A Zero Trust Architecture for Protecting Cyber-Physical Systems in the Aviation Sector

Contemporary aviation depends on tightly coupled information-technology, operational-technology and cyber-physical assets spanning aircraft, airports, air-traffic services, maintenance, ground operations and cloud platforms. Conventional perimeter security provides insufficient protection once credentials, suppliers, mobile devices or trusted network segments are compromised. This study proposes a Safety-Aware Adaptive Zero Trust Architecture (SA-AZTA) that continuously evaluates human, device, service and workload requests using identity confidence, device integrity, behavioural conformity, mission context, threat intelligence, privilege risk, asset criticality and prospective safety impact. A safety gate constrains automated response so that suspicious activity can be restricted, isolated or escalated without indiscriminately interrupting safety-critical services. The architecture was evaluated in a reproducible synthetic major-airport case study. A detailed main run comprised 50,000 access events, while 30 Monte Carlo runs of 20,000 events each compared perimeter security, role-based access control, static attribute-based access control, non-adaptive Zero Trust and SA-AZTA. Across the Monte Carlo runs, SA-AZTA achieved mean accuracy of 96.99%, precision of 92.78%, recall of 92.10%, F1-score of 92.43%, ROC-AUC of 99.25% and a false-positive rate of 1.79%. Mean attack containment was 93.09%, service availability was 99.40% and policy-decision latency was 7.58 ms. The improvement over every baseline was statistically significant in paired Wilcoxon tests (p < 1.9 × 10^-9), although the proposed model introduced approximately 2.17 ms additional latency relative to non-adaptive Zero Trust. Ablation analysis showed that behavioural analytics contributed most to detection performance, whereas microsegmentation contributed most to limiting lateral movement. The results provide evidence that context-rich, safety-constrained Zero Trust can improve cyber resilience in aviation CPS; however, findings remain simulation-based and require digital-twin, hardware-in-the-loop and regulated operational validation.

Keywords: zero trust architecture; aviation cybersecurity; cyber-physical systems; adaptive access control; safety-security co-engineering; microsegmentation; trust modelling; synthetic simulation.