Converging Zero Trust (ZT) with learning techniques can solve various operational and security challenges in Distributed Computing Continuum Systems (DCCS). Implementing centralized ZT architecture is seen as unsuitable for the computing continuum (e.g., computing entities with limited connectivity and visibility, etc.). At the same time, implementing decentralized ZT in the computing continuum requires understanding infrastructure limitations and novel approaches to enhance resource access management decisions. To overcome such challenges, we present a novel learning-driven ZT conceptual architecture designed for DCCS. We aim to enhance ZT architecture service quality by incorporating lightweight learning strategies such as Representation Learning (ReL) and distributing ZT components across the computing continuum. The ReL helps to improve the decision-making process by predicting threats or untrusted requests. Through an illustrative example, we show how the learning process detects and blocks the requests, enhances resource access control, and reduces network and computation overheads. Lastly, we discuss the conceptual architecture, processes, and provide a research agenda.
翻译:将零信任(Zero Trust, ZT)与学习技术相结合,能够解决分布式计算连续统系统(Distributed Computing Continuum Systems, DCCS)中的各类操作与安全挑战。集中式零信任架构被认为不适用于计算连续统(例如,存在连接性和可见性受限的计算实体等)。与此同时,在计算连续统中实施去中心化零信任需要理解基础设施局限性,并探索增强资源访问管理决策的新方法。为克服这些挑战,我们提出了一种专为分布式计算连续统系统设计的创新性学习驱动零信任概念架构。我们旨在通过融入表征学习(Representation Learning, ReL)等轻量级学习策略,并将零信任组件分布部署于计算连续统中,从而提升零信任架构的服务质量。表征学习通过预测威胁或不可信请求,有助于改进决策过程。通过一个实例演示,我们展示了学习过程如何检测并阻断异常请求、增强资源访问控制,并降低网络与计算开销。最后,我们讨论了该概念架构及其流程,并提出了研究路线图。