Zero Trust gets harder when every user, device, weapon, and AI agent needs an identity当每个用户、设备、武器和人工智能代理都需要身份认证时,零信任就变得更加困难。
The Army is expanding Zero Trust across 5,000 systems, tactical networks, weapon systems and AI agents as it works toward its 2027 cybersecurity milestones.

The Army continues to march forward with industry to meet its Unified Network effort goals, aligning the enterprise and tactical network programs to reduce network complexity and provide greater tactical mobility to support the Army’s division-centric warfighting at echelon. TEM 13 panelists discussed the efforts’ progress and pending milestones with industry attendees, providing updates on how the UN will underpin all modern network capabilities, including critical cyber security efforts such as Zero Trust. (U.S. Army Reserve photo by Spc. William Kuang)
For the Army, the hard part of Zero Trust is increasingly less about defining the concept than applying it across thousands of systems that were never designed for interoperability. The service is working to bring roughly 5,000 information technology systems onto a single Enterprise-Identity, Credential and Access Management (E-ICAM) platform, including legacy systems burdened by years of technical debt. At the same time, Zero Trust requirements are expanding beyond enterprise IT to the tactical edge, operational technology, weapon systems, and now AI agents.
That makes Zero Trust less an endpoint than a continuously changing security model.
“We can’t just buy Zero Trust from a vendor; it isn’t just compliance,” said David Thompson, product lead for E-ICAM at Army CPE Command and Control Information Network (C2IN), participating in a Breaking Defense webinar on Zero Trust . “Our adversaries are not static and the Army must continually work within the ZT framework to adapt to an ever-evolving cybersecurity threat-policy process or technology.”
At the center of that effort is identity. Zero Trust, Thompson said, means that anything attempting to access a resource must first be identified, tied to a credential, and authorized. That requirement goes beyond people to encompass machines and other non-human entities.
“Everything, everything that connects to another thing to access a resource has to be positively identified, strongly bound to credential and securely granted access,” he said. “Everything means literally everything from human users to non-human interfaces and every physical or virtual component in between.”
The phrase often heard today to represent that desired end state is often called “fine grain authentication” and it’s at the heart of Zero Trust, where users, devices, data, and AI agents undergo regular steps of authentication to remain logged in.
Pulling In 5,000 Systems
The immediate challenge is applying that principle across Army systems that vary widely in age and technical capability, with many in existence for decades without keeping pace with modernization. Rather than impose one technical solution across all of them, Thompson said the Army is developing different onboarding pathways and trying to impose the fine-grain access controls that each system can currently support.
He compared the problem to securing a government building. Security can be imposed at the gate, the front entrance, the elevator, interior doors, or even individual desk drawers. But an older building may not contain all of those barriers.
“If the building doesn’t have interior doors or desks, we have to secure what we can today with the expectation that we will support the customer’s future security improvements tomorrow,” Thompson said.
Legacy systems are likely to remain one of the biggest obstacles to full compliance with Zero Trust.
“There is absolutely going to be a significant amount of technical debt that they’re going to have to solve for that,” said Curtis Dukes, executive vice president and general manager of Security Best Practices at the Center for Internet Security, who also participated on the webinar panel. “It may be that you have to look at some of these older systems and they may have to be updated as part of that movement to this new concept around Zero Trust.”
That flexibility is important as the Army drives toward its end-of-2027 deadline for meeting all Zero Trust target milestones. Thompson called getting thousands of systems into a Zero Trust posture by then “a huge goal.”
Among the approaches being pursued is onboarding systems by operational domain rather than necessarily handling every system individually. The Army is also trying to give system owners the ability to perform more of the work themselves.
“We’re trying to pioneer a way to onboard operational domains that may have hundreds or maybe a thousand IT systems within them,” Thompson said. “The Army is also developing a ‘do-it-yourself kit’ so system owners can take actions on their own without having to work with Army CPE C2IN one-on-one. We’re trying to democratize this as much as we possibly can,” he said.
Doing that requires system owners to understand not only what systems and assets they have, but how those systems operate. Thompson said Army teams working directly with system owners have sometimes discovered that the owners themselves lack complete visibility into their environments.
“It’s not one-size-fits-all; every IT system is unique,” he said. “It’s hard, but it’s not because it’s complicated. It’s because it’s very detail-oriented.”
The Department of the Air Force Zero Trust Functional Management Office hosted its inaugural Milestone Champion Jamboree, Feb. 6-8 in Arlington, Virginia. This event brought together more than 40 Milestone Champions to continue the work of transforming DAF cybersecurity to face the security landscape presented in this era of Great Power Competition. (courtesy photo)
From Identity To Data
The expansion of Zero Trust across enterprises raises a second issue: authenticating and authorizing a user or device does not by itself protect the information that user or device can reach. That means the security controls should extend to the data itself.
Mario Puras, senior vice president of Global Solutions Engineering and Architecture at Netskope, said Zero Trust therefore has to extend security controls to the data itself.
“Zero Trust must go beyond identity and access control,” said Puras, speaking in a separate Breaking Defense interview. “It must encompass continuous verification, rapid threat containment, and full-spectrum data protection. The mission fails if user access is secured but the data is compromised.”
Puras described an approach in which identity, device posture, behavior, content, and other context are evaluated to make dynamic access decisions. That’s done through policy controls at the data level while drawing context from users, devices, network connections, applications, and the data itself, he said. Those policies can then change as the underlying risk changes.
That becomes particularly important as cloud services, APIs, collaboration platforms, and encrypted traffic become part of military environments. Puras pointed specifically to attempts to move sensitive information through API calls, cloud uploads, or chat messages as examples of data movement that Zero Trust architectures may need to inspect and control.
AI And The Tactical Edge Expand The Identity Problem
The definition of identity is also becoming more complicated as AI agents begin operating across networks.
For Thompson, the underlying Zero Trust rule does not change simply because the identity is no longer human. AI agents still need identities, limited entitlements, and least-privilege access.
“It’s not a different way of doing it or different paradigms – same paradigm, but we’ve got to get faster,” Thompson said. He warned that automation could increase the speed at which malicious activity occurs from “a few attacks per minute” to potentially “hundreds of attacks per second, even thousands per second.”
Dukes said agentic AI further muddles the problem because agents may delegate tasks to other agents, requiring organizations to establish and manage trust across chains of non-human identities. He also raised the prospect of unauthorized “shadow agents” and the need to contain agents that behave unexpectedly or are hijacked.
Moving to Zero Trust at the tactical level, the Army faces a different constraint as it’s pushed from enterprise networks toward deployed formations.
At brigade and higher, Thompson said, units can reasonably expect connectivity to Army cloud resources. Below brigade, forces are more likely to operate with denied, degraded, intermittent, or limited connectivity. Those formations therefore need enough E-ICAM capability locally to continue their mission when disconnected and to update information when connectivity returns.
The same Zero Trust principles being discussed for users and devices are expected to also soon apply to operational technology such as industrial control systems and Internet of Things devices, and the individual components that make up complete weapon systems.
Thompson offered the example of a helicopter, where identity attributes could determine whether an individual is authorized to start the aircraft.
“If Dave Thompson is going to go jump in a helicopter, does Dave Thompson have the authority to turn the helicopter on?” he asked. “Again, tying it back to the identity and the attributes of that identity and what that identity is allowed to do and not do.”
That illustrates how far the Zero Trust challenge has moved beyond logging onto a network. For the Army, it increasingly means determining which human, machine, application, or AI identity can touch a particular resource, what that identity can do once it gets there, and how those permissions have to change as the technology, mission, and threat change.
As Thompson put it when discussing operational technology, “it’s not an end state, it’s a continual action.”
陆军继续与业界携手推进其统一网络计划的目标,协调企业级和战术级网络项目,以降低网络复杂性,并提供更大的战术机动性,从而支持陆军以师为中心、层级分明的作战行动。TEM 13 的专家组成员与业界代表讨论了该计划的进展和即将达成的里程碑,并介绍了统一网络将如何支撑所有现代网络能力,包括零信任等关键网络安全措施。(美国陆军预备役下士 William Kuang 摄)
对陆军而言,零信任的难点越来越不在于定义概念本身,而在于将其应用于数千个原本并非为互操作性而设计的系统中。陆军正致力于将大约5000个信息技术系统整合到一个统一的企业身份、凭证和访问管理(E-ICAM)平台上,其中包括那些背负多年技术债务的遗留系统。与此同时,零信任的要求正从企业IT扩展到战术前沿、作战技术、武器系统,以及如今的人工智能代理。
这使得零信任与其说是一个终点,不如说是一个不断变化的安全模型。
“我们不能仅仅从供应商那里购买零信任;它不仅仅是合规性问题,”陆军CPE指挥与控制信息网络(C2IN)E-ICAM产品负责人David Thompson在参加Breaking Defense举办的零信任网络研讨会时表示。“我们的对手并非一成不变,陆军必须在零信任框架内不断努力,以适应不断演变的网络安全威胁策略流程或技术。”
这项工作的核心是身份识别。汤普森表示,零信任意味着任何试图访问资源的实体都必须首先被识别、绑定凭证并获得授权。这一要求不仅限于人,还涵盖机器和其他非人类实体。
他说:“所有与另一事物连接以访问资源的组件,都必须经过明确识别,与凭证紧密绑定,并安全地授予访问权限。这里的‘所有组件’指的是从人类用户到非人类界面,以及两者之间的所有物理或虚拟组件。”
如今,人们经常听到用“细粒度身份验证”来表示这种理想的最终状态,它是零信任的核心,用户、设备、数据和人工智能代理都需要定期进行身份验证才能保持登录状态。
引入 5,000 个系统
眼下的挑战在于如何将这一原则应用于陆军各个系统,这些系统在年代和技术能力上差异巨大,其中许多系统已经服役数十年,却未能跟上现代化步伐。汤普森表示,陆军并没有强行推行单一的技术方案,而是正在开发不同的系统上线路径,并尝试实施每个系统目前能够支持的细粒度访问控制。
他将这个问题比作政府大楼的安全保障。可以在大门、正门、电梯、室内门,甚至每个办公桌抽屉上都设置安保措施。但老旧建筑可能并不具备所有这些屏障。
汤普森说:“如果建筑物没有室内门或办公桌,我们必须确保今天能够保障的安全,并期望明天能够支持客户未来的安全改进。”
传统系统很可能仍然是全面遵守零信任原则的最大障碍之一。
“他们肯定需要解决大量的技术债务问题,”互联网安全中心安全最佳实践执行副总裁兼总经理柯蒂斯·杜克斯(Curtis Dukes)说道,他也参与了此次网络研讨会的讨论。“他们可能需要审视一些老旧的系统,并对其进行更新,以适应零信任这一新概念。”
这种灵活性至关重要,因为陆军正朝着2027年底实现所有零信任目标里程碑的目标迈进。汤普森称,届时让数千个系统进入零信任状态是“一项艰巨的目标”。
正在采取的方法之一是按作战领域对系统进行上线,而不是单独处理每个系统。陆军也在努力赋予系统所有者更多自主工作的能力。
汤普森说:“我们正在尝试开创一种方法,将可能包含数百甚至上千个IT系统的作战域接入系统。陆军还在开发一套‘自助工具包’,以便系统所有者可以自行操作,而无需与陆军CPE C2IN部门进行一对一的沟通。我们正努力尽可能地普及这项技术。”
这样做要求系统所有者不仅要了解他们拥有哪些系统和资产,还要了解这些系统是如何运行的。汤普森表示,陆军团队直接与系统所有者合作时,有时会发现所有者自身对其环境缺乏全面的了解。
“没有一成不变的模式;每个IT系统都是独一无二的,”他说。“这很难,但不是因为系统复杂,而是因为它非常注重细节。”
美国空军零信任功能管理办公室于2月6日至8日在弗吉尼亚州阿灵顿举办了首届里程碑冠军大会。此次大会汇聚了40多位里程碑冠军,共同推进美国空军网络安全转型,以应对当今大国竞争时代带来的安全挑战。(图片由美国空军零信任功能管理办公室提供)
从身份到数据
零信任在企业中的扩展引出了第二个问题:对用户或设备进行身份验证和授权本身并不能保护该用户或设备可以访问的信息。这意味着安全控制措施应该扩展到数据本身。
Netskope 全球解决方案工程与架构高级副总裁 Mario Puras 表示,因此零信任必须将安全控制扩展到数据本身。
“零信任必须超越身份和访问控制,”普拉斯在接受《防务新闻》的另一次采访时表示,“它必须涵盖持续验证、快速威胁遏制和全方位数据保护。如果用户访问安全得到保障,但数据却遭到泄露,那么零信任的目标就失败了。”
普拉斯描述了一种方法,该方法通过评估身份、设备状态、行为、内容和其他上下文信息来做出动态访问决策。他表示,这是通过数据层面的策略控制来实现的,同时从用户、设备、网络连接、应用程序以及数据本身获取上下文信息。这些策略会随着潜在风险的变化而变化。
随着云服务、API、协作平台和加密流量逐渐成为军事环境的一部分,这一点变得尤为重要。普拉斯特别指出,试图通过API调用、云上传或聊天消息传输敏感信息,就是零信任架构需要检查和控制的数据移动示例。
人工智能与战术优势扩大了身份认同问题
随着人工智能代理开始在网络中运行,身份的定义也变得越来越复杂。
汤普森认为,即使身份不再是人类,零信任的基本原则也不会改变。人工智能代理仍然需要身份、有限的权限和最小权限原则。
汤普森说:“这不是不同的方法或不同的范式——范式不变,但我们必须加快速度。”他警告说,自动化可能会将恶意活动的发生速度从“每分钟几次攻击”提高到“每秒数百次,甚至每秒数千次攻击”。
杜克斯表示,智能体人工智能进一步加剧了问题的复杂性,因为智能体可能会将任务委托给其他智能体,这就要求组织在非人类身份链中建立和管理信任。他还提出了未经授权的“影子智能体”的可能性,以及遏制行为异常或被劫持的智能体的必要性。
在战术层面推行零信任时,陆军面临着不同的限制,因为它正从企业网络向部署部队推进。
汤普森表示,旅级及以上单位可以合理预期能够连接到陆军云资源。而旅级以下单位则更有可能面临网络连接中断、性能下降、间歇性中断或受限的情况。因此,这些单位需要具备足够的本地电子信息获取与通信(E-ICAM)能力,以便在断网时继续执行任务,并在网络连接恢复后及时更新信息。
目前针对用户和设备讨论的零信任原则预计也将很快适用于工业控制系统、物联网设备以及构成完整武器系统的各个组件等操作技术。
汤普森举了一个直升机的例子,身份属性可以决定一个人是否有权启动飞机。
“如果戴夫·汤普森要跳上一架直升机,他有权启动直升机吗?”他问道。“这又回到了身份、身份的属性以及该身份被允许做什么和不被允许做什么的问题上。”
这表明,零信任挑战早已超越了网络登录的范畴。对陆军而言,它越来越意味着要确定哪些人、机器、应用程序或人工智能身份可以访问特定资源,这些身份在访问资源后可以执行哪些操作,以及随着技术、任务和威胁的变化,这些权限又该如何调整。
正如汤普森在讨论运营技术时所说,“这不是一个最终状态,而是一个持续的过程。”