Why Zero Trust Architectures Are Not Replacing Trust
摘要
With the globalization of information systems and services, the traditional perimeter based security paradigm has come under increasing pressure and Zero Trust Architecture (ZTA) have emerged as an interesting answer to many of the existing problems. By removing implicit trust in other entities, ZTA promises security based on verifiable attributes, such as identities (user and device), credentials, and policies. This provides an excellent foundation for security architectures, however, in most cases implicit trust is neither removed nor made explicit, but instead shifted to other system elements and Trusted Third Parties, that we are used to trust without question, e.g. the Certificate Authorities (CAs) in a Public Key Infrastructure (PKI). In this paper, we examine common elements in ZTA to expose the underlying trust relationships, which we believe should be explicitly acknowledged, so that they can be managed and considered in all security decisions.