Trust in the Factory: Mining Social Networks for NME Access Control
Discovering the Social Network and Trust Relationship in a Networked Manufacturing Environment
This paper proposes a social network-driven trust management framework for Access Control in Networked Manufacturing Environments (NME). It introduces a specific XML schema for log mining and an algorithm to calculate trust intensity based on role-based sub-environments (DAE, CPE, PSE).
TL;DR
In modern Networked Manufacturing Environments (NME), static permissions are insufficient. This paper introduces a method to automatically discover social networks and calculate Trust Intensity from system logs. By categorizing work into Daily Affairs, Projects, and Personal environments, the framework provides a mathematical basis for dynamic access control policies that adapt to how users actually interact.
The Contextual Trust Gap
In a collaborative manufacturing hub, a user named "A" wears many hats. They are a department member, a project sub-team leader, and a social individual. Existing security models often fail because they treat trust as a binary or global attribute.
The authors argue that Trust is domain-specific:
- DAE (Daily-Affairs Environment): Highly stable, based on organizational hierarchy.
- CPE (Collaborative Project Environment): Dynamic, time-limited, and task-specific.
- PSE (Personal Social Environment): Random and subjective.
The technical challenge lies in mining these nuances from messy system logs (ERP, CRM, MES) to inform who should see what, and when.
Methodology: From Logs to Logic
1. Unified Log Mining Schema
To solve the data heterogeneity problem, the paper proposes an XML-based Access Control Mining Format. This schema transforms standard transaction logs into security-relevant "Access Events," capturing the Actor (Subject and Owner), the Object (Resource ID and Type), and the Performance (Permit, Reject, or Suspend).

2. The Trust Intensity Formula
The core contribution is the quantitative modeling of trust. The authors identify three critical factors:
- Time Decay: Recent interactions are more relevant. They use an exponential decay function: .
- Access Results (): Successful accesses build trust (), while "Suspended" connections due to malicious intent result in a trust penalty ().
- Resource Sensitivity (): Trust is earned more by being granted access to sensitive files (e.g., "Highly Sensitive" data carries more weight than "Insensitive" data).
The trust value for a single event is defined as:
Experimental Insight: Direct vs. Recommendation Trust
The paper distinguishes between Direct Trust Relationships (DTR) and Recommendation Trust Relationships (RTR). If User A has never interacted with User B, the system calculates trust by traversing the social network graph to find intermediate "recommenders."

This dual approach ensures that even "cold-start" collaborative projects can have initial security policies based on the trust history of shared colleagues.
Critical Analysis & Future Directions
The strength of this work is its physical intuition: it mirrors how human trust works in a professional setting—weighted by time, risk, and context.
Limitations:
- Scalability: While the paper suggests a "Time Window" to manage log volume, the computational overhead of traversing large-scale recommendation chains in real-time remains a concern.
- Cold Start: The model relies on historical logs; new users with no history might face access hurdles until their "Social Network" is established.
Conclusion
This research moves us closer to "Self-Evolving Security" in manufacturing. By treating the NME as a living social network rather than a static database, the proposed trust model allows enterprises to balance collaboration and confidentiality dynamically.
Keywords: Access Control, Social Network, Trust Intention, Networked Manufacturing.
