting normal operating behavior within the network;

assigning each of the plurality of devices into one of a plurality of trust tiers based on the determined trust scores, wherein each trust tier specifies an authentication level for devices assigned to the trust tier; and

applying one or more authentication procedures to authenticate a given device of the plurality of devices operating within the network based on the authentication level specified by the trust tier to which the given device is assigned.

19. The server node of claim 18 , wherein each trust tier is allocated to a predefined range of trust scores, and wherein each device of the plurality of devices is assigned to a trust tier by determining which trust tier of the plurality of trust tiers has a predefined range of trust scores which includes the determined trust score of the device.

20. The server node of claim 18 , wherein determining trust scores for the devices comprises:

determining device interaction patterns between the devices operating within the network; and

determining a trust score for each of the devices based, at least in part, on the determined device interaction patterns;

wherein the trust score is determined using a trust scoring machine learning model which is trained to determine trust scores using a training dataset comprising features corresponding to device interaction patterns, wherein the features comprise:

a first feature comprising a number of neighbor nodes of each device of a given device pair;

a second feature comprising a sum and difference between the number of neighbor nodes of each device of the given device pair;

a third feature comprising a number of common neighbor nodes between the devices of the given device pair; and

a fourth feature comprising a value indicative of an intersection of the neighbor nodes of the devices of the given device pair divided by a union of the neighbor nodes of the devices of the given device pair.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2019
From: SOHAIL, MOHAMED; TABET, SAID
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049524/0459 →
Cited By (1)
US 12,399,771