Zero Trust for IoT devices without built-in identity

Implementing Zero Trust for IoT devices without inherent identity requires a strategic approach that combines network-based identity, compensating controls, and robust certificate management. This strategy ensures security and Zero Trust compliance, even for legacy devices.

The Zero Trust challenge for IoT without identity: Why traditional approaches fall short

Many Internet of Things (IoT) devices, particularly legacy or industrial (OT) systems, were not designed with embedded security mechanisms such as unique identity, secure boot, or Trusted Platform Modules (TPMs). This presents a significant challenge for Zero Trust (ZT) architectures, which are founded on the principle of “never trust, always verify.” The NIST 800-207 standard, which defines the Zero Trust architecture, mandates continuous identity verification for every access request, regardless of its origin.

Traditional security models, reliant on network perimeters, are insufficient for modern IoT environments where the number of connected devices is rapidly expanding, and the attack surface is significantly broadened. Each unsecured or unmonitored IoT device can become an entry point for attackers, potentially granting them access to corporate networks. Without unique device-level identity, direct application of ZT principles becomes impossible, necessitating the development of alternative strategies.

Network-based identity as a foundation for Zero Trust: Segmentation and microsegmentation

For IoT devices that lack built-in identification mechanisms, network-based identity can serve as a foundation for applying Zero Trust principles. This is achieved through meticulous network segmentation and microsegmentation, where devices are grouped by function, risk level, and data sensitivity. Utilizing IP addresses, MAC addresses, VLANs, and other network attributes allows for the creation of a virtual identity for such devices.

NIST and CISA recommendations emphasize the importance of network segmentation for Zero Trust in OT environments. CISA, in particular, notes that segmentation itself is an effective compensating control when device-level identification is not feasible. Microsegmentation enables the isolation of IoT traffic from critical IT systems, ensuring that even if one device is compromised, the breach does not propagate to other systems. This involves establishing secure zones and clearly defining policies that govern which devices can interact and under what conditions.

Compensating controls: Enhancing security at the edge

For IoT devices with limited security capabilities, compensating controls play a crucial role in providing the necessary level of trust and monitoring. These controls are implemented at the network edge or at the gateway level to ensure authentication and authorization for “unknown” devices.

Effective compensating controls include:

  • Network Access Control (NAC): Allows devices to be authenticated before granting network access, using attributes like MAC addresses or gateway-issued certificates.
  • Intrusion Detection/Prevention Systems (IDS/IPS): Monitor network traffic for anomalies and malicious activity, blocking potential threats.
  • Next-Generation Firewalls (NGFW): Provide deep packet inspection and context-aware policy enforcement, limiting device communications to only necessary resources.
  • Secure IoT gateways and proxy servers: Act as intermediaries that can perform authentication, encryption, and policy enforcement for devices that do not natively support these functions. CISA explicitly supports the use of compensating controls above the device level for legacy OT systems.

NIST IoT guidance also recommends applying compensating controls for devices with limited security capabilities, such as changing default passwords, disabling unnecessary functions, and implementing strict access control.

Certificate lifecycle management for IoT gateways and proxy servers

In a Zero Trust architecture, where every device must be authenticated, managing digital certificates is critically important. For IoT devices without built-in identity, IoT gateways and proxy servers can fulfill this role, acting as “representatives” for these devices within a secure environment.

Effective Certificate Lifecycle Management (CLM) for these intermediary devices is a complex task due to the scale of IoT deployments, device resource constraints, and their long operational lifespans. Automated CLM systems are essential for issuing, provisioning, renewing, and revoking certificates, integrating with IoT management platforms. This includes:

  • Automated certificate provisioning: Ensures zero-touch provisioning from manufacturing to field deployment.
  • Certificate rotation and revocation: Critical for maintaining security, especially for systems operating for years.
  • Secure firmware updates: Code signing certificates ensure the authenticity of updates, protecting against counterfeit versions.

The Matter standard, for example, mandates strict Device Attestation Certificates (DACs) based on Public Key Infrastructure (PKI), compelling manufacturers to implement enterprise-grade PKI hierarchies.

Minimizing and securely managing exceptions

Even with the most thorough planning, implementing Zero Trust for IoT devices may require creating certain exceptions to rules, especially for unique or critical systems that cannot be fully integrated into a standard ZT architecture. However, these exceptions must be minimized and strictly controlled.

Key aspects of exception management include:

  • Identification and documentation: Each exception must be clearly identified, justified, and thoroughly documented, including associated risks and mitigation measures.
  • Continuous monitoring and auditing: Enhanced behavioral monitoring and regular auditing must be implemented for all devices under exception to detect any anomalies or misuse attempts. CISA emphasizes the importance of continuous verification and risk adaptation.
  • Access limitation: Even for exceptions, access should be granted based on the principle of least privilege, meaning only to the resources absolutely necessary for the device's functions.
  • Regular review: Exceptions should not be permanent. They must be regularly reviewed and evaluated for the possibility of integrating devices into the standard ZT model in the future, for example, after firmware updates or hardware replacement.

Managing exceptions in Zero Trust architectures requires coordination between IT and OT teams to balance security and operational continuity.

Practical checklist for implementing Zero Trust for IoT without identity

CriterionStatus (Yes/No/In Progress)Comments/Next Steps
Are all IoT devices without built-in identity identified?Create a complete asset inventory.
Is network segmentation/microsegmentation implemented for these devices?Develop segmentation policies based on functions and risks.
Are compensating controls (NAC, IDS/IPS, NGFW) applied to each segment?Implement and configure appropriate solutions.
Is a certificate management strategy developed for IoT gateways/proxies?Automate certificate issuance, renewal, and revocation.
Are all necessary exceptions to Zero Trust rules defined and documented?Create an exception register with justification and risk mitigation plan.
Are monitoring and auditing mechanisms implemented for exceptions and compensating controls?Configure SIEM/SOC systems for continuous tracking.
Is there a plan for regular review and update of security policies for IoT devices without identity?Establish a schedule for policy review and update procedures.

The AZIOT platform can be used to aggregate data from diverse IoT devices, including those without built-in identity, allowing the application of access policies and monitoring at the gateway or software level, integrating with UnityBase. This ensures centralized management and compliance with Zero Trust principles through software-defined policies.

Implementing Zero Trust for IoT devices without built-in identity is not a one-time project but a continuous process of adaptation and improvement. By focusing on network-based identity, compensating controls, and meticulous certificate lifecycle management, organizations can significantly enhance the security of their IoT environments, minimizing risks and ensuring compliance with modern cybersecurity standards.

For more information on Intecracy and UnityBase enterprise solutions, visit Intecracy solutions and inbase.com.ua solutions.

Source list

  1. qcecuring.comqcecuring.com
  2. aeris.comaeris.com
  3. medium.commedium.com
  4. zscaler.comzscaler.com
  5. veridify.comveridify.com
  6. tigera.iotigera.io
  7. cloudsecurityalliance.orgcloudsecurityalliance.org
  8. beyondidentity.combeyondidentity.com