Author
Listed:
- Ashutosh Soni
(Biomedical Sensors & Systems Lab, University of Memphis, Memphis, TN 38152, USA
Department of Computer Science and Engineering, C. V. Raman Global University, Bhubaneswar 752054, India)
- Surendra Kumar Nanda
(Department of Computer Science and Engineering, C. V. Raman Global University, Bhubaneswar 752054, India)
- Jayanti Rout
(Biomedical Sensors & Systems Lab, University of Memphis, Memphis, TN 38152, USA
Department of Computer Science and Engineering, C. V. Raman Global University, Bhubaneswar 752054, India)
- Mrutyunjaya Sathua
(Department of Computer Science and Engineering, C. V. Raman Global University, Bhubaneswar 752054, India)
- Ganapati Panda
(Department of Computer Science and Engineering, C. V. Raman Global University, Bhubaneswar 752054, India)
- Manob Jyoti Saikia
(Biomedical Sensors & Systems Lab, University of Memphis, Memphis, TN 38152, USA
Electrical and Computer Engineering Department, University of Memphis, Memphis, TN 38152, USA)
Abstract
Organizations usually rely on stringent access control mechanisms where access policies are an important asset. Their storage or transmission in plaintext can compromise sensitive access rules. It is important in dynamic environments where access decisions are made in real time such as Zero Trust (ZT). Existing ZT approaches were found to oversee the aspect of securing these policies. This investigation presents a Multi-layer Access Policy Encryption System for ZT systems (MAPE-ZT). The first stage uses the trapdoor index to generate a secure index to find the applicable access policies. Advanced Encryption Standard-256 is used in counter mode for the encryption of the policies. They are re-encrypted using the Ciphertext-Policy Attribute-Based Encryption (CP-ABE) to allow decryption based on a matching set of attributes. Various experiments using quantitative metrics, including comparison with baseline access control systems simulation, scalability evaluation, storage overhead, etc., highlight the efficacy of the MAPE-ZT and establish new benchmarks. The result count entropy for the policies ranged 3.84–4.21 for different scales of policies. The evaluation in different scales of systems shows that the MAPE-ZT reduces various observable patterns even if the deployment size grows. Its unique design of securing policies makes this approach scalable for multi-domain integration.
Suggested Citation
Ashutosh Soni & Surendra Kumar Nanda & Jayanti Rout & Mrutyunjaya Sathua & Ganapati Panda & Manob Jyoti Saikia, 2026.
"MAPE-ZT: A Multi-Layer Access Policy Encryption System for Zero Trust Architectures,"
Future Internet, MDPI, vol. 18(3), pages 1-32, March.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:3:p:135-:d:1878991
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:3:p:135-:d:1878991. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.