{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T14:42:15Z","timestamp":1785249735029,"version":"3.55.0"},"reference-count":57,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2023,11,28]],"date-time":"2023-11-28T00:00:00Z","timestamp":1701129600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Shaanxi Key R&amp;D Program","award":["2019ZDLGY13-01"],"award-info":[{"award-number":["2019ZDLGY13-01"]}]},{"name":"Shaanxi Key R&amp;D Program","award":["2022JZ-40"],"award-info":[{"award-number":["2022JZ-40"]}]},{"name":"Natural Science Basic Research Plan in Shaanxi Province of China","award":["2019ZDLGY13-01"],"award-info":[{"award-number":["2019ZDLGY13-01"]}]},{"name":"Natural Science Basic Research Plan in Shaanxi Province of China","award":["2022JZ-40"],"award-info":[{"award-number":["2022JZ-40"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>As cross-border access becomes more frequent, traditional perimeter-based network security models can no longer cope with evolving security requirements. Zero trust is a novel paradigm for cybersecurity based on the core concept of \u201cnever trust, always verify\u201d. It attempts to protect against security risks related to internal threats by eliminating the demarcations between the internal and external network of traditional network perimeters. Nevertheless, research on the theory and application of zero trust is still in its infancy, and more extensive research is necessary to facilitate a deeper understanding of the paradigm in academia and the industry. In this paper, trust in cybersecurity is discussed, following which the origin, concepts, and principles related to zero trust are elaborated on. The characteristics, strengths, and weaknesses of the existing research are analysed in the context of zero trust achievements and their technical applications in Cloud and IoT environments. Finally, to support the development and application of zero trust in the future, the concept and its current challenges are analysed.<\/jats:p>","DOI":"10.3390\/e25121595","type":"journal-article","created":{"date-parts":[[2023,11,28]],"date-time":"2023-11-28T11:43:16Z","timestamp":1701171796000},"page":"1595","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":106,"title":["Theory and Application of Zero Trust Security: A Brief Survey"],"prefix":"10.3390","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2408-2380","authenticated-orcid":false,"given":"Hongzhaoning","family":"Kang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi\u2019an 710071, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0726-3164","authenticated-orcid":false,"given":"Gang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi\u2019an 710071, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quan","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi\u2019an 710071, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Meng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi\u2019an 710071, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jing","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Xi\u2019an University of Technology, Xi\u2019an 710048, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,11,28]]},"reference":[{"key":"ref_1","unstructured":"(2023, November 18). FireEye Mandiant M-Trends. Available online: https:\/\/mandiant.widen.net\/s\/kxbbdppzzk\/m-trends-2022-executive-summary."},{"key":"ref_2","unstructured":"Northcutt, S., Zeltser, L., Winters, S., Kent, K., and Ritchey, R.W. (2005). Inside Network Perimeter Security (Inside), Sams. [2nd ed.]."},{"key":"ref_3","unstructured":"Kindervag, J. (2010). No More Chewy Centers: Introducing the Zero Trust Model of Information Security, Forrester Research."},{"key":"ref_4","unstructured":"(2023, November 18). Jericho Forum Commandments, Version 1.2. Available online: https:\/\/static.spiceworks.com\/attachments\/post\/0016\/4842\/commandments_v1.2.pdf."},{"key":"ref_5","first-page":"6","article-title":"Beyondcorp: A new approach to enterprise security","volume":"39","author":"Ward","year":"2014","journal-title":"Login Usenix Mag."},{"key":"ref_6","first-page":"28","article-title":"Beyondcorp: Design to deployment at google","volume":"41","author":"Osborn","year":"2016","journal-title":"Login"},{"key":"ref_7","first-page":"38","article-title":"BeyondCorp: The user experience","volume":"42","author":"Escobedo","year":"2017","journal-title":"Login"},{"key":"ref_8","unstructured":"(2023, November 18). Software Defined Perimeter. Available online: https:\/\/cloudsecurityalliance.org\/download\/artifacts\/software-defined-perimeter\/."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Rose, S., Borchert, O., Mitchell, S., and Connelly, S. (2020). Zero Trust Architecture, Technical Report.","DOI":"10.6028\/NIST.SP.800-207-draft2"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"6476274","DOI":"10.1155\/2022\/6476274","article-title":"A survey on zero trust architecture: Challenges and future trends","volume":"2022","author":"He","year":"2022","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"102436","DOI":"10.1016\/j.cose.2021.102436","article-title":"Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust","volume":"110","author":"Buck","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"393","DOI":"10.5465\/amr.1998.926617","article-title":"Not so different after all: A cross-discipline view of trust","volume":"23","author":"Rousseau","year":"1998","journal-title":"Acad. Manag. Rev."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1109\/SURV.2011.042711.00083","article-title":"Trust computations and trust dynamics in mobile adhoc networks: A survey","volume":"14","author":"Govindan","year":"2011","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Nitti, M., Girau, R., Atzori, L., Iera, A., and Morabito, G. (2012, January 9\u201312). A subjective model for trustworthiness evaluation in the social internet of things. Proceedings of the 2012 IEEE 23rd International Symposium on Personal, Indoor and Mobile Radio Communications-(PIMRC), Sydney, NSW, Australia.","DOI":"10.1109\/PIMRC.2012.6362662"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"318","DOI":"10.1109\/JSAC.2005.861390","article-title":"On trust models and trust evaluation metrics for ad hoc networks","volume":"24","author":"Theodorakopoulos","year":"2006","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1139","DOI":"10.1111\/j.1539-6924.2006.00821.x","article-title":"Explicit and implicit trust within safety culture","volume":"26","author":"Burns","year":"2006","journal-title":"Risk Anal."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"122","DOI":"10.1037\/a0036673","article-title":"Trust at zero acquaintance: More a matter of respect than expectation of reward","volume":"107","author":"Dunning","year":"2014","journal-title":"J. Personal. Soc. Psychol."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Pearson, S., Mont, M.C., and Crane, S. (2005, January 23\u201326). Persistent and dynamic trust: Analysis and the related impact of trusted platforms. Proceedings of the Trust Management: Third International Conference, iTrust 2005, Paris, France.","DOI":"10.1007\/11429760_24"},{"key":"ref_19","unstructured":"ACT-IAC Zero-trust Project Team (2023, November 18). Zero-Trust Cybersecurity Current Trends. Available online: https:\/\/www.actiac.org\/system\/files\/ACT-IACZeroTrustProjectReport04182019.pdf."},{"key":"ref_20","unstructured":"Tidjon, L.N., and Khomh, F. (2022). Never trust, always verify: A roadmap for Trustworthy AI?. arXiv."},{"key":"ref_21","unstructured":"Kindervag, J., Balaouras, S., Mak, K., and Blackborow, J. (2016). No More Chewy Centers: The Zero Trust Model of Information Security, Forrester Research."},{"key":"ref_22","unstructured":"(2023, November 18). Embracing a Zero-Trust Security Model, Available online: https:\/\/media.defense.gov\/2021\/Feb\/25\/2002588479\/-1\/-1\/0\/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Garbis, J., and Chapman, J.W. (2021). Zero Trust Security, Apress.","DOI":"10.1007\/978-1-4842-6702-8"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1109\/MC.2020.3011081","article-title":"Beyond zero trust: Trust is a vulnerability","volume":"53","author":"Campbell","year":"2020","journal-title":"Computer"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Eidle, D., Ni, S.Y., De Cusatis, C., and Sager, A. (2017, January 19\u201321). Autonomic security for zero trust networks. Proceedings of the 2017 IEEE 8th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference (UEMCON), New York, NY, USA.","DOI":"10.1109\/UEMCON.2017.8249053"},{"key":"ref_26","first-page":"226","article-title":"Software-Defined Perimeter (SDP): State of the Art Secure Solution for Modern Networks","volume":"33","author":"Moubayed","year":"2019","journal-title":"Netwrk. Mag. Glob. Internetwkg."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kumar, P., Moubayed, A., Refaey, A., Shami, A., and Koilpillai, J. (2019, January 15\u201318). Performance analysis of sdp for secure internal enterprises. Proceedings of the 2019 IEEE Wireless Communications and Networking Conference (WCNC), Marrakesh, Morocco.","DOI":"10.1109\/WCNC.2019.8885784"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/MNET.011.1900563","article-title":"Multilevel security framework for nfv based on software defined perimeter","volume":"34","author":"Singh","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"57143","DOI":"10.1109\/ACCESS.2022.3174679","article-title":"Zero trust architecture (zta): A comprehensive survey","volume":"10","author":"Syed","year":"2022","journal-title":"IEEE Access"},{"key":"ref_30","unstructured":"(2023, November 18). AWS Identity & Access Management. Available online: https:\/\/aws.amazon.com\/cn\/iam\/."},{"key":"ref_31","unstructured":"(2023, November 18). Sailpoint IDM. Available online: https:\/\/www.sailpoint.com\/identity-management-solutions\/."},{"key":"ref_32","unstructured":"(2023, November 18). IBM Cloud Services. Available online: https:\/\/www.ibm.com\/cloud-computing\/in-en\/services\/cloud-managed-services\/."},{"key":"ref_33","unstructured":"(2023, November 18). Oracle Cloud Services. Available online: https:\/\/www.oracle.com\/cloud\/index.html."},{"key":"ref_34","unstructured":"(2023, November 18). Coresecurity IAM. Available online: https:\/\/www.rsa.com\/en-us\/products\/rsa-securid-suite.html."},{"key":"ref_35","unstructured":"(2023, November 18). Sailpoint IDM. Available online: https:\/\/www.coresecurity.com\/iam-products."},{"key":"ref_36","unstructured":"(2023, November 18). SDP, ZTNA, and CARTA: Making Sense of the Zero Trust Security Buzz. Available online: https:\/\/www.zscaler.com\/."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Leahy, D., and Thorpe, C. (2022, January 17\u201318). Zero Trust Container Architecture (ZTCA): A Framework for Applying Zero Trust Principals to Docker Containers. Proceedings of the International Conference on Cyber Warfare and Security, New York, NY, USA.","DOI":"10.34190\/iccws.17.1.35"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1186\/2192-113X-2-9","article-title":"Trust mechanisms for cloud computing","volume":"2","author":"Huang","year":"2013","journal-title":"J. Cloud Comput. Adv. Syst. Appl."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"DeCusatis, C., Liengtiraphan, P., Sager, A., and Pinelli, M. (2016, January 18\u201320). Implementing zero trust cloud networks with transport access control and first packet authentication. Proceedings of the 2016 IEEE International Conference on Smart Cloud (SmartCloud), New York, NY, USA.","DOI":"10.1109\/SmartCloud.2016.22"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Zaheer, Z., Chang, H., Mukherjee, S., and Van der Merwe, J. (2019, January 3\u20134). eZTrust: Network-independent zero-trust perimeterization for microservices. Proceedings of the 2019 ACM Symposium on SDN Research, San Jose, CA, USA.","DOI":"10.1145\/3314148.3314349"},{"key":"ref_41","first-page":"103138","article-title":"Exploiting lsb self-quantization for plaintext-related image encryption in the zero-trust cloud","volume":"66","author":"Liu","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Lehto, M., and Neittaanm\u00e4ki, P. (2022). Cyber Security, Springer.","DOI":"10.1007\/978-3-030-91293-2"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Sarkar, S., Choudhary, G., Shandilya, S.K., Hussain, A., and Kim, H. (2022). Security of zero trust networks in cloud computing: A comparative review. Sustainability, 14.","DOI":"10.3390\/su141811213"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1016\/j.jnca.2017.04.002","article-title":"Internet of Things security: A survey","volume":"88","author":"Alaba","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"2386","DOI":"10.1109\/JIOT.2017.2755620","article-title":"The future internet of things: Secure, efficient, and model-based","volume":"5","author":"Siegel","year":"2017","journal-title":"IEEE Internet Things J."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Samaniego, M., and Deters, R. (2018, January 2\u20137). Zero-trust hierarchical management in IoT. Proceedings of the 2018 IEEE International Congress on Internet of Things (ICIOT), San Francisco, CA, USA.","DOI":"10.1109\/ICIOT.2018.00019"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1080\/10919392.2020.1831870","article-title":"Securing IoT devices using zero trust and blockchain","volume":"31","author":"Dhar","year":"2021","journal-title":"J. Organ. Comput. Electron. Commer."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Zhao, S., Li, S., Li, F., Zhang, W., and Iqbal, M. (2020, January 6\u20137). Blockchain-enabled user authentication in zero trust internet of things. Proceedings of the Security and Privacy in New Computing Environments: Third EAI International Conference, SPNCE 2020, Lyngby, Denmark.","DOI":"10.1007\/978-3-030-66922-5_18"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1002\/spy2.191","article-title":"Augmenting zero trust architecture to endpoints using blockchain: A state-of-the-art review","volume":"5","author":"Alevizos","year":"2022","journal-title":"Secur. Priv."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MCE.2022.3207862","article-title":"Optimal Federation Method for Embedding Internet of Things in Software-Defined Perimeter","volume":"12","author":"Palmo","year":"2022","journal-title":"IEEE Consum. Electron. Mag."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1007\/s10922-021-09623-7","article-title":"Design of a Security and Trust Framework for 5G Multi-domain Scenarios","volume":"30","author":"Valero","year":"2022","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Li, S., Iqbal, M., and Saxena, N. (2022). Future industry internet of things with zero-trust security. Inf. Syst. Front., 1\u201314.","DOI":"10.1007\/s10796-021-10199-5"},{"key":"ref_53","unstructured":"Chen, Z., Yan, L., L\u00fc, Z., Zhang, Y., Guo, Y., Liu, W., and Xuan, J. (2020, January 23\u201325). Research on zero-trust security protection technology of power IoT based on blockchain. Proceedings of the 5th International Conference on Computer Science and Information Engineering (ICCSIE 2020), Dalian, China."},{"key":"ref_54","unstructured":"Zhang, X., Chen, L., Fan, J., Wang, X., and Wang, Q. (2021, January 8\u201310). Power IoT security protection architecture based on zero trust framework. Proceedings of the 2021 IEEE 5th International Conference on Cryptography, Security and Privacy (CSP), Zhuhai, China."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1016\/j.future.2018.04.007","article-title":"Building situational awareness for network threats in fog\/edge computing: Emerging paradigms beyond the security perimeter model","volume":"85","author":"Rapuzzi","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Mehraj, S., and Banday, M.T. (2020, January 22\u201324). Establishing a zero trust strategy in cloud computing environment. Proceedings of the 2020 International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, India.","DOI":"10.1109\/ICCCI48352.2020.9104214"},{"key":"ref_57","first-page":"4","article-title":"Insiders and Insider Threats-An Overview of Definitions and Mitigation Techniques","volume":"2","author":"Hunker","year":"2011","journal-title":"J. Wirel. Mob. Netw. Ubiquitous Comput. Dependable Appl."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/12\/1595\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:32:42Z","timestamp":1760131962000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/12\/1595"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,28]]},"references-count":57,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["e25121595"],"URL":"https:\/\/doi.org\/10.3390\/e25121595","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,28]]}}}