IP Library › Granted Patent US 12,375,496
Granted Patent B2
US 12,375,496 · App. 18/770,596 · Granted Jul 29, 2025

Inferring trust in computer networks

Inventors: Charles Damian O'Neill (Ballymena, GB); Kieran Gerald McPeake (Belfast, GB); Simon James (Newtownards, GB); Hayden Paul Shorter (Bangor, GB)
Assignee: Juniper Networks, Inc.
H04L63/102G06N5/04H04L41/12H04L63/105H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,496
App. No.
18/770,596
Filed
Jul 11, 2024
Granted
Jul 29, 2025
Kind
B2
Art Unit
2434
USPC
726/22
Abstract

This disclosure describes techniques including assessing trust in a computer network. In one example, this disclosure describes a method that includes determining a level of trust that a first network entity has for a second network entity; determining a level of trust that the second network entity has for a third network entity; determining that the first network entity is separated from the third network entity by the second network entity; determining, based on the level of trust that the first network entity has for the second network entity and further based on the level of trust that the second network entity has for the third network entity, a level of trust that the first network entity has for the third network entity; and enabling, based on the level of trust that the first network entity has for the third network entity, the first network entity to perform an operation.

Claims (68)

1. A system comprising a storage device and processing circuitry having access to the storage device, wherein the processing circuitry is configured to:

determine a first level of trust that a first network device has for a second network device;

determine a second level of trust that the second network device has for a third network device;

determine that the first network device is separated from the third network device by the second network device;

identify, based on the first level of trust and the second level of trust, an inferred level of trust that the first network device has for the third network device;

assign, based on the inferred level of trust, one of a finite number of trust categories to the inferred level of trust;

output a user interface expressing the inferred level of trust using the assigned one of the finite number of trust categories; and

enable, based on the inferred level of trust, the first network device to perform an operation with the third network device.

2. The system of claim 1 , wherein to assign one of the finite number of trust categories to the inferred level of trust, the processing circuitry is further configured to:

assign one of two trust categories to the inferred level of trust.

3. The system of claim 1 , wherein to assign one of the finite number of trust categories to the inferred level of trust, the processing circuitry is further configured to:

assign one of four trust categories to the inferred level of trust.

4. The system of claim 1 , wherein to assign one of the finite number of trust categories to the inferred level of trust, the processing circuitry is further configured to:

assign a category of trust for a specific operation.

5. The system of claim 4 , wherein to assign a category of trust for a specific operation, the processing circuitry is further configured to:

assign a category of trust for a data transfer operation.

6. The system of claim 4 , wherein to assign a category of trust for a specific operation, the processing circuitry is further configured to:

assign a category of trust for a testing operation.

7. The system of claim 1 , wherein the processing circuitry is further configured to:

detect a change in the first level of trust; and

adjust, based on the change in the first level of trust, the inferred level of trust that the first network device has for the third network device.

8. The system of claim 7 , wherein the processing circuitry is further configured to:

assign, based on the adjusted inferred level of trust, a different one of the finite number of trust categories to the adjusted inferred level of trust; and

output an updated user interface expressing the adjusted inferred level of trust using the different one of the finite number of trust categories.

9. The system of claim 1 , wherein the processing circuitry is further configured to:

detect a change in the second level of trust;

adjust, based on the change in the second level of trust, the inferred level of trust that the first network device has for the third network device;

assign, based on the adjusted inferred level of trust, a different one of the finite number of trust categories to the adjusted inferred level of trust; and

output an updated user interface expressing the adjusted inferred level of trust using the different one of the finite number of trust categories.

10. The system of claim 1 , wherein to enable the first network device to perform an operation with the third network device, the processing circuitry is further configured to:

enable a network to transfer data between the first network device and the third network device.

11. A method comprising:

determining, by a computing system, a first level of trust that a first network device has for a second network device;

determining, by the computing system, a second level of trust that the second network device has for a third network device;

determining, by the computing system, that the first network device is separated from the third network device by the second network device;

identifying, by the computing system and based on the first level of trust and the second level of trust, an inferred level of trust that the first network device has for the third network device;

assigning, by the computing system and based on the inferred level of trust, one of a finite number of trust categories to the inferred level of trust;

outputting, by the computing system, a user interface expressing the inferred level of trust using the assigned one of the finite number of trust categories; and

enabling, by the computing system and based on the inferred level of trust, the first network device to perform an operation with the third network device.

12. The method of claim 11 , wherein assigning one of the finite number of trust categories to the inferred level of trust includes:

assigning one of two trust categories to the inferred level of trust.

13. The method of claim 11 , wherein assigning one of the finite number of trust categories to the inferred level of trust includes:

assigning one of four trust categories to the inferred level of trust.

14. The method of claim 11 , wherein assigning one of the finite number of trust categories to the inferred level of trust includes:

assigning a category of trust for a specific operation.

15. The method of claim 14 , wherein assigning a category of trust for a specific operation includes:

assigning a category of trust for a data transfer operation.

16. The method of claim 14 , wherein assigning a category of trust for a specific operation includes:

assigning a category of trust for a testing operation.

17. The method of claim 11 , further comprising:

detecting, by the computing system, a change in the first level of trust; and

adjusting, by the computing system and based on the change in the first level of trust, the inferred level of trust that the first network device has for the third network device.

18. The method of claim 17 , further comprising:

assigning, by the computing system and based on the adjusted inferred level of trust, a different one of the finite number of trust categories to the adjusted inferred level of trust; and

outputting, by the computing system, an updated user interface expressing the adjusted inferred level of trust using the different one of the finite number of trust categories.

19. The method of claim 11 , further comprising:

detecting, by the computing system, a change in the second level of trust;

adjusting, by the computing system and based on the change in the second level of trust, the inferred level of trust that the first network device has for the third network device;

assigning, by the computing system and based on the adjusted inferred level of trust, a different one of the finite number of trust categories to the adjusted inferred level of trust; and

outputting, by the computing system, an updated user interface expressing the adjusted inferred level of trust using the different one of the finite number of trust categories.

20. Non-transitory computer-readable storage media comprising instructions that, when executed, configure processing circuitry of a computing system to:

determine a first level of trust that a first network device has for a second network device;

determine a second level of trust that the second network device has for a third network device;

determine that the first network device is separated from the third network device by the second network device;

identify, based on the first level of trust and the second level of trust, an inferred level of trust that the first network device has for the third network device;

assign, based on the inferred level of trust, one of a finite number of trust categories to the inferred level of trust;

output a user interface expressing the inferred level of trust using the assigned one of the finite number of trust categories; and

enable, based on the inferred level of trust, the first network device to perform an operation with the third network device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: O'NEILL, CHARLES DAMIAN; MCPEAKE, KIERAN GERALD; JAMES, SIMON; SHORTER, HAYDEN PAUL
To: JUNIPER NETWORKS, INC.
Reel/Frame 072054/0962 →
Continuity (2)
Continuation 17474871 · Sep 14, 2021
Related Publication 20240364694A1 · Oct 31, 2024
References Cited (122)
US 7558884B2 · Fuller et al. · 2009 [cited by applicant]
US 7788700B1 · Feezel et al. · 2010 [cited by applicant]
US 7895068B2 · LaSalle et al. · 2011 [cited by applicant]
US 7900259B2 · Jeschke et al. · 2011 [cited by applicant]
US 8205257B1 · Satish et al. · 2012 [cited by applicant]
US 8549622B2 · Byrne et al. · 2013 [cited by applicant]
US 8776180B2 · Kumar et al. · 2014 [cited by applicant]
US 9363283B1 · Herrera-Yagiie et al. · 2016 [cited by applicant]
US 9679254B1 · Mawji et al. · 2017 [cited by applicant]
US 9860275B2 · Kleinpeter et al. · 2018 [cited by applicant]
US 10068095B1 · Segal et al. · 2018 [cited by applicant]
US 10237293B2 · Hajmasan et al. · 2019 [cited by applicant]
US 10432605B1 · Lester et al. · 2019 [cited by applicant]
US 10491594B2 · Yan · 2019 [cited by applicant]
US 10511510B2 · Ricci · 2019 [cited by applicant]
US 10855619B1 · Andrews et al. · 2020 [cited by applicant]
US 10855725B2 · Pai et al. · 2020 [cited by applicant]
US 10924377B2 · Chauhan · 2021 [cited by applicant]
US 10958673B1 · Chen et al. · 2021 [cited by applicant]
US 11038766B2 · Shen et al. · 2021 [cited by applicant]
US 11321464B2 · Govardhan · 2022 [cited by applicant]
US 11386129B2 · Chrapko et al. · 2022 [cited by applicant]
US 11503061B1 · Lin et al. · 2022 [cited by applicant]
US 11640569B2 · Chrapko · 2023 [cited by applicant]
US 11683331B2 · Grammel et al. · 2023 [cited by applicant]
US 11695558B2 · Ray · 2023 [cited by examiner]
US 12074879B2 · O'Neill et al. · 2024 [cited by applicant]
US 12170670B2 · O'Neill et al. · 2024 [cited by applicant]
US 20050132229A1 · Zhang · 2005 [cited by examiner]
US 20060248573A1 · Pannu et al. · 2006 [cited by applicant]
US 20070107059A1 · Chasin et al. · 2007 [cited by applicant]
US 20070147594A1 · Aaron et al. · 2007 [cited by applicant]
US 20090100504A1 · Conner et al. · 2009 [cited by applicant]
US 20090165116A1 · Morris · 2009 [cited by applicant]
US 20090172776A1 · Makagon et al. · 2009 [cited by applicant]
US 20100220613A1 · Hendriks et al. · 2010 [cited by applicant]
US 20110072508A1 · Agarwal et al. · 2011 [cited by applicant]
US 20110280160A1 · Yang · 2011 [cited by applicant]
US 20130097317A1 · Sheleheda · 2013 [cited by examiner]
US 20130138290A1 · Falkenstein · 2013 [cited by applicant]
US 20130298192A1 · Kumar et al. · 2013 [cited by applicant]
US 20130298242A1 · Kumar et al. · 2013 [cited by applicant]
US 20130298244A1 · Kumar et al. · 2013 [cited by applicant]
US 20140325586A1 · Halliday et al. · 2014 [cited by applicant]
US 20150074390A1 · Stoback et al. · 2015 [cited by applicant]
US 20150156208A1 · Kirkham et al. · 2015 [cited by applicant]
US 20150180903A1 · Cooper et al. · 2015 [cited by applicant]
US 20150304327A1 · Burstein · 2015 [cited by examiner]
US 20150312267A1 · Thomas · 2015 [cited by applicant]
US 20160191540A1 · Fuka et al. · 2016 [cited by applicant]
US 20160261613A1 · Farmer et al. · 2016 [cited by applicant]
US 20160277424A1 · Mawji et al. · 2016 [cited by applicant]
US 20160373486A1 · Kraemer · 2016 [cited by applicant]
US 20160381079A1 · Ben-Shalom · 2016 [cited by examiner]
US 20170140305A1 · Moss · 2017 [cited by applicant]
US 20170171231A1 · Reybok, Jr. et al. · 2017 [cited by applicant]
US 20180075563A1 · Ananthanpillai et al. · 2018 [cited by applicant]
US 20180091453A1 · Jakobsson · 2018 [cited by applicant]
US 20180183827A1 · Zorlular et al. · 2018 [cited by applicant]
US 20180219865A1 · Das · 2018 [cited by applicant]
US 20190182286A1 · Zini · 2019 [cited by applicant]
US 20190207954A1 · Ahuja et al. · 2019 [cited by applicant]
US 20190268366A1 · Zeng et al. · 2019 [cited by applicant]
US 20200012796A1 · Trepagnier et al. · 2020 [cited by applicant]
US 20200067935A1 · Carnes, III et al. · 2020 [cited by applicant]
US 20200302540A1 · Xiu · 2020 [cited by applicant]
US 20200356676A1 · Gorlamandala · 2020 [cited by applicant]
US 20210029152A1 · Charles et al. · 2021 [cited by applicant]
US 20210075794A1 · Gazit et al. · 2021 [cited by applicant]
US 20210273968A1 · Al Shaieb et al. · 2021 [cited by applicant]
US 20210409405A1 · Salajegheh et al. · 2021 [cited by applicant]
US 20220043913A1 · Keith, Jr. · 2022 [cited by applicant]
US 20220103592A1 · Semel et al. · 2022 [cited by applicant]
US 20220210142A1 · Sohail et al. · 2022 [cited by applicant]
US 20220329630A1 · Li · 2022 [cited by applicant]
US 20220345394A1 · Vasseur et al. · 2022 [cited by applicant]
US 20230083952A1 · O'Neill et al. · 2023 [cited by applicant]
US 20230128998A1 · Ping · 2023 [cited by examiner]
US 20230185943A1 · Zhang et al. · 2023 [cited by applicant]
US 20230188527A1 · O'Neill et al. · 2023 [cited by applicant]
US 20230300150A1 · O'Neill et al. · 2023 [cited by applicant]
US 20240223589A1 · Grammel et al. · 2024 [cited by applicant]
US 20240364694A1 · O'Neill et al. · 2024 [cited by applicant]
US 20250030739A1 · O'Neill et al. · 2025 [cited by applicant]
CN 1716177A · 2006 [cited by applicant]
CN 101507229A · 2009 [cited by applicant]
CN 106575323A · 2017 [cited by applicant]
CN 108075925A · 2018 [cited by applicant]
CN 109196505A · 2019 [cited by applicant]
CN 109564669A · 2019 [cited by applicant]
CN 109891422A · 2019 [cited by applicant]
CN 109948911A · 2019 [cited by applicant]
CN 110249588A · 2019 [cited by applicant]
CN 110313009A · 2019 [cited by applicant]
EP 1832059A1 · 2007 [cited by applicant]
EP 3343864A1 · 2018 [cited by applicant]
EP 4002795A1 · 2022 [cited by applicant]
WO 2006070172A1 · 2006 [cited by applicant]
WO 2006094275A2 · 2006 [cited by applicant]
“Cybersecurity of 5G networks EU Toolbox of risk mitigating measures,” NIS Cooperation Group, CG Publication, Jan. 2020, 45 pp. [cited by applicant]
“Overview of Risks Introduced by 5G Adoption in the United States,” Critical Infrastructure Security and Resilience Note, Cybersecurity and Infrastructure Security Agency, Jul. 31, 2019, 16 pp. [cited by applicant]
“Time Guidance for Network Operators, Chief Information Officers, and Chief Information Security Officers,” Cybersecurity and Infrastructure Security Agency, Jun. 2020, 18 pp. [cited by applicant]
CIS Benchmarks, “CIS Cisco IOS 15 Benchmark”, National Institute of Standards and Technology, vol. 4, No. 1, Apr. 11, 2022, 214 pp., URL: https://ncp.nist.gov/checklist/599. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 22150744.5 dated Dec. 20, 2023, 7 pp. [cited by applicant]
Conran, “Zero Trust Networking (ZTN): don't trust anything,” The Network Architect, Sep. 18, 2018, 7 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 22150744.5 dated Jun. 27, 2022, 9 pp. [cited by applicant]
Jian et al., “Dynamic Evaluation Method of Network Trust based on Congnitive Behavior,” Communications Technology, vol. 49, No. 9, Sep. 2016, 6 pp. [cited by applicant]
Lu et al., “Trust Evaluation in Networked Manufacturing Environment,” Journal of WUT, vol. 35 No. 2, Apr. 2013, 4 pp. [cited by applicant]
Mandaglio et al, Generalized Preference Learning for Trust Network Inference, IEEE, Dec. 2, 2019, pp. 174583-174596. ( Year: 2019). [cited by applicant]
Omeyer, “7 Top Metrics for Measuring Your Technical Debt”, Jan. 13, 2022, 6 pp., URL: https://dev.to/alexomeyer/8-top-metrics-for-measuring-your-technical-debt-5bnm. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/474,871, dated Oct. 6, 2023 through Jul. 11, 2024, 55 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/655,140, dated May 20, 2024 through Aug. 20, 2024, 35 pp. [cited by applicant]
Response to Communication pursuant to Article 94(3) EPC dated Dec. 20, 2023, from counterpart European Application No. 22150744.5 filed Apr. 18, 2024, 10 pp. [cited by applicant]
Response to Extended Search Report dated Jun. 27, 2022, from counterpart European Application No. 22150744.5 filed Sep. 14, 2023, 17 pp. [cited by applicant]
U.S. Appl. No. 18/353,575, filed Jul. 17, 2023, by O'Neill et al. [cited by applicant]
Zhang et al., Mining Users Trust From E-commerce Reviews Based on Sentiment Similarity Analysis, IEEE, Jan. 31, 2019, pp. 13523-13535. (Year: 2019). [cited by applicant]
Advisory Action from U.S. Appl. No. 17/655,140 dated Feb. 5, 2025, 3 pp. [cited by applicant]
Final Office Action from U.S. Appl. No. 17/655,140 dated Nov. 21, 2024, 12 pp. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 22150744.5 dated Oct. 4, 2024, 71 pp. [cited by applicant]
Response to Final Office Action dated Nov. 21, 2024 from U.S. Appl. No. 17/655,140, filed Jan. 21, 2025, 8 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 25155589.2 dated Apr. 1, 2025, 11 pp. [cited by applicant]
First Office Action and Search Report from counterpart Chinese Application No. 202210044616.3 dated Apr. 16, 2025, 15 pp. Translation Attached. [cited by applicant]