Zero Trust Federation: Sharing Context under User Control toward Zero Trust in Identity Federation

09/22/2022
by   Koudai Hatakeyama, et al.
0

To securely control access to systems, the concept of Zero Trust has been proposed. Access Control based on Zero Trust concept removes implicit trust and instead focuses on evaluating trustworthiness at every access request by using contexts. Contexts are information about the entity making an access request like the user and the device status. Consider the scenario of Zero Trust in an identity federation where the entity (Relying Party; RP) enforces access control based on Zero Trust concept. RPs should continuously evaluate trustworthiness by using collected contexts by themselves, but RPs where users rarely access cannot collect enough contexts on their own. Therefore, we propose a new federation called Zero Trust Federation (ZTF). In ZTF, contexts as well as identity are shared so that RPs can enforce access control based on Zero Trust concept. Federated contexts are managed by a new entity called Context Attribute Provider, which is independent of Identity Providers. We design a mechanism sharing contexts among entities in a ZTF by using the two protocols; context transport protocol based on Continuous Access Evaluation Protocol and user consent protocol based on User Managed Access. We implemented the ZTF prototype and evaluated the capability of ZTF in 4 use-cases.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/22/2022

Linking Contexts from Distinct Data Sources in Zero Trust Federation

An access control model called Zero Trust Architecture (ZTA) has attract...
research
11/30/2022

Risks to Zero Trust in a Federated Mission Partner Environment

Recent cybersecurity events have prompted the federal government to begi...
research
05/16/2018

Practical Decentralized Attribute-Based Delegation using Secure Name Systems

Identity and trust in the modern Internet are centralized around an olig...
research
08/04/2023

SoK: The Ghost Trilemma

Trolls, bots, and sybils distort online discourse and compromise the sec...
research
04/18/2020

CryptoCam: Privacy Conscious Open Circuit Television

The prevalence of Closed Circuit Television (CCTV) in today's society ha...
research
09/19/2023

Incentivized Third Party Collateralization for Stablecoins

Stablecoins, which are primarily intended to function as a global reserv...

Please sign up or login with your details

Forgot password? Click here to reset