Source-linked AI summary
Zero Trust Architecture: A Systematic Literature Review
Muhammad Liman Gambo, Ahmad Almulhem
TL;DR
Increasingly distributed digital ecosystems and sophisticated attacks expose limitations in perimeter-based security and motivate Zero Trust Architecture. This paper applies a PRISMA-based systematic literature review to synthesize ZTA applications, enabling technologies, and adoption challenges. It produces a structured taxonomy and identifies validity boundaries and implementation challenges relevant to ZTA adoption.
Problem
Distributed connectivity, heterogeneous access, and evolving cyberattacks have exposed limitations in perimeter-based security, while existing research lacked a systematic review of ZTA domains, technologies, and adoption challenges.
Method
The study uses a PRISMA-based systematic literature review to synthesize ZTA applications, enabling technologies, requirements, and challenges.
Results
The review provides a structured taxonomy of ZTA applications, implementation requirements, enabling technologies, and associated challenges across diverse domains.
Takeaways & Limitations
The taxonomy offers a reference for researchers and practitioners studying or adopting ZTA across diverse contexts and critical infrastructures.
Takeaways & Limitations
The review may omit relevant studies because its search terms could miss alternative terminology and its database coverage is limited to Scopus, Web of Science, and IEEE Xplore.
Abstract
from arXiv · showhide
The increasing complexity of digital ecosystems and evolving cybersecurity threats have highlighted the limitations of traditional perimeter-based security models, leading to the growing adoption of Zero Trust Architecture (ZTA). ZTA operates on the principle of "never trust, always verify", enforcing continuous authentication, conditional access, dynamic trust evaluation, and the principle of least privilege to enhance security across diverse domains. This study applies the PRISMA framework to analyze 10 years of research (2016-2025) on ZTA, presenting a systematic literature review (SLR) that synthesizes its applications, enabling technologies, and associated challenges. It provides a detailed taxonomy that organizes ZTA's application domains, together with the emerging technologies that facilitate its implementation, and critically examines the barriers to ZTA adoption. Additionally, the study traces the historical evolution of ZTA alongside notable events and publications trends while highlighting some potential factors for the surge over the past few years. This comprehensive analysis serves as a practical guide for researchers and practitioners seeking to leverage ZTA for stronger, more adaptive security frameworks in a rapidly shifting threat landscape.
1 Introduction
Distributed connectivity, heterogeneous access, and sophisticated attacks have exposed limits in perimeter-based security, motivating ZTA research. This SLR synthesizes ZTA applications, enabling technologies, and adoption challenges through a systematic taxonomy.
- Motivation: IoT, cloud computing, BYOD, WFH, and external partnerships have extended network boundaries and weakened the relevance of perimeter-based security models.
- ZTA Principles: ZTA applies “never trust, always verify” through continuous verification of users, devices, applications, and transactions regardless of network location.
- ZTA Principles: Continuous authentication, conditional authorization, and least privilege restrict access to resources on a per-request or transaction basis.
- Research Gap: Existing studies examined ZTA principles, security potential, implementation, applications, and architectures, but lacked a systematic review of domains, technologies, and adoption challenges.
- Contributions: The SLR proposes a taxonomy covering ZTA applications, implementation requirements, enabling technologies, and associated challenges for researchers and practitioners.
- Contributions: The study critically analyzes enabling technologies, identifies adoption challenges, and synthesizes application domains with examples and case studies.
2 Zero Trust Architecture (ZTA)
ZTA replaces perimeter-centered assumptions with dynamic, resource-focused access control for distributed environments. Its architecture relies on policy components that evaluate, authorize, enforce, monitor, and terminate access.
- ZTA versus PBSM: Perimeter-based security builds a barrier around internal networks, while ZTA treats access as dynamic rather than implicitly trusted.
- ZTA versus PBSM: 47%: insider attacks increased between 2022 and 2024, affecting 34% of firms worldwide and reinforcing the need for continuous monitoring.
- ZTA versus PBSM: ZTA protects individual resources through precise, least-privilege, per-request decisions instead of protecting the enterprise as a whole.
- Core Components: The Policy Engine decides whether to grant, deny, or restrict access using enterprise policies and inputs such as activity records, logs, and threat intelligence.
- Core Components: The Policy Administrator translates Policy Engine decisions into session permissions, while together they form the ZTA control plane.
- Core Components: The Policy Enforcement Point interfaces with subjects and resources, then enables, monitors, and terminates access.
3 History and Publication Trend
ZTA developed from early de-perimeterization and zero-trust concepts into an increasingly recognized security solution, with research activity expanding alongside remote work, cloud adoption, policy initiatives, and escalating cyber threats.
- Kindervag’s 2010 work formalized Zero Trust around secure resource access regardless of location, least privilege, and strict access control.
- Early zero-trust work emerged from the Jericho Forum’s de-perimeterization concept, which addressed complex firewalls, internal vulnerabilities, and changing business practices.
- Figure 2 presents notable events in ZTA’s historical development across the years.
- Early ZTA research contributions were limited and initially focused on foundational principles before expanding toward architectural frameworks and practical implementations.
- The 2020 pandemic and remote-work surge exposed weaknesses in perimeter-based models as employees accessed corporate resources from varied locations.
- Cloud computing and BYOD increased distributed attack surfaces, strengthening the need for security models suited to heterogeneous environments.
- Government initiatives and standards, including Executive Order 14028, NIST SP 800-207, and CISA’s maturity model, may have stimulated ZTA research and implementation.
- High-profile cyberattacks between 2020 and 2023 highlighted perceived inadequacies in traditional security approaches and accompanied increased interest in ZTA.
4 Methodology
The study uses a PRISMA-based systematic literature review to examine ZTA applications, adoption challenges, and enabling technologies. It searches three scholarly databases, applies staged screening and eligibility criteria, and synthesizes the resulting literature.
- Review scope: The review investigates ZTA applications, adoption and implementation challenges, and emerging enabling technologies through structured research questions and objectives.
- Information sources: Scopus, Web of Science, and IEEE Xplore were selected as information sources because of their extensive collections, academic recognition, and potential to reduce duplicate records.
- Search strategy: The search progressed from unconstrained database queries to filters for final English publications in Computer Science or Engineering, including articles, conference papers, and reviews.The initial queries returned 1,122 Scopus, 539 Web of Science, and 642 IEEE Xplore records before filtering.
- Screening and selection: The study used four PRISMA stages—Identification, Screening, Eligibility, and Inclusion—to select relevant publications using titles, abstracts, full texts, and predefined criteria.
- Study selection: 1,774 records were identified, 831 duplicates were removed, and 91 articles remained after screening, full-text eligibility assessment, and exclusion of seven unrelated studies.
- Study characteristics: The included literature was characterized by publication sources, with IEEE Access contributing 12 studies and the remaining 62% distributed across diverse journals and conferences.
- Threats to validity: The review may omit studies because of incomplete searches, alternative terminology, or its restriction to Scopus, Web of Science, and IEEE Xplore.
5 Taxonomy
The SLR organizes ZTA into application domains, application requirements, and enabling technologies. These categories were derived through iterative thematic analysis and refined through expert validation.
- The proposed taxonomy has three categories: application domains, application requirements, and enabling technologies.It is intended to organize ZTA concepts and applications systematically.
- The categories were derived by extracting themes, grouping conceptual similarities or proposed applications, and refining them through expert validation.
- Application Domains: Application domains identify sectors and use cases where ZTA principles are adapted to sector-specific constraints.
- Application Requirements: Application requirements identify foundational implementation elements and distinguish complete ZTA implementations from partial adoptions or traditional PBSM.
- Enabling Technologies: Enabling technologies comprise innovations that facilitate ZTA implementation and support its effectiveness in practice.
5.1 Application Domains
The reviewed literature applies ZTA across healthcare and medical contexts, where diverse devices, sensitive data, and distributed connectivity create substantial security demands. Proposed approaches use continuous verification, granular access control, encryption, microservices, and hybrid deployment strategies.
- Healthcare and Medical: Healthcare ZTA applications protect sensitive medical records and health data through access controls, secure data exchange, and real-time monitoring.
- Healthcare and Medical: Healthcare environments combine IoT, legacy, and unmanaged devices with internet and cloud connectivity, expanding the attack surface around sensitive data.
- Healthcare and Medical: A healthcare case study favored ZTA over PBSM for security but identified cost and support overheads, leading to a hybrid approach aligned with seven NIST SP 800-207 tenets.
- Healthcare and Medical: A healthcare implementation framework combines basic controls, MFA, encryption, DNS sinkholing, secure access, and behavior analysis across five stages.The framework was developed and tested using Cisco Modelling Labs, but its authors cautioned that simulation results may differ from real-world implementations.
- Healthcare and Medical: Other healthcare proposals combine ZTA with blockchain, OTP, RBAC, secure hashing, tokens, AES, and SHA-256 to strengthen authentication, authorization, and data protection.
- Healthcare and Medical: A microservice-integrated ZTA framework for EHRs assigns security policies to individual services, creating isolated trust zones that limit breach impact across services.A case study reported improved security posture while maintaining acceptable performance and user experience.
5.1.2 Communication Networks
The literature applies ZTA to 5G/6G, O-RAN, satellite, and corporate communication networks facing expanded connectivity, openness, and evolving cyber threats. Proposed solutions combine continuous authentication, AI, blockchain, cryptography, and learning-based detection.
- 5G/6G Networks: 5G/6G networks motivate ZTA applications because increasing complexity and connectivity create additional cybersecurity threats beyond traditional perimeter defenses.
- 5G/6G Networks: An intelligent ZTA framework for 5G/6G dynamically assesses access requests using security policies, subject privileges, AI trust evaluation, and graph-neural-network risk assessment.
- 5G/6G Networks: A 6G IoT authentication system uses lightweight attribute-based encryption for dynamic access control and blockchain for mutual authentication without relying on secure channels.
- Satellite Communication: A satellite-network ZTA framework uses edge intelligence, periodic re-evaluation, and Neural-Backed Decision Trees for continuous authentication.Simulation results reported increased authentication accuracy and performance exceeding a conventional ABAC model.
- Communication Networks: Communication-network ZTA research also includes distributed blockchain MFA using zero-knowledge proofs, ECC, ECDSA, and time-limited authentication tokens.The framework was evaluated experimentally and compared with existing works.
- O-RAN: O-RAN ZTA proposals address multi-vendor supply-chain complexity and attack-surface expansion through blockchain authentication, continuous verification, and learning-based security models.Reported approaches include Q-learning, Deep Sarsa, and Transformers evaluated using the UNSW dataset.
5.1.3 Finance and Commerce
The reviewed literature extends ZTA across finance, IoT, computing continuums, remote work, and social media. Proposed solutions emphasize adaptive trust evaluation, blockchain, decentralized identity, micro-segmentation, behavioral verification, and anomaly detection.
- Finance and Commerce: Financial-sector ZTA frameworks combine blockchain, IAM, threat detection, and adaptive security postures to address complex cyber threats while targeting operational efficiency.
- Finance and Commerce: A machine-learning trust-level model is proposed for integration into ZTA policy enforcement in financial institutions.
- Internet of Things: IoT and Industrial IoT applications use micro-segmentation and SDN to create isolated trust zones and enforce policies across heterogeneous environments.
- Internet of Things: IoT access-control research continuously monitors and re-evaluates trust levels and authorization policies as subject, resource, environmental, or trust features change.A prototype was validated under three test conditions using re-evaluation time relative to the number of attributes.
- Computing Continuum: Computing-continuum proposals use Self-Sovereign Identity to preserve individuals’ control over digital identities while supporting authentication, authorization, privacy, and trust management.
- Remote Work and Social Media: Remote-work and social-media frameworks apply behavioral biometrics, blockchain, federated learning, OAuth 2.0, OpenID Connect, biometric recognition, and digital signatures.These approaches target continuous user verification, adaptive trust computation, identity security, and content integrity.
5.1.6 Virtual Environments
Virtual environments and connected logistics systems expand attack surfaces beyond traditional perimeter defenses. The reviewed literature applies ZTA through decentralized identity, continuous verification, micro-segmentation, and trust-aware access control across cloud, metaverse, vehicular, and supply-chain contexts.
- Cloud and Edge Computing: Cloud and edge platforms face growing security complexity as data volumes and interconnected infrastructure challenge conventional threat detection.The Okta breach illustrates risks from compromised credentials, cookies, and session tokens.
- Cloud and Edge Computing: S-ZAC uses SGX technology to protect a service-mesh control plane and preserve information confidentiality, integrity, and availability against privileged attackers.
- Metaverse: Metaverse security concerns include identity theft, unauthorized access, and data breaches, while perimeter-based defenses perform poorly in open, dynamic environments.
- Metaverse: A blockchain-enabled ZTA framework combines decentralized identity verification with cryptography, graph theory, and machine learning for metaverse security.The framework is evaluated using metrics including dynamic threat response, decentralized authentication and response, and scalability.
- Transport and Logistics: ZTA applications in logistics address distributed supply-chain exposure, UAV communication threats, and vehicular-network risks through authentication, micro-segmentation, anomaly detection, and encryption.A lightweight VANET framework reports high throughput and protection against impersonation attacks, while blockchain-based frameworks secure UAV delivery systems.
- Transport and Logistics: Combining attribute-based access control with trust evaluation improves authorization flexibility for Internet of Vehicle Things security.The framework incorporates user trust scores to address ABAC's limitations in capturing user intentions.
5.1.8 Military and Defense
Military and defense systems require ZTA because evolving cyber threats exceed the full protective capacity of perimeter-based security models. The reviewed approaches emphasize continuous verification, segmentation, secure collaboration, and hybrid integration with existing defense-in-depth architectures.
- Defense and Tactical Systems: ZTA is applied to tactical networks, military IoT and UAVs, and classified data exchanges because perimeter-based security lacks sufficient protection against evolving threats.
- Defense and Tactical Systems: Defense-oriented ZTA uses continuous verification, micro-segmentation, and secure inter-domain collaboration to protect sensitive operations in dynamic environments.
- Defense and Tactical Systems: Multifactor authentication addresses identity fabrication and credential misuse, while SDN and micro-segmentation address network-security challenges.
- Aerospace and Military UAV: A National Airspace System approach combines existing defense-in-depth perimeter protections with ZT capabilities including real-time device trust, MFA, and SOAR.
- Aerospace and Military UAV: Military UAV security requires protection across four distinct vulnerability levels because traditional perimeter-based models are insufficient against sophisticated cyberattacks.
5.1.9 Manufacturing
Manufacturing and smart-energy environments gain efficiency from interconnected technologies but face expanded attack surfaces and infrastructure vulnerabilities. Reviewed ZTA frameworks respond with dynamic authorization, trust evaluation, distributed enforcement, and identity-centered controls.
- Manufacturing: Digital transformation, Industrial IoT, smart factories, and automation improve manufacturing efficiency while expanding the attack surface.
- Manufacturing: A manufacturing framework uses dynamic access control and trust evaluation to provide fine-grained permissions, continuously reassessing legitimate access and denying illegal roles.
- Manufacturing: A distributed smart-factory framework based on SDP and a cloud-edge-gateway reports improved efficiency and security in simulation results.
- Smart Energy Systems: Smart energy systems integrate IoT, cloud computing, and AI but expose interconnected power infrastructure to cybersecurity risks.
- Smart Energy Systems: ZTA secures smart EV communications and charging infrastructure through strict authentication, with one framework combining ShangMi cryptography, blockchain, and zero-trust strategies.
- Metering Infrastructure: AMI protection applies encryption, identity authentication, real-time monitoring, blockchain, and ROPUFs to verify devices and access requests.
- Smart Energy Systems: A power-IoT architecture separates real-time trust decisions, decision execution, and identity-policy management across control, data, and identity-security modules.
- Smart Energy Systems: ZTA frameworks for smart energy systems use continuous trust evaluation and dynamic access control to assess requests and enforce granular policies.
5.2 Application Requirements
Successful ZTA deployment requires isolated network zones, defined trust dimensions, continuous monitoring, strong identity management, and context-based authorization. These requirements collectively support dynamic policy enforcement and least-privilege access.
- Micro-segmentation divides networks into isolated zones, minimizing breach impact and preventing lateral threat movement.
- Each access request requires defined trust dimensions so authorization occurs only when specified security parameters are satisfied.
- Continuous monitoring and verification analyze user and device activity in real time to detect anomalies and dynamically enforce security policies.SIEM and SOAR support centralized logging, threat detection, and automated response.
- Authentication and identity management verify users and devices through biometrics, multifactor authentication, and identity federation.
- Trust evaluation assigns authorization-relevant values from contextual factors such as behavior, device health, and location.Dynamic and conditional access mechanisms restrict permissions to what a task or role requires.
5.3 Enabling Technologies
The review identifies blockchain, machine learning, privacy-preserving techniques, encryption, and SASE as technologies supporting ZTA implementation across dynamic environments.
- Blockchain: Blockchain supports distributed policy enforcement, secure information sharing, authentication, and device identity management in ZTA.It can implement Policy Decision Points and Policy Enforcement Points through distributed ledgers and smart contracts.
- Machine Learning and Automation: Machine learning evaluates trust attributes, analyzes network traffic, detects anomalies, and supports real-time access-control decisions.Deep learning is also used for device identification and user authentication, including CNN-based identification from RF signals.
- Machine Learning and Automation: Federated Learning enables decentralized model training for continuous authentication while preserving user privacy.The reviewed work includes federated authentication using multimodal biometric data.
- Zero Knowledge Proofs (ZKPs): Zero-knowledge proofs support authentication and secure data migration by proving knowledge without revealing the underlying information.Applications include verifying one-time-password knowledge and supporting private cloud-to-cloud data migration.
- Secure Access Service Edge (SASE): SASE integrates networking and security services by treating end users as untrusted and verifying requests before resource access.Distributed inspection points support consistent enforcement of ZTA principles across internet connections.
6 ZTA Adoption and Implementation Challenges
ZTA adoption faces pre-implementation and post-implementation barriers involving policy complexity, scale, performance, organizational change, legacy integration, cost, decentralization, cryptography, interoperability, and policy management.
- Fine-grained access control strategies: Fine-grained access control strengthens permission accuracy but makes policy definition, maintenance, and enforcement resource-intensive as networks change.The challenge is especially pronounced in complex networks protecting sensitive resources.
- Large-scale Networks: Large and geographically distributed networks require advanced micro-segmentation, yet their size and attack surface make ZTA implementation difficult.Software-Defined Networking is identified as one technology supporting micro-segmentation.
- Scalability Bottlenecks: Scalability requires ZTA to accommodate more devices, users, and data without compromising performance or security.Expansion may require decentralized control, harmonized policies, enhanced identity management, and further network segmentation.
- Real-time Authentication and Authorization: Real-time authentication and authorization can degrade performance, increase latency, consume resources, and create reliability problems.These effects may be particularly problematic for large, diverse, or real-time-critical networks.
- Organizational and technical barriers: Organizational resistance, training requirements, legacy-system incompatibility, regulatory obligations, and upfront costs can impede adoption.The review also identifies decentralization, lightweight-cryptography trade-offs, interoperability, and complex policy management as implementation challenges.
7 Conclusion
The SLR synthesizes ZTA’s evolution, applications, enabling technologies, and adoption challenges through a structured taxonomy. It reports a recent surge in publications, a slower growth rate between 2023 and 2024, and limited research on ZTA’s core weaknesses and trade-offs.
- Contributions: The SLR provides a comprehensive analysis of ZTA’s evolution, application domains, enabling technologies, and adoption challenges.Its structured taxonomy is intended to support future refinement of implementation strategies and address barriers to adoption.
- Research trends: ZTA research publications have surged in recent years, but growth slowed between 2023 and 2024, possibly indicating a plateau in research interest.The passage states that recent publication counts nearly doubled compared with the preceding year before this slowdown.
- Future research: Research frequently proposes ZTA-based security frameworks for IoT networks and devices, while core ZTA aspects, weaknesses, and trade-offs remain underexplored.The conclusion calls for further examination of perceived real-world security benefits relative to implementation complexity.