Open Access

Zero Trust Architecture in Modern Cybersecurity: A Review of Core Principles, Applications, And Research Directions

4 Associate Professor, Department of Computer Science and Engineering, ITM(SLS) University, Vadodara, Gujarat, India

Abstract

Cloud computing, Internet of Things (IoT) devices, remote working environments and distributed digital infrastructures have driven the evolution of the perimeter-based security model to its limits. To counter this, Zero Trust Architecture (ZTA) has become a contemporary cybersecurity paradigm based on the principle of “never trust, always verify,” which would involve ongoing checks, authentication, and authorization of users, devices, and applications. The paper provides a summary and covers all the key points of the ZTA, such as its principles, logical structure, security models and implementation. The study applies some of the main concepts, such as least-privilege access, micro-segmentation, continuous verification, policy-based access control and real-time security analytics. Additionally, the paper covers the use of ZTA in different industries, including IoT, cloud computing, Secure Access Service Edge (SASE), and identity-centric security solutions.  A comparative analysis of the research contributions in the recent years is conducted to assess the recent advances, issues, and barriers of ZTA adoption. The survey points out other areas for further research including lightweight cryptography, dynamic trust evaluation, automated orchestration, scalability, interoperability, regulatory compliance. The survey provides a detailed reference guide for researchers, practitioners and policymakers to grasp and apply the principles of ZTA in the modern cyber security environment.

Keywords

References

R. Keshava, S. K. Pandurangan, M. Sakthivanitha, S. Parmsivan, G. Sunkara, and R. Maruthi, “AI-Powered Algorithms for the Prevention and Detection of Computer Malware Infections,” in 2025 6th International Conference on Electronics and Sustainable Communication Systems (ICESC), IEEE, Sep. 2025, pp. 1673–1680. doi: 10.1109/ICESC65114.2025.11212519.
V. Sharma, “Zero Trust Architecture for 5G Networks,” Int. J. Innov. Res. Eng. Multidiscip. Phys. Sci., vol. 12, no. 6, pp. 1–11, Nov. 2024, doi: 10.37082/IJIRMPS.v12.i6.232707.
J. B. Mehta, “Securing Test Automation in Zero Trust Architectures: A Framework for Continuous Verification,” in 2025 International Conference on Computer and Applications (ICCA), IEEE, Dec. 2025, pp. 1–5. doi: 10.1109/ICCA66035.2025.11430950.
S. Tyagi and A. Tyagi, “Evaluating the Performance with Deep Learning Techniques in Cybersecurity for Effective Threat Detection,” 2026, pp. 437–452. doi: 10.1007/978-981-96-8687-2_31.
N. Adik, “The Rise of Open and Free Networks: A Community-Driven Paradigm for Decentralized Connectivity,” in 2025 IEEE First International Conference on Innovations in Engineering and Next-Generation Technologies for Sustainability (ICINVENTS), Coimbatore, India: IEEE, 2025, pp. 1–9, November. doi: 10.1109/ICINVENTS64613.2025.11402224.
S. Ameer, L. Praharaj, R. Sandhu, S. Bhatt, and M. Gupta, “ZTA-IoT: A Novel Architecture for Zero-Trust in IoT Systems and an Ensuing Usage Control Model,” ACM Trans. Priv. Secur., vol. 27, no. 3, Aug. 2024, doi: 10.1145/3671147.
S. Al-Tamimi, Q. A. Al-Haija, and K. Alrawashdeh, “Zero-Trust Architecture for Securing Internet of Things (IoT) Networks: A Review,” in CIEES 2024 - IEEE International Conference on Communications, Information, Electronic and Energy Systems, 2024. doi: 10.1109/CIEES62939.2024.10811176.
Z. ElSayed, N. Elsayed, and S. Bay, “A Novel Zero-Trust Machine Learning Green Architecture for Healthcare IoT Cybersecurity: Review, Analysis, and Implementation,” in SoutheastCon 2024, IEEE, Mar. 2024, pp. 686–692. doi: 10.1109/SoutheastCon52093.2024.10500139.
I. A. Khan et al., “A context-aware zero trust-based hybrid approach to IoT-based self-driving vehicles security,” Ad Hoc Networks, 2025, doi: 10.1016/j.adhoc.2024.103694.
K. Li et al., “Zero-Trust Foundation Models: A New Paradigm for Secure and Collaborative Artificial Intelligence for Internet of Things,” IEEE Internet Things J., May 2025, doi: 10.1109/JIOT.2025.3603957.
A. M. Abdelmagid and R. Diaz, “Zero Trust Architecture as a Risk Countermeasure in Small–Medium Enterprises and Advanced Technology Systems,” Risk Anal., 2025, doi: 10.1111/risa.70026.
S. Mushtaq, M. Mohsin, and M. M. Mushtaq, “A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains,” 2025. doi: 10.3390/s25196118.
J. B. Mehta, “An Autonomous Dependency And Failure-Propagation Modeling System For Security-Critical Distributed Enterprise Cloud Computing Environments,”,” 202641001713, 2026
N. D. Bhandarwar, “A Mathematical Framework For Explainable And Adversarially Robust Ids Using Ml For Large-Scale Enterprise And Cloud Systems,” Int. J. Appl. Math., vol. 39, no. 1s, pp. 1200–1212, Jan. 2026, doi: 10.12732/ijam.v39i1s.1910.
V. K. Bollu, “Threat Landscape in Artificial Intelligence Systems: Taxonomy, Attack Vectors and Security Implications,” World J. Adv. Res. Rev., vol. 29, no. 1, pp. 285–294, 2026, doi: 10.30574/wjarr.2026.29.1.0007.
B. Embrey, “The top three factors driving zero trust adoption,” Comput. Fraud Secur., 2020, doi: 10.1016/S1361-3723(20)30097-X.
N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero Trust Architecture (ZTA): A Comprehensive Survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022, doi: 10.1109/ACCESS.2022.3174679.
D. Jain and S. Jain, “Artificial Intelligence (AI)-Driven Network Traffic Anomaly Detection for IT Infrastructure Security,” in 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC), IEEE, Feb. 2026, pp. 1–6. doi: 10.1109/ICAIC67076.2026.11395685.
H. K. Yadav, “Design and Implement Machine Learning Based Predictive Analytics for Road Safety and Accident Prevention,” in 2026 IEEE International Conference on Interdisciplinary Approaches in Technology and Management for Social Innovation (IATMSI), Gwalior, India: IEEE, 2026, pp. 1–6, March. doi: 10.1109/IATMSI68868.2026.11465965.
Y. Muni, “A Review of Efficient Routing Architectures Using OSPF, BGP, and MPLS in Multi-Protocol Networks,” Eng. Technol. J., vol. 11, no. 01, Jan. 2026, doi: 10.47191/etj/v11i01.21.
Z. Yan, P. Zhang, and A. V. Vasilakos, “A survey on trust management for Internet of Things,” J. Netw. Comput. Appl., vol. 42, pp. 120–134, Jun. 2014, doi: 10.1016/j.jnca.2014.01.014.
S. Singh, “Advancing Network Security in 5G: Leveraging the 5G-NIDD Dataset for Intrusion Detection and Mitigation,” in 2025 IEEE 12th International Conference on Cyber Security and Cloud Computing (CSCloud), IEEE, Nov. 2025, pp. 1–6. doi: 10.1109/CSCloud66326.2025.00055.
D. Horne and S. Nair, “Introducing Zero Trust by Design: Principles and Practice Beyond the Zero Trust Hype,” dvances Secur. Networks, Internet Things (SAM, ICWN, ICOMP, ESCS 2021), pp. 512–525, 2021.
R. Lingam, S. Nagi, M. Chigurupati, and B. T. Myneni, “Resilient DevSecOps: Self-Healing Cloud-Native Systems via SRE-Driven AI Threat Detection and Response,” in 2026 International Conference on Smart Futuristic Technology, IEEE, Jan. 2026, pp. 1–6. doi: 10.1109/ICSFT66733.2026.11508049.
S. Ghasemshirazi, G. Shirvani, and M. A. Alipour, “Zero Trust: Applications, Challenges, and Opportunities,” 2023.
S. Yiliyaer and Y. Kim, “Secure Access Service Edge: A Zero Trust Based Framework For Accessing Data Securely,” in 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC), IEEE, Jan. 2022, pp. 0586–0591. doi: 10.1109/CCWC54503.2022.9720872.
S. R. Kandula, N. Kassetty, K. S. ALANG, and P. Pandey, “Context-Aware Multi-Factor Authentication in Zero Trust Architecture: Enhancing Security Through Adaptive Authentication,” Int. J. Glob. Innov. Solut., Dec. 2024, doi: 10.21428/e90189c8.f525ef41.
T. Chuan, Y. Lv, Z. Qi, L. Xie, and W. Guo, “An Implementation Method of Zero-trust Architecture,” J. Phys. Conf. Ser., vol. 1651, no. 1, p. 012010, Nov. 2020, doi: 10.1088/1742-6596/1651/1/012010.
S. Ahmadi, “Zero Trust Architecture in Cloud Networks: Application, Challenges and Future Opportunities,” J. Eng. Res. Reports, vol. 26, pp. 215–228, 2024, doi: 10.9734/JERR/2024/v26i21083.
Y. Cao, S. R. Pokhrel, Y. Zhu, R. Doss, and G. Li, “Automation and Orchestration of Zero Trust Architecture: Potential Solutions and Challenges,” 2024. doi: 10.1007/s11633-023-1456-2.
M. Nasiruzzaman, M. Ali, I. Salam, and M. H. Miraz, “The Evolution of Zero Trust Architecture (ZTA) from Concept to Implementation,” in 2025 29th International Conference on Information Technology, IT 2025, 2025. doi: 10.1109/IT64745.2025.10930254.
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” Gaithersburg, MD, Aug. 2020. doi: 10.6028/NIST.SP.800-207.
S. Mthethwa, E. Jembere, and M. Dlamini, “IAM-based Zero Trust Architecture for IoT: Securing Non-Human Identities in a Connected World,” in 2025 IEEE International Conference on Smart Internet of Things (SmartIoT), IEEE, Nov. 2025, pp. 428–435. doi: 10.1109/SmartIoT66867.2025.00069.
L. Ahuja, S. Vashisth, and A. Thakur, “Integrating SIEM with Zero Trust Architecture,” in 2025 International Conference on Intelligent and Innovative Technologies in Computing, Electrical and Electronics (IITCEE), IEEE, Jan. 2025, pp. 1–6. doi: 10.1109/IITCEE64140.2025.10915422.
P. SumanPrakash et al., “Learning-driven Continuous Diagnostics and Mitigation program for secure edge management through Zero-Trust Architecture,” Comput. Commun., vol. 220, pp. 94–107, Apr. 2024, doi: 10.1016/j.comcom.2024.04.007.
R. P. Reddy, “Zero Trust Architectures in Modern Enterprises: Principles, Implementation Challenges, and Best Practices,” Int. J. Comput. Trends Technol., vol. 73, no. 6, pp. 48–57, Jun. 2025, doi: 10.14445/22312803/IJCTT-V73I6P107.
A. Soni, S. Kumar Nanda, R. Priyadarshini, and G. Panda, “A comprehensive review and comparative analysis of zero trust architecture: Evolution, implementation strategies, and key challenges,” J. Comput. Secur., vol. 34, no. 2, pp. 85–110, Mar. 2026, doi: 10.1177/0926227X251409922.
A. Pigola, F. de Souza Meirelles, and P. R. da Costa, “Trust Management in the Age of Zero trust: a comprehensive multi-method analysis from enterprise challenges,” Enterp. Inf. Syst., vol. 20, no. 1, Jan. 2026, doi: 10.1080/17517575.2025.2588753.
M. L. Gambo and A. Almulhem, “Zero Trust Architecture: A Systematic Literature Review,” 2025.
P. Dhiman et al., “A Review and Comparative Analysis of Relevant Approaches of Zero Trust Network Model,” Sensors, vol. 24, no. 4, p. 1328, Feb. 2024, doi: 10.3390/s24041328.
F. Mensah, “Zero Trust Architecture: A Comprehensive Review of Principles, Implementation Strategies, and Future Directions in Enterprise Cybersecurity,” Int. J. Adv. Res., vol. 10, no. 6, pp. 2454–132, 2024.
H. Kang, G. Liu, Q. Wang, L. Meng, and J. Liu, “Theory and Application of Zero Trust Security: A Brief Survey,” Entropy, vol. 25, no. 12, 2023, doi: 10.3390/e25121595.
Y. He, D. Huang, L. Chen, Y. Ni, and X. Ma, “A Survey on Zero Trust Architecture: Challenges and Future Trends,” Wirel. Commun. Mob. Comput., vol. 2022, no. 1, Jan. 2022, doi: 10.1155/2022/6476274.

Similar Articles

11-20 of 61

You may also start an advanced similarity search for this article.