While we have previously explored the fundamental shift from binary to quantifiable trust, the actual realisation of this vision requires a specialised architecture capable of monitoring every corner of the Computing Continuum. In heterogeneous and distributed high-stakes environments like autonomous drone swarms or first responder networks -where end-to-end service assurances demand the tight convergence of volatile network Quality of Service (QoS) and continuous runtime security guarantees- a centralised security model creates “trust blind spots”. CASTOR addresses this by a federated trust assessment framework, a “dual brain” system that intelligently divides the massive task of trust assessment between the Local TAF Agent and the Global TAF.
The first half of this “dual brain” is the Local TAF agent, which is instantiated directly on each element in the infrastructure layer where the network functions are deployed. The Local TAF agent relies on the layered CASTOR Trusted Computing Base (TCB) for the secure measurement, collection, and sharing of trustworthiness evidence with respect to critical security properties of the forwarding plane. These pieces of evidence elevate the agent to the primary sensory organ for the device’s internal health, continuously assessing “atomic” propositions (the most granular and measurable trust statements possible) to verify that the device is behaving exactly as expected.
This includes confirming the device booted from a verified, cryptographically signed image, ensuring platform configurations match trusted references, and utilising Finite State Machine (FSM) analysis to detect real-time behavioural anomalies in critical routing functions.
While the Local TAF understands the individual device, the Global TAF understands the network as a whole. Located at the orchestration layer, this centralised service maintains a dynamic, end-to-end view of the entire infrastructure by collecting and composing reports from all local agents. The Global TAF’s primary responsibility is to elevate local trustworthiness claims into actionable, topology-wide trust insights. This process is mathematically rigorous; for instance, it can apply a minimum rule for integrity requirements (where the weakest node along a path dictates the final score) or an average rule when assessing statistical resilience. To maintain absolute accuracy, the Global TAF applies subjective logic discounting, effectively weighting a device’s report based on how trustworthy that specific Local TAF agent is currently perceived to be.
The ultimate goal of this interconnected assessment model is to guarantee that every critical service travels over a path that strictly satisfies its Secure Service Level Agreement (SSLA). By constantly comparing real-time path scores against the Required Trust Level (RTL), the Global TAF can trigger immediate adaptation. If a router’s runtime integrity degrades, the system detects the drop in the Actual Trust Level (ATL) and initiates fast “re-colouring” adaptation strategies and alerts the optimisation engine to instantly steer sensitive traffic onto a new, compliant route.
This federated trust model ensures that even in the most dynamic scenarios, network trust posture is never assumed, but continuously proven and enforced.