Trust No One, Verify Everyone: An Identity-Centric Adaptive Framework for Zero Trust Architecture

  • Unique Paper ID: 208446
  • PageNo: 159-170
  • Abstract:
  • Traditional perimeter-based security relies on implicit trust and is increasingly ineffective against credential compromise, insider threats, and lateral movement in cloud and distributed environments. Zero Trust Architecture (ZTA) eliminates this implicit trust by continuously verifying identities, devices, and access requests. This paper investigates Identity and Access Management (IAM) as the foundation of ZTA, examining authentication, authorization, least-privilege access, human and non-human identities, and modern access-control models including RBAC, ABAC, ReBAC, and PBAC. It further integrates context-aware risk assessment and Continuous Access Evaluation (CAEP) to address dynamically changing security conditions. Based on this analysis, the study proposes an identity-centric adaptive Zero Trust framework that combines identity verification, contextual risk assessment, policy-based authorization, and continuous access evaluation into a unified access-decision mechanism. The proposed framework aims to enable adaptive access control, minimize unauthorized access and lateral movement, and strengthen security across cloud, hybrid, and distributed environments.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{208446,
        author = {Shreya Miskin and Sanchi Mane},
        title = {Trust No One, Verify Everyone: An Identity-Centric Adaptive Framework for Zero Trust Architecture},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {no},
        pages = {159-170},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=208446},
        abstract = {Traditional perimeter-based security relies on implicit trust and is increasingly ineffective against credential compromise, insider threats, and lateral movement in cloud and distributed environments. Zero Trust Architecture (ZTA) eliminates this implicit trust by continuously verifying identities, devices, and access requests. This paper investigates Identity and Access Management (IAM) as the foundation of ZTA, examining authentication, authorization, least-privilege access, human and non-human identities, and modern access-control models including RBAC, ABAC, ReBAC, and PBAC. It further integrates context-aware risk assessment and Continuous Access Evaluation (CAEP) to address dynamically changing security conditions. Based on this analysis, the study proposes an identity-centric adaptive Zero Trust framework that combines identity verification, contextual risk assessment, policy-based authorization, and continuous access evaluation into a unified access-decision mechanism. The proposed framework aims to enable adaptive access control, minimize unauthorized access and lateral movement, and strengthen security across cloud, hybrid, and distributed environments.},
        keywords = {Zero Trust Architecture (ZTA), Identity and Access Management (IAM), Context-Aware Risk Assessment, Continuous Access Evaluation (CAEP), Adaptive Access Control, Least-Privilege Access, Policy-Based Authorization.},
        month = {September},
        }

Cite This Article

Miskin, S., & Mane, S. (2026). Trust No One, Verify Everyone: An Identity-Centric Adaptive Framework for Zero Trust Architecture. International Journal of Innovative Research in Technology (IJIRT), 159–170.

Related Articles