Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1250-1263.doi: 10.3969/j.issn.1671-1122.2026.08.007

Previous Articles     Next Articles

Review of zero trust architecture and its technical applications

Zhao Min, Qu Kangjian()   

  1. College of Command and Control Engineering, Army Engineering University, Nanjing 210007, China
  • Received:2026-03-10 Online:2026-08-10 Published:2026-09-23
  • Contact: Qu Kangjian E-mail:1622038290@qq.com

Abstract:

With the rapid development of cloud computing and the Internet of things (IoT), network boundaries are becoming increasingly blurred, exposing the limitations of traditional perimeter-based security models. The zero trust security model follows the principle of “never trust, always verify”, requiring continuous authentication for every access attempt without assuming trust for any device or user. This paper reviewed the core concepts and evolution of zero trust, summarized leading architectures, and examined key supporting technologies. It further explored zero trust applications in cloud computing, IoT, and blockchain, analyzed its advantages and limitations, particularly its applicability in multi-cloud environments and resource-constrained IoT devices. Finally, it investigated technical challenges and debated surrounding zero trust implementation, highlighted future research directions, with a focus on the potential integration of artificial intelligence and zero trust.

Key words: zero trust, identity and access management, software-defined perimeter, micro-segmentation, zero trust application

CLC Number: