Continuous Authorization Architecture for Dynamic Trust Evaluation
摘要
The modern security paradigms emphasizing dynamic trust assessment and resilient access controls form the fundamental principles of Zero Trust Architecture. Within this architecture, the relationship between stakeholders is always untrusted and requires continuous assessment. This principle gains special attention in contemporary systems and applications, like Internet of Things (IoT) or cyber-physical systems, that are omnipresent and embedded in every aspect of our lives, which also, at the same time, are highly dynamic and uncertain. In response, users’ trust in the embedded devices fluctuates over time, necessitating dynamic adaptive mechanisms. Traditional access control models lack continuous monitoring, increasing interest in usage access control models that evaluate access in response to evolving attributes. This paper presents an innovative integration of a lifecycle-oriented Usage Control with a Trust Level Evaluation Engine (TLEE) within a Zero-Trust application. Continuously monitoring trust levels as a dynamic attribute is at the core of our strategy. Relying solely on this monitoring process, we facilitate a transition that enables access management, encompassing the possibilities of granting, withholding, or revoking access based on real-time trust evaluations. The proposed architecture implements a distinct separation between TLEE and the authorization engine, resulting in an adaptable and policy-independent framework. Through this integration, we aim to enhance the effectiveness of authorization mechanisms in evolving IoT landscapes like Smart Homes. Lastly, our approach presents a workflow featuring an example of a subjective logic-based TLEE.