@techreport{li-ztcpp-network-infra-consideration-00, number = {draft-li-ztcpp-network-infra-consideration-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-li-ztcpp-network-infra-consideration/00/}, author = {Xueting Li and Aijun Wang and iqjie@mail.ustc.edu.cn and Wenhao Li}, title = {{Consideration of Applying Zero Trust Philosophy in Network Infrastructure}}, pagetotal = 8, year = 2026, month = may, day = 13, abstract = {Network security has traditionally relied on a perimeter-centric model, assuming that traffic originating within the network can be implicitly trusted. This model is fundamentally challenged by modern, highly distributed, and software-driven network environments where internal compromise is a realistic and high-impact threat scenario. This document examines the critical limitations of edge- only network protection and the systemic risks that arise from insufficient internal validation. Once the network perimeter is bypassed, the absence of internal protection mechanisms facilitates rapid lateral movement, impersonation of network entities, and interference with critical control and management functions. The document argues that Zero Trust (ZT) principles, which mandate continuous, dynamic verification of all entities and communications regardless of network location, are necessary to address contemporary threat models. Deploying ZT-aligned network protection mechanisms beyond the network edge is essential to build resilient, controllable, and trustworthy networks.}, }