International Journal of Innovative Research in Computer and Communication Engineering
ISSN Approved Journal | Impact factor: 8.771 | ESTD: 2013 | Follows UGC CARE Journal Norms and Guidelines
| Monthly, Peer-Reviewed, Refereed, Scholarly, Multidisciplinary and Open Access Journal | High Impact Factor 8.771 (Calculated by Google Scholar and Semantic Scholar | AI-Powered Research Tool | Indexing in all Major Database & Metadata, Citation Generator | Digital Object Identifier (DOI) |
| TITLE | A Zero-Trust Secure Remote Access Framework Using Mutual TLS and Device Posture Verification |
|---|---|
| ABSTRACT | Traditional remote access solutions such as VPNs authenticate users only at login and then grant broad internal network access, exposing organizations to credential theft and lateral movement attacks. This paper proposes a Zero-Trust Secure Remote Access Framework that continuously verifies device identity and security posture before granting access. Mutual TLS (mTLS) restricts connectivity to organization-registered devices through certificate-based authentication, while a Device Posture Agent continuously evaluates antivirus, firewall, operating-system update, and disk-encryption status. The collected posture data is evaluated by a FastAPI-based Policy Engine, which grants application-level access only to compliant devices and redirects non-compliant devices for remediation. Unlike VPNs, which expose the entire internal network, the proposed framework restricts access to individual applications. Experimental results confirm that the framework correctly authenticates registered devices, detects posture violations in real time, and enforces dynamic ALLOW/REMEDIATE/DENY decisions, demonstrating a practical and scalable approach to Zero-Trust remote access. |
| AUTHOR | SYED SUFYAANUDDIN, DR. R. SRIDEVI Post-Graduate Student, Department of Computer Science Engineering, Jawaharlal Nehru Technological University, Hyderabad, Telangana, India Professor, Department of Computer Science Engineering, Jawaharlal Nehru Technological University, Hyderabad, Telangana, India |
| VOLUME | 186 |
| DOI | DOI: 10.15680/IJIRCCE.2026.1407054 |
| pdf/54_A Zero-Trust Secure Remote Access Framework Using Mutual TLS and Device Posture Verification.pdf | |
| KEYWORDS | |
| References | [1] M. Asim, N. Tariq, A. I. Awad, F. Waheed, U. Ullah, and G. Murtaza, “SecT: A Zero-Trust Framework for Secure Remote Access in Next-Generation Industrial Networks,” IEEE Journal on Selected Areas in Communications, vol. 43, no. 6, pp. 2293–2311, 2025. [2] C. Wilcox, “Towards a Zero Trust Based Hybrid Access Control Model,” IEEE, 2024. [3] L. Bradatsch et al., “Zero Trust Score-Based Network-Level Access Control in Enterprise Networks,” IEEE, 2023. [4] Y. W. Ma and P. H. Chiu, “A Novel Risk-Based Access Control Engine in Zero Trust Architecture for IoT Networks,” International Journal of Information Security, 2025. [5] N. Mavroeidis and S. Bromander, “Cyber Threat Intelligence Model for Network Security,” IEEE Access, vol. 5, pp. 12653–12671, 2017. |