Skip to content

Trust Zone Architecture

Why this chapter matters

Trust zones make the invisible borders of infrastructure visible. They show what may communicate, what must be isolated, and why no network segment or administrative account becomes trusted merely by being inside the system.

Continue to Model Routing and Execution to see how intelligence moves through those borders.

Defines implementation-neutral trust boundaries, permitted flows, identity checks, evidence, and failure handling.

  • INFRA2-R001: Each trust zone SHALL define purpose, assets, identities, permitted flows, prohibited flows, policy checks, logging, owner, and recovery boundary.
  • INFRA2-R002: Crossing a zone boundary SHALL require authenticated identity, least-privilege policy, purpose, and retained evidence.
  • INFRA2-R003: A zone SHALL fail closed or into an explicitly bounded degraded state when its policy or identity service is unavailable.
  • INFRA2-R004: Zone membership SHALL not create authority, consent, or permission beyond the governing record.
  • INFRA2-R005: Zone definitions SHALL identify trust assumptions, boundary owners, data classes, failure states, and evidence required to challenge membership.
  • INFRA2-R006: A cross-zone flow SHALL be attributable to an approved purpose and SHALL expire, narrow, or pause when identity, policy, evidence, or ownership becomes uncertain.
  • INFRA2-R007: Zone review SHALL test direct, transitive, delegated, emergency, and recovery flows rather than validating only the normal path.
  • INFRA2-R008: A zone design SHALL NOT create live access, surveillance, credential issuance, or authority; it remains an implementation-neutral architecture proposal.

This Draft does not select providers, networks, credentials, or live zones.

Design method

Zone design shall begin with assets and consequences, then define identities, flows, policy points, evidence, and recovery. A proposed flow with unknown ownership, purpose, or destination remains unapproved. Zone diagrams shall show trust assumptions and the evidence required to challenge them.

Failure cases

Shared credentials, implicit transitive trust, missing boundary logs, policy-service outage, and emergency bypass are material failures. A temporary bypass requires an explicit governing authorisation or delegation, named owner, scope, expiry, compensating control, and retrospective review. No bypass may weaken constitutional, identity, secret, privacy, safety, or evidence controls.

Design evidence

Each zone proposal should include an asset inventory, trust assumptions, flow matrix, policy decision points, identity evidence, logging coverage, degraded state, recovery owner, and test of prohibited paths. Unknown ownership or transitive trust remains a blocking gap.

Operating model and evidence

Zone analysis begins with protected assets and consequence classes. It maps identities, data flows, policy points, owners, evidence, degraded states, recovery dependencies, and the conditions for admission or denial. Trust is scoped to a purpose and an evidence state; it is not inherited merely because two zones share an operator, network, or provider.

Reviewers should test direct and transitive paths, shared dependencies, delegated access, emergency exceptions, and restoration. Each exception has a named authority, scope, expiry, compensating control, and retrospective review. A zone remains provisional while ownership, policy, identity, or recovery evidence is incomplete.

Interpretation cases

  • Conforming: A zone records assets, identities, flows, policy, owner, evidence, degraded state, and recovery.
  • Prohibited: Network reachability or membership is treated as authority.
  • Boundary: A degraded zone denies uncertain flows while preserving bounded safe functions.
  • Failure: Policy or identity service loss causes pause, containment, and evidence preservation.
  • Loophole: Transitive trust or emergency bypass silently expands scope.
  • Misuse: Zone data is used for unrelated surveillance or private identity disclosure.
  • Care-control: Protective segmentation limits exposure while preserving agency and review.