IP Library › Granted Patent US 10,412,074
Granted Patent B2
US 10,412,074 · App. 16/151,819 · Granted Sep 10, 2019

Remote crowd attestation in a network

Inventors: Tao Zhang (Fort Lee, NJ); Yi Zheng (San Jose, CA); Helder F. Antunes (Morgan Hill, CA); Marcelo Yannuzzi (Vufflens-la-Ville, CH); Gonzalo Salgueiro (Raleigh, NC); Joseph Michael Clarke (Raleigh, NC)
Assignee: Cisco Technology, Inc.
H04L63/08H04L43/08H04L63/123H04L63/126H04L63/0823H04W4/70H04W12/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,412,074
App. No.
16/151,819
Granted
Sep 10, 2019
Kind
B2
Abstract

In one embodiment, a first device in a network receives information regarding one or more nodes in the network. The first device determines a property of the one or more nodes based on the received information. The first device determines a degree of trustworthiness of the one or more nodes based on the received information. The first device attests to the determined property and degree of trustworthiness of the one or more nodes to a verification device. The verification device is configured to verify the attested property and degree of trustworthiness.

Claims (50)

1. A method, comprising:

receiving, at a first device in a network, information regarding a plurality of nodes in the network;

determining, by the first device, a property of the plurality of nodes based on the received information, wherein the property of the plurality of nodes comprises at least one of: a hardware configuration, a software configuration, a physical location, or a traffic pattern of the one or more nodes;

observing, by the first device, a behavior of the plurality of nodes;

constructing, by the first device, a behavioral model based on the observed behavior;

determining, by the first device, a degree of trustworthiness of the plurality of nodes based on the received information by comparing the determined property to the behavioral model;

ensuring, by the first device, a degree of trustworthiness of the observed behavior; and

attesting, by the first device, to the determined property and degree of trustworthiness of the plurality of nodes to a verification device, wherein the verification device is configured to verify the attested property and degree of trustworthiness, as part of a hierarchy of attester devices in the network.

2. The method as in claim 1 , wherein the verification device is further configured to attest to the property and degree of trustworthiness of the plurality of nodes to a higher level attester device in the hierarchy.

3. The method as in claim 1 , wherein the behavioral model was constructed by the first device while in a learning mode.

4. The method as in claim 1 , wherein the behavioral model comprises an inferred finite state machine (FSM) that models the observed behavior of the plurality of nodes.

5. The method as in claim 1 , further comprising:

selecting, by the first device, the plurality of nodes based on a security policy, wherein the security policy identifies a set of trusted device types.

6. The method of claim 1 , further comprising:

comparing the received information regarding the plurality of nodes to a history of information regarding the plurality of nodes.

7. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

receive information regarding a plurality of nodes in the network;

determine a property of the plurality of nodes based on the received information;

observe a behavior of the plurality of nodes;

construct a behavioral model based on the observed behavior;

determine a degree of trustworthiness of the plurality of nodes based on the received information by comparing the determined property to the behavioral model;

ensure a degree of trustworthiness of the observed behavior; and

attest to the determined property and degree of trustworthiness of the plurality of nodes to a verification device, wherein the verification device is configured to verify the attested property and degree of trustworthiness as part of a hierarchy of attester devices in the network.

8. The apparatus as in claim 7 , wherein the process when executed is further configured to:

compare the received information regarding the plurality of nodes to a history of information regarding the plurality of nodes.

9. The apparatus as in claim 8 , wherein the verification device is further configured to attest to the property and degree of trustworthiness of the plurality of nodes to a higher level attester device in the hierarchy.

10. The apparatus as in claim 9 , wherein the behavioral model was constructed by the first device while in a learning mode.

11. The apparatus as in claim 8 , wherein the behavioral model comprises an inferred finite state machine (FSM) that models the observed behavior of the plurality of nodes.

12. The apparatus as in claim 8 , wherein the process when executed is further configured to:

select the plurality of nodes based on a security policy, wherein the security policy identifies a set of trusted device types.

13. The apparatus as in claim 8 , wherein the process when executed is further configured to:

compare the received information regarding the plurality of nodes to a history of information regarding the plurality of nodes.

14. A tangible, non-transitory, computer-readable media having software encoded thereon, the software when executed by a processor configured to:

receive information regarding a plurality of nodes in the network;

determine a property of the plurality of nodes based on the received information;

observe a behavior of the plurality of nodes;

construct a behavioral model based on the observed behavior;

determine a degree of trustworthiness of the plurality of nodes based on the received information by comparing the determined property to the behavioral model;

ensure a degree of trustworthiness of the observed behavior; and

attest to the determined property and degree of trustworthiness of the plurality of nodes to a verification device, wherein the verification device is configured to verify the attested property and degree of trustworthiness as part of a hierarchy of attester devices in the network.

15. The computer-readable media as in claim 14 , wherein the verification device is further configured to attest to the property and degree of trustworthiness of the plurality of nodes to a higher level attester device in the hierarchy.

16. The computer-readable media as in claim 14 , wherein the behavioral model was constructed by the first device while in a learning mode.

17. The computer-readable media as in claim 14 , wherein the behavioral model comprises an inferred finite state machine (FSM) that models the observed behavior of the plurality of nodes.

18. The computer-readable media as in claim 14 , wherein the software when executed by the processor is further configured to:

select the plurality of nodes based on a security policy, wherein the security policy identifies a set of trusted device types.

19. The computer-readable media of claim 14 , wherein the software when executed by the processor is further configured to:

compare the received information regarding the plurality of nodes to a history of information regarding the plurality of nodes.

Continuity (2)
Continuation 14924799 · Oct 28, 2015
Related Publication 20190036900A1 · Jan 31, 2019
Cited By (3)
US 12,395,439 US 12,501,225 US 12,511,424