Abstract:
The accelerated digital transformation of university laboratories has led to the development of hybrid infrastructures integrating on-premise resources, virtual machines, IoT devices, and cloud-based educational services. Traditional Virtual Private Network (VPN) solutions provide encrypted remote access but rely on an implicit trust model that may expose extended network segments after authentication. In contrast, Zero Trust Network Access (ZTNA) enforces continuous verification and fine-grained access control based on identity and contextual attributes. This paper analyzes the performance impact of deploying a ZTNA architecture in a hybrid academic environment. A reference architectural model is proposed, integrating Identity and Access Management (IAM), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and micro-segmentation mechanisms. The authentication process is analytically modeled using queueing theory (M/M/1 and M/M/c), and the total latency is formulated as the sum of authentication, policy evaluation, secure channel establishment, and resource access components. The analytical model is validated through stochastic discrete-event simulations for 50–1000 concurrent users and compared with a traditional VPN architecture. Results indicate a moderate and predictable latency increase under ZTNA, minimal impact on throughput, and superior scalability under high-load conditions. The proposed framework provides a quantitative basis for evaluating the security–performance trade-off in hybrid academic infrastructures.