Identity-Centric Zero Trust Against Next-Generation Supply Chain Attacks: Rethinking Trust in Human and Non-Human Identities
Abstract
The modern cybersecurity landscape is shifting from perimeter-based defense toward identity-centric and continuously verified security models. As cloud-native architectures, software supply chains, CI/CD ecosystems, and autonomous AI systems become deeply interconnected, adversaries are increasingly exploiting trusted identities, workload credentials, build pipelines, software dependencies, and established trust relationships rather than relying solely on conventional vulnerabilities. This article investigates the emerging convergence of Zero Trust Architecture, identity security, and software supply chain threats, with a particular focus on non-human identities, workload authentication, software provenance, continuous authorization, and runtime supply chain attacks. It examines how a legitimate identity can be weaponized as an entry point into critical infrastructure and why identity validation alone is no longer sufficient to establish trust. The article further proposes an identity- and provenance-centric Zero Trust perspective, in which access decisions are continuously evaluated using identity, contextual signals, workload integrity, software provenance, authorization scope, and runtime behavior. It also explores how the emergence of agentic AI is expanding the software supply chain beyond traditional build-time dependencies toward dynamic tools, APIs, models, data sources, and runtime interactions. Ultimately, the discussion reframes Zero Trust from a conventional access-control strategy into a continuous, evidence-based trust evaluation model, where identity, software integrity, provenance, and behavioral context collectively determine whether an entity should be trusted. This perspective provides a foundation for understanding and mitigating next-generation supply chain attacks across cloud-native, distributed, and AI-driven environments.
// Source
Authors: Shuaib Bin Salih