Enhancing Security With a Custom Authenticator App and Comprehensive Zero Trust Architecture
摘要
Due to the immense surge in the acceptance of Internet of Things (IoT) devices, securing the networks has become more of a challenge because of the diversity and complexity of devices as well as a lack of robust security provisions. In order to make the IoT networks even more secure, the present study proposes a new type of Zero Trust Architecture (ZTA) together with a special multi-factor authentication (MFA) scheme. The solution is to employ an Android authenticator app that will dispatch OTPs over Firebase Cloud Messaging (FCM) and provide real-time user verification. Also integrated in the system are mobility solutions based on Amazon Web Services that provide important ZTA attributes such as least privilege access control, continuous verification of user identity, and secure device registration. Consequently, by also augmenting the central tenet of Zero Trust Architecture, which eliminates trust assumptions and mandates identity verification for all devices and users in the system, the framework effectively reduces risk associated with unauthorized access and security incidents. This paper evaluates the real-world application of the system technology in an Internet of Things platform, where improved security and ease of use, and expansion have been achieved. Combining the Zero Trust model with modern authentication mechanisms appears to provide an effective way to secure IoT networks.