Integrating Trusted Computing Mechanisms with Trust Models to Achieve Zero Trust Principles

Muntaha Alawneh, Imad M. Abbadi · 2022

One of the main pillars for creating a sustainable model to address changes in the threat landscape is the Zero Trust principle of "Never Trust/Always Verify". Zero Trust focuses on addressing insiders and creeping insiders problem including those existing in clouds, IoT and social networks environment. We noticed Zero Trust did not yet get enough attention from academia and most of the work done on Zero Trust is coming from industry. Majority of the work on this domain are vendor specific and not well covered from an enterprise security architecture point of view. This results in narrow focus and inconsistencies. The use of trust models to implement the "Never Trust" principle, and the "Always Verify" concept utilizing trusted computing techniques is our major contribution. The integration of Trusted Computing mechanisms with Trust Models would strongly help in achieving the Zero Trust principles.

Read the paper · More papers on PaperTik