Effective command and control (C2) can be problematic in the tactical coalition environment because of heterogeneous technology and complex information sharing agreements among coalition partners. A coalition must enable secure information exchange without imposing cost on coalition partners. This thesis identified the requirements and key components of a coalition tactical zero trust architecture (T-ZTA), and investigated how they can remediate challenges to coalition C2. Using military doctrine and previous work on T-ZTA to identify the requirements for a coalition T-ZTA, we designed a prototype architecture and evaluated its fulfillment of the T-ZTA requirements. We identified a device-based authentication solution, gateway-based authentication solution, and coalition gateway as key components of a coalition T-ZTA, then used a large-scale virtual environment to implement a coalition T-ZTA. Evaluation of the coalition T-ZTA prototype performance revealed that it improves interoperability and provides reliable continuous authentication, but is vulnerable to interruption in denied, disrupted, intermittent, or limited bandwidth (DDIL) scenarios and lacks an ad-hoc capability for communication without the gateway.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Tactical Zero Trust Architectures in a Coalition Environment

  • Thomas Schmitt,
  • Alan Shaffer,
  • Gurminder Singh

摘要

Effective command and control (C2) can be problematic in the tactical coalition environment because of heterogeneous technology and complex information sharing agreements among coalition partners. A coalition must enable secure information exchange without imposing cost on coalition partners. This thesis identified the requirements and key components of a coalition tactical zero trust architecture (T-ZTA), and investigated how they can remediate challenges to coalition C2. Using military doctrine and previous work on T-ZTA to identify the requirements for a coalition T-ZTA, we designed a prototype architecture and evaluated its fulfillment of the T-ZTA requirements. We identified a device-based authentication solution, gateway-based authentication solution, and coalition gateway as key components of a coalition T-ZTA, then used a large-scale virtual environment to implement a coalition T-ZTA. Evaluation of the coalition T-ZTA prototype performance revealed that it improves interoperability and provides reliable continuous authentication, but is vulnerable to interruption in denied, disrupted, intermittent, or limited bandwidth (DDIL) scenarios and lacks an ad-hoc capability for communication without the gateway.