ADAPTATION OF ZERO TRUST ARCHITECTURE FOR CYBER-PHYSICAL ROBOTIC SYSTEMS: BASIC REQUIREMENTS AND WIRELESS CHANNEL RESILIENCE LIMITS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1359Keywords:
Zero Trust, cybersecurity, cyber-physical system, robotic system, ns-3, resilience, wireless communication, continuous verification, authorization, security policyAbstract
The problem of applying the Zero Trust approach to the security of Cyber-Physical Robotic Systems is analyzed. It is substantiated that the close interaction of network computing, sensors, actuators and physical control systems forms a single risk plane, where the compromise of identification data, telemetry or communication channels threatens both information leakage and dangerous physical incidents. The research area covers industrial and mobile robots, unmanned aerial vehicles, service and collaborative robots, the functioning of which depends on cyber components capable of influencing physical behavior. Within the framework of the architecture development, five basic Zero Trust requirements were formulated: verifiable identification, contextual authorization, network segmentation, assessment of telemetry relevance and reliability, as well as adaptive response with limited operation and local fault tolerance. To determine the limits of the stability of the wireless control channel, simulation modeling was performed in the ns-3 environment (IEEE 802.11ax WiFi 6 standard, one access point, 20 client stations). Based on the analysis of 140 routes (distances 30–125 m, total load 100 Mbps), the aggregate useful throughput (aggregate goodput), p95 delay, and packet loss percentage were estimated. A two-stage nature of the communication channel degradation was revealed: the early time degradation limit was recorded at a distance of 40 m (p95 delay jump to 351.8 ms with almost no loss), and the limit of stable loss degradation was recorded at 50 m (losses of 9.61%). At a critical distance of 125 m, goodput decreases to 0.387 Mbps with losses of 99.81%. It was established that the obtained wireless communication stability limits are decisive for telemetry delivery and response mode selection, but in isolation do not guarantee the implementation of Zero Trust. For comprehensive validation of the zero-trust architecture, a pipeline for synchronized analysis of network metrics, security events, and the physical state of the robot is proposed.
Downloads
References
Yaacoub, J.-P. A., Noura, H. N., Salman, O., & Chehab, A. (2021). Robotics Cyber Security: Vulnerabilities, Attacks, Countermeasures, and Recommendations. Int. J. Inf. Secur., 21, 115–158. https://doi.org/10.1007/s10207-021-00545-8
Pu, H., He, L., Cheng, P., Sun, M., & Chen, J. (2023). Security of Industrial Robots: Vulnerabilities, Attacks, and Mitigations. IEEE Netw., 37, 111–117. https://doi.org/10.1109/mnet.116.2200034
Haskard, A., & Herath, D. (2025). Secure Robotics: Navigating Challenges at the Nexus of Safety, Trust, and Cybersecurity in Cyber-Physical Systems. ACM Comput. Surv., 57, 1–48. https://doi.org/10.1145/3723050
Yu, Z., Gao, H., Cong, X., Wu, N., & Song, H. (2023). A Survey on Cyber-Physical Systems Security. IEEE Internet Things J., 10, 21670–21686. https://doi.org/10.1109/jiot.2023.3289625
Syed, N., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z. A., & Doss, R. (2022). Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/access.2022.3174679
He, Y., Huang, D., Chen, L., Ni, Y., & Ma, X. (2022). A Survey on Zero Trust Architecture: Challenges and Future Trends. Wirel. Commun. Mob. Comput., 2022(1). https://doi.org/10.1155/2022/6476274
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207
Cybersecurity and Infrastructure Security Agency. (2023). Zero Trust Maturity Model, Version 2.0. CISA Guidance. https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
Feng, X., & Hu, S. (2023). Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems. IEEE Trans. Ind. Cyber Phys. Syst., 1, 394–405. https://doi.org/10.1109/ticps.2023.3333850
Hasan, S., Amundson, I., & Hardin, D. S. (2023). Zero Trust Architecture Patterns for Cyber-Physical Systems. SAE Tech. Pap. Ser.. https://doi.org/10.4271/2023-01-1001
Bello, A., Diyan, M., & Asghar, I. (2025). Zero Trust Implementation for Legacy Systems using Dynamic Microsegmentation, Role-Based Access Control (RBAC), and Attribute-Based Access Control (ABAC). In 2025 4th Int. Conf. on Computing and Information Technology (ICCIT), 181–189. https://doi.org/10.1109/iccit63348.2025.10989392
Zanasi, C., Russo, S., & Colajanni, M. (2024). Flexible Zero Trust Architecture for the Cybersecurity of Industrial IoT Infrastructures. Ad Hoc Netw., 156, 103414. https://doi.org/10.1016/j.adhoc.2024.103414
Paul, B., & Rao, M. (2022). Zero-Trust Model for Smart Manufacturing Industry. Appl. Sci. https://doi.org/10.3390/app13010221
Li, K., Li, C., Yuan, X., Li, S.-F., Zou, S., Ahmed, S. S., Ni, W., Niyato, D., Jamalipour, A., Dressler, F., & Akan, O. B. (2025). Zero-Trust Foundation Models: A New Paradigm for Secure and Collaborative Artificial Intelligence for Internet of Things. IEEE Internet Things J., 12, 46269–46293. https://doi.org/10.1109/jiot.2025.3603957
Mahmud, R., Jin, J., Kua, J., Afrin, M., Mistry, S., & Krishna, A. (2025). Trusted Microservice Orchestration for Secure Edge Computing in Industrial Cyber-Physical Systems. IEEE Netw., 39, 70–78. https://doi.org/10.1109/mnet.2025.3541032
Zhukabayeva, T., Zholshiyeva, L., Karabayev, N., Khan, S., & Alnazzawi, N. (2025). Cybersecurity Solutions for Industrial Internet of Things-Edge Computing Integration: Challenges, Threats, and Future Directions. Sens., 25. https://doi.org/10.3390/s25010213
Zanasi, C., Marasco, I., & Colajanni, M. (2025). Graph based threat detection system for a microsegmentation Zero Trust Architecture. In 2025 IEEE Conf. on Dependable, Autonomic and Secure Computing (DASC), 31–39. https://doi.org/10.1109/
dasc68382.2025.00012
Goerke, N., Timmermann, D., & Baumgart, I. (2021). Who Controls Your Robot? An Evaluation of ROS Security Mechanisms. In 2021 7th Int. Conf. on Automation, Robotics and Applications (ICARA), 60–66. https://doi.org/10.1109/icara51699.2021.9376468
Xia, L., Gao, X., & Shi, W. (2025). Investigating Security Threats in Multi-Tenant ROS 2 Systems. 2025 IEEE International Conference on Robotics and Automation (ICRA), 16441–16448. https://doi.org/10.1109/icra55743.2025.11127490
Shaik, A. K., Mohammadi, A., & Malik, H. A. M. (2025). A Systematic Review of Sensor Vulnerabilities and Cyber-Physical Threats in Industrial Robotic Systems. IET Cyber Phys. Syst. Theory Appl., 10. https://doi.org/10.1049/cps2.70023
Bhardwaj, A., Bharany, S., Rehman, A., Tejani, G. G., & Hussen, S. (2025). Securing Cyber-Physical Robotic Systems for Enhanced Data Security and Real-Time Threat Mitigation. EURASIP J. Inf. Secur., 2025. https://doi.org/10.1186/s13635-025-00186-7
Holdbrook, R., Odeyomi, O., Yi, S., & Roy, K. (2024). Network-Based Intrusion Detection for Industrial and Robotics Systems: A Comprehensive Survey. Electron. https://doi.org/10.3390/electronics13224440
Burg, A., Chattopadhyay, A., & Lam, K.-Y. (2018). Wireless Communication and Security Issues for Cyber-Physical Systems and the Internet-of-Things. Proceedings of the IEEE, 106(1), 38–60. https://doi.org/10.1109/JPROC.2017.2780172
Guo, P., Kim, H., Virani, N., Xu, J., Zhu, M., & Liu, P. (2017). Exploiting Physical Dynamics to Detect Actuator and Sensor Attacks in Mobile Robots. arXiv:1708.01834. https://doi.org/10.48550/arXiv.1708.01834
Ge, Y., & Zhu, Q. (2024). GAZETA: GAme-Theoretic Zero-Trust Authentication for Defense Against Lateral Movement in 5G IoT Networks. IEEE Trans. Inf. Forensics Secur., 19, 540–554. https://doi.org/10.1109/TIFS.2023.3326975
Tushkanova, O., Levshun, D., Branitskiy, A., Fedorchenko, E., Novikova, E., & Kotenko, I. (2023). Detection of Cyberattacks and Anomalies in Cyber-Physical Systems: Approaches, Data Sources, Evaluation. Algorithms, 16, 85. https://doi.org/10.3390/a16020085
Moriano, P., Hespeler, S., Li, M., & Mahbub, M. (2024). Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review. Artif. Intell. Rev., 58. https://doi.org/10.1007/s10462-025-11292-w
Ji, R., Padha, D., Singh, Y., & Sharma, S. (2024). Review of Intrusion Detection System in Cyber-Physical System Based Networks: Characteristics, Industrial Protocols, Attacks, Data Sets and Challenges. Trans. Emerg. Telecommun. Technol., 35. https://doi.org/10.1002/ett.5029
Zhukabayeva, T., Ahmad, Z., Adamova, A., Karabayev, N., & Abdildayeva, A. (2025). An Edge-Computing-Based Integrated Framework for Network Traffic Analysis and Intrusion Detection to Enhance Cyber-Physical System Security in Industrial IoT. Sens., 25. https://doi.org/10.3390/s25082395
Manzoor, S., Yin, Y., Gao, Y., Hei, X., & Cheng, W. (2020). A Systematic Study of IEEE 802.11 DCF Network Optimization From Theory to Testbed. IEEE Access, 8, 154114–154132. https://doi.org/10.1109/access.2020.3018088
Venkateswaran, S. K., Tai, C.-L., Garnayak, R., Ben-Yehezkel, Y., Alpert, Y., & Sivakumar, R. (2024). IEEE 802.11ax Target Wake Time: Design and Performance Analysis in ns-3. In 2024 Workshop on ns-3. https://doi.org/10.1145/3659111.3659115
Assasa, H., Grosheva, N., Ropitault, T., Blandino, S., Golmie, N., & Widmer, J. (2021). Implementation and Evaluation of a WLAN IEEE 802.11ay Model in Network Simulator ns-3. In 2021 Workshop on ns-3. https://doi.org/10.1145/3460797.3460799
Hasan, S., Amundson, I., & Hardin, D. (2024). Zero-trust Design and Assurance Patterns for Cyber-Physical Systems. J. Syst. Archit., 155, 103261. https://doi.org/10.1016/
j.sysarc.2024.103261
Botta, A., Rotbei, S., Zinno, S., & Ventre, G. (2023). Cyber Security of Robots: A Comprehensive Survey. Intell. Syst. Appl., 18, 200237. https://doi.org/10.1016/
j.iswa.2023.200237
Campanile, L., Gribaudo, M., Iacono, M., Marulli, F., & Mastroianni, M. (2020). Computer Network Simulation with ns-3: A Systematic Literature Review. Electron. https://doi.org/10.3390/electronics9020272
Jeffrey, N., Tan, Q., & Villar, J. (2023). A Review of Anomaly Detection Strategies to Detect Threats to Cyber-Physical Systems. Electron. https://doi.org/10.3390/
electronics12153283
Puccetti, T., Nardi, S., Cinquilli, C., Zoppi, T., & Ceccarelli, A. (2024). ROSPaCe: Intrusion Detection Dataset for a ROS2-Based Cyber-Physical System and IoT Networks. Sci. Data, 11. https://doi.org/10.1038/s41597-024-03311-2
Manzoor, S., Manzoor, M., Manzoor, H., Adan, D. E., & Kayani, M. A. (2023). Which Simulator to Choose for Next Generation Wireless Network Simulations? NS-3 or OMNeT++. IEEC 2023. https://doi.org/10.3390/engproc2023046036
Pakhomov, M. V. (2026). ns3-wifi6-zero-trust-cprs: ns-3 Simulation Environment and Traces for the 20 STA / 1 AP IEEE 802.11ax Campaign [Source code]. GitHub. https://github.com/m1fril/ns3-wifi6-zero-trust-cprs
Dhiman, P., Saini, N., Gulzar, Y., Turaev, S., Kaur, A., Nisa, K. U., & Hamid, Y. (2024). A Review and Comparative Analysis of Relevant Approaches of Zero Trust Network Model. Sens., 24. https://doi.org/10.3390/s24041328
Dattatreya, V., Adudhodla, M., Anupkant, S., Bande, V., Prasad, C. G. V. N., & Manellore, P. K. R. (2025). Edge-Forged Resilience: A Zero-Trust Security Architecture for Autonomous Cyber-Physical Systems in Industry 5.0. In 2025 6th Int. Conf. on Smart Electronics and Communication (ICOSEC), 1262–1268. https://doi.org/10.1109/
icosec67334.2025.11459650
Kim, S., Park, K.-J., & Lu, C. (2022). A Survey on Network Security for Cyber-Physical Systems: From Threats to Resilient Design. IEEE Commun. Surv. Tutor., 24, 1534–1573. https://doi.org/10.1109/comst.2022.3187531
Kayan, H., Nunes, M., Rana, O., Burnap, P., & Perera, C. (2021). Cybersecurity of Industrial Cyber-Physical Systems: A Review. ACM Comput. Surv., 54, 1–35. https://doi.org/10.1145/3510410
Nweke, L. O. (2021). A Survey of Specification-based Intrusion Detection Techniques for Cyber-Physical Systems. Int. J. Adv. Comput. Sci. Appl., 12. https://doi.org/10.14569/ijacsa.2021.0120506
Tan, S., Guerrero, J., Xie, P., Han, R., & Vasquez, J. (2020). Brief Survey on Attack Detection Methods for Cyber-Physical Systems. IEEE Syst. J., 14, 5329–5339. https://doi.org/10.1109/jsyst.2020.2991258
Xing, W., & Shen, J. (2024). Security Control of Cyber-Physical Systems under Cyber Attacks: A Survey. Sens., 24. https://doi.org/10.3390/s24123815
Ferrag, M., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. J. Inf. Secur. Appl., 50. https://doi.org/10.1016/j.jisa.2019.102419
Da Silva, E. F., Santoso, F., & Zheng, L. (2025). A Deep Learning-Based Intrusion Detection System for Safeguarding ROS 2-Powered Unmanned Ground Vehicles Against DoS Attacks. In 2025 Int. Joint Conf. on Neural Networks (IJCNN), 1–9. https://doi.org/10.1109/ijcnn64981.2025.11229203
Santoso, F., & Finn, A. (2023). A Data-Driven Cyber-Physical System Using Deep-Learning Convolutional Neural Networks: Study on False-Data Injection Attacks in an Unmanned Ground Vehicle Under Fault-Tolerant Conditions. IEEE Trans. Syst. Man Cybern. Syst., 53, 346–356. https://doi.org/10.1109/tsmc.2022.3170071
Fernandez, I., Neupane, S., Chakraborty, T., Mitra, S., Mittal, S., Pillai, N., Chen, J., & Rahimi, S. (2024). A Survey on Privacy Attacks Against Digital Twin Systems in AI-Robotics. In 2024 IEEE 10th Int. Conf. on Collaboration and Internet Computing (CIC), 70–79. https://doi.org/10.1109/cic62241.2024.00019
Alauthman, A., & Shraa, T. (2025). Performance Evaluation and Latency Optimization of Wi-Fi 7 in High-Density Wireless Environments. Int. J. Electr. Electron. Eng. Telecommun.. https://doi.org/10.18178/ijeetc.14.6.354-364
Ahrar, E. M., Wilhelmi, F., Galati-Giordano, L., Imputato, P., Menth, M., & Avallone, S. (2025). R-TWT in Wi-Fi 7 and Beyond: Enabling Bounded Latency, Energy Efficiency, and Reliability. In 2025 IEEE 30th Int. Conf. on Emerging Technologies and Factory Automation (ETFA), 1–8. https://doi.org/10.1109/etfa65518.2025.11205686
Alauthman, A., & Shraa, T. (2025). Deep Reinforcement Learning-Driven Dynamic Spectrum Access in Dense Wi-Fi Environments. IEEE Access, 13, 178663–178680. https://doi.org/10.1109/access.2025.3621489
Yang, S., Guo, J., & Rui, X. (2024). Formal Analysis and Detection for ROS2 Communication Security Vulnerability. Electron. https://doi.org/10.3390/electronics13091762
Soriano, E., Martin, F., & Guardiola, G. (2024). Implementing a Robot Intrusion Prevention System (RIPS) for ROS 2. arXiv:2412.19272. https://arxiv.org/abs/2412.19272
Santoso, F., & Finn, A. (2024). Trusted Operations of a Military Ground Robot in the Face of Man-in-the-Middle Cyberattacks Using Deep Learning Convolutional Neural Networks: Real-Time Experimental Outcomes. IEEE Trans. Dependable Secur. Comput., 21, 2273–2284. https://doi.org/10.1109/tdsc.2023.3302807
Zailan, N. S. B., Ong, L.-Y., & Lim, H. (2026). NAVBOT25: Dataset for ROS-Based Autonomous Robot Navigation. Data Br., 65. https://doi.org/10.1016/j.dib.2026.112617
Yaseen, Y. A., Almomani, I., & Al-Akhras, M. (2025). A Survey of Security Threats and Defense Mechanisms in ROS2-Based Internet of Drones Systems. In 2025 Int. Conf. on Computer and Applications (ICCA), 1–6. https://doi.org/10.1109/icca66035.2025.11430817
Papoutsakis, M., Hatzivasilis, G., Michalodimitrakis, E., Ioannidis, S., Michael, M. K., Savva, A. D., Nikolaou, P., Stokkou, E., & Bozdemir, G. (2025). SESAME: Automated Security Assessment of Robots and Modern Multi-Robot Systems. Electron. https://doi.org/10.3390/electronics14050923
Muriithi, G., Papari, B., Arsalan, A., Timilsina, L., Muriithi, A., Buraimoh, E., Khan, A., Ozkan, G., Edrington, C. S., & Papari, A. (2025). Zero Trust Architecture for Electric Transportation Systems: A Systematic Survey and Deep Learning Framework for Replay Attack Detection. IEEE Open J. Veh. Technol., 6, 2171–2194. https://doi.org/10.1109/ojvt.2025.3592041
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Михайло Пахомов, Володимир Соколов

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.