A Zero-Trust Framework for Automated Identity Governance in Cloud-Native Applications

Authors

  • Dr. Rajan Krishna Department of Computer Applications, Kongunadu Engineering College, Tamil Nadu, India. Author

DOI:

https://doi.org/10.63282/3117-5481/AIJCST-V1I6P104

Keywords:

Blockchain, Secure Multi-Party Machine Learning, Cloud-Edge Collaboration, Zero-Trust Security, Identity Governance, Access Control, Privacy-Preserving Machine Learning, Cloud-Native Applications, Automated Policy Enforcement, Risk-Aware Authorization

Abstract

The traditional forms of identity and access management are not effective at controlling constantly evolving identities of users, services or workloads, which is where cloud-native applications thrive with highly distributed architectures, microservices, APIs, containers, and dynamic cloud resources. This paper presents a Zero-Trust Framework for Automated Identity Governance in Cloud-Native Applications, which comprises real-time identity verification, automated policy enforcement, identity lifecycle management, context-aware authorization, and continuous risk assessment, all aimed at reducing granting of unnecessary privileges and unauthorized access. Security attributes, access context, resource sensitivity, behavioral patterns, and risk levels are continually assessed to determine appropriate access privileges and automatically revoke or adjust privileges when security circumstances change. A policy-driven identity governance mechanism is designed to automatically manage identity provisioning, privilege management, access review and deprovisioning in distributed cloud-native environments. Security and performance measures, such as access-control accuracy, unauthorized-access detection rate, policy enforcement latency, privilege reduction and system overhead, are used to assess the framework. The experimental results show the effectiveness of the proposed approach in terms of identity governance and expose fewer privileges than the existing approach, with minimal impact on performance in dynamic cloud-native environments. The key takeaway from this work is an integrated zero-trust identity governance architecture that allows for ongoing, automated and risk-aware management of identities for secure and scalable cloud-native applications.

References

[1] Laszewski, T., Arora, K., Farr, E., & Zonooz, P. (2018). Cloud Native Architectures: Design high-availability and cost-effective applications for the cloud. Packt Publishing Ltd.

[2] Gannon, D., Barga, R., & Sundaresan, N. (2017). Cloud-native applications. IEEE Cloud Computing, 4(5), 16-21.

[3] Hu, V. C., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., & Scarfone, K. (2014). Guide to attribute based access control (abac) definition and considerations. NIST special publication, 800(162), 1-54.

[4] Hu, V. C., Ferraiolo, D. F., & Kuhn, D. R. (2019). Attribute considerations for access control systems. NIST Special Publication, 800, 205.

[5] Sandhu, R. S., Coyne, E. J., Feinstein, H. L., & Youman, C. E. (1996). Role-based access control models. Computer, 29(2), 38-47.

[6] Chandramouli, R. (2019). Microservices-based application systems. NIST Special Publication, 800(204), 800-204.

[7] Souppaya, M., Morello, J., & Scarfone, K. (2017). Application container security guide (No. NIST Special Publication (SP) 800-190 (Draft)). National Institute of Standards and Technology.

[8] Jones, M., & Hardt, D. (2012). The oauth 2.0 authorization framework: Bearer token usage (No. rfc6750).

[9] Sakimura, N., Bradley, J., & Agarwal, N. (2015). Proof key for code exchange by OAuth public clients (No. rfc7636).

[10] Sinthiya, C. (2019). A Secure and Scalable Model for Heterogeneous Cloud-Based Computing Infrastructures. American International Journal of Computer Science and Technology, 1(2), 11-20. https://doi.org/10.63282/3117-5481/AIJCST-V1I2P102

[11] Bertino, E., & Takahashi, K. (2010). Identity management: Concepts, technologies, and systems. Artech House.

[12] Hansen, M., Pfitzmann, A., & Steinbrecher, S. (2008). Identity management throughout one's whole life. Information security technical report, 13(2), 83-94.

[13] Ross, R. S. (2012). Guide for conducting risk assessments.

[14] Uddin, M., Islam, S., & Al-Nemrat, A. (2019). A dynamic access control model using authorising workflow and task-role-based access control. Ieee Access, 7, 166676-166689.

[15] Sanders, M. W., & Yue, C. (2018, March). Minimizing privilege assignment errors in cloud services. In Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy (pp. 2-12).

[16] Kayes, A. S. M., Han, J., Rahayu, W., Dillon, T., Islam, M. S., & Colman, A. (2019). A policy model and framework for context-aware access control to information resources. The Computer Journal, 62(5), 670-705.

[17] Ward, R., & Beyer, B. (2014). Beyondcorp: A new approach to enterprise security. login, 39(6), 6-11.

[18] Brunner, S., Blöchlinger, M., Toffetti, G., Spillner, J., & Bohnert, T. M. (2015, December). Experimental evaluation of the cloud-native application design. In 2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing (UCC) (pp. 488-493). IEEE.

[19] Casola, V., Cuomo, A., Rak, M., & Villano, U. (2013). The CloudGrid approach: Security analysis and performance evaluation. Future Generation Computer Systems, 29(1), 387-401.

[20] Sun, Y. L., Han, Z., Yu, W., & Liu, K. R. (2006, April). A trust evaluation framework in distributed networks: Vulnerability analysis and defense against attacks. In Proceedings IEEE INFOCOM 2006. 25th IEEE international conference on computer communications (pp. 1-13). IEEE.

[21] Dai, L., & Cooper, K. (2006). Modeling and performance analysis for security aspects. Science of Computer Programming, 61(1), 58-71.

Downloads

Published

2019-12-03

Issue

Section

Articles

How to Cite

[1]
R. Krishna, “A Zero-Trust Framework for Automated Identity Governance in Cloud-Native Applications”, AIJCST, vol. 1, no. 6, pp. 37–47, Dec. 2019, doi: 10.63282/3117-5481/AIJCST-V1I6P104.

Similar Articles

1-10 of 263

You may also start an advanced similarity search for this article.