US 11,700,258 B2
Access relationships in a computer system
Vesa Luukkala, Helsinki (FI)
Assigned to SSH Communications Security OYJ, Helsinki (FI)
Filed by SSH Communications Security OYJ, Helsinki (FI)
Filed on Dec. 30, 2016, as Appl. No. 15/394,871.
Prior Publication US 2018/0191725 A1, Jul. 5, 2018
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/101 (2013.01) [H04L 63/0281 (2013.01); H04L 63/0428 (2013.01); H04L 63/06 (2013.01); H04L 63/083 (2013.01); H04L 63/0823 (2013.01); H04L 63/102 (2013.01); H04L 63/1466 (2013.01); H04L 63/166 (2013.01); H04L 63/20 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for controlling, by a network control apparatus of a computerised network system, trust relationships between entities capable of communicating with each other in the computerised network system, the method comprising:
determining, by the network control apparatus, an existing chain of trust relationships from a first entity via at least one intermediate entity to a second entity, wherein the first entity, the second entity, and the at least one intermediate entity each provide a separate node in the determined existing chain of trust relationships,
creating, by the network control apparatus and based on the determined existing chain of trust relationships from the first entity via the at least one intermediate entity to the second entity, at least one new secured direct trust relationship between the first entity and the second entity, wherein the created at least one new secured direct trust relationship between the first entity and the second entity provides a shorter chain of trust relationships via fewer intermediate entities than the determined existing chain of trust relationships from the first entity via the at least one intermediate entity to the second entity and wherein the created at least one new secured direct trust relationship is secured based on security credentials comprising at least one of a key or a certificate according to a security protocol, and
causing, by the network control apparatus, storing information of the created at least one new secured direct trust relationship between the first entity and the second entity in a database of trust relationships.