Converging Zero Trust and IoT Security: A Multivocal Literature Review MARIAM WEHBE and LAURENT BOBELIN, INSA Centre Val de Loire, France The convergence of Internet of Things (IoT) security and Zero Trust (ZT) principles is a trending topic, demanding a comprehensive, multi-perspective analysis. We present the first multivocal literature review (MLR) on this topic, combining 68 academic and 36 industrial studies. This comprehensive review identifies two complementary yet divergent perspectives: academia focuses on IoT compliance with ZT principles through IoT modifications, while industry prioritizes practical integration within existing ZT frameworks guided by NIST standards. The analysis reveals critical research gaps in socio-technical understanding, cost-benefit evaluation, and
CS UR
CCS Concepts: • Security and privacy → Network security; • Computer systems organization → Embedded systems. Additional Key Words and Phrases: Zero Trust, Internet of Things, Multivocal Literature Review, Cybersecurity ACM Reference Format:
Mariam Wehbe and Laurent Bobelin. 2025. Converging Zero Trust and IoT Security: A Multivocal Literature Review. 1, 1 (April 2025), 34 pages. https://doi.org/XXXXXXX.XXXXXXX
Introduction
AC M
1
Zero Trust (ZT) security [88] was designed to avoid implicit trust - a philosophy summarized by the motto “Never trust, always verify". Since Google’s seminal BeyondCorp initiative [46], both academia and industry have shown growing interest in ZT. For the former, it proposes exciting new challenges, for the latter, ZT enforces security at an unprecedented level.
Internet of Things (IoT) devices are now widely deployed around the world. Modern systems commonly combine IoT
to
devices with server, cloud, fog, and edge-based computation and storage, as seen in IIoT, smart systems, and dataspaces. IoT security is considered a specific subdomain of cybersecurity [83]. Integrating IoT devices increases the complexity of adopting ZT: IoT and ZT security paradigms must converge to form a consistent model. This issue has been examined
ed
by numerous researchers and industry stakeholders. However, despite the growing adoption of ZT, no comprehensive synthesis exists of how ZT principles apply to IoT security in both academic and industrial contexts.
itt
The convergence between ZT and IoT security can be approached in two ways: (1) align IoT security with ZT architecture.
m
principles to create a ZT-compliant model for IoT platforms, or (2) integrate IoT security into a broader ZT-based Many challenges exist for the first approach — making IoT systems follow ZT guidelines. ZT requires end-to-end security but IoT is a vulnerable endpoint. IoT devices may lack the capacity to encrypt traffic or authenticate themselves,
Su b
arXiv:2604.24205v1 [cs.CR] 27 Apr 2026
interdisciplinary collaboration, highlighting these as key directions for future research.
yet encryption and authentication are core ZT requirements.Even when IoT devices implement these features, they Authors’ Contact Information: Mariam Wehbe, [email protected]; Laurent Bobelin, [email protected], INSA Centre Val de Loire, Bourges, France. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]. © 2025 Copyright held by the owner/author(s). Publication rights licensed to ACM. Manuscript submitted to ACM Manuscript submitted to ACM
1
2
Mariam Wehbe and Laurent Bobelin
may still lack the capacity to protect credentials or apply strong encryption. As ZT rejects the concept of implicit trust and adopts a philosophy of continuous verification, IoT devices often fail to reach the level of trust that ZT requires. Additional challenges arise with the second approach — integrating IoT into larger ZT-based systems. Most ZT security architectures rely on centralized knowledge management of the entities that compose a system, consistent with NIST recommendations [88]. The decentralized and short-lived nature of IoT devices — combined with their heterogeneity and sheer number — adds complexity to their integration into ZT architectures. IoT integration into the ZT platform then necessitates tailored strategies and solutions. Obtaining a comprehensive overview of how this convergence is occurring in industry is complex. Mainstream ZT solutions are primarily offered by large vendors (such as GAFAM), since providing ZT capabilities requires developing and integrating numerous components into a consistent platform. These companies offer varying levels of transparency
CS UR
about their tools and differing support for ZT, IoT security, and their convergence [19].
ZT’s status as a widely used term complicates market analysis. The situation is further complicated because many so-called ZT or IoT solutions do not actually implement either concept in practice. Academic publications are likewise influenced by terminological trends; some authors frame their work as addressing ZT or IoT even when the connection is limited. The contribution of this paper is to give a better understanding of this domain, by answering the question: What is the current state of the art and evolution of IoT security and ZT convergence?
AC M
To answer this question, this paper presents the first Multivocal Literature Review (MLR)[41] on this topic. An MLR is a type of Systematic Literature Review (SLR) [57, 108] that encompasses both academic and industrial sources. An SLR applies a systematic methodology to review literature in a reproducible manner. MLR extends SLR by including the industrial literature. This MLR followed the widely adopted PRISMA 2020 framework guidelines for meta reviews [79] for the current reporting of this work, while using Garousi and al [41] process for conducting the MLR. Prior reviews on ZT such as [20], [3], [52], focus on specific subtopics (implementation, Intrusion Detection Systems,
to
for example) related to IoT security and ZT convergence. None of them encompasses industrial and academic point of view on IoT security convergence with ZT to have an overview of the current state of the art.
ed
Key contributions of this paper are:
• First MLR on IoT security–ZT convergence.
itt
• Comparative analysis of academic vs industrial perspectives. • Identification of research gaps.
m
The remainder of the paper is structured as follows. Section 2 explains the basics of ZT, IoT security, and the main ideas behind IoT security and ZT convergence. Section 3 gives an overview of work related to this paper. Then, Section
Su b
4 describes this MLR approach to select and analyze literature, criteria for inclusion, search strategies, data extraction methods, and Research Questions (RQs) structuring the study. Section 5 provides an analysis of the collected data, and Section 6 answers the RQs. Section 7 provides avenue for future research. Section 8 summarizes the threats to the
validity of our study. Finally, Section 9 provides concluding remarks. 2 2.1
Background ZT Overview
ZT is a security model relying on the idea that perimeter-based security is inefficient when the so-called perimeter is breached; nowadays, as phishing campaigns are more and more common, a user will likely compromise at least one of the resources enclosed within a perimeter. From an initial compromise of a single host, an attacker uses lateral Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
3
movement—enabled by credential harvesting and remote execution—to progressively spread malware and gain control over a whole system by compromising adjacent machines, then networks, by compromising highly privileged accounts. ZT addresses the problem by requiring to never grant trust to other resources by default, thus forbidding lateral movements. In practice, ZT is commonly understood either as: (1) A motto/model/set of guidelines, or (2) A type of security architecture formally defined by NIST [88] and known as Zero Trust Architectures (ZTA). 2.1.1
ZT Guidelines. There is a consensus on the set of guidelines to follow [44]: • All network flows SHOULD be encrypted before being transmitted.
CS UR
• All network flows MUST be authenticated before being processed. • Authentication and encryption MUST be performed by the endpoints in the network.
• All network flows MUST be enumerated so that access can be enforced by the system.
• The strongest authentication and encryption suites SHOULD be used within the network.
• Authentication SHOULD NOT rely on public PKI providers. Private PKI systems should be used instead. • Devices SHOULD be regularly scanned, patched, and rotated.
ZT Architecture. To comply with ZT guidelines, NIST recommended the logical architecture depicted inFigure
AC M
2.1.2
Su b
m
itt
ed
to
1.
Fig. 1. ZT Architecture (PIP in blue, core component with thick lines)
The standard identifies the issuer of the request as a subject that can be either a (human) user or an application/service. This subject uses a device to issue the request. This device may or may not be hosting a software agent, part of the ZT architecture, that will secure the asset and information provided by this device. The request for access targets a protected resource (that may be thought of as data or a service). Policy Enforcement Point (PEP) is often implemented Manuscript submitted to ACM
4
Mariam Wehbe and Laurent Bobelin
as a gateway: it enforces decisions about whether or not to grant trust to a flow by the Policy Decision Point (PDP). The separation between PEP and PDP relies on the separation between the control plane (which makes decisions on how to handle the traffic) and the data plane. PEP belongs to the data plane, while PDP relies on the control plane. The PDP decision-making is done using as many data sources as possible to make the wisest decision: information about the system state, the users, policies deployed, threat intelligence, etc. Those sources are named Policy Information Points (PIP). PDP itself in the NIST standard includes the Policy Engine (PE) component, which is the decision-making component, and the Policy Administration (PA) component, which is responsible for coordinating the actions of the PEP to reflect the decisions of the PE. Some authors and companies (see for instance [6]) add a Trust Engine component (TE). TE is responsible for running a Trust Algorithm (TA), interacting with the different data sources to evaluate risk. PE in this
CS UR
case makes its decision based on the risk evaluation returned by TE and the policies applying to the system. It is then not responsible for evaluating the risk per se. Google ZT solution BeyondCorp has pioneered the use of TE: it helps maintain a lower complexity of the system policy, by discarding edge cases and other unknown/unaddressed cases. 2.2
IoT Security Overview
IoT devices’ exposure stems from both intrinsic constraints—limited energy, computation, and storage—and extrinsic farming, to name a few) [37, 60, 96, 114].
AC M
conditions such as physical accessibility and non-expert administration in consumer contexts (e.g., smart homes, smart
ed
to
Application Layer Smart Services, Data Analytics, User Interfaces, Cloud Platforms Examples: Smart city dashboards, healthcare apps
Policy Decision Point (PDP) Access Policies, Risk Engine
Middleware Layer
m
itt
Data Processing, Storage, API Management, Context Awareness Examples: IoT brokers (MQTT, CoAP), edge nodes, message queues
Policy Enforcement Point (PEP) API Gateway, Broker Security
ID Management IAM, MFA, Certificates
Perception (Sensing) Layer Sensors, Actuators, RFID, Embedded Controllers Examples: Temperature sensors, RFID tags, motion detectors
Policy Information Point (PIP) Telemetry, Continuous Monitoring
Su b
Network Layer Communication Infrastructure, Protocols, Gateways, Security Controls Examples: 5G, Wi-Fi, ZigBee, IPv6, VPNs, routing, firewalls
Fig. 2. Four-layer IoT architecture (on the left) with mapped Zero Trust (ZT) control components (on the right). Each layer interacts with corresponding ZT elements to enforce continuous authentication, policy decision-making, and telemetry-driven trust evaluation. Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
5
While IoT security borrows concepts from general device protection—encryption, secure boot, patch management, and access control—it remains uniquely constrained by heterogeneity, decentralization, and limited hardware capabilities. Consequently, IoT security enforcement adopts tailored protocols and lightweight mechanisms rather than replicating enterprise-level models. To do so, IoT security mechanisms spans the four typical IoT architecture layers illustrated by boxes on the left in Figure 2: (1) perception (sensing and actuation), (2) network (communication), (3) middleware (data aggregation and storage), and (4) application (analytics and services). Each layer introduces distinct attack vectors and protection requirements. IoT Security Integration management platforms. Common threats include[7]: • Denial of service via device unavailability, • Data poisoning or sensor cloning, • Information leakage through unsecured communications, and • System compromise by exploiting IoT as an initial intrusion vector.
CS UR
When IoT components integrate with broader infrastructures, they expand the attack surface to both endpoints and
Mitigation relies on comprehensive security ecosystems offering capabilities such as:
AC M
• Asset discovery and vulnerability scanning to identify connected devices and weak configurations [73], [113], [34],
• Device authentication and authorization to control access based on identity and privileges, • Secure communication through encryption protocols (e.g., TLS/SSL),
• Continuous monitoring and threat detection for anomaly identification, and
to
• Patch management and vulnerability assessment for timely remediation [37].
Ultimately, securing IoT ecosystems requires harmonizing these operational controls with ZT principles—ensuring continuous verification and context-aware enforcement across highly heterogeneous environments.
ed
Figure 2 illustrates how ZT elements defined in the NIST architecture (on the right) interact with the four foundational layers of the IoT architecture (on the left). At the application level, policy decision points (PDPs) evaluate contextual
itt
access requests; in the middleware, policy enforcement points (PEPs) implement those decisions and regulate data exchange through APIs and brokers. The network layer relies on identity providers (IdPs) to authenticate entities
m
and manage cryptographic credentials, while the perception layer integrates telemetry and device-trust mechanisms that continuously assess sensor integrity, and thus provide information, and then may be considered as a PIP. Effec-
Su b
tive convergence requires synchronized advances in technical infrastructure, cryptographic agility, and workforce competencies, and this effort can be done in two ways: adapt ZT architecture to IoT, or adapt IoT to ZT architecture. 2.3
IoT Security and ZT Convergence
An overview of the problem of securing systems containing IoT using ZT security model is given in Figure 3. It can be seen as the conjunction of 3 different fields, and decomposed into different topics: making the system security compliant with ZT, making IoT compliant with ZT, and integrating IoT (sub)system into the whole system security. This paper deals only with topics related to ZT and IoT security convergence. Securing IoT devices themselves, securing the system itself, refining/defining the ZT model, and system compliance with ZT requirements, are all out of the scope of this study. Manuscript submitted to ACM
Mariam Wehbe and Laurent Bobelin
CS UR
6
AC M
Fig. 3. Integration of IoT security into ZT
However, two different topics are crucial: (1) IoT compliance with ZT requirements, (2) IoT and ZT integration. The former deals with how the IoT device may be refactored, modified, or configured to be able to be included in the ZT architecture, or at least to embrace its philosophy. An example of work in this paper includes the use of blockchain to increase IoT trust [65]. The latter deals with how the ZT model may be changed to take into account the IoT characteristics, or how specific tools or mechanisms may be put in place to integrate IoT into a ZT platform. Isolation for
to
example is the solution advocated by most of the industry falling into that topic [19]. This paper deals with academics and industrial solutions for both of those interrelated topics. Related Work
ed
3
As stated before, there is no -up to our knowledge- MLR related to the subject of IoT security and ZT convergence.
itt
IoT security has been an active subject for many years, and therefore many SLRs have been published either directly on IoT security [31], [83], or more specifically on IoT forensic [2] for example. [71] deals with generative IA applications
m
to IoT security. Other SLRs that deal with IoT may contain sections dedicated to security, for example, [17] deals with IoT in general, [18] focuses on IoT gateways, [98] focuses on lightweight blockchains for IoT, [74] focuses on IoT
Su b
applications in healthcare. [24] is a state-of-the-art on access control enforcement in IoT. Much work exists for ZT: [3], for example, is an SLR focusing on Intrusion Detection Systems, and ZT, [52] is an MLR
focusing on implementation aspects of ZT. Some of them discuss, to a certain extent, IoT security and ZT convergence.
Another state-of-the-art focuses on ZT [67] and then considers how ZT may be implemented given the IoT context. An SLR recently published focuses on ZT and its possible use in IoT, but does not encompass the industrial work [14]. [11] surveys ZT in the context of autonomous vehicles. Industrial solutions that integrate IoT in ZT are reviewed in [19]. This work targets only complete solutions provided by major industrial actors, with a specific focus on estimating how strong the support for IoT integration into available products is. [20] is an MLR focusing on ZT that includes some statements on IoT; [99] is a survey on ZT with some discussion about the challenges IoT induces, as well as [110], [56], and [43]. [101] is a book chapter discussing ZT and IoT. [54] is a handbook on IoT security that integrates a small Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
7
Table 1. Condensed Classification of Related Work References by Topic (IoT, Zero Trust, IoT + ZT)
[3] [52] [20] [99] [43]
ZT
Acad.
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
Ind.
Syst.
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ✓ ✓
✓ ✓ ✓
✓ ✓
✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ✓ ✓ ✓
✓
✓
✓ ✓ ✓
✓ ✓ ✓ ✓ ✓
✓ ✓ ✓ ✓ ✓
✓
✓
to
[24] [67] [14] [11] [19] [110] [56] [101] [54] [63] [64] [26] This work
IoT
IoT-focused Systematic Reviews Systematic Literature Review of IoT Security Patterns and Architectures for IoT Security Blockchain-based IoT Forensic Investigation Models Generative AI Solutions in IoT Security The Anatomy of IoT Platforms — Multivocal Mapping Systematic Review on IoT Gateways Lightweight Blockchain for IoT: SLR Enabling IoT in Healthcare: Motivations, Challenges, and Recommendations Zero Trust (ZT)-focused Studies Zero Trust for Intrusion Detection Systems: SLR Multivocal Review on Zero-Trust Implementation Never Trust, Always Verify: A Multivocal Review of ZeroTrust Zero Trust Architecture (ZTA): Comprehensive Survey Zero Trust: Applications, Challenges, and Opportunities IoT + ZT Convergence Studies Access Control in IoT: Challenges in the Zero Trust Era Dissecting Zero Trust and Its Implementation in IoT Verify and Trust: Zero-Trust Security in the Age of IoT Towards Zero Trust Security in Connected Vehicles Industrial Literature Review: Zero Trust in IoT Survey on Zero-Trust Network Security Theory and Application of Zero Trust Security Cyber Risks on IoT Platforms and Zero Trust Solutions IoT and OT Security Handbook Editorial: Zero Trust based Internet of Things Future Industry IoT with Zero-trust Security Shared Responsibility and Zero Trust in the Industrial IoT Converging Zero Trust and IoT Security: A MLR
CS UR
[31] [83] [2] [71] [17] [18] [98] [74]
Title
AC M
Citation
chapter on IoT integration into ZT. [63] is an editorial that introduces ZT for IoT. [64] introduces challenges induced by
ed
ZT in 5G/6G environments. [26] focuses on ZT implementations for IIoT. Table 1 gives a summary of the related work and how they relate to IoT, ZT, academic work, industrial aspects, and if
Methodology
m
4
itt
they used a Systematization of Knowledge methodology (SLR, MLR or other systematic approaches).
The industrial sector plays a leading role in research on the convergence of ZT and IoT security. To analyze existing
Su b
knowledge from both academic and industrial perspectives, a Multivocal Literature Review (MLR) [41] was conducted. The review followed Garousi et al.’s methodology [40] and PRISMA 2020 guidelines [79]. More details about our methodology is provided in appendix A. MLR combines Academic Literature (AL), which includes peer-reviewed scholarly works, with Grey Literature (GL), such as technical reports, white papers, and blogs. While GL is less formal, it often provides practical insights and recent developments. In a MLR, sources are categorized in tiers by their credibility and level of outlet control: Tier 1 (High) for white papers, tier 2 (Medium) for news articles and corporate reports, and Tier 3 (Low) for social media. To ensure relevance, only high and medium quality GL (tiers 1 and 2) were considered in this study. Tier 1 includes sources like NIST SP 800-207 [88] and industry white papers such as Microsoft Azure’s white paper Zero Trust Cybersecurity for the Internet of Things [15]. Manuscript submitted to ACM
8
Mariam Wehbe and Laurent Bobelin Table 2. Research Questions Summarized
Level of analy- Design and features sis
Measurement and value
Management and organization
4.1
AC M
CS UR
Concept and ar- RQ1: How to technically re- RQ2: What are the benefits RQ3: What are the human chitecture alize convergence of IoT se- and limitations of IoT secu- resources needed to maincurity and ZT? rity and ZT convergence? tain a system that adopted a ZT and IoT security convergence philosophy? Firms and in- RQ4: How can organiza- RQ5: How do IoT security RQ6: How should organidustries tions realize IoT security and ZT convergence pro- zations organize, govern, and ZT convergence? vide added value for orga- fund, and develop IoT secunizations? rity and ZT convergence? Users and soci- RQ7: How do IoT secu- RQ8: What are the benefits RQ9: How does one balance ety rity and ZT convergence af- and costs of ZT and IoT se- user privacy and ZT and fect the interaction between curity convergence for indi- IoT security convergence reusers and technology? vidual users and society? quirements?
Research Questions and Data Analysis Strategy
This review used and adapted the research questions framework already appearing in former MLRs such as [20], [85], or [12]. The basic idea of this framework is to consider the literature from two different perspectives they named dimensions.
Those two dimensions are activities and levels of analysis influenced by activities. Activities pertain to the actions
to
that developers or users undertake and are categorized into three groups. First, design and feature activities involve understanding the implementation and design of concepts, including the consequences of certain design choices.
ed
Second, measurement and value questions revolve around the added value provided, specifically how to create and measure additional value for stakeholders. Third, management and organization encompass actions necessary for
itt
successful implementation, including required organizational capabilities, skills, talents, and management of sensitive governance-related aspects.
The level of analysis specifies the scope of the research object. This review used the level of analysis defined in [20].
m
This review consider the concept and architecture level, focusing on architectural variations and protocols, Firms and
Su b
industries level focusing on organizations, and users and society level focusing on end users and societal issues. For each couple of levels and activities, questions to be answered were defined; those are listed in Table 2. 4.2
Search Strategies
GL and AL artifacts to analyze were searched concurrently on academic databases (IEEE Xplore, ACM Digital Library, Science Direct, and Google Scholar) and using Google search engine for GL. The searches were looking for documents containing both keywords relevant for IoT and ZT ("IoT" OR "Internet Of Things", "ZT" OR "Zero Trust"), published since 2014. The searches were performed during a period between November 2023 and March 2024. The full process is described in appendix B. Figure 4 provides an outline of this study search strategies and results, as a PRISMA flow diagram [79]. Manuscript submitted to ACM
9
AC M
CS UR
Converging Zero Trust and IoT Security: A MLR
Preliminary Data Analysis
ed
5
to
Fig. 4. PRISMA flow diagram (AL on the left, GL on the right)
Figure 5 illustrates the distribution of AL and GL items over time and shows that there are just a few academic papers that address IoT security and ZT convergence before 2021. The first academic paper dealing with this topic was published
Su b
m
itt
in 2017. This is consistent with the timeline of the growing interest in ZT observed in previous SLRs such as [20].
Fig. 5. Distribution of AL and GL over time (AL on the left, GL on the right side)
Manuscript submitted to ACM
Mariam Wehbe and Laurent Bobelin
AC M
CS UR
10
to
Fig. 6. Distribution of papers per topic (AL in blue, and GL in red)
ed
An analysis based on the topics of both AL and GL was also done. To do so, after reviewing papers, an identification of topics shared by multiple papers was performed. Details about the topic description and how it is considered in both
itt
AL and GL is given in Appendix C Figure 6 shows the number of papers that deal with those topics, for both AL and GL. The first observation is that there is no strong predominance of a particular subject. This topic diversity is expected given the broad scope of ZT and IoT security convergence, and is consistent with previous studies that dealt only with
m
AL, such as [14], confirming the accuracy of the dataset the search methodology produced. This Figure also shows a
Su b
preliminary result: as the study also addresses GL contrary to the previous one, it show that some topics are addressed only by the AL and not by the industry (privacy, power IoT and attacks). The Tables 3 and 4 give the number of relevant papers for each RQs for AL and GL respectively. One immediate
conclusion is that most of the work, in both GL and AL, is focused on design and features activities at the concept and architecture level of analysis. On the other hand, the user and society level, and the management and organization activities remain almost unexplored research fields. 6
Results
This section gives answers to the different RQ defined in Section 4. The answers rely on an in-depth study of the corpus artifacts given in Appendix D, by providing a detailed analysis of most relevant artifacts for each RQ. Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
11
Table 3. AL mapping to RQ
Level of analysis
Design and features
Measurement and value
Management and organization
60 17 0
3 1 2
0 2 1
Concept and architecture Firms and industries Users and society
Table 4. GL mapping to RQ
Design and features
Measurement and value
Management and organization
37 15 0
4 34 0
0 0 0
Concept and architecture Firms and industries Users and society
6.1
Level of Analysis: Concept and Architecture
CS UR
Level of analysis
6.1.1 RQ1: Technical convergence of IoT security and ZT . As discussed in Section 2, two distinct approaches to the
AC M
convergence of IoT security and Zero Trust (ZT) can be identified: (1) adapting IoT systems to comply with ZT principles, and (2) integrating IoT components within an organization-wide ZT architecture.
Regarding Academic Literature (AL), most studies emphasize the first approach—aligning IoT design and operation with ZT philosophy. These works focus on technical adaptations such as lightweight encryption, decentralized identity management, and context-aware trust mechanisms that enable IoT devices to function as native actors within a ZT ecosystem. In contrast, Grey Literature (GL) predominantly supports the second approach, prioritizing the pragmatic
to
integration of IoT into existing enterprise ZT frameworks. Industrial reports and white papers tend to assume that IoT systems already exist in production and therefore explore methods to extend ZT controls—such as identity, credential, and access management (ICAM) or policy enforcement points (PEPs)—to heterogeneous and resource-constrained IoT
ed
environments.
This divergence constitutes a key finding of the present study: academic and industrial sources fundamentally
itt
differ in their vision of how IoT security should converge with ZT principles. Academic works largely propose reengineering IoT devices and protocols to make them inherently ZT-compliant, while industrial sources focus on
m
incremental integration into enterprise-grade ZT implementations guided by NIST SP 800-207. The emphasis observed in GL reflects the operational reality of complex, brownfield IoT deployments, where
Su b
full redesign is rarely feasible. These works operate under realistic assumptions about device heterogeneity, legacy constraints, and limited computational capabilities. Consequently, they advocate a gradual convergence path—embedding IoT within NIST-compliant ZT architectures and leveraging centralized policy decision mechanisms. This practical orientation also reveals the slow adoption of emerging security standards and limited organizational agility in evolving security postures [16, 89]. Conversely, academic perspectives remain largely speculative, addressing next-generation IoT paradigms that could natively embody ZT principles through architectural redesigns and cryptographic innovation. While this line of inquiry advances theoretical understanding, it is often detached from immediate industrial applicability. Bridging this gap between conceptual design and operational integration remains an open challenge and a promising direction for future research. Manuscript submitted to ACM
12
Mariam Wehbe and Laurent Bobelin
6.1.2 RQ2: Technical benefits and limitations of IoT security and ZT convergence. Only limited work in either the academic literature (AL) or grey literature (GL) explicitly quantifies the benefits and limitations of IoT security and Zero Trust (ZT) convergence. Assessing the trade-offs and risks associated with the two dominant convergence strategies—(1) making IoT systems compliant with ZT principles, and (2) integrating IoT into existing ZT architectures—remains an open research area. Yet this question is central to the adoption of ZT, as perceived benefits, implementation costs, and organizational acceptability strongly influence decision-making [20]. While several studies examine ZT adoption in general organizational contexts [43, 67, 70, 112], none isolate or quantify the specific cost–benefit dynamics of ZT–IoT convergence. Existing evaluations typically focus on overall ZT return-on-investment, performance, or risk reduction, but not on how IoT integration modifies those metrics. Consequently, no empirical or comparative study has yet evaluated the concrete advantages, trade-offs, or
CS UR
unintended consequences of converging IoT security and ZT principles. Establishing such evidence is essential for guiding both academic design choices and industrial deployment strategies.
6.1.3 RQ3: Human resources needed to maintain a system that adopted a ZT and IoT security convergence philosophy. Neither AL nor GL provides a detailed analysis of workforce requirements for sustaining ZT–IoT convergence. Although some industrial materials include training components, no formal studies assess the competencies or organizational
AC M
capacities necessary to operate converged systems. Transitioning from perimeter-based security to ZT already demands expertise spanning identity, network, and policy management [44]. Integrating IoT further amplifies this challenge by introducing device heterogeneity, embedded constraints, and operational technology (OT) considerations. This lack of multidisciplinary expertise is a recognized factor in the slow adoption of ZT frameworks [43, 67, 70, 112], and the complexity increases when IoT ecosystems are involved.
The NIST National Initiative for Cybersecurity Education (NICE) Workforce Framework [76] offers a useful taxonomy
to
of knowledge, skills, and abilities (KSAs) for cybersecurity roles. Several NICE roles—such as those related to identity and access management, cryptographic key operations, and continuous monitoring—align directly with ZT functions.
ed
However, ZT–IoT convergence introduces interdisciplinary requirements that are underrepresented in current workforce models. Effective deployment and maintenance of distributed trust architectures call for professionals who can bridge OT, embedded systems, and enterprise IT domains.
itt
This competency gap also extends to cryptographic agility, emphasized in the NIST Considerations for Achieving Cryptographic Agility white paper [16]. The ability to rapidly update cryptographic algorithms, keys, and protocols
m
in response to evolving threats is becoming an operational necessity for ZT environments that integrate long-lived, resource-constrained IoT devices. It is also mandatory for an engineer managing the platform to understand inter-
Su b
operability problems that occurs when dealing with heterogeneous cryptographic protocols and implementations.
Table 5 summarizes the alignment between technical functions, workforce competencies, and relevant NIST guidance, highlighting the need for new interdisciplinary training and certification pathways, to train expert able to manage the IoT security and ZT operational convergence.
6.2
Level of analysis: Firms and Industries
6.2.1 RQ4: How can an organization realize IoT security and ZT convergence. Both AL and GL address this topic, but with different points of view. AL focuses mainly on specific industrial sector or application (healthcare, IIOT) and the impact of their specificity on the implementation of IoT security and ZT convergence, while GL is more oriented toward Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
13
Table 5. Alignment between Technical Requirements, Workforce Competencies, and NIST Framework References for ZT–IoT Convergence
Corresponding Workforce Compe- Relevant NIST Framework or Guidtencies (NICE Roles / KSAs) ance NICE SP 800–181 Rev. 1, “Protect and Defend” category; NIST SP 800–207 (Zero Trust Architecture) NIST CSWP 39, “Considerations for Achieving Cryptographic Agility” (2025)
NICE “Analyze” and “Operate & Maintain” categories; NIST SP 800–137 (Information Security Continuous Monitoring) NICE “Securely Provision” category; NIST SP 800–213 (IoT Device Cybersecurity Guidance) NIST Privacy Framework (2020)
AC M
Identity, credential, and ac- Identity and Access Management Specess management (ICAM) cialist; Knowledge of authentication, authorization, and credential lifecycle management Cryptographic agility and Cryptographic Technician / Security Arkey management chitect; Skills in algorithm migration, certificate management, and key rotation Continuous monitoring Cyber Defense Analyst; Ability to anaand trust evaluation lyze security telemetry and apply riskbased access control policies IoT device posture assess- Systems Security Engineer; Understandment and attestation ing of embedded/OT systems and secure provisioning Privacy and data mini- Privacy Engineer; Competence in mization in telemetry privacy-by-design and data governance controls
CS UR
Technical Requirement (ZT–IoT)
generic off-the-shelf solutions. AL analyzes the cost of adoption of converged solutions by sectors, while those costs may be underestimated by the industry, or hidden from their customers.
to
6.2.2 RQ5: How does IoT security and ZT convergence provide added value for organizations. In AL, there is little to no attempt to measure the added value for organizations about this convergence. In the corpus, only [36] compares
ed
perimeter-based security and ZT in the context of IIoT.
In GL, this topic is massively discussed, as it is a key factor in the adoption of this convergence in the organization.
itt
Indeed, the promise of stronger security is in most of the GL reviewed. However, no artifacts address the question of concretely quantifying the gain associated with the IoT and ZT convergence. Demonstrating the added value of ZT and IoT security convergence is done by comparing it to segmentation-based security. The drawbacks of such a
m
convergence, often listed when dealing with ZT adoption (see for example [44]), are not addressed in GL.
Su b
The organization-level choice of either strengthening IoT subsystem by making it comply with ZT philosophy or integrating IoT subsystem into ZT organization-wide system is never discussed in any of the literature. In sum, there is a lack of formal (independent) study about the costs and added value of this convergence in AL, which would be undoubtedly of interest to organizations. 6.2.3 RQ6: Organizations setup, government and development of IoT security and ZT convergence. One may foresee the complexity of the process induced by a shift from an existing IoT security to the convergence of IoT and ZT by looking at the complexity of shifting from perimeter-based security to ZT. Shifting is a long process that usually lasts for years, carefully migrating segments one after the other, with meticulous transcription of policies [44]. Neither AL nor GL dataset contains paper dealing with the subject of how an organization may manage these projects. Two papers in this study discuss factors influencing the organization of this process, focusing on healthcare systems. Manuscript submitted to ACM
14
Mariam Wehbe and Laurent Bobelin
[90] studies factors behind the adoption of ZT and IoT in the Malaysian healthcare system. [45] analyses the impact on privacy of IoT integration in ZT, and the impact on adoption of IoT in healthcare systems. While those papers give insights into this domain, there is no detailed definition of the process and verification of security assessment during transition to a ZT-based IoT security. 6.3
Level of Analysis: Users and Society
This study shares the same observation as a previous MLR focusing only on ZT [20]: there are very few papers, either in AL or GL, that consider ZT and IoT from the users and society level of analysis. It could be either an artifact of the methodology of this study1 , or a real lack of support for those aspects.
CS UR
6.3.1 RQ7: How does IoT security and ZT convergence affect the interaction between users and technology. Both AL and GL remain largely silent on the human–technology interaction dimension of ZT and IoT security convergence. Existing work focuses primarily on technical implementation rather than usability or user experience, as for example in the case of smart homes [29] or wearable devices [30]. However, ZT introduces continuous authentication, contextual access validation, and device trust scoring — mechanisms that fundamentally reshape how end users interact with connected systems.
AC M
These continuous verification processes can increase interaction friction for users, particularly in domains such as smart homes, healthcare, and wearables, where low-latency and seamless operation are essential. The literature on usable security [25] and technology acceptance [27] indicates that excessive security prompts or cognitive load often lead to user fatigue, security bypassing, or decreased compliance. Integrating insights from these frameworks can help reconcile ZT’s security rigor with acceptable usability levels, supporting smoother adoption and compliance. Future research should bridge Human-Computer Interaction (CI, [87]) and Usable Security (USEC, [38]) perspectives
to
to design ZT mechanisms that are adaptive and minimally intrusive. For IoT contexts, lightweight, context-aware authentication and invisible trust re-evaluation could maintain ZT principles while preserving user experience and
ed
accessibility.
6.3.2 RQ8: Benefits and costs of ZT and IoT security convergence for individual users and society. In AL, several works
itt
mention this topic for some specific communities or sectors of activity. GL does not address it; that might be explained or society.
m
by the fact that IoT security and ZT convergence GL papers are oriented towards organizations rather than end users Literature on this subject may be useful to end users and society, as well as to organizations when they want
Su b
to plan to realize IoT security and ZT convergence. The societal implications of ZT and IoT convergence extend beyond organizational boundaries. While ZT improves
collective resilience by minimizing implicit trust and lateral movement, it also introduces increased energy and computational costs for IoT devices due to continuous encryption and verification. Moreover, the need for pervasive monitoring can amplify privacy risks and data-collection externalities. Few studies have quantified these trade-offs, yet cost–benefit modeling at the societal level is critical for guiding policy and regulation. Future research should incorporate sustainability and equity perspectives, examining how ZT–IoT convergence redistributes security costs and benefits across users, industries, and infrastructures.
1 Because of the literature considered, as the search methods used are oriented toward research (so, technical) papers. This is discussed in section 8
Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
15
6.3.3 RQ9: How does one balance user privacy and ZT and IoT security convergence requirements. In AL, only [82] surveys the adoption of IoT in healthcare, with an emphasis on ZT. In the GL considered, there is no discussion about that topic. Privacy and the empowerment of users in the context of ZT and IoT security convergence are still open research fields. Balancing ZT’s demand for pervasive telemetry with privacy principles remains a critical challenge. Continuous verification mechanisms depend on extensive device and user data, potentially conflicting with privacy-by-design and data minimization mandates. Emerging approaches—such as federated identity models, privacy-preserving authentication, and on-device trust evaluation—offer ways to maintain ZT compliance without excessive data centralization. Integrating guidance from the NIST Privacy Framework [77] and aligning with GDPR [32] principles could help organizations
7
CS UR
achieve “privacy-aware ZT,” ensuring user trust in both technical and ethical dimensions of IoT ecosystems. Avenues for Future Research
Divergence points from AL and GL are already identified in Section 5 and 6, as well as under-explored research fields. Hereafter is a list of research gaps and opportunities deducted during the study. These gaps and opportunities are organized according to 3 different categories of research avenues identified during the study, requiring growing levels
AC M
of interactions between communities:
• Yet-to-explore technical under-explored research topics, that are still open AL research topics. Such lists of topics can be found elsewhere in the existing literature, as it is usually identified from AL in both ZT/IoT security. This topics then does not require many interactions between industry and academics. This paper provide a list of subtopics identified during the review, with an emphasis on the topics not yet identified by the literature reviewed, as for example, attacks and forensic.
to
• Technical divergences that requires to open up a dialogue in between academic security experts and industry to realign both research. Those topics were identified by searching for topics only covered by GL. For each of
ed
these research avenues, one has to determine why research transfer in between communities did not happen yet, and if there is any further research to do to apply AL research to industry. An example of such a technical
itt
divergence between AL and GL is identified in RQ1 (section 6.1.1). It reflects a broader epistemic divide: academic work privileges formal security modeling and compliance to guidelines, while industry discourse is driven by deployability, regulatory timelines, and risk management constraints, thus advocating for IoT integration into
m
ZTA. Bridging this gap requires hybrid research approaches — e.g., design-science studies, field experiments, and
Su b
participatory action research — that can validate conceptual ZT models within operational IoT environments, and thus, may require collaborative work in between industry and academics. • Cooperative research topics, that requires strong collaboration in between industry and research to be explored, due to their interdisciplinary and applied nature, as for example the benefit/cost estimate of the IoT security and ZT convergence. 7.1
Technical Under-Explored Research Topics
Trust Interoperability. Various mechanisms can be used in ZT to build trust in a device or subject, either with or without agents. IoT often requires to use agentless trust evaluation because it is not possible to install it or make it run without consuming too many resources. Manuscript submitted to ACM
16
Mariam Wehbe and Laurent Bobelin It is then mandatory to use other means to build trust in IoT devices, the most studied one being either digital twin
or reputation-based systems. Some of the AL reviewed were studying these methods ([53] for example), but do not address the question of how to integrate these trust scores into a system-wide scheme. While this kind of trust score may be interoperable with system-wide trust score used in some products including system-wide trust and digital twins (for example [81] and [15]), there is no formal method described to achieve this interoperability. Explaining Trust for IoT Devices. Explainable AI received a lot of attention recently. While this topic is a buzzword in 2024, it is not identified in the related work given in section 3. Explainable AI would enhance transparency by providing clear insights into how trust scores are determined, helping
CS UR
to identify and mitigate potential risks effectively. This transparency builds confidence among stakeholders by ensuring that trust decisions are based on understandable and justifiable criteria. Additionally, it facilitates compliance with regulatory requirements by offering auditable decision-making processes. While there is no paper on explainable AI, some discuss the implementation of Machine Learning techniques for various purposes. However, explaining security decisions made automatically is mandatory in an operational context; it would then be a research avenue for the future. Attacks. The corpus only contains 1 academic paper that focuses on attacks on platforms integrating IoT into a ZT
AC M
architecture[86]. This might be explained by the fact that ZT is still an active topic for defense and that most of the effort is now put into defining it properly rather than studying possible attacks and how to be resilient to those. However, ZT may be attacked using IoT as vectors, by using, for example, their number to organize a DDoS on PDP/PEP, similar to attacks on SDN controllers (see for example [4]).
to
Forensic. For ZT-based systems integrating IoT, forensic tools are critical for rapidly and reliably collecting, analyzing, and preserving immutable logs and device state data. How to adapt existing tools for Forensic IoT to be used in a larger ZT system is still an open research field. Specific forensic tools are essential for investigating in such systems
ed
because the architecture itself creates unique evidential challenges. ZT inherently limits access and mandates microsegmentation, meaning evidence is highly distributed across numerous isolated devices and network zones, making
Technical Divergences
m
7.2
itt
traditional centralized collection ineffective.
Privacy Issues with ZT and IoT Security Convergence. ZT and IoT security convergence presents privacy challenges. ZT
Su b
often requires extensive data collection from devices to assess trust, especially when integrated into a ZT architecture, raising concerns about what data is gathered, how it is used, and who has access to it. ZT algorithms can be opaque, limiting user understanding of how data impacts their ability to interact with devices. Additionally, ZT might centralize
vast amounts of user information from numerous devices, creating a potential target for misuse if not properly secured.
To mitigate these concerns, organizations should focus on data minimization, anonymization, and providing users with clear explanations and control over their data privacy within the ZT framework. While the privacy is addressed by some papers in AL, it is mainly focused on preserving information undisclosed, not using anonymization techniques but pseudo anonymization or de-identification, especially in some specific domains like healthcare [6], [22], [45], power IoT [50], [51], or 5G/6G [111]. It is then not focused on the end user privacy (except for [30]), and more precisely on the end users control of their personal data. Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
17
Blockchain-Based Convergence. Blockchain-based convergence is an active topic in AL, but there is no mention of it in the GL. Blockchain is widely studied in AL for IoT. A lot of the interest in it is drawn from the decentralized nature of blockchain-based approaches. It well fits the problem of trusted interaction in between IoTs, and is compatible with the compliance of IoT security to ZT philosophy. However, IoT security integration to ZT relies on a relatively strong centralized control of security. As industry is more focused on the later approach, efforts should be put to realign the AL research on this topics with the industry approach, or to demonstrate the added value of blockchain-based approach in an industrial context. Cryptography agility. Cryptography is one of the topics that are addressed by AL but not GL. This may be explained by
CS UR
the traditional inertia of cryptograph, when it comes to adopt new standards, but also with the strong relationships between hardware and cryptography. Those two factors may slow the adoption of new techniques developed in AL by the GL, but existing work demonstrates that research must be undertaken to transfer work between communities. Trust Modeling. While the convergence of ZT and IoT security presents a promising approach to enhancing the security posture of IoT systems, the role of trust modeling in this context remains largely under-explored in GL, while explored in AL. Further research is needed to develop and transfer to industry robust trust models that can effectively address
AC M
the unique challenges posed by IoT environments, such as device heterogeneity, dynamic topologies, and the potential for adversarial attacks. 7.3
Cooperative Research Topics
Evaluation of Benefits and Costs of ZT and IoT Security Convergence. As shown by answers of RQ questions related to
to
measurement and values, while the ZT and IoT security convergence is an active topic in both communities, there is little to no evaluation of benefits and costs of it, either from the industry, the society or the end user point of view. To be able to measure, evaluate and forecast such benefits and costs requires cooperation in between industry that
ed
has access to data, and experts from both security and social sciences to analyze, model and forecast benefits and costs. are mandatory to choose.
itt
By now, there is no clear model for an organization planning to adopt such a convergence to estimate those values, that
User Acceptability. While ongoing work on the convergence of ZT and IoT security offers significant potential for
m
enhancing security, its acceptability by end user is unclear. Overly restrictive security measures can hinder usability and productivity, as demonstrated by the reluctance of users to adopt MFA, which is one of the core ZT technology.
Su b
IoT that are in strong interactions with end-users (wearable devices for example) may reveal difficulties to converge. End-users may encounter challenges such as increased authentication steps, slower response times, or limited device functionality. To explore such a research field, it is mandatory to rely on industrial solutions and effective deployment, and to study with social sciences experts the impact of the convergence on end-users. Sustainable Cryptography. ZT–IoT convergence demands cryptographic operations that are both resilient and energyefficient. The challenge lies in maintaining continuous authentication and encryption across millions of constrained IoT nodes without compromising performance or sustainability. Cooperative research should focus on lightweight cryptography, post-quantum algorithm agility, and energy-aware key management. Integrating environmental metrics into cryptographic protocol evaluation would support the development of sustainable cybersecurity practices. Collaboration Manuscript submitted to ACM
18
Mariam Wehbe and Laurent Bobelin
between cryptographers, hardware engineers, and environmental computing specialists could establish benchmarks for green cryptography, balancing cryptographic robustness with reduced computational and energy overhead. Governance and Policy Alignment. The long-term success of ZT–IoT adoption depends on coherent governance frameworks that align technical design, regulatory compliance, and operational accountability. Existing initiatives—such as NIST’s ZT Architecture, ISO/IEC 27001 revisions, and the EU Cyber Resilience Act—offer complementary but fragmented guidance. Cooperative research should map these frameworks to identify overlaps and gaps, proposing harmonized compliance pathways for global interoperability. Engaging policymakers, industry consortia, and standardization bodies in joint studies will accelerate regulatory consistency, reduce implementation ambiguity, and enhance trust between cross-border IoT stakeholders.
CS UR
In-Field Effective Convergence. Deploying effective tools that seamlessly integrate ZT principles and IoT security presents a significant research challenge, demanding a collaborative effort between industry and academia, spanning both computer science and social science domains. This interdisciplinary approach is essential to address the complexities involved in implementing and adopting such solutions.
Researchers and industry practitioners must collaborate to devise innovative solutions for device authentication, secure communication protocols, and robust access control mechanisms, that may be acceptable by the users and still
AC M
fit the requirements of ZT and the organizations infrastructure constraints.
Beyond technical challenges, the successful deployment of ZT and IoT security solutions hinges on user acceptance and adoption. Social scientists can contribute valuable insights into user behavior, privacy concerns, and the impact of security measures on usability. By understanding the human factors involved, researchers and developers can design more user-friendly and effective security solutions.
to
Human-Centric ZT. Future research should prioritize the design of ZT architectures that integrate usability and humanbehavioral considerations when ZT integrates IoT - thus increasing direct encounters between end users and ZT.
ed
Continuous verification and adaptive authentication mechanisms must be optimized for user experience, reducing cognitive and procedural friction. Collaboration between cybersecurity engineers, Human-Computer Interaction researchers, and behavioral scientists can help create models of usable ZT, combining strong access control with
itt
transparency and trust cues. Empirical studies—such as user-in-the-loop simulations and usability testing—will be critical to evaluate compliance and detect security fatigue, ensuring that security enforcement supports rather than
Threats to Validity
Su b
8
m
hinders productive human interaction with IoT systems.
Following [93], we assessed construct, internal, external, and conclusion validity, as recommended in various previous studies [39], [109]. Because our review is multivocal, we also assessed source credibility using the Garousi et al. [42] checklist for grey literature (authority, methodology, objectivity, date/novelty, position vs. related sources, impact, outlet type). We give a summary of our checklist for quality assessment in appendix F, that are addressed by following a standard methodology. Below is a list of main threats to validity identified for this study. Construct Validity: database bias. Most of the database used are oriented toward technical literature. This fact may have impacted by the validity of this study concerning less technical levels and activities. This bias may have been mitigated by including Google Scholar that gather publications for a broad number of disciplines Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
19
Construct Validity: search engine. Another bias may come from the search engine used when searching for GL. Recent studies, such as [116], suggest that this bias for big companies comes from recent adjustments in Google algorithms, which leads to the disappearance of smaller website results compared to larger ones. We mitigated this by applying changes in the search we did, described in section B. 9
Conclusion
This multivocal literature review offers the first consolidated analysis of how Zero Trust (ZT) and Internet of Things (IoT) security intersect across academic and industrial domains. This study identifies a pronounced epistemic divide: academic works predominantly pursue IoT compliance—rethinking device-level trust mechanisms and lightweight cryptography—whereas industrial grey literature promotes system-level integration within enterprise ZT architectures.
CS UR
The study highlights four critical research gaps:
(1) Socio-technical factors—user acceptance, privacy implications, and organizational readiness remain underexplored.
(2) Measurement and validation—few studies empirically quantify the benefits or costs of IoT–ZT convergence. (3) Governance frameworks—there is limited discussion on migration paths and lifecycle management within organizations.
AC M
(4) Standardization misalignment—industrial adoption largely follows NIST guidance, while academic research explores diverse conceptual models.
Ultimately, the discussion underscores that ZT–IoT convergence is not a purely technical migration but a socio-technical transformation. Addressing it requires synchronized progress in standards, workforce development, privacy assurance, and public trust — the cornerstones of a resilient digital ecosystem.
to
Future work should establish joint evaluation frameworks between academia and industry, including longitudinal case studies, reference architectures, and cost–benefit analyses. Interdisciplinary collaboration—bridging computer
Declarations
10.1
Data Availability
itt
10
ed
science, human factors, and policy research—is essential for realizing ZT’s full potential in IoT ecosystems.
m
As the paper is a Multivocal Literature Review, the data necessary to reproduce this work are mainly papers. The paper contains references for both AL papers and GL artifacts. Papers from academic sources are available
Su b
through the usual search engines and subject to various access restrictions, but most of them are freely accessible. Authors keep as an archive the industrial literature gathered during the MLR process. Many of the white papers considered were accessible only once provided personal information, and GL authors do not allow them to be freely redistributed.
Acknowledgments References [1] Khaled Ali Abuhasel. 2023. A Zero-Trust Network-Based Access Control Scheme for Sustainable and Resilient Industry 5.0. IEEE Access 11, unknown (2023), 116398–116409. doi:10.1109/ACCESS.2023.3325879 [2] Alex Akinbi, Áine MacDermott, and Aras M. Ismael. 2022. A systematic literature review of blockchain-based Internet of Things (IoT) forensic investigation process models. Forensic Science International: Digital Investigation 42-43, unknown (2022), 301470. doi:10.1016/j.fsidi.2022.301470 Manuscript submitted to ACM
20
Mariam Wehbe and Laurent Bobelin
Su b
m
itt
ed
to
AC M
CS UR
[3] Abeer Alalmaie, Nazar Waheed, Mohrah Alalyan, Wenjing Jia, and Xiangjian He. 2024. Zero Trust for Intrusion Detection System: A Systematic Literature Review. In Proceedings of the 16th International Conference on Agents and Artificial Intelligence (ICAART 2024), Vol. 3. SCITEPRESS, Roma, Italy, 170–177. doi:10.5220/0012312300003636 [4] Abdussalam Ahmed Alashhab, Mohd Soperi Mohd Zahid, Mohamed Mostafa A. Azim, Muhammad Yunis Daha, Babangida Isyaku, and Shimhaz Ali. 2022. A Survey of Low Rate DDoS Detection Techniques Based on Machine Learning in Software-Defined Networks. Symmetry 14, 8 (2022), 1563. doi:10.3390/SYM14081563 [5] Muntaha Alawneh and Imad M. Abbadi. 2022. Integrating Trusted Computing Mechanisms with Trust Models to Achieve Zero Trust Principles. 2022 9th International Conference on Internet of Things, Systems, Management and Security, IOTSMS 2022 unknown, unknown (2022), unknown. doi:10.1109/IOTSMS58070.2022.10062269 [6] Belal Ali, Mark A. Gregory, and Shuo Li. 2021. Uplifting Healthcare Cyber Resilience with a Multi-access Edge Computing Zero-Trust Security Model. 2021 31st International Telecommunication Networks and Applications Conference, ITNAC 2021 unknown, unknown (2021), 192–197. doi:10.1109/ITNAC53136.2021.9652141 medical devices and health equipment are considered as iot ?. [7] Mohammed Almutairi and Frederick T. Sheldon. 2023. IoT–Cloud Integration Security: A Survey of Challenges, Solutions, and Directions. Electronics 14, 7 (2023), 1394. doi:10.3390/electronics14071394 [8] Shrooq Alshomrani and Shancang Li. 2022. PUFDCA: A Zero-Trust-Based IoT Device Continuous Authentication Protocol. Wireless Communications and Mobile Computing 2022, unknown (2022), unknown. doi:10.1155/2022/6367579 [9] Safwa Ameer, Maanak Gupta, Smriti Bhatt, and Ravi Sandhu. 2022. BlueSky: Towards Convergence of Zero Trust Principles and Score-Based Authorization for IoT Enabled Smart Systems. In Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies (New York, NY, USA) (SACMAT ’22). Association for Computing Machinery, New York, NY, USA, 235–244. doi:10.1145/3532105.3535020 [10] Safwa Ameer, Ram Krishnan, Ravi Sandhu, and Maanak Gupta. 2023. Utilizing The DLBAC Approach Toward a ZT Score-based Authorization for IoT Systems. CODASPY 2023 - Proceedings of the 13th ACM Conference on Data and Application Security and Privacy unknown, unknown (4 2023), 283–285. doi:10.1145/3577923.3585046 [11] Malak Annabi, Abdelhafid Zeroual, and Nadhir Messai. 2024. Towards zero trust security in connected vehicles: A comprehensive survey. Computers & Security 145, unknown (oct 2024), 104018. doi:10.1016/j.cose.2024.104018 [12] Sinan Aral, Chrysanthos Dellarocas, and David Godes. 2013. Introduction to the Special Issue: Social Media and Business Transformation: A Framework for Research. Information Systems Research 24, 1 (2013), 3–13. http://www.jstor.org/stable/42004266 [13] Samia Masood Awan, Muhammad Ajmal Azad, Junaid Arshad, Urooj Waheed, and Tahir Sharif. 2023. A Blockchain-Inspired Attribute-Based Zero-Trust Access Control Model for IoT. Information 2023, Vol. 14, Page 129 14, unknown (2 2023), 129. Issue 2. doi:10.3390/INFO14020129 [14] Muhammad Ajmal Azad, Sidra Abdullah, Junaid Arshad, Harjinder Lallie, and Yussuf Hassan Ahmed. 2024. Verify and trust: A multidimensional survey of zero-trust security in the age of IoT. Internet of Things unknown, unknown (2024), 101227. doi:10.1016/j.iot.2024.101227 [15] Microsoft Azure. 2021. Zero Trust Cybersecurity for the Internet of Things. https://azure.microsoft.com/mediahandler/files/resourcefiles/zerotrust-cybersecurity-for-the-internet-of-things/Zero%20Trust%20Security%20Whitepaper_4.30_3pm.pdf [16] E. Barker, L. Chen, D. Cooper, D. Moody, A. Regenscheid, M. Souppaya, B. Newhouse, R. Housley, S. Turner, W. Barker, and K. Scarfone. 2025. Considerations for Achieving Cryptographic Agility: Strategies and Practices. Technical Report 39. National Institute of Standards and Technology (NIST). https://csrc.nist.gov/pubs/cswp/39/considerations-for-achieving-cryptographic-agility/2pd Second Public Draft (2pd). [17] Tiago G. F. Barros, Eronides F. Da Silva Neto, João Alexandre Da Silva Neto, André G. M. De Souza, Vitor B. Aquino, and Erico S. Teixeira. 2022. The Anatomy of IoT Platforms—A Systematic Multivocal Mapping Study. IEEE Access 10, unknown (2022), 72758–72772. doi:10.1109/ACCESS.2022. 3189660 [18] Gunjan Beniwal and Anita Singhrova. 2022. “A systematic literature review on IoT gateways”. Journal of King Saud University - Computer and Information Sciences 34, 10, Part B (2022), 9541–9563. doi:10.1016/j.jksuci.2021.11.007 [19] Laurent Bobelin. 2023. Zero Trust in the Context of IoT: Industrial Literature Review, Trends, and Challenges. In Proceedings of the 30th Computer & Electronics Security Application Rendezvous Conference (C&ESAR 2023) co-located with the 8th European Cyber Week (ECW 2023), Rennes, France, November 21-22, 2023 (CEUR Workshop Proceedings, Vol. 3610), Gurvan Le Guernic (Ed.). CEUR-WS.org, Rennes, France, 37–52. https://ceur-ws.org/Vol-3610/paper-02.pdf [20] Christoph Buck, Christian Olenberger, André Schweizer, Fabiane Völter, and Torsten Eymann. 2021. Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust. Computers & Security 110, unknown (11 2021), 102436. doi:10.1016/J.COSE. 2021.102436 MLR for ZT<br/>didn’t mention iot in abstract, but SDP in keywords. [21] Claudio Bustos Navarrete, María Gabriela Morales Malverde, Pedro Salcedo Lagos, and Alejandro Díaz Mujica. 2018. Buhos: A web-based systematic literature review management software. SoftwareX 7, unknown (2018), 360–372. doi:10.1016/j.softx.2018.10.004 [22] Baozhan Chen, Siyuan Qiao, Jie Zhao, Dongqing Liu, Xiaobing Shi, Minzhao Lyu, Haotian Chen, Huimin Lu, and Yunkai Zhai. 2021. A Security Awareness and Protection System for 5G Smart Healthcare Based on Zero-Trust Architecture. IEEE Internet of Things Journal 8, unknown (7 2021), 10248–10263. Issue 13. doi:10.1109/JIOT.2020.3041042 considered iot ?<br/>. [23] Zhiyu Chen, Longchuan Yan, Zitong Lü, Yanling Zhang, Yonghe Guo, Wenjing Liu, and Jiaxing Xuan. 2021. Research on Zero-trust Security Protection Technology of Power IoT based on Blockchain. Journal of Physics: Conference Series 1769, unknown (1 2021), 012039. Issue 1. doi:10.1088/1742-6596/1769/1/012039 abstract doesn’t discuss ZT<br/>.
Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
21
Su b
m
itt
ed
to
AC M
CS UR
[24] Pietro Colombo, Elena Ferrari, and Engin Deniz Tumer. 2021. Access Control Enforcement in IoT: state of the art and open challenges in the Zero Trust era. Proceedings - 2021 3rd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications, TPS-ISA 2021 unknown, unknown (2021), 156–163. doi:10.1109/TPSISA52974.2021.00018 [25] Lorrie Faith Cranor. 2008. A Framework for Reasoning about Humans in Security Systems. Commun. ACM 51, 4 (2008), 56–63. doi:10.1145/1330311. 1330320 [26] Kenneth G. Crowther. 2024. Blending Shared Responsibility and Zero Trust to Secure the Industrial Internet of Things . IEEE Security & Privacy 22, 05 (sep 2024), 96–102. doi:10.1109/MSEC.2024.3432208 [27] Fred D. Davis. 1989. Perceived Usefulness, Perceived Ease of Use, and User Acceptance of Information Technology. MIS Quarterly 13, 3 (1989), 319–340. doi:10.2307/249008 [28] Suparna Dhar and Indranil Bose. 2021. Securing IoT Devices Using Zero Trust and Blockchain. Journal of Organizational Computing and Electronic Commerce 31, unknown (1 2021), 18–34. Issue 1. doi:10.1080/10919392.2020.1831870 [29] Theo Dimitrakos, Tezcan Dilshener, Alexander Kravtsov, Antonio La Marra, Fabio Martinelli, Athanasios Rizos, Alessandro Rosett, and Andrea Saracino. 2020. Trust aware continuous authorization for zero trust in consumer internet of things. Proceedings - 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2020 unknown, unknown (12 2020), 1801–1812. doi:10.1109/ TRUSTCOM50675.2020.00247 [30] Atefeh Mohseni Ejiyeh. 2023. Real-Time Lightweight Cloud-Based Access Control for Wearable IoT Devices: A Zero Trust Protocol. In Proceedings of the First International Workshop on Security and Privacy of Sensing Systems. Association for Computing Machinery (ACM), New York, NY, USA, 22–29. doi:10.1145/3628356.3630118 [31] Abla El Bekkali, Mohamed Essaaidi, Mohammed Boulmalf, and Driss el Majdoubi. 2022. Systematic Literature Review of Internet of Things (IoT) Security. Advances in Dynamical Systems and Applications 16, unknown (01 2022), 1671–1692. [32] European Parliament and Council of the European Union. 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Official Journal of the European Union, L 119, 4 May 2016, p. 1-88. http://data.europa.eu/eli/reg/2016/679/oj The main legal instrument is Regulation (EU) 2016/679, commonly referred to as GDPR.. [33] Fabio Federici, Davide Martintoni, and Valerio Senni. 2023. A Zero-Trust Architecture for Remote Access in Industrial IoT Infrastructures. Electronics 2023, Vol. 12, Page 566 12, unknown (1 2023), 566. Issue 3. doi:10.3390/ELECTRONICS12030566 in abstract they talk about perimiter.<br/>then in the article they discuss ZT<br/>and it is for Industrial IoT<br/>. [34] Pietro Ferrara, Amit K. R. Mandal, Agostino Cortesi, and Fausto Spoto. 2021. Static Analysis for Discovering IoT Vulnerabilities. International Journal on Software Tools for Technology Transfer 23, unknown (2021), 71–88. doi:10.1007/s10009-020-00592-x [35] Peng Gao, Longchuan Yan, Zhiyu Chen, Xingshen Wei, Liang Guo, and Rui Shi. 2021. Research on Zero-Trust Based Network Security Protection for Power Internet of Things. 4th IEEE International Conference on Automation, Electronics and Electrical Engineering, AUTEEE 2021 unknown, unknown (2021), 458–461. doi:10.1109/AUTEEE52864.2021.9668726 [36] Yuan Gao and Xinxin Lou. 2021. Operational Security Analysis and Challenge for IoT Solutions. doi:10.18420/inf2020_30 [37] Oscar Garcia-Morchon, Sandeep Kumar, and Mohit Sethi. 2019. Internet of Things (IoT) Security: State of the Art and Challenges. RFC 8576. doi:10.17487/RFC8576 [38] Simson Garfinkel and Heather Richter Lipford. 2014. Usable Security: History, Themes, and Challenges. Morgan & Claypool Publishers, San Rafael, CA. doi:10.2200/S00594ED1V01Y201408SPT011 [39] Vahid Garousi, Michael Felderer, and Mika V. Mäntylä. 2016. The need for multivocal literature reviews in software engineering: complementing systematic literature reviews with grey literature. In Proceedings of the 20th International Conference on Evaluation and Assessment in Software Engineering (Limerick, Ireland) (EASE ’16). Association for Computing Machinery, New York, NY, USA, Article 26, 6 pages. doi:10.1145/2915970. 2916008 [40] Vahid Garousi, Michael Felderer, and Mika V. Mäntylä. 2017. Guidelines for including the grey literature and conducting multivocal literature reviews in software engineering. CoRR abs/1707.02553, unknown (2017), 101–121. arXiv:1707.02553 https://www.sciencedirect.com/science/article/ pii/S0950584918301939 [41] Vahid Garousi, Michael Felderer, and Mika V. Mäntylä. 2019. Guidelines for including grey literature and conducting multivocal literature reviews in software engineering. Inf. Softw. Technol. 106, unknown (2019), 101–121. doi:10.1016/J.INFSOF.2018.09.006 [42] Vahid Garousi, Michael Felderer, and Mika V. Mäntylä. 2019. Guidelines for including grey literature and conducting multivocal literature reviews in software engineering. Information and Software Technology 106, unknown (2019), 101–121. doi:10.1016/j.infsof.2018.09.006 [43] Saeid Ghasemshirazi, Ghazaleh Shirvani, and Mohammad Ali Alipour. 2023. Zero Trust: Applications, Challenges, and Opportunities. arXiv:2309.03582 [cs.CR] https://arxiv.org/abs/2309.03582 [44] Evan Gilman and Doug Barth. 2017. Zero Trust Networks: Building Secure Systems in Untrusted Networks (first ed.). O’Reilly Media, Sebastopol, CA. https://www.amazon.fr/Zero-Trust-Networks-Building-Untrusted/dp/1491962194 [45] Morgan Morgak Gofwen, Bartholomew Idoko, and John Bush Idoko. 2023. Application of Zero-Trust Networks in e-Health Internet of Things (IoT) Deployments. Studies in Computational Intelligence 1115, unknown (2023), 209–233. doi:10.1007/978-3-031-42924-8_14/COVER in abstract they didn’t discuss zero trust. [46] Google. 2023. BeyondCorp. Retrieved 2023 from https://cloud.google.com/beyondcorp Manuscript submitted to ACM
22
Mariam Wehbe and Laurent Bobelin
Su b
m
itt
ed
to
AC M
CS UR
[47] Chenchen Han, Gwang-Jun Kim, Osama Alfarraj, Amr Tolba, and Yongjun Ren. 2022. ZT-BDS: A Secure Blockchain-based Zero-trust Data Storage Scheme in 6G Edge IoT. Journal of Internet Technology 23, unknown (3 2022), 289–295. Issue 2. doi:10.53106/160792642022032302009 [48] Xiaohan Hao, Wei Ren, Ruoting Xiong, Tianqing Zhu, and Kim Kwang Raymond Choo. 2021. Asymmetric cryptographic functions based on generative adversarial neural networks for Internet of Things. Future Generation Computer Systems 124, unknown (11 2021), 243–253. doi:10.1016/J.FUTURE.2021.05.030 [49] Zhi hua Wang, Ming hui Jin, Lin Jiang, Chen jia Feng, Jing yi Cao, and Zhang Yun. 2023. Secure Access Method of Power Internet of Things Based on Zero Trust Architecture. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 13969 LNCS, unknown (2023), 386–399. doi:10.1007/978-3-031-36625-3_31/COVER [50] Wenhua Huang, Xuemin Xie, Ziying Wang, and Jingyu Feng. 2023. A Zero Trust and Attribute-Based Encryption Scheme for Dynamic Access Control in Power IoT Environments. Lecture Notes on Data Engineering and Communications Technologies 153, unknown (2023), 1338–1345. doi:10.1007/978-3-031-20738-9_145/COVER [51] Wenhua Huang, Xuemin Xie, Ziying Wang, Jing Yu Feng, Gang Han, and Wenbo Zhang. 2023. ZT-Access: A combining zero trust access control with attribute-based encryption scheme against compromised devices in power IoT environments. Ad Hoc Networks 145, unknown (6 2023), 103161. doi:10.1016/J.ADHOC.2023.103161 [52] Cornelius Itodo and Murat Ozer. 2024. Multivocal literature review on zero-trust security implementation. Computers & Security 141, unknown (2024), 103827. doi:10.1016/j.cose.2024.103827 [53] Jithin Jagannath, Keyvan Ramezanpour, and Anu Jagannath. 2022. Digital Twin Virtualization with Machine Learning for IoT and Beyond 5G Networks: Research Directions for Security and Optimal Control. WiseML 2022 - Proceedings of the 2022 ACM Workshop on Wireless Security and Machine Learning unknown, unknown (5 2022), 81–86. doi:10.1145/3522783.3529519 [54] SMITA. LAKSHMI JAIN. 2023. IOT AND OT SECURITY HANDBOOK assess risk, manage vulnerability, monitor and mitigate threat with... microsoft defender for iot. PACKT PUBLISHING LIMITED, Birmingham, UK. [55] S. Kailash, Yuvaraj, and Saswati Mukherjee. 2023. Zero Trust Framework in Integrated Cloud Edge IoT Environment. Lecture Notes in Electrical Engineering 1021 LNEE, unknown (2023), 331–342. doi:10.1007/978-981-99-1051-9_21/COVER [56] Hongzhaoning Kang, Gang Liu, Quan Wang, Lei Meng, and Jing Liu. 2023. Theory and Application of Zero Trust Security: A Brief Survey. Entropy 25, 12 (2023), unknown. doi:10.3390/e25121595 [57] Barbara Kitchenham, O. Pearl Brereton, David Budgen, Mark Turner, John Bailey, and Stephen Linkman. 2009. Systematic literature reviews in software engineering – A systematic literature review. Information and Software Technology 51, 1 (2009), 7–15. doi:10.1016/j.infsof.2008.09.009 Special Section - Most Cited Articles in 2002 and Regular Research Papers. [58] Nobuhiro Kobayashi. 2023. Zero Trust Security Framework for IoT Actuators. Proceedings - International Computer Software and Applications Conference 2023-June, unknown (2023), 1285–1292. doi:10.1109/COMPSAC57700.2023.00195 [59] Vijaya Bhaskar Kondaveety, Hemraj Lamkuche, and Suneel Prasad. 2022. A zero trust architecture for next generation automobiles. AIP Conference Proceedings 2519, unknown (10 2022), unknown. Issue 1. doi:10.1063/5.0110599/2828650 sensors connected to automobiles, cars are considered iot ?<br/>. [60] Djamel Eddine Kouicem, Abdelmadjid Bouabdallah, and Hicham Lakhlef. 2018. Internet of things security: A top-down survey. Computer Networks 141, unknown (2018), 199–221. doi:10.1016/j.comnet.2018.03.012 [61] Yun Kyung Lee, Young Ho Kim, and Jeong Nyeo Kim. 2021. IoT standard platform architecture that provides defense against DDoS attacks. 2021 IEEE International Conference on Consumer Electronics-Asia, ICCE-Asia 2021 unknown, unknown (2021), unknown. doi:10.1109/ICCEASIA53811.2021.9641892 [62] Wenxin Lei, Zhibo Pang, Hong Wen, Wenjing Hou, and Wen Li. 2023. Physical Layer Enhanced Zero-Trust Security for Wireless Industrial Internet of Things. IEEE Transactions on Industrial Informatics PP, unknown (2023), 1–10. doi:10.1109/TII.2023.3321106 [63] Shancang Li. 2019. Editorial: Zero Trust based Internet of Things. EAI Endorsed Transactions on Internet of Things 5, unknown (10 2019), e1–e1. Issue 20. doi:10.4108/EAI.5-6-2020.165168 [64] Shan Li, Muddesar Iqbal, and Neetesh Saxena. 2022. Future Industry Internet of Things with Zero-trust Security. Information Systems Frontiers unknown, unknown (3 2022), 1–14. doi:10.1007/S10796-021-10199-5/FIGURES/6 [65] Shancang Li, Surya Nepal, Theo Tryfonas, and Hongwei Li. 2023. Blockchain-based Zero Trust Cybersecurity in the Internet of Things. ACM Transactions on Internet Technology 23, unknown (8 2023), unknown. Issue 3. doi:10.1145/3594535 regarder les differents articles sur le lien<br/>. [66] Zhenyu Li, Yong Ding, Honghao Gao, Bo Qu, Yujue Wang, and Jun Li. 2023. A Highly Compatible Verification Framework with Minimal Upgrades to Secure an Existing Edge Network. ACM Transactions on Internet Technology 23, unknown (8 2023), unknown. Issue 3. doi:10.1145/3511901 [67] Chunwen Liu, Ru Tan, Yang Wu, Yun Feng, Ze Jin, Fangjiao Zhang, Yuling Liu, and Qixu Liu. 2024. Dissecting zero trust: research landscape and its implementation in IoT. Cybersecurity 7, 1 (03 May 2024), 20. doi:10.1186/s42400-024-00212-0 [68] Yizhi Liu, Xiaohan Hao, Wei Ren, Ruoting Xiong, Tianqing Zhu, Kim Kwang Raymond Choo, and Geyong Min. 2023. A Blockchain-Based Decentralized, Fair and Authenticated Information Sharing Scheme in Zero Trust Internet-of-Things. IEEE Trans. Comput. 72, unknown (2 2023), 501–512. Issue 2. doi:10.1109/TC.2022.3157996 [69] Yizhong Liu, Xinxin Xing, Ziheng Tong, Xun Lin, Jing Chen, Zhenyu Guan, Qianhong Wu, and Willy Susilo. 2023. Secure and Scalable Cross-Domain Data Sharing in Zero-Trust Cloud-Edge-End Environment Based on Sharding Blockchain. IEEE Transactions on Dependable and Secure Computing unknown, unknown (2023), unknown. doi:10.1109/TDSC.2023.3313799 ?<br/>ZT is just a part of the study, and didn’t mention in the abstracct ZT
Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
23
Su b
m
itt
ed
to
AC M
CS UR
for IoT. [70] Brady D. Lund, Tae-Hee Lee, Ziang Wang, Ting Wang, and Nishith Reddy Mannuru. 2024. Zero Trust Cybersecurity: Procedures and Considerations in Context. Encyclopedia 4, 4 (2024), 99. doi:10.3390/encyclopedia4040099 [71] Juan Luis López Delgado and Juan Antonio López Ramos. 2024. A Comprehensive Survey on Generative AI Solutions in IoT Security. Electronics 13, 24 (2024), unknown. doi:10.3390/electronics13244965 [72] Lei Meng, Daochao Huang, Jiahang An, Xianwei Zhou, and Fuhong Lin. 2022. A continuous authentication protocol without trust authority for zero trust architecture. China Communications unknown, unknown (2022), unknown. doi:10.23919/JCC.2022.08.015 they used the term device<br/>is it iot considered ?. [73] Markus Miettinen, Samuel Marchal, Ibbad Hafeez, N. Asokan, Ahmad-Reza Sadeghi, and Sasu Tarkoma. 2017. IoT SENTINEL: Automated Device-Type Identification for Security Enforcement in IoT. In Proceedings of the 37th IEEE International Conference on Distributed Computing Systems (ICDCS). IEEE, New York City, USA, 2177–2184. doi:10.1109/ICDCS.2017.283 demo / extended version available as arXiv:1611.04880. [74] Huda Hussein Mohamad Jawad, Zainuddin Bin Hassan, Bilal Bahaa Zaidan, Farah Hussein Mohammed Jawad, Duha Husein Mohamed Jawad, and Wajdi Hamza Dawod Alredany. 2022. A Systematic Literature Review of Enabling IoT in Healthcare: Motivations, Challenges, and Recommendations. Electronics 11, 19 (2022), unknown. doi:10.3390/electronics11193223 [75] Saubhagya Munasinghe, Nuwan Piyarathna, Erandana Wijerathne, Upul Jayasinghe, and Suneth Namal. 2023. Machine Learning Based Zero Trust Architecture for Secure Networking. 2023 IEEE 17th International Conference on Industrial and Information Systems, ICIIS 2023 - Proceedings unknown, unknown (2023), 365–370. doi:10.1109/ICIIS58898.2023.10253610 [76] National Institute of Standards and Technology. 2020. National Initiative for Cybersecurity Education (NICE) Workforce Framework for Cybersecurity (NIST SP 800-181, Rev. 1). Technical Report. U.S. Department of Commerce, Gaithersburg, MD. doi:10.6028/NIST.SP.800-181r1 NIST Special Publication 800-181 Revision 1. [77] National Institute of Standards and Technology. 2020. NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management. Technical Report. U.S. Department of Commerce, Gaithersburg, MD. doi:10.6028/NIST.CSWP.01162020 [78] Mohamed G Nour. 2003. Implementing Machine Learning to achieve dynamic Zero-Trust Intrusion Detection Systems (ZT-IDS) in 5G based IoT Networks. Ph. D. Dissertation. The School of Engineering and Applied Science of The George Washington University. [79] Matthew J Page, Joanne E McKenzie, Patrick M Bossuyt, Isabelle Boutron, Tammy C Hoffmann, Cynthia D Mulrow, Larissa Shamseer, Jennifer M Tetzlaff, Elie A Akl, Sue E Brennan, Roger Chou, Julie Glanville, Jeremy M Grimshaw, Asbjørn Hróbjartsson, Manoj M Lalu, Tianjing Li, Elizabeth W Loder, Evan Mayo-Wilson, Steve McDonald, Luke A McGuinness, Lesley A Stewart, James Thomas, Andrea C Tricco, Vivian A Welch, Penny Whiting, and David Moher. 2021. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. PLOS Medicine 18, 3 (2021), e1003583. doi:10.1371/journal.pmed.1003583 [80] Yangchen Palmo, Shigeaki Tanimoto, Hiroyuki Sato, and Atsushi Kanai. 2023. Optimal Federation Method for Embedding Internet of Things in Software-Defined Perimeter. IEEE Consumer Electronics Magazine 12, unknown (9 2023), 68–75. Issue 5. doi:10.1109/MCE.2022.3207862 [81] PaloAlto. 2022. The Right Approach to Zero Trust Security for Enterprise IoT Devices. https://www.paloaltonetworks.com/resources/whitepapers/ right-approach-zero-trust-iot [82] Kashav Piya, Quynh Anh Au, Srijal Shrestha, Apoorva Singh, and Tauheed Khan Mohd. 2021. IoT in Health Care Industry: A Promising Prospect. 2021 IEEE 12th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference, UEMCON 2021 unknown, unknown (2021), 466–474. doi:10.1109/UEMCON53757.2021.9666731 [83] Tanusan Rajmohan, Phu H. Nguyen, and Nicolas Ferry. 2022. A decade of research on patterns and architectures for IoT security. Cybersecurity 5, 1 (05 Jan 2022), 2. doi:10.1186/s42400-021-00104-7 [84] Khan Reaz and Gerhard Wunder. 2022. ASOP: A Sovereign and Secure Device Onboarding Protocol for Cloud-based IoT Services. 2022 6th Cyber Security in Networking Conference, CSNet 2022 unknown, unknown (2022), unknown. doi:10.1109/CSNET56116.2022.9955610 [85] Marten Risius and Kai Spohrer. 2017. A Blockchain Research Framework: What We (don’t) Know, Where We Go from Here, and How We Will Get There. Business & Information Systems Engineering 59, unknown (12 2017), 385–409. doi:10.1007/s12599-017-0506-0 [86] Bruno Carneiro Da Rocha, Laerte Peotta De Melo, and Rafael Timoteo De Sousa. 2021. Preventing APT attacks on LAN networks with connected IoT devices using a zero trust based security model. 2021 Workshop on Communication Networks and Power Systems, WCNPS 2021 unknown, unknown (2021), unknown. doi:10.1109/WCNPS53648.2021.9626270 [87] Yvonne Rogers, Helen Sharp, and Jenny Preece. 2022. Interaction Design: Beyond Human-Computer Interaction (6th ed.). John Wiley & Sons, Hoboken, USA. [88] Scott Rose, Oliver Borchert, Stuart Mitchell, and Sean Connelly. 2020. Zero Trust Architecture. doi:10.6028/NIST.SP.800-207 [89] Larri Rosser. 2023. Applying Agility for Sustainable Security. INSIGHT 26, unknown (06 2023), 45–52. doi:10.1002/inst.12445 [90] Irza Hanie Abu Samah, Intan Maizura Abd Rashid, Abdul Shukor Shamsudin, Wan Ahmad Fauzi Wan Husain, Mohammad Harith Amlus, and Hariri Hamzah. 2023. Fundamental of zero trust among digital employees in migration to industry 4.0: Cyber security and movement to iot in Malaysian perspectives. AIP Conference Proceedings 2608, unknown (6 2023), unknown. Issue 1. doi:10.1063/5.0127923/2895782 [91] Mayra Samaniego and Ralph Deters. 2018. Zero-trust hierarchical management in IoT. Proceedings - 2018 IEEE International Congress on Internet of Things, ICIOT 2018 - Part of the 2018 IEEE World Congress on Services unknown, unknown (9 2018), 88–95. doi:10.1109/ICIOT.2018.00019 [92] Hichem Sedjelmaci and Nirwan Ansari. 2023. Zero Trust Architecture Empowered Attack Detection Framework to Secure 6G Edge Computing. IEEE Network 38, 1 (2023), 196–202. doi:10.1109/MNET.131.2200513 <br/><br/>sur IEEEE, à regarder<br/><br/>for 6G edge computing<br/>iot Manuscript submitted to ACM
24
Mariam Wehbe and Laurent Bobelin
Su b
m
itt
ed
to
AC M
CS UR
included ?. [93] William R. Shadish, Thomas D. Cook, and Donald T. Campbell. 2002. Experimental and Quasi-Experimental Designs for Generalized Causal Inference. Houghton Mifflin, Boston, MA. [94] Syed W. Shah, Naeem F. Syed, Arash Shaghaghi, Adnan Anwar, Zubair Baig, and Robin Doss. 2021. LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA). Computers & Security 108, unknown (9 2021), 102351. doi:10.1016/J.COSE.2021.102351 [95] Ali M. Al Shahrani, Ali Rizwan, Manuel Sánchez-Chero, Lilia Lucy Campos Cornejo, and Mohammad Shabaz. 2023. Blockchain-enabled federated learning for prevention of power terminals threats in IoT environment using edge zero-trust model. Journal of Supercomputing unknown, unknown (11 2023), 1–27. doi:10.1007/S11227-023-05763-6/METRICS [96] Ahmed Srhir, Tomader Mazri, and Mohammed BENBRAHIM. 2023. Security in the IoT: State-of-the-Art, Issues, Solutions, and Challenges. International Journal of Advanced Computer Science and Applications 14, 5 (06 2023), 65–75. doi:10.14569/IJACSA.2023.0140507 [97] Aviral Srivastava and Usha Jain. 2023. Securing the Future of IoT: A Comprehensive Framework for Real-Time Attack Detection and Mitigation in IoT Networks. 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT) unknown, unknown (7 2023), 1–6. doi:10.1109/ICCCNT56998.2023.10307306 [98] Denis Stefanescu, Leticia Montalvillo, Patxi Galán-García, Juanjo Unzilla, and Aitor Urbieta. 2022. A Systematic Literature Review of Lightweight Blockchain for IoT. IEEE Access 10, unknown (2022), 123138–123159. doi:10.1109/ACCESS.2022.3224222 [99] Naeem Firdous Syed, Syed W. Shah, Arash Shaghaghi, Adnan Anwar, Zubair Baig, and Robin Doss. 2022. Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access 10, unknown (2022), 57143–57179. doi:10.1109/ACCESS.2022.3174679 abstract and keywords don’t include iot<br/>but article discusses iot. [100] Ted H. Szymanski. 2022. The ’Cyber Security via Determinism’ Paradigm for a Quantum Safe Zero Trust Deterministic Internet of Things (IoT). IEEE Access 10, unknown (2022), 45893–45930. doi:10.1109/ACCESS.2022.3169137 [101] Marcus Tanque and Harry J. Foxwell. 2023. Cyber risks on IoT platforms and zero trust solutions. Advances in Computers 131, unknown (1 2023), 79–148. doi:10.1016/BS.ADCOM.2023.04.003 [102] Dan Tyler and Thiago Viana. 2021. Trust No One? A Framework for Assisting Healthcare Organisations in Transitioning to a Zero-Trust Network Architecture. Applied Sciences 2021, Vol. 11, Page 7499 11, unknown (8 2021), 7499. Issue 16. doi:10.3390/APP11167499 medical devices considered as iot ?. [103] Minoru Uehara. 2021. Zero Trust Security in the Mist Architecture. Lecture Notes in Networks and Systems 278, unknown (2021), 185–194. doi:10.1007/978-3-030-79725-6_18/COVER [104] unknown. 2024. IEEE Standard for Blockchain-Based Zero-Trust Framework for the Internet of Things (IoT). [105] unknown. unknown. ICORE Conference Portal. https://portal.core.edu.au/conf-ranks/. Accessed: 2024-01-01. [106] unknown. unknown. Scimago Jounal and Country Rank. https://www.scimagojr.com/. Accessed: 2024-01-01. [107] Jin Wang, Jiahao Chen, Neal Xiong, Osama Alfarraj, Amr Tolba, and Yongjun Ren. 2023. S-BDS: An Effective Blockchain-based Data Storage Scheme in Zero-Trust IoT. ACM Transactions on Internet Technology 23, unknown (8 2023), unknown. Issue 3. doi:10.1145/3511902 [108] Jane Webster and Richard Watson. 2002. Analyzing the Past to Prepare for the Future: Writing a Literature Review. MIS Quarterly 26, 2 (06 2002), 1–11. doi:10.2307/4132319 [109] Claes Wohlin, Per Runeson, Martin Höst, Magnus C. Ohlsson, Björn Regnell, and Anders Wesslén. 2000. Experimentation in Software Engineering: An Introduction. Kluwer Academic Publishers, Norwell, MA. https://doi.org/10.1371/journal.pmed.1003583 [110] Xiangshuai Yan and Huijuan Wang. 2020. Survey on Zero-Trust Network Security. Communications in Computer and Information Science 1252 CCIS, unknown (2020), 50–60. doi:10.1007/978-981-15-8083-3_5/COVER [111] YangYinghong, BaiFenhua, YuZhuo, ShenTao, LiuYingli, and GongBei. 2022. An Anonymous and Supervisory Cross-Chain Privacy Protection Protocol for Zero-Trust IoT Application. ACM Transactions on Sensor Networks 20, 2 (8 2022), 1–20. doi:10.1145/3583073 discusses privacy and not security ? <br/>to remove ?<br/>. [112] William Yeoh, Marina Liu, Malcolm Shore, and Frank Jiang. 2023. Zero trust cybersecurity: Critical success factors and A maturity assessment framework. Computers & Security 133, unknown (2023), 103412. doi:10.1016/j.cose.2023.103412 [113] Miao Yu, Jianwei Zhuge, Meng Cao, Zhenjiang Shi, and Lei Jiang. 2020. A Survey of Security Vulnerability Analysis, Discovery, Detection, and Mitigation on IoT Devices. Future Internet 12, 2 (2020), 27. doi:10.3390/fi12020027 [114] Zhiyuan Yu, Zack Kaplan, Qiben Yan, and Ning Zhang. 2021. Security and Privacy in the Emerging Cyber-Physical World: A Survey. IEEE Communications Surveys & Tutorials 23, 3 (2021), 1879–1919. doi:10.1109/COMST.2021.3081450 [115] Przemysław Zawadzki, Justyna Trojanowska, Biplob Paul, and Muzaffar Rao. 2022. Zero-Trust Model for Smart Manufacturing Industry. Applied Sciences 2023, Vol. 13, Page 221 13, unknown (12 2022), 221. Issue 1. doi:10.3390/APP13010221 [116] Fan Zhang. 2024. Research on Google’s Latest Algorithm Rules and Application Strategies. Academic Journal of Science and Technology 9, unknown (02 2024), 185–192. doi:10.54097/bv25t069 [117] Qianqian Zhang, Guining Geng, and Zhiyuan Wang. 2023. Internet of Things Data Security Management System and Method Based on Zero Trust. In Proceedings of the 3rd International Conference on Management Science and Software Engineering (ICMSSE 2023). Atlantis Press, Zhengzhou, China, 459–471. doi:10.2991/978-94-6463-262-0_49 result by Google Scholar research, pdf found on https://www.atlantis-press.com/proceedings/icmsse23/125992445<br/>. Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
25
[118] Xiaojian Zhang, Liandong Chen, Jie Fan, Xiangqun Wang, and Qi Wang. 2021. Power IoT security protection architecture based on zero trust framework. 2021 IEEE 5th International Conference on Cryptography, Security and Privacy, CSP 2021 unknown, unknown (1 2021), 166–170. doi:10.1109/CSP51677.2021.9357607 [119] Shanshan Zhao, Shancang Li, Fuzhong Li, Wuping Zhang, and Muddesar Iqbal. 2021. Blockchain-Enabled User Authentication in Zero Trust Internet of Things. Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST 344, unknown (2021), 265–274. doi:10.1007/978-3-030-66922-5_18/COVER in abstract no ZT <br/>.
A
Detailed Methodology
MLR considers two literature types: Academic Literature (AL) and Grey Literature (GL). AL consists of scholarly articles, conference papers, and books that have undergone rigorous peer review, ensuring a high level of credibility and methodological soundness. In contrast, GL includes non-peer-reviewed sources such as technical reports, white papers,
CS UR
government documents, and blog posts. While GL may lack the formal vetting process of academic publications, it often provides practical insights, recent developments, and real-world applications that are not yet captured in academic research. By synthesizing both AL and GL, an MLR leverages the strengths of each to address complex research questions more comprehensively and capture a wide range of perspectives and findings.
GL is usually divided into 3 tiers depending on its reliability and quality [20]:
AC M
• High-quality GL (tier 1): This tier includes sources that are well-respected, often produced by reputable organizations such as government agencies, international bodies (e.g., WHO, UN), or large non-profit organizations. These documents often undergo some form of review or quality control and are cited frequently in both grey and academic literature. Examples include government reports, white papers from major research institutions, technical standards, and guidelines from reputable organizations.
• Medium-quality GL (tier 2): This tier includes sources that are generally reliable but may not have undergone
to
rigorous peer review. They are typically produced by industry groups, smaller nonprofits, or other organizations with expertise in the field. While useful, these sources may contain some bias, particularly if they are produced
ed
by organizations with specific agendas or commercial interests. Examples include industry reports, conference proceedings, white papers from smaller organizations, and reports from think tanks. • Low-quality GL (tier 3): This tier includes sources that are less reliable, and often produced by individuals,
itt
small organizations, or entities without established credibility in the field. These documents may lack proper documentation, be anecdotal, or serve promotional purposes, making them less suitable for academic research.
m
Examples include blog posts, opinion pieces, newsletters, and informal publications from lesser-known sources.
Su b
This work is focused on tiers 1 and 2, as the results of the searches gave a few results belonging to tier 1 (5 out of 36). Tier 1 papers are for example NIST SP 800-207 Zero Trust Architecture [88] ; Tier 2 papers are mainly industrial white papers, such as Zero Trust Cybersecurity for the Internet of Things [15] from Microsoft. The MLR was conducted based on the process defined by Garousi et al [40], while following PRISMA 2020 framework guidelines [79] for systematic reviews. Garousi’s process is divided in phases: Planning phase, conducting phase, and reporting phase. In the planning phase, one has to establish the need for research, define its goal, and formulate research questions to guide the investigation. Then, the conduct phase consists of literature searches via databases and grey literature via web search. During that phase, one also has to define inclusion and exclusion criteria for paper selection. Finally, the reviewing phase consists of systematically extracting and synthesizing data from selected studies and deriving meaningful insights. Manuscript submitted to ACM
26
Mariam Wehbe and Laurent Bobelin
B
Search Strategies
B.1
Database Search for AL
Key terms related to the search are zero trust, and IoT, and serve as the basis for constructing search queries. The following (case-insensitive) search string was defined: ("zt" AND "iot") OR ("zt" AND "internet of things") OR ("zero trust" AND "iot") OR ("zero trust" AND "internet of things") The following academic databases were used: IEEE Xplore, ACM Digital Library, Science Direct, and Google Scholar. It has been decided to consider only documents published between January 2014 and November 2023. The title and abstract search yielded 93 articles without duplicates.
CS UR
After that, data has been collected to determine the papers suitability for inclusion in the study based on inclusion and exclusion criteria. Thereafter, titles, abstracts, and keywords were screened to assess the relevance and appropriateness of terms used to index articles, and include only literature closely aligned with the research focus for further analysis. The study only included items that were published in peer-reviewed journals and conferences, books, and thesis reports that are ranked on CORE [105] or SCIMAGO [106]. Exclusion criteria were (1) items that are preprints, graduate projects, master’s and technical reports and (2) articles that don’t include ZT and IoT.
AC M
Finally, backward snowballing has been performed. At first, as an automated process by using Buhos [21], a web-based tool that manages the systematic literature review. Automated snowballing helped retrieve one new document. A manual snowballing was also performed, as some references were not parsed correctly by the tool, as an alternative to automated review. The papers in the reference lists were evaluated using the inclusion and exclusion criteria. 3 additional AL papers were retrieved this way.
B.2
to
The structured literature search generated 68 AL articles. Web Search for Grey Literature
ed
The study relied on the following search in Google for documents written in English matching the following search string in their title, using the same methodology to construct a search string for GL in MLR as [42], [41] or [20]:
itt
("zt" AND "iot") OR ("zt" AND "internet of things") OR ("zero trust" AND "iot") OR ("zero trust" AND "internet of things")
m
The query was split in independent subqueries, and results aggregated after this first search. This gave a total of 262 documents. However, the number of valuable results was very low: out of those 262 documents: (1) 34 were duplicates of
Su b
the AL review, (2) 175 were blogs/news/event announcements, most of them coming from websites of major industrial actors, and (3) 40 videos or podcasts. At last, only 13 white papers dealing with the topic remained, most of them coming from major actors (such as Microsoft, Palo Alto, Fortinet, ...), 1 being provided by a public organization (IEEE), while all the other came from software providers. It is unclear to us if those numbers come from the topic or a shift in the way the industry communicates. Indeed many technical blog notes and videos that might be of interest were found, but are not considered as relevant in the usual MLR methodology . Another bias may come from the search engine used. Recent studies, such as [116], suggest that this bias for big companies comes from recent adjustments in Google algorithms, which leads to the disappearance of smaller website results compared to larger ones. A modified query was then used, specifically focusing on white papers written in English and that should contain text matching the following query: Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
27
"white paper" AND (("zt" AND "iot") OR ("zt" AND "internet of things") OR ("zero trust" AND "iot") OR ("zero trust" AND "internet of things")) This gave a total of 163 documents, retrieved between November 2023 and March 20242 . Out of those, 108 white papers were accessed, most of the time not directly, but by browsing through the websites and giving business details to retrieve the document. Removing duplicates (found either using this search or the previous one) gave a total of 93 white papers, 16 coming from government agencies, 6 coming from industrial consortia, and 72 remaining from the industrial sector. The quality and relevance to the topic of the papers were assessed, and lead to the exclusion of 55 of them. A snowballing pass to retrieve relevant papers cited in GL was performed, but no additional papers was found, leading to
C
CS UR
36 GL papers to review. Data Analysis: Topic Description
• Models: papers discussing the ZT model. Both GL and AL papers discuss the ZT model and how to implement it in the IoT context. However, the way it is discussed in AL and GL differs. In AL, papers that discuss this topic present the model, the pros and cons of it, and how it should be modified. In GL, papers usually compare segmentation-based and ZT to show the pros of integrating IoT into the perimeter of a ZT architecture, but do
AC M
not propose to modify the model, and usually comply with the NIST ZT standard architecture. • Access control: papers discussing access control paradigm for IoT (ABAC, dynamic access control, ...). Many AL papers discuss new access control paradigms designed to respect the ZT pillars for IoT. GL papers falling in this category discuss the centralized management of access control and the tools to do it. • Authentication and Identification: papers about authentication methods, continuous authentication, decentralized authentication and identification, MFA for IoT. AL papers discuss decentralized authentication and new
to
methods to identify/authenticate devices or subjects using devices. On the other hand, GL discusses MFA for IoT, the use of a gateway to provide strong authentication to brownfield devices, for example.
ed
• Privacy: AL papers often discuss privacy. The review conducted respect AL authors’ choices and count papers dealing with this topic when one of the keywords they chose was privacy. None but one of the papers is centered on privacy issues and their impact. 13 out of 36 GL papers discuss about privacy briefly, mainly to list it as a
itt
threat. Papers in GL dealing with healthcare contain a slightly longer description of privacy threats, but without any formal analysis of them.
m
• Cryptography: Adoption of new cryptographic protocols or ideas is usually done very slowly compared to the pace of adoption of new security models or ideas. That may explain why papers discussing cryptography are
Su b
mainly AL ones.
• Applications: papers discussing application domains. AL papers mainly discuss implementation challenges and/or provide feedback on adopting ZT for specific domains that use IoT, such as healthcare, IIoT, or smart home. Some GL papers present specific implementations of ZT and IoT security convergence for healthcare and IIoT. • Infrastructure: fog/edge/MEC and other device-to-device infrastructure underlying the IoT deployment, and the specificity of this context for ZT. AL and GL papers present an adaptation of the ZT model for those platforms, a specific implementation for edge servers, for example. 2 The retrieval process was long due to the fact that entreprise often requires you to provide business contact and other details before being able to
retrieve documents.
Manuscript submitted to ACM
28
Mariam Wehbe and Laurent Bobelin • Blockchain: this study shows that while there is a lot of work published in AL concerning blockchain-based authentication, this is not a choice being documented in GL, as just one of the white papers reviewed was discussing blockchain (an IEEE standard for blockchain-based ZT framework for the IoT [104]). • Tools: papers discussing tools dedicated to ZT and IoT security convergence, such as Digital Twin and reputation systems to estimate whether a device is compromised, IDS, firewalls, and so on. Both GL and AL papers present tools that are implemented to be deployed specifically in the context of ZT and IoT security convergence. • Power IoT: Power Grid IoT, i.e., IoT deployed on power grids. The review found only AL papers discussing this topic, all of them coming from China. • Trust: trust score, trust evaluation, management, and modeling for IoT. Mainly discussed in AL, those aspects are just often mentioned in GL, without further description of them. More details can be found in the 3-tier GL;
CS UR
the way those subjects are mentioned in the 2-tier GL possibly indicates that those subjects are confidential to the industry.
• IIoT: Both AL and GL discuss how to apply, implement, and/or modify ZT model in this context. • Network: Network aspects of ZT and IoT security convergence. Topics covered in both AL and GL include the deployment point of view, network infrastructure, and specificity on policy enforcement in an IoT environment. trust evaluation, and intrusion detection.
AC M
• AI: Artificial intelligence applied to ZT and IoT security convergence. Papers in AL and GL discuss digital twins, • 5G/6G: ZT and IoT security convergence in the context of 5G/6G. Both AL and GL discuss how ZT can be implemented and/or modified for use in this context.
• Attacks: attacks in the context of ZT and IoT security convergence. Just a few papers discuss attacks in such a context, mainly from defense point of view. Results: detailed RQ/Literature Mapping
D.1
to
D
Level of Analysis: Concept and Architecture
ed
D.1.1 RQ1: Technical convergence of IoT security and ZT. One may differentiate work dealing with IoT compliance to ZT philosophy from those oriented toward integration into an organization-wide ZT system.
itt
Concerning AL, on the IoT compliance with ZT philosophy side, the most considered topic is (continuous) authentication and identification. [8] presents continuous authentication techniques for IoT devices using physical
m
functions to integrate an IoT device seamlessly into ZT. [94] also provides continuous authentication techniques, but is oriented toward device-to-device authentication. [72] proposes a blockchain-based protocol to remove the trust authority
Su b
involved in mutual authentication between IoT, arguing that this trust authority is granted an implicit trust. [119] presents a method to authenticate users using blockchains in an IoT environment. [69] introduces lightweight protocols to check identity on IoT. [62] proposes to use physical-layer security to enhance ZT in IIoT, including authentication, but the paper has a larger scope because it merges the physical-layer security within the ZT model. [115] discusses how a smart manufacturing system may comply with ZT. Access control is addressed by 4 papers: [30] introduces a lightweight access-control protocol for wearable devices. [28] and [65] introduce blockchain-based methods to assess a trust score for IoT and control access. [13] proposes a blockchain-based attribute-based access control (ABAC) for IoT. Data protection is a subject addressed by two papers: [47] and [107] provide a ZT blockchain-based data storage scheme, where data are stored on IoT. Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
29
Other work enforcing the compliance of IoT to ZT standard includes [61] that implements lightweight Software Defined Perimeter (SDP) at the IoT level. Concerning AL, on the integration of IoT in a ZT architecture, some works deal with trust: [1] introduces an algorithm evaluating the risk of access to an IIoT device, that can be deployed in a TE. [5] makes the bridge between the notion of trust computing used in IoT and how it may be integrated into ZT. [53] provides a framework to integrate Digital Twins (DT) of IoT into ZT architecture to provide a trust score to ZT. [75] presents a method to calculate the Trust Score using AI. [68] proposes a blockchain-based solution to integrate IoT devices in ZT while preserving anonymity in a cryptocurrency environment. [111] does the same without targeting a specific environment. Dealing with modifying, enhancing, or adapting the ZT principles to IoT, [9] and [10] propose to enhance ZT with an authorization framework based on the score to deal with uncertainty on whether the device is compromised and its
CS UR
identity. [22] presents how to leverage ZT to 5G smart healthcare platforms, which implies considering additional entities when evaluating trust, as 5G runs on a shared infrastructure. [48] presents a ZT blockchain-based information-sharing protocol between IoT; this work, however, breaks the assumption of centralized management of trust between entities. [55] proposes a framework to integrate IoT into ZT, oriented toward using gateways, similar to the Azure approach. [58] studies the integration of CPS into ZT architecture and proposes a framework to deal with such platforms. [80] presents a framework to integrate IoT in SDP. [84] presents a protocol to onboard new IoT devices into a system without fully
AC M
trusting its supply chain. [97] introduces a framework containing actual guidelines and recommendations to deploy ZT in an IoT environment, with details on how to do it technically. [100] provides a framework that includes ZT and IoT to deal with the post-quantum era. [117] proposes a method to implement ZT in the context of an IoT data security management system.
GL mainly advocates integration rather than making the IoT more compliant with ZT philosophy. Some literature deals with manufacturing ZT-compliant IoT. However, the vast majority of the GL explains how to integrate IoT into
to
the ZT system.
D.1.2 RQ2: Technical benefits and limitations of IoT security and ZT convergence. In both AL and GL, the question of
ed
the benefits and limitations of IoT security and ZT convergence is rarely and briefly discussed. It is more often implicit system policies.
itt
that the choice of the architecture shows if the choice has been made to isolate IoT resources or to embed them in the In AL, one paper discusses the opportunity of integrating IoT in ZT systems and decides to let them apart. On the
m
other hand, some papers define strategies to include them, but without discussing if including IoT is beneficial. [91] states that IoT cannot be trusted, and thus provides a blockchain-based framework for managing (and thus isolating
Su b
from the system) IoT devices. [103] provides a framework to isolate IoT in a mist architecture, and, by doing so, avoid the complexity of IoT integration.
In GL, some papers explicitly give integration techniques, for example, by the use of gateway or micro-segmentation, while others isolate the devices.
D.1.3 RQ3: Human resources needed to maintain a system that adopted a ZT and IoT security convergence philosophy. Shifting from traditional security to ZT is a process requiring expertise in both ZT and the targeted systems [44]. IoT security and ZT convergence add the need for IoT skills and a good knowledge of operational conditions of exposure to the risk of any of the IoT considered. AL does not address this topic. GL does not either, while some offers include training sessions; it is nevertheless a key point in the ZT and IoT security convergence. Manuscript submitted to ACM
30
Mariam Wehbe and Laurent Bobelin
D.2
Level of analysis: Firms and Industries
D.2.1 RQ4: How can an organization realize IoT security and ZT convergence. How to realize IoT security and ZT convergence is explored through the angle of sectors of activity in AL. [6] introduces techniques to gather information in healthcare systems, including IoT to implement ZT. [35] and [49] present techniques for implementing ZT into Power IoT. [23] provides blockchain-based technologies to secure data flows into a power network system. [95] presents methods to decentralize the trust score computation in the same context, using Federated Learning and blockchains. [50] and [51] introduce a method to continuously monitor and provide ABAC, and integrate it into a TE for power IoT. [29] does the same in the context of a smart home. [33] discusses how to implement ZT for IIoT ; so does [118], with a specific focus on continuous authentication. [58] studies the integration of CPS into ZT architecture and proposes a framework to deal with such platforms. [78] introduces an
CS UR
ML-supervised IDS to integrate in a ZT-based 5G environment. [92] also introduces an IDS to integrate into a ZT-based system, but targets 6G instead of 5G. [59] introduces a ZT framework for connected vehicles. [66] presents methods that focus on the security of edges and how to integrate them into ZT architectures. [86] introduces a method to prevent APT attacks in an IoT based on ZT model. [102] provides the results of experiences in using a ZT framework and following Cisco guidelines in a healthcare environment.
In GL a lot of papers discuss how to realize ZT and IoT security convergence, without specifying for which domain it
AC M
may be relevant to do this convergence. GL only discusses the specificity of two sectors: healthcare and IIoT. D.2.2 RQ5: How does IoT security and ZT convergence provide added value for organizations. In AL there is little to no attempt to measure the added value for organizations about this convergence. In this corpus, only [36] compares perimeter-based security and ZT in the context of IIoT.
In GL, this topic is massively addressed, as it is a key factor in the adoption of this convergence in the organization.
to
Indeed, the promise of stronger security is in most of the GL reviewed. Demonstrating the added value of ZT and IoT security convergence is done by comparing it to segmentation-based security. The drawbacks of such a convergence,
ed
often listed when dealing with ZT adoption (see for example [44]), are not addressed in GL. D.2.3 RQ6: Organizations setup, government and development of IoT security and ZT convergence. One may foresee the
itt
complexity of the process induced by a shift from an existing IoT security to the convergence of IoT and ZT by looking at the complexity of shifting from perimeter-based security to ZT. Shifting from perimeter-based security to ZT is a
m
long process that usually lasts for years, carefully migrating segments one after the other, with meticulous transcription of policies [44].
Su b
The review did not find either AL or GL dealing with the subject of how an organization may manage these projects.
Two papers in this study discuss factors influencing the organization of this process, focusing on healthcare systems. [90] studies factors behind the adoption of ZT and IoT in the Malaysian healthcare system. [45] analyses the impact on privacy of IoT integration in ZT, and the impact on the adoption of IoT in healthcare systems. D.3
Level of Analysis: Users and Society
There are very few papers, either in AL or GL, that consider ZT and IoT from users and society level of analysis. It could be either an artifact of the methodology3 , or a real lack of support for those aspects. 3 The literature considered, as the search methods are oriented toward research (so, technical) papers.
Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
31
D.3.1 RQ7: How does IoT security and ZT convergence affect the interaction between users and technology. There is no paper, neither in AL nor GL, that addresses this issue. While the review found papers about IoT security and ZT convergence in the context of smart homes [29] or wearable devices [30], both of them study the technical point of view and not the adoption by end users. D.3.2 RQ8: Benefits and costs of ZT and IoT security convergence for individual users and society. In AL, several works mention this topic for some specific communities or sectors of activity. As stated before, [90] studies factors behind the adoption of ZT and IoT in the Malaysian healthcare system. [45] analyses the impact on privacy of IoT integration in ZT, and the impact of the adoption of IoT in healthcare systems. The primary focus of those works is the impact on the organization and not end users. GL does not address this topic; that might be explained by the fact that IoT security and
CS UR
ZT convergence GL papers are oriented towards organizations rather than end users or society. D.3.3 RQ9: How does one balance user privacy and ZT and IoT security convergence requirements. In AL, only [82] surveys the adoption of IoT in healthcare, with an emphasis on ZT. The review did not find any discussion about that topic in GL. Privacy and the empowerment of users are still open research fields. E
GL document list
Title
Enterprise
5 Must-Haves for Comprehensive
Palo Alto Networks, Inc
Zero Trust IoT Security
Summary
2023
List of tools required to achieve IoT and ZT
Healthcare: 3 Main Drivers that Make the Case nected Devices
Su b
Architecting the Zero Trust EnterArista Zero Trust Security for Cloud
epam
2020
segmentation of IoT/unmanaged devices (white paper) Recommendations for ZT in healthcare with
Palo Alto Networks, Inc.
2021
Recommendations for IoT integration in ZT framework (white paper) Recommendations for IoT integration in ZT framework (white paper) General recommendations for ZT architecture (white paper)
Arista
2023
Bolstering Enterprise Security Us-
cradlepoint (part of Erics-
2023
ing Zero Trust Architecture
son)
Total Visibility: The Master Key to
Forescout
Networking
Zero Trust Security
Recommendations for isolation and micro-
IoT support (white paper) 2023
m
Architecting Security into Your
2023
netskope
itt
Achieving Zero Trust for Con-
Cynerio
ed
Adopting Zero Trust Security for
2024
to
ordr
aged and IoT Devices
prise
Year
integration
5 Steps to Zero Trust for Unman-
Modern Enterprise
AC M
Table 6. GL Artifacts Summaries
General recommendations for ZT architecture (white paper) General recommendations for ZT architecture (white paper)
2021
General recommendations for ZT adoption (white paper) Continued on next page
Manuscript submitted to ACM
32
Mariam Wehbe and Laurent Bobelin Table 6 – continued from previous page
Title
Enterprise
Date
Summary
Zero Trust Manufacturing
KEYFACTOR
2022
Recommendations to implement ZT in a system where IoT comes from complex supply chains (white paper)
Best Practices for Extending Zero
Forescout
Recommendations for US federal agency’s
2021
Trust to Government Networks
adoption of ZT with a strategy for handling IoT (white paper)
A Unified Architecture for Achiev-
EMA
2021
Recommendations for ZT architecture across
ing Zero Trust Across all Network
networks domains (white paper)
Domain ETSI
2022
support and future evolutions Extending Zero-Trust Security to In-
Recommendations for MEC security based
CS UR
MEC security; Status of standards
on ZT (white paper)
Cisco
2021
Fijoport Zero Trust Architecture
Fijowave Cyber Security
2022
Edge Security Essentials
Dell Technologies
2024
Identity and Zero Trust: a HEALTH-
H-ISAC
dustrial Operations
Recommendations for ZT in IIoT (white paper)
Description of a solution for IoT security
ISAC guide for CISOS Zero Trust Manufacturing
Farallon
AC M
based on ZT
2024
Technology
2021
Implementing zero trust for industrial environments
Claroty (ITSARI) Forescout
ed
IoT Security: Choose a flexible zero
to
Group & KEYFACTOR
Recommendations for ZT at edges (white paper) Recommendations for merging ZT and HEALTH-ISAC framework identities management Challenges and best practices to implement ZT in a system where IoT comes from complex supply chains (white paper)
2022
Recommendations for IoT integration in ZT framework (white paper)
2022
trust approach to secure nontradi-
Recommendations for IoT integration in ZT framework
itt
tional devices in your digital terrain
m
Front-End Access Control (FEAC)
Moving To An Endpoint-Centric
SafePay Systems
2021
SentinelOne
2021
European Union’s Horizon 2020 IoTAC)
Zero Trust Security Model with Sen-
Su b
ZT Access Control for IoT (deliverable from Recommendations for moving to ZT framework an IoT environment (white paper)
tinelOne
Security: Creating Trust in a Zero
opentext
2021
Trust World
The Right Approach to Zero Trust
Palo Alto Networks, Inc
2023
infineon
2021
for Medical IoT Devices Secure IoT begins with Zero-Touch Provisioning at scale
Recommendations for adopting ZT framework (white paper) Recommendations for implementing ZT framework for medical IoT (white paper) Recommendations for IoT identity management for ZT Continued on next page
Manuscript submitted to ACM
Converging Zero Trust and IoT Security: A MLR
33
Table 6 – continued from previous page Title
Enterprise
Date
Summary
Securing a New Digital World with
HIKVISION
2021
Recommendations for deploying ZT on IoT
Zero Trust: How Zero Trust Cyber-
for video surveillance (white paper)
security is Transforming the IoT Industry Seven Elements of Highly Success-
Zscaler
2022
MEDIGATE
2024
ful Zero Trust Architecture
Recommendations for ZT architecture implementation
What is Clinical Zero Trust?
Recommendations for implementing ZT framework for medical IoT in a clinical environment (white paper)
Sepio
2024
access security model
Recommendations of how to enforcing end-
CS UR
Embracing a Zero Trust hardware
point an IoT access in ZT (whitepaper)
Zero Trust Edge Computing
mainsail
2023
Recommendations of how to leverage Western Digital Ultrastar Edge, Red Hat Enterprise, and Mainsail Metalvisor to implement ZT at the edges (whitepaper)
SD-WAN for Manufacturing
Aruba
2022
How SD-WAN can be part of a SASE ZT
AC M
framework to secure IoT devices (technical paper)
Securing Digital Innovation De-
Fortinet
2021
mands Zero-trust Access Closing hidden security gaps in zero
Armis, Inc.
2022
trust architectures: what public sec-
to
Zero Trust Cybersecurity for the In-
Microsoft Azure
ternet of Things
Ericsson
itt
Zero Trust Architecture for advanc-
ExtraHop
ed
Accelerate Zero Trust Adoption
2021
2022
m
tities
F
NEXUS, IN groupe
Introduction to Azure solution to ZT+IoT convergence (white paper) Recommendations to accelerate ZT adoption
2024
Introduction to ZTA convergence with mobile networks (white paper)
2024
Identity management for IoT and IIoT in a ZT environment (white paper)
Su b
Zero Trust with Secure Device Iden-
sets and IoT (white paper)
(white paper)
ing mobile network security operaIoT and IIoT security: Achieving
Public sector oriented to introduce ZT and specific challenges, including unmanaged as-
tor needs to know
tions
Recommendations for adoption of ZT at net-
work edge (whitepaper)
Quality Assessment Checklist
Received ; revised ; accepted
Manuscript submitted to ACM
34
Mariam Wehbe and Laurent Bobelin Table 7. Quality and validity assessment criteria for included studies in the MLR
Indicators
Solution provided in this MLR Construct Validity
Extent to which the study correctly operationalizes and measures its theoretical concepts. Evaluate whether key constructs (e.g., “IoT”, “Zero Trust”) are clearly defined and linked to measures. • Clear definition of constructs • Alignment between theory and measurement • Use of established definitions or metrics
✓extensive literature about concepts ✓results in line with literature ✓standard methods applied
Internal Validity
CS UR
Confidence that study results are not affected by confounding variables or design bias. Focus on rigor of design, control of bias, and reasoning chain. • Methodological transparency • Bias/limitations discussed • Triangulation or validation methods
✓Detailed methodology provided ✓Dedicated section ✓Different data sources, investigator triangulation Conclusion Validity
AC M
Whether conclusions are justified given the evidence presented. Assess logical coherence and whether conclusions overstate findings. • Data support claims • Discussion of uncertainty • Statistical/qualitative justification
✓Detailed mapping in appendix ✓Discussed ✓Provided in tables and figures
External Validity
✓Detailed description given ✓Not applicable ✓Full list of selected artifact provided
ed
• Context description • Discussion of generalizability • Replicability of setting or sample
to
Extent to which findings can be generalized to other contexts, populations, or applications.
Source Credibility (MLR
itt
Specific to multivocal reviews: credibility and trustworthiness of each source, based on Garousi et al. (2019) guidelines for grey literature.
Su b
m
• Tiers classification of GL
Manuscript submitted to ACM
✓Used