Authors :
Mohammed Ibrahim Abba; Womeodu Blessing; Raymond Ternenge Igbudu
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/ymbmp753
DOI :
https://doi.org/10.38124/ijisrt/26aug612
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Industrial Internet of Things (IoT) networks connect sensors, programmable logic controllers (PLCs), supervisory
control and data acquisition (SCADA) systems, enterprise platforms, and cloud services to support automation, monitoring,
predictive maintenance, and data-driven decision-making. This connectivity also expands the attack surface of operational
technology (OT), particularly where legacy equipment, remote access, heterogeneous protocols, and stringent availability and
safety requirements coexist. This paper develops a Zero Trust Architecture (ZTA) tailored to IIoT environments. The proposed
architecture combines strong device and user identity, continuous verification, least-privilege and attribute-based access control,
micro-segmentation, secure gateways for legacy devices, encrypted communication, continuous monitoring, and risk-adaptive
policy enforcement. A simulation-oriented evaluation framework is specified using a representative industrial network
comprising field devices, PLCs, SCADA/HMI systems, an edge gateway, enterprise resources, and a remote maintenance user.
The evaluation is designed to compare authorized and unauthorized access, lateral-movement attempts, malicious commands,
and controller or gateway failures using security and performance metrics. The architecture is intended to contain compromise
while preserving the availability and timing requirements of industrial processes. Importantly, the manuscript distinguishes the
proposed evaluation framework from experimentally measured results: numerical performance values are not presented as
empirical findings unless generated by an executable testbed. The study concludes that Zero Trust is most practical in IIoT
when implemented incrementally, with OT safety and availability treated as first-class requirements and legacy assets protected
through compensating controls rather than forced modernization.
Keywords :
Zero Trust Architecture; Industrial Internet of Things; Operational Technology; Micro-Segmentation; Access Control; PLC; SCADA; Network Security; Legacy Systems; Remote Access.
References :
- K. Stouffer et al., “Guide to Operational Technology (OT) Security,” NIST Special Publication 800-82 Rev. 3, National Institute of Standards and Technology, Gaithersburg, MD, USA, Sep. 2023. doi: 10.6028/NIST.SP.800-82r3.
- S. W. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, National Institute of Standards and Technology, Gaithersburg, MD, USA, Aug. 2020. doi: 10.6028/NIST.SP.800-207.
- F. Federici, D. Martintoni, and V. Senni, “A Zero-Trust Architecture for Remote Access in Industrial IoT Infrastructures,” Electronics, vol. 12, no. 3, Art. no. 566, 2023. doi: 10.3390/electronics12030566.
- C. Zanasi, S. Russo, and M. Colajanni, “Flexible Zero Trust Architecture for the Cybersecurity of Industrial IoT Infrastructures,” Ad Hoc Networks, vol. 156, Art. no. 103414, 2024.
- N. Basta et al., “Towards a Zero-Trust Micro-segmentation Network Security Strategy: An Evaluation Framework,” in Proc. IEEE/IFIP Network Operations and Management Symposium (NOMS), 2022.
- G. M. Køien, “Zero-Trust Principles for Legacy Components,” Wireless Personal Communications, vol. 121, pp. 1169–1186, 2021.
- Industrial Internet Consortium, “The Industrial Internet of Things Trustworthiness Framework Foundations,” Industrial Internet Consortium, 2019.
- U.S. Department of Defense Chief Information Officer, “Department of Defense Zero Trust Reference Architecture,” Version 2.0, Jul. 2022.
Industrial Internet of Things (IoT) networks connect sensors, programmable logic controllers (PLCs), supervisory
control and data acquisition (SCADA) systems, enterprise platforms, and cloud services to support automation, monitoring,
predictive maintenance, and data-driven decision-making. This connectivity also expands the attack surface of operational
technology (OT), particularly where legacy equipment, remote access, heterogeneous protocols, and stringent availability and
safety requirements coexist. This paper develops a Zero Trust Architecture (ZTA) tailored to IIoT environments. The proposed
architecture combines strong device and user identity, continuous verification, least-privilege and attribute-based access control,
micro-segmentation, secure gateways for legacy devices, encrypted communication, continuous monitoring, and risk-adaptive
policy enforcement. A simulation-oriented evaluation framework is specified using a representative industrial network
comprising field devices, PLCs, SCADA/HMI systems, an edge gateway, enterprise resources, and a remote maintenance user.
The evaluation is designed to compare authorized and unauthorized access, lateral-movement attempts, malicious commands,
and controller or gateway failures using security and performance metrics. The architecture is intended to contain compromise
while preserving the availability and timing requirements of industrial processes. Importantly, the manuscript distinguishes the
proposed evaluation framework from experimentally measured results: numerical performance values are not presented as
empirical findings unless generated by an executable testbed. The study concludes that Zero Trust is most practical in IIoT
when implemented incrementally, with OT safety and availability treated as first-class requirements and legacy assets protected
through compensating controls rather than forced modernization.
Keywords :
Zero Trust Architecture; Industrial Internet of Things; Operational Technology; Micro-Segmentation; Access Control; PLC; SCADA; Network Security; Legacy Systems; Remote Access.