Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: Avirneni, Surya Teja
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908336809574400
author Avirneni, Surya Teja
author_facet Avirneni, Surya Teja
contents This paper introduces the Identity Control Plane (ICP), an architectural framework for enforcing identity-aware Zero Trust access across human users, workloads, and automation systems. The ICP model unifies SPIFFE-based workload identity, OIDC/SAML user identity, and scoped automation credentials via broker-issued transaction tokens. We propose a composable enforcement layer using ABAC policy engines (e.g., OPA, Cedar), aligned with IETF WIMSE drafts and OAuth transaction tokens. The paper includes architectural components, integration patterns, use cases, a comparative analysis with current models, and theorized performance metrics. A FedRAMP and SLSA compliance mapping is also presented. This is a theoretical infrastructure architecture paper intended for security researchers and platform architects. No prior version of this work has been published.
format Preprint
id arxiv_https___arxiv_org_abs_2504_17759
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
Avirneni, Surya Teja
Cryptography and Security
Software Engineering
This paper introduces the Identity Control Plane (ICP), an architectural framework for enforcing identity-aware Zero Trust access across human users, workloads, and automation systems. The ICP model unifies SPIFFE-based workload identity, OIDC/SAML user identity, and scoped automation credentials via broker-issued transaction tokens. We propose a composable enforcement layer using ABAC policy engines (e.g., OPA, Cedar), aligned with IETF WIMSE drafts and OAuth transaction tokens. The paper includes architectural components, integration patterns, use cases, a comparative analysis with current models, and theorized performance metrics. A FedRAMP and SLSA compliance mapping is also presented. This is a theoretical infrastructure architecture paper intended for security researchers and platform architects. No prior version of this work has been published.
title Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2504.17759