Safety-Aware Zero Trust Enforcement for IoT and Cyber-Physical Systems
Researchers propose Safety-Aware Zero Trust that weighs physical harm from restricting IoT and cyber-physical components.
The paper proposes Safety-Aware Zero Trust for IoT and cyber-physical systems, where restricting a component can cause physical harm by removing needed telemetry or control. It maps NIST Zero Trust tenets to nine IoT and CPS strains and adds a Safety Engine and Telemetry Broker that weigh residual cyber risk against enforcement consequences. Command-side enforcement separates raw visibility, automated influence, and state-changing authority. An IEEE 30-bus false-data-injection case study makes containment, telemetry influence, physical impact, and authorization timing explicit.
- SA-ZT treats physical harm caused by a restriction as a policy input.
- A Safety Engine and Telemetry Broker extend the NIST Zero Trust Architecture.
- Enforcement separates visibility, automated influence, and state-changing authority.
- An IEEE 30-bus false-data-injection study illustrates the resulting trade-offs.
Full article216 words · extracted from arxiv.org · click to collapse
Zero Trust (ZT) replaces the implicit trust of perimeter-based security with explicit, continuous, context-aware authorization. This shift is particularly relevant to IoT and cyber-physical systems, whose heterogeneous, long-lived, and remotely connected components make persistent trust untenable. Yet their physical coupling complicates ZT adoption: restricting a suspicious component can reduce cyber exposure while removing telemetry or control capabilities required for operation. Existing work mainly models physical harm caused by attacks, with less attention to consequences introduced by enforcement itself. We introduce Safety-Aware Zero Trust (SA-ZT), which treats restriction-induced physical consequences as policy inputs. We map the NIST ZT tenets to nine IoT/CPS convergence strains, distinguish IoT-amplified challenges from those specific to cyber-physical coupling, and derive corresponding operational requirements. SA-ZT extends the NIST ZT Architecture with a Safety Engine and a Telemetry Broker. The Safety Engine selects among admissible responses by jointly considering residual cyber risk and restriction-induced consequences, while the Telemetry Broker mediates raw telemetry visibility and estimator influence. With command-side enforcement, these entities separate raw visibility, automated influence, and state-changing authority, preserving observations for monitoring while constraining their influence on automated control. An IEEE 30-bus case study under false-data-injection attack illustrates how SA-ZT makes cyber containment, telemetry visibility and influence, physical consequences, and authorization timing explicit, providing an implementable and inspectable representation of cyber-physical enforcement trade-offs.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.28170