错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The Application of Zero Trust Architecture to Mitigate Password Compromise in Accessing Cloud Services

  • Mathew William Chamley,
  • Emadeldin Elgamal,
  • P. W. C. Prasad

摘要

The inherent weakness in password based single-factor authentication (SFA), combined with the traditional static network perimeter (SNP) model, has resulted in the reduced effectiveness of this access control. Moreso, compromise enables access to broader network resources. SNP has also lost relevance with the increase in remote working and cloud services being positioned outside the perimeter. Accordingly, Zero Trust Architecture (ZTA) has emerged as an approach to logically isolate resources, require enhanced validation of identity, and provide authentication on a per-resource/per-session basis. The aim of this paper is to identify the potential benefits of ZTA in the mitigation of password compromise in accessing cloud services. The research was conducted through a literature review of contemporary peer-reviewed papers published since 1 January 2021 and found through the Charles Sturt University Primo Search tool. The findings and contributions of this paper are a rationalization of the ZTA definition and design, validation, and identification of the benefits of ZTA to address password compromise, identification of the challenges in supporting cloud services, and guidance on future research initiatives into the trust algorithm, privacy implication of continuous observation, chained authorization, and the development of cloud ZTA.