A Multi-Cloud Framework for Zero-Trust Workload Authentication

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Deochake, Saurabh, Murphy, Ryan, Gearheart, Jeremiah
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915561139601408
author Deochake, Saurabh
Murphy, Ryan
Gearheart, Jeremiah
author_facet Deochake, Saurabh
Murphy, Ryan
Gearheart, Jeremiah
contents Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control.
format Preprint
id arxiv_https___arxiv_org_abs_2510_16067
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Multi-Cloud Framework for Zero-Trust Workload Authentication
Deochake, Saurabh
Murphy, Ryan
Gearheart, Jeremiah
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Networking and Internet Architecture
Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control.
title A Multi-Cloud Framework for Zero-Trust Workload Authentication
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
Networking and Internet Architecture
url https://arxiv.org/abs/2510.16067