A Multi-Cloud Framework for Zero-Trust Workload Authentication
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | , , |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866915561139601408 |
|---|---|
| author | Deochake, Saurabh Murphy, Ryan Gearheart, Jeremiah |
| author_facet | Deochake, Saurabh Murphy, Ryan Gearheart, Jeremiah |
| contents | Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2510_16067 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | A Multi-Cloud Framework for Zero-Trust Workload Authentication Deochake, Saurabh Murphy, Ryan Gearheart, Jeremiah Cryptography and Security Distributed, Parallel, and Cluster Computing Networking and Internet Architecture Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control. |
| title | A Multi-Cloud Framework for Zero-Trust Workload Authentication |
| topic | Cryptography and Security Distributed, Parallel, and Cluster Computing Networking and Internet Architecture |
| url | https://arxiv.org/abs/2510.16067 |