Linking Contexts from Distinct Data Sources in Zero Trust Federation
Masato Hirai, Daisuke Kotani, Yasuo Okabe

TL;DR
This paper proposes a method to link identifiers between data sources and a central context provider in Zero Trust Federation, enabling better context collection for improved access control in ZTA.
Contribution
It introduces a general model for collecting context from diverse data sources in ZTF by linking identifiers, which was not previously addressed.
Findings
Successfully linked identifiers between RADIUS and MDM data sources.
Enabled collection and utilization of context from multiple data sources.
Validated the proposed method through implementation and testing.
Abstract
An access control model called Zero Trust Architecture (ZTA) has attracted attention. ZTA uses information of users and devices, called context, for authentication and authorization. Zero Trust Federation (ZTF) has been proposed as a framework for extending an idea of identity federation to support ZTA. ZTF defines CAP as the entity that collects context and provides it to each organization (Relying Party; RP) that needs context for authorization based on ZTA. To improve the quality of authorization, CAPs need to collect context from various data sources. However, ZTF did not provide a method for collecting context from data sources other than RP. In this research, as a general model for collecting context in ZTF, we propose a method of linking identifiers between the data source and CAP. This method provides a way to collect context from some of such data sources in ZTF. Then, we…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Cloud Data Security Solutions · Privacy-Preserving Technologies in Data
