⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



Zero Trust Architecture for Industrial IoT Networks


Authors : Mohammed Ibrahim Abba; Womeodu Blessing; Raymond Ternenge Igbudu

Volume/Issue : Volume 11 - 2026, Issue 8 - August


Google Scholar : https://tinyurl.com/ymbmp753

DOI : https://doi.org/10.38124/ijisrt/26aug612

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : Industrial Internet of Things (IoT) networks connect sensors, programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, enterprise platforms, and cloud services to support automation, monitoring, predictive maintenance, and data-driven decision-making. This connectivity also expands the attack surface of operational technology (OT), particularly where legacy equipment, remote access, heterogeneous protocols, and stringent availability and safety requirements coexist. This paper develops a Zero Trust Architecture (ZTA) tailored to IIoT environments. The proposed architecture combines strong device and user identity, continuous verification, least-privilege and attribute-based access control, micro-segmentation, secure gateways for legacy devices, encrypted communication, continuous monitoring, and risk-adaptive policy enforcement. A simulation-oriented evaluation framework is specified using a representative industrial network comprising field devices, PLCs, SCADA/HMI systems, an edge gateway, enterprise resources, and a remote maintenance user. The evaluation is designed to compare authorized and unauthorized access, lateral-movement attempts, malicious commands, and controller or gateway failures using security and performance metrics. The architecture is intended to contain compromise while preserving the availability and timing requirements of industrial processes. Importantly, the manuscript distinguishes the proposed evaluation framework from experimentally measured results: numerical performance values are not presented as empirical findings unless generated by an executable testbed. The study concludes that Zero Trust is most practical in IIoT when implemented incrementally, with OT safety and availability treated as first-class requirements and legacy assets protected through compensating controls rather than forced modernization.

Keywords : Zero Trust Architecture; Industrial Internet of Things; Operational Technology; Micro-Segmentation; Access Control; PLC; SCADA; Network Security; Legacy Systems; Remote Access.

References :

  1. K. Stouffer et al., “Guide to Operational Technology (OT) Security,” NIST Special Publication 800-82 Rev. 3, National Institute of Standards and Technology, Gaithersburg, MD, USA, Sep. 2023. doi: 10.6028/NIST.SP.800-82r3.
  2. S. W. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, National Institute of Standards and Technology, Gaithersburg, MD, USA, Aug. 2020. doi: 10.6028/NIST.SP.800-207.
  3. F. Federici, D. Martintoni, and V. Senni, “A Zero-Trust Architecture for Remote Access in Industrial IoT Infrastructures,” Electronics, vol. 12, no. 3, Art. no. 566, 2023. doi: 10.3390/electronics12030566.
  4. C. Zanasi, S. Russo, and M. Colajanni, “Flexible Zero Trust Architecture for the Cybersecurity of Industrial IoT Infrastructures,” Ad Hoc Networks, vol. 156, Art. no. 103414, 2024.
  5. N. Basta et al., “Towards a Zero-Trust Micro-segmentation Network Security Strategy: An Evaluation Framework,” in Proc. IEEE/IFIP Network Operations and Management Symposium (NOMS), 2022.
  6. G. M. Køien, “Zero-Trust Principles for Legacy Components,” Wireless Personal Communications, vol. 121, pp. 1169–1186, 2021.
  7. Industrial Internet Consortium, “The Industrial Internet of Things Trustworthiness Framework Foundations,” Industrial Internet Consortium, 2019.
  8. U.S. Department of Defense Chief Information Officer, “Department of Defense Zero Trust Reference Architecture,” Version 2.0, Jul. 2022.

Industrial Internet of Things (IoT) networks connect sensors, programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, enterprise platforms, and cloud services to support automation, monitoring, predictive maintenance, and data-driven decision-making. This connectivity also expands the attack surface of operational technology (OT), particularly where legacy equipment, remote access, heterogeneous protocols, and stringent availability and safety requirements coexist. This paper develops a Zero Trust Architecture (ZTA) tailored to IIoT environments. The proposed architecture combines strong device and user identity, continuous verification, least-privilege and attribute-based access control, micro-segmentation, secure gateways for legacy devices, encrypted communication, continuous monitoring, and risk-adaptive policy enforcement. A simulation-oriented evaluation framework is specified using a representative industrial network comprising field devices, PLCs, SCADA/HMI systems, an edge gateway, enterprise resources, and a remote maintenance user. The evaluation is designed to compare authorized and unauthorized access, lateral-movement attempts, malicious commands, and controller or gateway failures using security and performance metrics. The architecture is intended to contain compromise while preserving the availability and timing requirements of industrial processes. Importantly, the manuscript distinguishes the proposed evaluation framework from experimentally measured results: numerical performance values are not presented as empirical findings unless generated by an executable testbed. The study concludes that Zero Trust is most practical in IIoT when implemented incrementally, with OT safety and availability treated as first-class requirements and legacy assets protected through compensating controls rather than forced modernization.

Keywords : Zero Trust Architecture; Industrial Internet of Things; Operational Technology; Micro-Segmentation; Access Control; PLC; SCADA; Network Security; Legacy Systems; Remote Access.

Paper Submission Last Date
30 - September - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe