The Application of Zero Trust Architecture to Mitigate Password Compromise in Accessing Cloud Services
摘要
The inherent weakness in password based single-factor authentication (SFA), combined with the traditional static network perimeter (SNP) model, has resulted in the reduced effectiveness of this access control. Moreso, compromise enables access to broader network resources. SNP has also lost relevance with the increase in remote working and cloud services being positioned outside the perimeter. Accordingly, Zero Trust Architecture (ZTA) has emerged as an approach to logically isolate resources, require enhanced validation of identity, and provide authentication on a per-resource/per-session basis. The aim of this paper is to identify the potential benefits of ZTA in the mitigation of password compromise in accessing cloud services. The research was conducted through a literature review of contemporary peer-reviewed papers published since 1 January 2021 and found through the Charles Sturt University Primo Search tool. The findings and contributions of this paper are a rationalization of the ZTA definition and design, validation, and identification of the benefits of ZTA to address password compromise, identification of the challenges in supporting cloud services, and guidance on future research initiatives into the trust algorithm, privacy implication of continuous observation, chained authorization, and the development of cloud ZTA.