According to the Government Zero Trust Architecture Guidelines published by the National Institute of Cyber Security (NICS) in 2023, traditional network security concepts rely on perimeter-based defense, assuming that all access within the perimeter is trusted. However, given the increasingly complex use cases and network environments, many attacks now originate from within the supposedly trusted perimeter, which implicitly makes establishing an effective perimeter a difficult task.
According to the NIST SP 800–207 standard document formally published by the National Institute of Standards and Technology (NIST) in 2020, untrusted users and devices must undergo an access verification process whenever they attempt to access resources.

Core Logical Components Architecture Diagram of ZTA (Image Source: NICS Zero Trust Architecture Guidelines_V2.0_1120616)

Government Zero Trust Architecture Guidelines (Image Source: NICS Zero Trust Architecture Guidelines_V2.0_1120616)
Traditional Architecture vs. Zero Trust Architecture

Types of UPAS ZTA Zero Trust Solutions
UPAS supports Zero Trust Network Access (ZTNA) and Zero Trust Application Access: it conducts device authentication based on the device's Trusted Platform Module (TPM), performs trust inference according to device health scores, and offers an all-in-one integration of the three stages of Zero Trust, comprehensively implementing a Zero Trust cybersecurity architecture.

UPAS All-in-One Integrated 3-Stage Zero Trust Solution
1. Identity Authentication (UPAS collaborates with multiple vendors)
Multi-Factor Authentication (MFA), such as the FIDO MFA mechanism, utilizes physical security keys (USB Tokens) or mobile apps to enable passwordless login (via fingerprints, SMS, etc.).
2. Device Authentication (Supported by UPAS)
Executes software certificates or Trusted Platform Module (TPM) public-key cryptography authentication protocols. Combined with authorized network access trust validation, it ensures that user endpoint devices are organization-managed before granting access to the internal network and running systems. It also continuously manages device authentication, including health status monitoring and management, dynamically updating the device's health trust level based on its real-time condition.
3. Trust Inference (Supported by UPAS)
Based on identity authentication results, device authentication results, device health trust levels, and user contexts, it continuously validates device health scores to dynamically adjust network access permissions. Only devices that satisfy the trust inference criteria are permitted to access the system, with device health trust scores dynamically adjusted over specified intervals.
Built upon the foundation of Zero Trust Architecture, UPAS provides 5 major cybersecurity solutions and 20 expandable functional modules. The features of the DAM (Device Authentication Module) and TIM (Trust Inference Module) are detailed below.
By deploying an Agent on endpoint devices, UPAS can inspect the software and hardware protection levels of each device. This not only verifies that connecting devices are trusted at the moment they go online, but also applies to resource access scenarios. Through seamless integration with identity authentication vendors, it delivers comprehensive security protection measures. Furthermore, the UPAS NAC solution boasts the advantage of a 100% asset inventory, ensuring that device Agents for device authentication are properly deployed, thereby maximizing deployment rates.

UPAS: DAM (Device Authentication Module)
The TIM (Trust Inference Module) audits device information—including OS versions, antivirus status, installed software, and potential risk vulnerabilities—to serve as the foundation for device security assessments. It collects device security data to establish trust score evaluation standards for resource access, allowing the Policy Decision Point (PDP) to determine access outcomes. Furthermore, UPAS ZTA features a Risk Device Dashboard that visually displays device health status through interactive charts, providing 24/7 real-time monitoring.

UPAS: TIM (Trust Inference Module)
UPAS ZTA supports systems from multiple identity authentication vendors. It assists in performing comprehensive asset inventory and health checks when devices connect to the internal network, effectively blocking unauthorized devices, and completing a robust Zero Trust security mesh. Below are the key advantages of UPAS ZTA:
• Patented NAC Network Blocking Technology
• 100% Asset Inventory: Provides a complete display of the device list.
• Agent Detection: Identifies devices without the Agent installed.
• Device Health Collection: Gathers comprehensive device health information.
• Multi-Vendor Support: Integrates with systems from various identity authentication providers.
• Device Authentication: Supports advanced device authentication features.
• Trust Inference: Supports continuous device trust inference functionality.
• Comprehensive ZTA: Provides Zero Trust for both network access and application system access.
Welcome to contact us via "Project Consultation" or "Enterprise Trial Application."