{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T22:26:34Z","timestamp":1783635994793,"version":"3.55.0"},"reference-count":98,"publisher":"Emerald","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"abstract":"<jats:p>The notion of Zero Trust Architecture (ZTA) has been introduced as a fine-grained defense approach. It assumes that no entities outside and inside the protected system can be trusted and, therefore, requires articulated and high-coverage deployment of security controls. However, ZTA is a complex notion that does not have a single design solution; rather, it consists of numerous interconnected concepts and processes that need to be assessed prior to deciding on a solution. In this monograph, we cover the principles and architectural foundations of ZTA, basically following the guidelines by NIST, and provide a detailed analysis of ZT architectures proposed by research and industry. The monograph also describes an approach for the automatic generation of ZT policies based on application communication requirements, network topology, and organizational information. This approach was designed to meet a critical need of ZTA, that is, the generation and implementation of a large number of fine-grained policies. Finally, the monograph discusses several research directions, including the incorporation of threat intelligence into ZT networks and the use of large language models (LLMs).<\/jats:p>","DOI":"10.1561\/3300000046","type":"journal-article","created":{"date-parts":[[2025,6,10]],"date-time":"2025-06-10T05:27:37Z","timestamp":1749533257000},"page":"122-253","source":"Crossref","is-referenced-by-count":1,"title":["The Zero-trust Paradigm: Concepts, Architectures and Applications"],"prefix":"10.1108","volume":"8","author":[{"given":"Charalampos","family":"Katsis","sequence":"first","affiliation":[{"name":"Purdue University ,","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elisa","family":"Bertino","sequence":"additional","affiliation":[{"name":"Purdue University ,","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2025,6,30]]},"reference":[{"key":"2026033014315456900_ref001","doi-asserted-by":"crossref","first-page":"523","DOI":"10.1007\/978-3-030-58951-6_26","author":"Abu Jabal","year":"2020","journal-title":"Computer Security-ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020"},{"key":"2026033014315456900_ref002","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1145\/3532105.3535020","article-title":"Bluesky: Towards convergence of zero trust principles and score-based authorization for iot enabled smart systems","author":"Ameer","year":"2022","journal-title":"Proceedings of the 27th ACM on symposium on access control models and technologies."},{"key":"2026033014315456900_ref003","doi-asserted-by":"crossref","DOI":"10.1145\/3671147","article-title":"ZTA-IoT: A Novel Architecture for Zero-Trust in IoT Systems and an Ensuing Usage Control Model","author":"Ameer","year":"2024","journal-title":"ACM Transactions on Privacy and Security."},{"key":"2026033014315456900_ref004","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1145\/3532105.3535029","article-title":"Removing the reliance on perimeters for security using network views","author":"Anjum","year":"2022","journal-title":"Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies."},{"key":"2026033014315456900_ref005","first-page":"121","article-title":"MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy","author":"Anjum","year":"2023","journal-title":"Proceedings of the 28th ACM Symposium on Access Control Models and Technologies."},{"key":"2026033014315456900_ref006","unstructured":"Aviatrix.\n           (2024). \u201cAviatrix DCF Documentation v7.1\u201d. URL: https:\/\/docs.aviatrix.com\/documentation\/v7.1\/network-security\/index.html."},{"key":"2026033014315456900_ref007","article-title":"Distributed Cloud Firewall","author":"Aviatrix.","year":"2025"},{"key":"2026033014315456900_ref008","unstructured":"Aviatrix.\n           (2025b). \u201cSecure Cloud Networking Products\u201d. URL: https:\/\/aviatrix.com\/secure-cloud-networking-products\/."},{"key":"2026033014315456900_ref009","unstructured":"Axiomatics.\n           (2025). \u201cAbbreviated Language for Authorization (ALFA)\u201d. URL: https :\/\/axiomatics.com\/resources\/reference\u2013library\/abbreviated-language-for-authorization-alfa."},{"key":"2026033014315456900_ref010","first-page":"147","article-title":"P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF","author":"Bajaber","year":"2024","journal-title":"2024 IEEE Symposium on Security and Privacy (SP)."},{"key":"2026033014315456900_ref011","first-page":"1","article-title":"ONOS: towards an open, distributed SDN OS","author":"Berde","year":"2014","journal-title":"Proceedings of the third workshop on Hot topics in software defined networking."},{"key":"2026033014315456900_ref012","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1109\/CIC58953.2023.00025","article-title":"A Pro-Active Defense Framework for IoT Systems","author":"Bertino","year":"2023","journal-title":"2023 IEEE 9th International Conference on Collaboration and Internet Computing (CIC)."},{"key":"2026033014315456900_ref013","unstructured":"Blockcerts.\n           (2024). \u201cBlockcerts: Open Standard for Verifiable Credentials\u201d. URL: https:\/\/www.blockcerts.org\/."},{"key":"2026033014315456900_ref014","unstructured":"Bloom.\n           (2020). \u201cBloomID: A Guide to Your Secure Identity\u201d. URL: https:\/\/bloom.co\/blog\/bloomid-a-guide-to-your-secure-identity\/."},{"key":"2026033014315456900_ref015","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1109\/EuroSP.2018.00015","article-title":"Language-independent synthesis of firewall policies","author":"Bodei","year":"2018","journal-title":"Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P)."},{"key":"2026033014315456900_ref016","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1109\/LCN53696.2022.9843821","article-title":"Secure service function chaining in the context of zero trust security","volume-title":"2022 IEEE 47th Conference on Local Computer Networks (LCN)","author":"Bradatsch","year":"2022"},{"key":"2026033014315456900_ref017","doi-asserted-by":"crossref","first-page":"125307","DOI":"10.1109\/ACCESS.2023.3330706","article-title":"ZTSFC: a service function chaining-enabled zero trust architecture","volume":"11","author":"Bradatsch","year":"2023","journal-title":"IEEE Access."},{"key":"2026033014315456900_ref018","first-page":"1422","article-title":"Zero Trust Score-based Network-level Access Control in Enterprise Networks","author":"Bradatsch","year":"2023","journal-title":"2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (Trust-Com)."},{"key":"2026033014315456900_ref019","unstructured":"California\n              State Assembly.\n            \n           (2018). \u201cCalifornia Consumer Privacy Act (CCPA)\u201d. URL: https:\/\/oag.ca.gov\/privacy\/ccpa."},{"issue":"4","key":"2026033014315456900_ref020","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1282427.1282382","article-title":"Ethane: Taking control of the enterprise","volume":"37","author":"Casado","year":"2007","journal-title":"ACM SIGCOMM computer communication review."},{"key":"2026033014315456900_ref021","unstructured":"CISA.\n           (2014). \u201cFederal Information Security Modernization Act (FISMA)\u201d. URL: https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/federal-information-security-modernization-act."},{"key":"2026033014315456900_ref022","doi-asserted-by":"crossref","first-page":"699","DOI":"10.1145\/3564625.3567968","article-title":"Ze-roDNS: Towards Better Zero Trust Security using DNS","author":"Csikor","year":"2022","journal-title":"Proceedings of the 38th Annual Computer Security Applications Conference"},{"key":"2026033014315456900_ref023","article-title":"Mis-configuration management of network security components","author":"Cuppens","year":"2019","journal-title":"arXiv preprint arXiv:1912.07283."},{"key":"2026033014315456900_ref024","first-page":"203","article-title":"A formal approach to specify and deploy a network security policy","author":"Cuppens","year":"2004","journal-title":"IFIP World Computer Congress, TC 1"},{"key":"2026033014315456900_ref025","first-page":"1","article-title":"P4guard: Designing p4 based firewall","author":"Datta","year":"2018","journal-title":"MILCOM 2018\u20132018 IEEE Military Communications Conference (MILCOM)."},{"key":"2026033014315456900_ref026","doi-asserted-by":"crossref","first-page":"1801","DOI":"10.1109\/TrustCom50675.2020.00247","article-title":"Trust aware continuous authorization for zero trust in consumer internet of things","author":"Dimitrakos","year":"2020","journal-title":"2020 IEEE 19th international conference on trust, security and privacy in computing and communications (TrustCom)."},{"key":"2026033014315456900_ref027","article-title":"DoD Zero Trust Strategy","author":"DoD.","year":"2022","journal-title":"DoD Office of Prepublication and Security Review."},{"key":"2026033014315456900_ref028","first-page":"386","article-title":"Evaluating behavioral biometrics for continuous authentication: Challenges and metrics","author":"Eberz","year":"2017","journal-title":"Proceedings of the 2017 ACM on Asia conference on computer and communications security."},{"issue":"3","key":"2026033014315456900_ref029","first-page":"38","article-title":"BeyondCorp: The user experience","volume":"42","author":"Escobedo","year":"2017","journal-title":"login."},{"key":"2026033014315456900_ref030","unstructured":"European\n              Parliament.\n            \n           (2016). \u201cGeneral Data Protection Regulation (GDPR)\u201d. URL: https:\/\/gdpr.eu\/."},{"key":"2026033014315456900_ref031","article-title":"Exploring the next generation of access control methodologies","author":"Ferraiolo","year":"2016"},{"issue":"3","key":"2026033014315456900_ref032","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1145\/501978.501980","article-title":"Proposed NIST standard for role-based access control","volume":"4","author":"Ferraiolo","year":"2001","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"issue":"7","key":"2026033014315456900_ref033","doi-asserted-by":"crossref","first-page":"1322","DOI":"10.1109\/JSAC.2020.2999654","article-title":"Trident: Toward distributed reactive SDN programming with consistent updates","volume":"38","author":"Gao","year":"2020","journal-title":"IEEE Journal on Selected Areas in Communications."},{"key":"2026033014315456900_ref034","unstructured":"Geant.\n           (2024). eduroam. url: https:\/\/eduroam.org\/ (accessed on 09\/30\/2024)."},{"key":"2026033014315456900_ref035","article-title":"BeyondCorp and the long tail of Zero Trust","author":"Gongalves","year":"2023"},{"key":"2026033014315456900_ref036","doi-asserted-by":"crossref","first-page":"82721","DOI":"10.1109\/ACCESS.2019.2924045","article-title":"A survey on IoT security: application areas, security threats, and solution architectures","volume":"7","author":"Hassija","year":"2019","journal-title":"IEEe Access."},{"issue":"162","key":"2026033014315456900_ref037","first-page":"154","article-title":"Guide to attribute based access control (abac) definition and considerations (draft)","volume":"800","author":"Hu","year":"2013","journal-title":"NIST special publication."},{"key":"2026033014315456900_ref038","first-page":"12","article-title":"Security assertion markup language (saml) v2. 0 technical overview","volume":"13","author":"Hughes","year":"2005","journal-title":"OASIS SSTC Working Draft sstc-saml-tech-overview-2.0-draft-08."},{"issue":"6","key":"2026033014315456900_ref039","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3295749","article-title":"Methods and tools for policy analysis","volume":"51","author":"Jabal","year":"2019","journal-title":"ACM Computing Surveys (CSUR)."},{"issue":"3","key":"2026033014315456900_ref040","first-page":"24","article-title":"Beyondcorp 6: Building a healthy fleet","volume":"43","author":"Janosko","year":"2018","journal-title":"login."},{"key":"2026033014315456900_ref041","doi-asserted-by":"crossref","DOI":"10.17487\/RFC7519","article-title":"JSON Web Token (JWT)","author":"Jones","year":"2015"},{"key":"2026033014315456900_ref042","first-page":"595","article-title":"Programmable {In-Network} security for context-aware {BYOD} policies","author":"Kang","year":"2020","journal-title":"29th USENIX Security Symposium (USENIX Security 20)."},{"issue":"2","key":"2026033014315456900_ref043","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3712262","article-title":"ZT-SDN: An ML-powered Zero-Trust Architecture for Software-Defined Networks","volume":"28","author":"Katsis","year":"2025","journal-title":"ACM Transactions on Privacy and Security."},{"key":"2026033014315456900_ref044","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1145\/3450569.3463558","article-title":"Can i reach you? do i need to? new semantics in security policy specification and testing","author":"Katsis","year":"2021","journal-title":"Proceedings of the 26th ACM Symposium on Access Control Models and Technologies."},{"key":"2026033014315456900_ref045","first-page":"167","article-title":"NEUTRON: a graph-based pipeline for zero-trust network architectures","author":"Katsis","year":"2022","journal-title":"Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy."},{"key":"2026033014315456900_ref046","author":"Katz","year":"2008"},{"key":"2026033014315456900_ref047","first-page":"13","article-title":"Yarrow-160: Notes on the design and analysis of the yarrow cryptographic pseudorandom number generator","author":"Kelsey","year":"1999","journal-title":"International Workshop on Selected Areas in Cryptography."},{"key":"2026033014315456900_ref048","first-page":"107","article-title":"Secure Desktop Computing in the Cloud","author":"Krisler","year":"2019","journal-title":"2019 6th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)\/2019 5th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom)."},{"key":"2026033014315456900_ref049","first-page":"361","article-title":"Translating Natural Language Specifications into Access Control Policies by Leveraging Large Language Models","author":"Lawal","year":"2024","journal-title":"2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)."},{"key":"2026033014315456900_ref050","first-page":"561","article-title":"Password policies of most top websites fail to follow best practices","author":"Lee","year":"2022","journal-title":"Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)."},{"key":"2026033014315456900_ref051","unstructured":"Lockheed\n              Martin Corporation.\n            \n           (2025). \u201cCyber Kill Chain\u201d. URL: https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html."},{"issue":"4","key":"2026033014315456900_ref052","doi-asserted-by":"crossref","first-page":"290","DOI":"10.1145\/2043164.2018470","article-title":"Debugging the data plane with anteater","volume":"41","author":"Mai","year":"2011","journal-title":"ACM SIGCOMM Computer Communication Review."},{"key":"2026033014315456900_ref053","article-title":"Merkle tree patent","author":"Merkle","year":"1979"},{"key":"2026033014315456900_ref054","article-title":"Embrace proactive security with Zero Trust.","author":"Microsoft.","year":"2024"},{"key":"2026033014315456900_ref055","article-title":"Evolving Zero Trust: How Real-World Deployments and Attacks Are Shaping the Future of Zero Trust Strategies","author":"Microsoft","year":"2021","journal-title":"Tech. rep."},{"key":"2026033014315456900_ref056","article-title":"Decentralized Identifier Overview -Microsoft Entra Verified ID","author":"Microsoft","year":"2024"},{"key":"2026033014315456900_ref057","article-title":"Zero Trust Strategy and Architecture","author":"Microsoft","year":"2025"},{"key":"2026033014315456900_ref058","article-title":"Kitsune: an ensemble of autoencoders for online network intrusion detection","author":"Mirsky","year":"2018","journal-title":"arXiv preprint arXiv:1802.09089."},{"key":"2026033014315456900_ref059","article-title":"Common Vulnerabilities and Exposures (CVE)","author":"Corporation.","year":"2025"},{"key":"2026033014315456900_ref060","unstructured":"MITRE\n              Corporation.\n            \n           (2025b). \u201cMITRE ATT&CK Enterprise Matrix\u201d. url: https:\/\/attack.mitre.org\/matrices\/enterprise\/."},{"key":"2026033014315456900_ref061","first-page":"1","article-title":"Composing software defined networks","author":"Monsanto","year":"2013","journal-title":"10th USENIX Symposium on Networked Systems Design and Implementation (NSDI13)."},{"key":"2026033014315456900_ref062","first-page":"1","article-title":"Sovrin network for decentralized digital identity: Analysing a self-sovereign identity system based on distributed ledger technology","author":"Naik","year":"2021","journal-title":"2021 IEEE International Symposium on Systems Engineering (ISSE)."},{"key":"2026033014315456900_ref063","unstructured":"National Institute of Standards and Technology (NIST)\n          . (2025). \u201cNational Vulnerability Database (NVD)\u201d. url: https:\/\/nvd.nist.gov\/vuln."},{"key":"2026033014315456900_ref064","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1016\/j.cose.2018.03.001","article-title":"A systematic survey on multi-step attack detection","volume":"76","author":"Navarro","year":"2018","journal-title":"Computers & Security."},{"key":"2026033014315456900_ref065","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1145\/1592681.1592684","article-title":"Resonance: Dynamic access control for enterprise networks","author":"Nayak","year":"2009","journal-title":"Proceedings of the 1st ACM workshop on Research on enterprise networking."},{"key":"2026033014315456900_ref066","article-title":"The margrave tool for firewall analysis","author":"Nelson","year":"2010","journal-title":"Proceedings of the 24th Large Installation System Administration Conference (LISA 10)."},{"key":"2026033014315456900_ref067","unstructured":"Nginx, I.\n           (2024). NJS Scripting Language. url: https:\/\/nginx.org\/en\/docs\/njs\/."},{"key":"2026033014315456900_ref068","unstructured":"OASIS.\n           (2013). \u201ceXtensible Access Control Markup Language (XACML) Version 3.0 Core Specification\u201d. url: https:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.html."},{"key":"2026033014315456900_ref069","unstructured":"ONF.\n           (2024). \u201cONOS: Open Network Operating System\u201d. url: https:\/\/onosproject.org\/."},{"key":"2026033014315456900_ref070","unstructured":"Open Information Security Foundation.\n           (2025). \u201cSuricata \u2013 Open Source Threat Detection Engine\u201d. URL: https:\/\/suricata.io\/."},{"key":"2026033014315456900_ref071","article-title":"OpenFlow Switch Specification (version 1.5.1)","author":"Open","year":"2015","journal-title":"Tech. rep."},{"key":"2026033014315456900_ref072","unstructured":"OpenBSD.\n          \n          PF Manual Page. url: https:\/\/man. openbsd. org\/pf (accessed on 06\/20\/2021)."},{"key":"2026033014315456900_ref073","unstructured":"OpenID\n              Foundation.\n            \n           (2014). \u201cOpenID Connect Core 1.0\u201d. url: https:\/\/openid.net\/specs\/openid-connect-core-1_0.html."},{"key":"2026033014315456900_ref074","unstructured":"OpenZiti.\n           (2025a). \u201cIntroduction to OpenZiti\u201d. url: https:\/\/openziti.io\/docs\/learn\/introduction\/."},{"key":"2026033014315456900_ref075","article-title":"OpenZiti Components","author":"OpenZiti.","year":"2025"},{"issue":"1","key":"2026033014315456900_ref076","first-page":"28","article-title":"Design to deployment at Google","volume":"41","author":"Osborn","year":"2016","journal-title":"Usenix Login."},{"key":"2026033014315456900_ref077","unstructured":"Palo\n              Alto Networks.\n            \n           (2022). Zero Trust Enterprise: Design Guide. url: https:\/\/www.paloaltonetworks.com\/resources\/guides\/zero-trust-overview."},{"issue":"2","key":"2026033014315456900_ref078","first-page":"1","article-title":"Migrating to BeyondCorp: maintaining productivity while improving security","volume":"42","author":"Peck","year":"2017","journal-title":"login."},{"key":"2026033014315456900_ref079","first-page":"1","article-title":"An overview of limitations and approaches in identity management","author":"Pohn","year":"2020","journal-title":"Proceedings of the 15th International Conference on Availability, Reliability and Security."},{"issue":"2","key":"2026033014315456900_ref080","doi-asserted-by":"crossref","first-page":"1376","DOI":"10.1109\/COMST.2023.3239220","article-title":"Understanding O-RAN: Architecture, interfaces, algorithms, security, and research challenges","volume":"25","author":"Polese","year":"2023","journal-title":"IEEE Communications Surveys & Tutorials."},{"issue":"1","key":"2026033014315456900_ref081","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1145\/103140.103144","article-title":"A model of authorization for next-generation database systems","volume":"16","author":"Rabitti","year":"1991","journal-title":"ACM Transactions on Database Systems (TODS)."},{"key":"2026033014315456900_ref082","author":"Rais","year":"2024"},{"issue":"9","key":"2026033014315456900_ref083","doi-asserted-by":"crossref","first-page":"12781308","DOI":"10.1109\/PROC.1975.9939","article-title":"The protection of information in computer systems","volume":"63","author":"Saltzer","year":"1975","journal-title":"Proceedings of the IEEE."},{"key":"2026033014315456900_ref084","unstructured":"Salvador, S. and P. K.Chan. (2004). \u201cFastDTW: Toward Accurate Dynamic Time Warping in Linear Time and Space\u201d. In: URL: https:\/\/api.semanticscholar.org\/CorpusID:6226669."},{"key":"2026033014315456900_ref085","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1016\/S0065-2458(08)60206-5","article-title":"Role-based access control","volume":"46","author":"Sandhu","year":"1998","journal-title":"Advances in computers."},{"key":"2026033014315456900_ref086","unstructured":"Shah, A. and J.Roberts. (2019). \u201cPolicy Machine Core\u201d. URL: https:\/\/github.com\/usnistgov\/policy-machine-core."},{"issue":"1","key":"2026033014315456900_ref087","first-page":"1","article-title":"Improving efficiency of apriori algorithm using transaction reduction","volume":"3","author":"Singh","year":"2013","journal-title":"International Journal of Scientific and Research Publications."},{"key":"2026033014315456900_ref088","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1109\/CIC.2018.00-45","article-title":"Blockchain-based PKI solutions for IoT","author":"Singla","year":"2018","journal-title":"2018 IEEE 4th international conference on collaboration and internet computing (CIC)."},{"issue":"04","key":"2026033014315456900_ref089","first-page":"28","article-title":"Beyond corp: the access proxy","volume":"41","author":"Spear","year":"2016","journal-title":"Login."},{"key":"2026033014315456900_ref090","first-page":"207","article-title":"Zero trust architecture","volume":"800","author":"Stafford","year":"2020","journal-title":"NIST special publication."},{"key":"2026033014315456900_ref091","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1145\/3205977.3206000","article-title":"Network policy enforcement using transactions: The neutron approach","author":"Thomsen","year":"2018","journal-title":"Proceedings ofthe 23nd ACM on Symposium on Access Control Models and Technologies."},{"issue":"2","key":"2026033014315456900_ref092","doi-asserted-by":"crossref","first-page":"787","DOI":"10.1109\/SURV.2012.072412.00129","article-title":"A survey on identity management for the future network","volume":"15","author":"Torres","year":"2012","journal-title":"IEEE Communications Surveys & Tutorials."},{"key":"2026033014315456900_ref093","unstructured":"Trinsic.\n           (2025). \u201cTrinsic: Decentralized Identity Ecosystem\u201d. URL: https:\/\/trinsic.id\/."},{"issue":"6","key":"2026033014315456900_ref094","first-page":"6","article-title":"Beyondcorp: A new approach to enterprise security","volume":"39","author":"Ward","year":"2014","journal-title":"; login:: the magazine of USENIX & SAGE."},{"key":"2026033014315456900_ref095","first-page":"907","article-title":"Decentralized public key infrastructure for internet-of-things","author":"Won","year":"2018","journal-title":"MILCOM 20182018 IEEE Military Communications Conference (MILCOM)."},{"key":"2026033014315456900_ref096","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3528960","article-title":"Advancing Passwordless Authentication: A Systematic Review of Methods, Challenges, and Future Directions for Secure User Identity","author":"Yusop","year":"2025","journal-title":"IEEE Access."},{"key":"2026033014315456900_ref097","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.adhoc.2024.103414","article-title":"Flexible zero trust architecture for the cybersecurity of industrial IoT infrastructures","volume":"156","author":"Zanasi","year":"2024","journal-title":"Ad Hoc Networks."},{"key":"2026033014315456900_ref098","article-title":"Lightweight Directory Access Protocol (LDAP): The Protocol","author":"Zeilenga","year":"2006"}],"container-title":["Foundations and Trends\u00ae in Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/ftsec\/article-pdf\/8\/2\/122\/11147755\/3300000046en.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/ftsec\/article-pdf\/8\/2\/122\/11147755\/3300000046en.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T18:53:13Z","timestamp":1777488793000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/ftsec\/article\/8\/2\/122\/1332175\/The-Zero-trust-Paradigm-Concepts-Architectures-and"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":98,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,6,30]]}},"URL":"https:\/\/doi.org\/10.1561\/3300000046","relation":{},"ISSN":["2474-1558","2474-1566"],"issn-type":[{"value":"2474-1558","type":"print"},{"value":"2474-1566","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,30]]}}}