Recently, with the rapid proliferation of smart homes due to the advancement of Internet of Things (IoT) technology, user convenience has significantly increased, but it has simultaneously exposed users to new security threats. Conventional smart home...
Recently, with the rapid proliferation of smart homes due to the advancement of Internet of Things (IoT) technology, user convenience has significantly increased, but it has simultaneously exposed users to new security threats. Conventional smart home security largely relies on the 'boundary-based security model,' which focuses on blocking external intrusions. However, this model exhibits structural vulnerabilities to threats that have already infiltrated the internal network, such as 'Lateral Movement' by attackers or infected internal devices, as demonstrated by the large-scale 'wall-pad' hacking incident in 2021. This vulnerability has been consistently pointed out in numerous preceding studies. The purpose of this study is to propose a concrete security model that applies the core principles of the global Zero Trust standard 'NIST SP 800-207' and the domestic 'Zero Trust Guideline' to the smart home environment to overcome these limitations. To this end, this research designed architectures by classifying domestic residential environments into 'In-home (single-family)' and 'Apartment Complex' types, relocating the core components of Zero Trust Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) to fit each environment. Furthermore, three key operational procedures 'New Device Registration,' 'Dynamic Access Control,' and 'Threat Detection and Automated Isolation' were specified through flowcharts to clarify how the proposed model operates in real-world scenarios. To validate the feasibility of the proposed model, a survey was conducted with 21 information security experts. The analysis showed highly positive evaluations for 'Effectiveness of Dynamic Access Control Procedure' (Avg. 4.10) and 'Effectiveness of Multi-layered PEP Structure' (Avg. 4.00). However, concerns regarding cost and implementation realism were raised for the 'Practical Applicability of the In-home Model' (Avg. 3.62). Open-ended responses also confirmed the need for AI-based enhancements and improvements in user convenience. This study holds academic and practical significance in that it presents a concrete architecture and operational procedures by applying the abstract Zero Trust concept based on NIST standards and prior research to the specific 'smart home' environment, and validated its feasibility through an expert survey. For the future commercialization of this model, follow-up research is needed on AI-based trust evaluation algorithms and cost-effective implementation methods, as commonly suggested by prior studies and the expert survey. Keywords: Zero Trust, Smart Home Security, Zero Trust Architecture (ZTA), NIST SP 800-207, In-home Model, Apartment Complex Model