IP Library Granted Patent US 12,647,449
Granted Patent B2
US 12,647,449 · App. 18/630,797 · Granted Jun 2, 2026

Systems and methods for estimating a crypto-agility score of a network of computing assets

Inventors: Richard Toohey (Burlington, VT); Peter Bordow (Fountain Hills, AZ); Chao Chen (New York, NY)
Assignee: Wells Fargo Bank, N.A.
H04L63/1433H04L41/0869H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,449
App. No.
18/630,797
Granted
Jun 2, 2026
Kind
B2
Abstract

Systems, apparatuses, methods, and computer program products are disclosed for estimating a crypto-agility score of a network of computing assets. An example method includes receiving a network graph and a set of expert-determined importance weights and selecting a first network node from a set of network nodes. The example method further includes computing an upgrade cost for the first network node based on a set of dependency network nodes and applying an expert-determined importance weight to the upgrade cost for the first network node to determine a weighted upgrade cost for the first network node. The example method further includes adding the weighted upgrade cost for the first network node to a set of weighted upgrade costs and summing, by the graph circuitry, each weighted upgrade cost from the set of weighted full upgrade costs to determine the crypto-agility score for the network of computer assets.

Claims (88)

1 . A method for estimating a crypto-agility score of a network of computing assets, the method comprising:

receiving, by communications hardware, a network graph comprising a set of network nodes and a set of weights corresponding to the set of network nodes;

selecting, by graph circuitry, a first network node from the set of network nodes;

computing, by upgrade analysis circuitry, an upgrade cost for the first network node based on a set of dependency network nodes comprising dependencies of the first network node;

applying, by the graph circuitry, a weight from the set of weights to the upgrade cost for the first network node to determine a weighted upgrade cost for the first network node;

adding, by the graph circuitry, the weighted upgrade cost for the first network node to a set of weighted upgrade costs;

summing, by the graph circuitry, each weighted upgrade cost from the set of weighted upgrade costs to determine the crypto-agility score for the network of computer assets; and

providing, by the communications hardware, the crypto-agility score to an expert user.

2 . The method of claim 1 , further comprising:

computing, by the upgrade analysis circuitry, an individual upgrade cost associated with an upgrade of the first network node;

determining, by the upgrade analysis circuitry, the set of dependency network nodes representing computing assets that provide dependencies for the upgrade of the first network node;

generating a set of individual upgrade costs associated with the set of dependency network nodes; and

computing, by the upgrade analysis circuitry, a full upgrade cost for the first network node based on a set of upgrade costs associated with dependency network nodes from the set of dependency network nodes,

wherein the upgrade cost is further based on the full upgrade cost.

3 . The method of claim 2 , wherein computing the full upgrade cost for the first network node comprises:

computing, by the upgrade analysis circuitry, a dependency full upgrade cost for a dependency network node from the set of dependency network nodes, wherein the dependency full upgrade cost is based on a set of nested dependency upgrade costs associated with dependencies of the dependency network node; and

adding, by the graph circuitry, the dependency full upgrade cost for the dependency network node to the full upgrade cost for the first network node.

4 . The method of claim 2 , wherein generating the set of individual upgrade costs associated with the dependency network nodes comprises:

selecting, by the graph circuitry, a next network node, wherein the next network node has not previously been selected, wherein the next network node provides a dependency for the upgrade of the first network node;

computing, by the upgrade analysis circuitry, a next individual upgrade cost associated with the next network node; and

adding, by the graph circuitry, the next individual upgrade cost to the set of upgrade costs associated with the dependency network nodes.

5 . The method of claim 1 , further comprising computing the set of weighted upgrade costs by:

selecting, by the graph circuitry, a next network node, wherein the next network node has not previously been selected;

computing, by the upgrade analysis circuitry, a next upgrade cost for the next network node based on a set of next dependency network nodes comprising dependencies of the next network node;

applying, by the graph circuitry, a next weight from the set of weights to the next upgrade cost for the next network node to determine a next weighted upgrade cost for the next network node; and

adding, by the graph circuitry, the next weighted upgrade cost for the next network node to the set of weighted upgrade costs.

6 . The method of claim 1 , further comprising:

causing, by the graph circuitry, a perturbation of the network graph to produce a perturbed network graph;

computing a set of perturbed weighted upgrade costs based on the perturbed network graph; and

summing, by the graph circuitry, each perturbed weighted upgrade cost from the set of perturbed weighted upgrade costs to determine a perturbed crypto-agility score for the perturbed network graph of computer assets.

7 . The method of claim 6 , further comprising:

computing a set of crypto-agility scores comprising the crypto-agility score and the perturbed crypto-agility score; and

selecting a greatest score from the set of crypto-agility scores to designate a locally optimal network configuration, wherein the locally optimal network configuration corresponds to the greatest score.

8 . The method of claim 6 , further comprising:

computing a set of crypto-agility scores comprising the crypto-agility score and the perturbed crypto-agility score, wherein each particular crypto-agility score from the set of crypto-agility scores is associated with a particular network graph from a set of network graphs;

providing, by the communications hardware, the set of crypto-agility scores and the set of network graphs to the expert user; and

receiving, by the communications hardware, an indication of a validation of the set of crypto-agility scores.

9 . The method of claim 8 , further comprising:

modifying, by the graph circuitry, a selected weight from the set of weights based on the validation of the set of crypto-agility scores.

10 . The method of claim 8 , further comprising:

modifying, by the graph circuitry, a selected upgrade cost associated with a particular network node from the set of network graphs based on the validation of the set of crypto-agility scores.

11 . The method of claim 1 , wherein the network graph is a knowledge graph.

12 . The method of claim 11 , wherein computing the upgrade cost is based on one or more subject-predicate-object relationships between the first network node and a dependency network node from the set of dependency network nodes.

13 . An apparatus for estimating a crypto-agility score of a network of computing assets, the apparatus comprising:

communications hardware configured to:

receiving a network graph comprising a set of network nodes and a set of weights corresponding to the set of network nodes;

graph circuitry configured to:

select a first network node from the set of network nodes; and

upgrade analysis circuitry configured to:

compute an upgrade cost for the first network node based on a set of dependency network nodes comprising dependencies of the first network node,

wherein the graph circuitry is further configured to:

apply a weight from the set of weights to the upgrade cost for the first network node to determine a weighted upgrade cost for the first network node;

add the weighted upgrade cost for the first network node to a set of weighted upgrade costs; and

sum each weighted upgrade cost from the set of weighted upgrade costs to determine the crypto-agility score for the network of computer assets;

wherein the communications hardware is further configured to provide the crypto-agility score to an expert user.

14 . The apparatus of claim 13 , wherein the upgrade analysis circuitry is further configured to:

compute an individual upgrade cost associated with an upgrade of the first network node;

determine the set of dependency network nodes representing computing assets that provide dependencies for the upgrade of the first network node;

generate a set of individual upgrade costs associated with the set of dependency network nodes; and

compute a full upgrade cost for the first network node based on a set of upgrade costs associated with dependency network nodes from the set of dependency network nodes,

wherein the upgrade cost is further based on the full upgrade cost.

15 . The apparatus of claim 14 , wherein the upgrade analysis circuitry is further configured to compute the full upgrade cost for the first network node by:

computing a dependency full upgrade cost for a dependency network node from the set of dependency network nodes, wherein the dependency full upgrade cost is based on a set of nested dependency upgrade costs associated with dependencies of the dependency network node; and

adding the dependency full upgrade cost for the dependency network node to the full upgrade cost for the first network node.

16 . The apparatus of claim 14 , wherein the graph circuitry is further configured to generate the set of individual upgrade costs associated with the dependency network nodes by:

selecting a next network node, wherein the next network node has not previously been selected, wherein the next network node provides a dependency for the upgrade of the first network node;

computing a next individual upgrade cost associated with the next network node; and

adding the next individual upgrade cost to the set of upgrade costs associated with the dependency network nodes.

17 . The apparatus of claim 13 , wherein the graph circuitry is further configured to compute the set of weighted upgrade costs by:

selecting a next network node, wherein the next network node has not previously been selected;

computing a next upgrade cost for the next network node based on a set of next dependency network nodes comprising dependencies of the next network node;

applying a next weight from the set of weights to the next upgrade cost for the next network node to determine a next weighted upgrade cost for the next network node; and

adding the next weighted upgrade cost for the next network node to the set of weighted upgrade costs.

18 . The apparatus of claim 13 , wherein the graph circuitry is further configured to:

cause a perturbation of the network graph to produce a perturbed network graph;

computing a set of perturbed weighted upgrade costs based on the perturbed network graph; and

sum each perturbed weighted upgrade cost from the set of perturbed weighted upgrade costs to determine a perturbed crypto-agility score for the perturbed network graph of computer assets.

19 . The apparatus of claim 18 , wherein the graph circuitry is further configured to:

compute a set of crypto-agility scores comprising the crypto-agility score and the perturbed crypto-agility score; and

select a greatest score from the set of crypto-agility scores to designate a locally optimal network configuration, wherein the locally optimal network configuration corresponds to the greatest score.

20 . A computer program product for estimating a crypto-agility score of a network of computing assets, the computer program product comprising at least one non-transitory computer-readable storage medium storing software instructions that, when executed, cause an apparatus to:

receive a network graph comprising a set of network nodes and a set of weights corresponding to the set of network nodes;

select a first network node from the set of network nodes;

compute an upgrade cost for the first network node based on a set of dependency network nodes comprising dependencies of the first network node;

apply a weight from the set of weights to the upgrade cost for the first network node to determine a weighted upgrade cost for the first network node;

add the weighted upgrade cost for the first network node to a set of weighted upgrade costs;

sum each weighted upgrade cost from the set of weighted upgrade costs to determine the crypto-agility score for the network of computer assets; and

provide the crypto-agility score to an expert user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2024
From: TOOHEY, RICHARD; BORDOW, PETER; CHEN, CHAO
To: WELLS FARGO BANK, N.A.
Reel/Frame 069043/0141 →
Continuity (1)
Related Publication 20250317465A1 · Oct 9, 2025
References Cited (31)
US 10178120B1 · Keegan · 2019 [cited by applicant]
US 11265159B1 · Truskovsky · 2022 [cited by examiner]
US 20150100671A1 · Song · 2015 [cited by examiner]
US 20170032130A1 · Joseph Durairaj · 2017 [cited by applicant]
US 20170180408A1 · Yu · 2017 [cited by examiner]
US 20180048669A1 · Lokamathe · 2018 [cited by applicant]
US 20180159876A1 · Park · 2018 [cited by applicant]
US 20180278642A1 · Joy · 2018 [cited by applicant]
US 20200175173A1 · Krishnamoorthy · 2020 [cited by applicant]
US 20200267074A1 · Wang · 2020 [cited by applicant]
US 20200280577A1 · Segal · 2020 [cited by applicant]
US 20200326924A1 · A · 2020 [cited by examiner]
US 20210014250A1 · Walsh · 2021 [cited by applicant]
US 20210019674A1 · Crabtree · 2021 [cited by applicant]
US 20210149658A1 · Cannon · 2021 [cited by examiner]
US 20210234889A1 · Burle · 2021 [cited by applicant]
US 20220084049A1 · Soramaki · 2022 [cited by applicant]
US 20220210200A1 · Crabtree · 2022 [cited by examiner]
US 20220224723A1 · Crabtree · 2022 [cited by examiner]
US 20220366332A1 · Duessel · 2022 [cited by examiner]
US 20230132703A1 · Marsenic · 2023 [cited by applicant]
US 20230289444A1 · Ermey · 2023 [cited by applicant]
US 20240273227A1 · Thompson · 2024 [cited by examiner]
US 20250103720A1 · Bordow · 2025 [cited by examiner]
CN 110113314A · 2019 [cited by applicant]
CN 111177417A · 2020 [cited by applicant]
CN 117675413A · 2024 [cited by applicant]
CN 114662328B · 2024 [cited by applicant]
Hohm et al., “Towards a maturity model for crypto-agility assessment,” retrieved from https://arxiv.org/pdf/2202.07645; Feb. 17, 2022. [cited by applicant]
Ma et al., “CARAF: Crypto Agility Risk Assessment Framework,” Journal of Cybersecurity; Apr. 30, 2021. [cited by applicant]
Valence, Arnaud, “ICAR, a categorical framework to connect vulnerability, threat and asset managements,” retrieved from https://arxiv.org/pdf/2306.12240v1; Jun. 21, 2023. [cited by applicant]