信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1250-1263.doi: 10.3969/j.issn.1671-1122.2026.08.007

• 学术研究 • 上一篇    下一篇

零信任架构及其技术应用研究综述

赵敏, 瞿康健()   

  1. 陆军工程大学指挥控制工程学院南京 210007
  • 收稿日期:2026-03-10 出版日期:2026-08-10 发布日期:2026-09-23
  • 通讯作者: 瞿康健 E-mail:1622038290@qq.com
  • 作者简介:赵敏(1980—),男,江苏,副教授,博士,主要研究方向为网络安全、软件安全|瞿康健(1999—),男,江苏,硕士研究生,主要研究方向为网络安全、零信任
  • 基金资助:
    国家自然科学基金(62172432);江苏省自然科学基金(BK20242076)

Review of zero trust architecture and its technical applications

Zhao Min, Qu Kangjian()   

  1. College of Command and Control Engineering, Army Engineering University, Nanjing 210007, China
  • Received:2026-03-10 Online:2026-08-10 Published:2026-09-23
  • Contact: Qu Kangjian E-mail:1622038290@qq.com

摘要:

随着云计算、物联网等技术的迅速发展,网络边界日趋模糊,传统基于边界的网络安全防护模型逐渐显现出其局限性。零信任安全模型遵循“默认不信任”原则,对所有设备和用户均不预设信任,并通过持续动态验证来确保每次访问的安全性。文章系统梳理了零信任的核心理念及其演进历程,回顾了近年来国内外主流零信任架构,并综述支撑零信任架构的关键技术。在此基础上,文章还深入探讨零信任在云计算、物联网和区块链等领域的应用现状,分析其优势与不足,并指出在跨云环境、物联网设备等资源受限场景下所面临的适用性问题。最后,文章分析了零信任架构在实现过程中面临的争议与技术挑战,展望了零信任架构及其技术应用的未来发展方向,尤其关注人工智能与零信任深度融合等潜在应用场景。

关键词: 零信任, 身份与访问管理, 软件定义边界, 微隔离, 零信任应用

Abstract:

With the rapid development of cloud computing and the Internet of things (IoT), network boundaries are becoming increasingly blurred, exposing the limitations of traditional perimeter-based security models. The zero trust security model follows the principle of “never trust, always verify”, requiring continuous authentication for every access attempt without assuming trust for any device or user. This paper reviewed the core concepts and evolution of zero trust, summarized leading architectures, and examined key supporting technologies. It further explored zero trust applications in cloud computing, IoT, and blockchain, analyzed its advantages and limitations, particularly its applicability in multi-cloud environments and resource-constrained IoT devices. Finally, it investigated technical challenges and debated surrounding zero trust implementation, highlighted future research directions, with a focus on the potential integration of artificial intelligence and zero trust.

Key words: zero trust, identity and access management, software-defined perimeter, micro-segmentation, zero trust application

中图分类号: