Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
This paper introduces the Identity Control Plane (ICP), an architectural framework for enforcing identity-aware Zero Trust access across human users, workloads, and automation systems. The ICP model unifies SPIFFE-based workload identity, OIDC/SAML user identity, and scoped automation credentials via broker-issued transaction tokens. We propose a composable enforcement layer using ABAC policy engines (e.g., OPA, Cedar), aligned with IETF WIMSE drafts and OAuth transaction tokens. The paper includes architectural components, integration patterns, use cases, a comparative analysis with current models, and theorized performance metrics. A FedRAMP and SLSA compliance mapping is also presented. This is a theoretical infrastructure architecture paper intended for security researchers and platform architects. No prior version of this work has been published.
Surya Teja Avirneni
计算技术、计算机技术
Surya Teja Avirneni.Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure[EB/OL].(2025-04-24)[2025-07-16].https://arxiv.org/abs/2504.17759.点此复制
评论