Oct 2026· JPAIR Multidisciplinary Research· 0 citations
TL;DR
This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control with Row-Level Security and Just-in-Time privilege elevation, and metadata-driven Attribute-Based Access Control through data classification without requiring external security middleware.
Abstract
Enterprise database systems are frequently targeted due to their reliance on perimeter-based, static access control models that lack continuous verification and privilege minimization. This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control (RBAC) with Row-Level Security (RLS) and Just-in-Time (JIT) privilege elevation, and metadata-driven Attribute-Based Access Control (ABAC) through data classification — all without requiring external security middleware. Employing design science and applied experimental methodology, architecture was deployed in a live production environment comprising 589 databases and 132 identities over a 90-day post-implementation period. Chi-square tests of independence with Cramér's V effect size confirmed statistically significant reductions: login misuse declined by 82.1%, malicious authentication attempts by 66.7%, deployment errors by 59.8%, and reporting disruptions by 43.7%. Overprivileged accounts decreased by 84.2%. These results demonstrate that a coordinated, database native Zero Trust pipeline substantially reduces attack surfaces and insider risk in enterprise SQL Server environments. The proposed architecture aligns with globally recognized compliance frameworks, including ISO/IEC 27001 and GDPR, offering a replicable and regulatory-ready deployment model for enterprise environments across diverse jurisdictions.
A four-plane theoretical model can be introduced to separate authentication, authorization reasoning, enforcement, and auditability into four closely coupled but independent evolving planes for the system, providing a unified point of reference for both researchers and practitioners in the field of secure and scalable...
Ravi Kumar Kotapati· International Research Journ...· 0 citations
This paper synthesizes reported evidence on ZTA across three research questions: effectiveness relative to perimeter models, the implementation challenges enterprises face, and the security contribution of individual components.
Md Shahnawaj, Hamim Islam Hellol, Debabrata Biswas et al.· Journal of Computers, Mechan...· 0 citations
This architecture provides a systematic foundation for the three core Zero Trust behaviors while eliminating, for participating mechanisms that use the coordinated namespace, the class of cross-namespace correspondence dependencies the authors call identifier glue.
A secure, containerized self-hosted cloud architecture integrating Nextcloud, PostgreSQL, and Docker, secured via a Zero Trust Network Access (ZTNA) tunnel to achieve a "Closed-Default" security posture is proposed.
Zen Aufa Bahalwan, Arry Avorizano· Jurnal Teknik Informatika (J...· 0 citations
This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.
Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al.· International Journal of Inf...· 0 citations
LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...