Zero Trust Security in Multi-Tenant Cloud Environments
Main Article Content
Abstract
As more organizations move to use the multi-tenant cloud infrastructure, the perimeter-based security model is insufficient for the concept of zero-trust security states. Thatently, curing this complex environment, It has “never trust, always verify”. Completely contradicting the conventional models, Zero Trust continually promotes authentication and validation of every access request (inside or outside the network perimeter). As they try to understand how to protect the isolation of tenants, stop alteration movements, and support identity cross services, the paper investigates the challenges and parts of zero trust taking effect in the multi-tenant cloud. Everything must always be authenticated, no matter the connection status, to ensure the user (only the user) has permission to do all the things they need. Further, it shows that Artificial Intelligence (AI) and Machine Learning (ML) technologies can highly enhance the detection of threats and adaptive access control. It shall see an exhibited case study of a SaaS provider going from providing limited risk mitigation against these risks, such as credential stuffing, API abuse, and insider data leakage, to Zero Trust security. This paper discusses decentralized identity (DID), post-quantum cryptography, blockchain as immutable audit trails, and AI-led autonomous zero trust systems as some of the future emerging trends. As the world reaches the multi-tenant cloud architecture, they are ready to enhance cloud security further.