A
system for zero-trust cybersecurity
access control using continuous identity
verification (100), comprising: a
Policy Decision and
Enforcement Orchestrator (1) configured to receive an access request from a
user device and enforce a session with minimal privileges; an engine for continuous identity
verification (2) configured to generate a time-dependent identity
trust score by continuously verifying the user identity during an active session; a device state and
telemetry collector (3) configured to acquire device state parameters, runtime signals and network
telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic
authentication and secure token module (5) configured to issue and update a short-lived, bound
access token associated with at least the identity trust value and the state value; and an
adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions,
network segmentation and session privileges in real time, based on an aggregated
risk assessment derived from modules (2) to (4), where the
system (100) continuously reassesses
trustworthiness during the session and selectively allows, restricts, requires enhanced
authentication or terminates the session based on the aggregated
risk assessment.