IP Library › Granted Patent US 12,074,879
Granted Patent B2
US 12,074,879 · App. 17/474,871 · Granted Aug 27, 2024

Inferring trust in computer networks

Inventors: Charles Damian O'Neill (Ballymena, GB); Kieran Gerald McPeake (Belfast, GB); Simon James (Newtownards, GB); Hayden Paul Shorter (Bangor, GB)
Assignee: Juniper Networks, Inc.
H04L63/102G06N5/04H04L41/12H04L63/105H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,074,879
App. No.
17/474,871
Granted
Aug 27, 2024
Kind
B2
Abstract

This disclosure describes techniques that include assessing trust in a computer network. In one example, this disclosure describes a method that includes determining a level of trust that a first network entity has for a second network entity; determining a level of trust that the second network entity has for a third network entity; determining that the first network entity is separated from the third network entity by the second network entity; determining, based on the level of trust that the first network entity has for the second network entity and further based on the level of trust that the second network entity has for the third network entity, a level of trust that the first network entity has for the third network entity; and enabling, based on the level of trust that the first network entity has for the third network entity, the first network entity to perform an operation with the third network entity.

Claims (56)

1. A method comprising:

determining, by a computing system, a level of trust that a first network device has for a second network device;

determining, by the computing system, a level of trust that the second network device has for a third network device;

determining, by the computing system, that the first network device is separated from the third network device by the second network device;

determining, by the computing system and based on the level of trust that the first network device has for the second network device and further based on the level of trust that the second network device has for the third network device, a level of trust that the first network device has for the third network device;

enabling, by the computing system and based on the level of trust that the first network device has for the third network device, the first network device to perform an operation with the third network device;

detecting, by the computing system, a change in the level of trust that the first network device has for the second network device; and

adjusting, by the computing system, based on the change in the level of trust that the first network device has for the second network device, the level of trust that the first network device has for the third network device.

2. The method of claim 1 , wherein determining the level of trust that the first network device has for the third network device includes:

determining, by the computing system, attributes of a separation between the first network device and the second network device.

3. The method of claim 2 , wherein determining attributes of the separation between the first network device and the second network device includes:

determining, by the computing system, a count of entities that separate the first network device from the second network device.

4. The method of claim 1 , wherein a fourth network device neighbors the third network device but does not neighbor the first network device, and wherein the method further comprises:

determining, by the computing system, a level of trust that the first network device has for the fourth network device by inferring the level of trust that the first network device has for the fourth network device.

5. The method of claim 1 , further comprising:

detecting, by the computing system, a change in the level of trust that the second network device has for the third network device; and

further adjusting, by the computing system, based on the change in the level of trust that the second network device has for the third network device, the level of trust that the first network device has for the third network device.

6. The method of claim 1 ,

wherein the first network device, the second network device, and the third network device are each network devices, and wherein each of the first network device, the second network device, and the third network device are connected through a network.

7. The method of claim 6 ,

wherein the first network device is connected to the third network device on the network by a network path through the second network device.

8. The method of claim 6 ,

wherein the network includes quantitative entities.

9. The method of claim 6 ,

wherein the network includes qualitative entities.

10. The method of claim 1 , wherein enabling the first network device to perform an operation with the third network device includes:

enabling, by the computing system, network data to flow between the first network device and the third network device.

11. A system comprising a storage device and processing circuitry having access to the storage device, wherein the processing circuitry is configured to:

determine a level of trust that a first network device has for a second network device;

determine a level of trust that the second network device has for a third network device;

determine that the first network device is separated from the third network device by the second network device;

determine, based on the level of trust that the first network device has for the second network device and further based on the level of trust that the second network device has for the third network device, a level of trust that the first network device has for the third network device;

enable, based on the level of trust that the first network device has for the third network device, the first network device to perform an operation with the third network device;

detect a change in the level of trust that the first network device has for the second network device; and

adjust, based on the change in the level of trust that the first network device has for the second network device, the level of trust that the first network device has for the third network device.

12. The system of claim 11 , wherein to determine the level of trust that the first network device has for the third network device, the processing circuitry is further configured to:

determine attributes of a separation between the first network device and the second network device.

13. The system of claim 12 , wherein to determine attributes of the separation between the first network device and the second network device, the processing circuitry is further configured to:

determine a count of entities that separate the first network device from the third network device.

14. The system of claim 11 , wherein a fourth network device neighbors the third network device but does not neighbor the first network device, and wherein the processing circuitry is further configured to:

determine a level of trust that the first network device has for the fourth network device by inferring the level of trust that the first network device has for the fourth network device.

15. The system of claim 11 , wherein the processing circuitry is

detect a change in the level of trust that the second network device has for the third network device; and

further adjust, based on the change in the level of trust that the second network device has for the third network device, the level of trust that the first network device has for the third network device.

16. The system of claim 11 ,

wherein the first network device, the second network device, and the third network device are each network devices, and wherein each of the first network device, the second network device, and the third network device are each connected through a network.

17. The system of claim 16 ,

wherein the first network device is connected to the third network device on the network by a network path through the second network device.

18. A non-transitory computer-readable storage medium comprising instructions that, when executed, configure processing circuitry of a computing system to:

determine a level of trust that a first network device has for a second network device;

determine a level of trust that the second network device has for a third network device;

determine that the first network device is separated from the third network device by the second network device;

determine, based on the level of trust that the first network device has for the second network device and further based on the level of trust that the second network device has for the third network device, a level of trust that the first network device has for the third network device;

enable, based on the level of trust that the first network device has for the third network device, the first network device to perform an operation with the third network device;

detect a change in the level of trust that the first network device has for the second network device; and

adjust, based on the change in the level of trust that the first network device has for the second network device, the level of trust that the first network device has for the third network device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2022
From: MCPEAKE, KIERAN GERALD; O'NEILL, CHARLES DAMIAN; JAMES, SIMON; SHORTER, HAYDEN PAUL
To: JUNIPER NETWORKS, INC.
Reel/Frame 060143/0906 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2021
From: O'NEILL, CHARLES DAMIAN; MCPEAKE, KIERAN GERARD; JAMES, SIMON; SHORTER, HAYDEN PAUL
To: JUNIPER NETWORKS, INC.
Reel/Frame 057479/0670 →
Continuity (1)
Related Publication 20230083952A1 · Mar 16, 2023
Cited By (3)
US 12,355,803 US 12,375,496 US 12,701,123