Saved in:
Bibliographic Details
Main Authors: Sandjaja, Fannya R., Majeed, Ayesha A., Abdullah, Abdullah, Wickremasinghe, Gyan, Rafferty, Karen, Sharma, Vishal
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2508.04526
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916971144019968
author Sandjaja, Fannya R.
Majeed, Ayesha A.
Abdullah, Abdullah
Wickremasinghe, Gyan
Rafferty, Karen
Sharma, Vishal
author_facet Sandjaja, Fannya R.
Majeed, Ayesha A.
Abdullah, Abdullah
Wickremasinghe, Gyan
Rafferty, Karen
Sharma, Vishal
contents Traditional security architectures are becoming more vulnerable to distributed attacks due to significant dependence on trust. This will further escalate when implementing agentic AI within the systems, as more components must be secured over a similar distributed space. These scenarios can be observed in consumer technologies, such as the dense Internet of things (IoT). Here, zero-trust architecture (ZTA) can be seen as a potential solution, which relies on a key principle of not giving users explicit trust, instead always verifying their privileges whenever a request is made. However, the overall security in ZTA is managed through its policies, and unverified policies can lead to unauthorized access. Thus, this paper explores challenges and solutions for ZTA policy design in the context of distributed networks, which is referred to as zero-trust distributed networks (ZTDN). This is followed by a case-study on formal verification of policies using UPPAAL. Subsequently, the importance of accountability and responsibility in the system's security is discussed.
format Preprint
id arxiv_https___arxiv_org_abs_2508_04526
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Policy Design in Zero-Trust Distributed Networks: Challenges and Solutions
Sandjaja, Fannya R.
Majeed, Ayesha A.
Abdullah, Abdullah
Wickremasinghe, Gyan
Rafferty, Karen
Sharma, Vishal
Networking and Internet Architecture
Distributed, Parallel, and Cluster Computing
Traditional security architectures are becoming more vulnerable to distributed attacks due to significant dependence on trust. This will further escalate when implementing agentic AI within the systems, as more components must be secured over a similar distributed space. These scenarios can be observed in consumer technologies, such as the dense Internet of things (IoT). Here, zero-trust architecture (ZTA) can be seen as a potential solution, which relies on a key principle of not giving users explicit trust, instead always verifying their privileges whenever a request is made. However, the overall security in ZTA is managed through its policies, and unverified policies can lead to unauthorized access. Thus, this paper explores challenges and solutions for ZTA policy design in the context of distributed networks, which is referred to as zero-trust distributed networks (ZTDN). This is followed by a case-study on formal verification of policies using UPPAAL. Subsequently, the importance of accountability and responsibility in the system's security is discussed.
title Policy Design in Zero-Trust Distributed Networks: Challenges and Solutions
topic Networking and Internet Architecture
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2508.04526