Institution profile

Association for Computing Machinery

Academic institutionnorthamerica · us
Official website
Research library4linked papers
Opportunities0open roles
Selected work

Representative Papers

Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication

Apr 20, 2025

CI/CD systems in enterprises commonly rely on static keys or short-lived credentials for authentication, lacking robust runtime identity assurance—leading to excessive privileges, insufficient isolation, and heightened risk during supply chain attacks. This paper introduces the first zero-trust identity framework specifically designed for CI/CD workloads. It systematically adopts the SPIFFE standard to decouple identity from infrastructure, integrating OpenID Connect–based federated authentication, dynamic SVID issuance, workload attestation, and policy-driven access control. The framework enables automated, job-level identity provisioning, mutual TLS-based authentication, and fine-grained authorization. Evaluated across multi-cloud and hybrid environments, it significantly mitigates risks of credential leakage and lateral movement, delivering a portable, auditable zero-trust identity foundation. By shifting CI/CD security from implicit trust to runtime-verifiable, context-aware interactions, the approach advances the operational paradigm toward verifiable, least-privilege execution.

2 citationsRead paper

Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD

Apr 20, 2025

To address static permission bloat, coarse-grained auditing, and inadequate support for zero-trust principles in CI/CD pipelines, this paper proposes a dynamic credential proxy architecture grounded in runtime-verifiable identities (SPIFFE/SVID). The architecture decouples identity from access permissions and enables instantaneous, short-lived (second-scale) cross-trust-domain credential issuance via OAuth 2.0 Token Exchange. It integrates a gRPC-based proxy with unified RBAC/ABAC policy enforcement, enabling fine-grained, policy-driven authorization. This work introduces the first pipeline-centric dynamic credential proxy design paradigm, bridging a critical engineering gap in applying zero-trust identity models to continuous delivery. Evaluation in production demonstrates sub-500 ms policy enforcement latency, substantial reduction in long-lived credential exposure risk, and significant improvements in audit real-time performance and traceability.

1 citationsRead paper

Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure

Apr 24, 2025

In zero-trust architectures, fragmented identities across human users, workloads, and automated systems hinder unified access control. Method: This paper introduces the Identity Control Plane (ICP)—the first cross-domain identity governance framework integrating SPIFFE identity primitives, OIDC/SAML-based federated authentication, and scoped transactional tokens. It designs a composable, standards-compliant ABAC enforcement layer aligned with IETF WIMSE and OAuth specifications; integrates OPA/Cedar policy engines; and establishes FedRAMP/SLSA compliance mapping mechanisms. Contributions: (1) Unified multi-source identity modeling with fine-grained, dynamic authorization; (2) Transaction-token-driven real-time credential lifecycle management; and (3) A complete theoretical architecture, component specifications, performance modeling, comparative analysis against mainstream zero-trust models, and a production-ready, compliance-validated deployment pathway.

0 citationsRead paper

Intent-Aware Authorization for Zero Trust CI/CD

Apr 21, 2025

This paper addresses the overreliance on static identities and the absence of operational intent modeling in authorization decisions for zero-trust CI/CD systems. To this end, it proposes an intent-aware dynamic authorization paradigm. Methodologically, it integrates SPIFFE workload identities, OPA/Cedar policy engines, credential brokers, and a closed-loop control model to dynamically couple runtime context, operational intent, and human approvals into real-time policy enforcement. Its core contributions are: (i) the first explicit modeling and deep integration of operational intent into a zero-trust authorization framework, enabling fine-grained, auditable, and adaptive access control; and (ii) support for real-time decision-making, verifiable policy execution, and end-to-end traceability in highly dynamic pipeline environments. Experimental evaluation demonstrates significant improvements in software supply chain authorization security and policy responsiveness agility.

0 citationsRead paper
Recent publications

Latest Papers

Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure

Apr 24, 2025

In zero-trust architectures, fragmented identities across human users, workloads, and automated systems hinder unified access control. Method: This paper introduces the Identity Control Plane (ICP)—the first cross-domain identity governance framework integrating SPIFFE identity primitives, OIDC/SAML-based federated authentication, and scoped transactional tokens. It designs a composable, standards-compliant ABAC enforcement layer aligned with IETF WIMSE and OAuth specifications; integrates OPA/Cedar policy engines; and establishes FedRAMP/SLSA compliance mapping mechanisms. Contributions: (1) Unified multi-source identity modeling with fine-grained, dynamic authorization; (2) Transaction-token-driven real-time credential lifecycle management; and (3) A complete theoretical architecture, component specifications, performance modeling, comparative analysis against mainstream zero-trust models, and a production-ready, compliance-validated deployment pathway.

0 citationsRead paper

Intent-Aware Authorization for Zero Trust CI/CD

Apr 21, 2025

This paper addresses the overreliance on static identities and the absence of operational intent modeling in authorization decisions for zero-trust CI/CD systems. To this end, it proposes an intent-aware dynamic authorization paradigm. Methodologically, it integrates SPIFFE workload identities, OPA/Cedar policy engines, credential brokers, and a closed-loop control model to dynamically couple runtime context, operational intent, and human approvals into real-time policy enforcement. Its core contributions are: (i) the first explicit modeling and deep integration of operational intent into a zero-trust authorization framework, enabling fine-grained, auditable, and adaptive access control; and (ii) support for real-time decision-making, verifiable policy execution, and end-to-end traceability in highly dynamic pipeline environments. Experimental evaluation demonstrates significant improvements in software supply chain authorization security and policy responsiveness agility.

0 citationsRead paper

Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD

Apr 20, 2025

To address static permission bloat, coarse-grained auditing, and inadequate support for zero-trust principles in CI/CD pipelines, this paper proposes a dynamic credential proxy architecture grounded in runtime-verifiable identities (SPIFFE/SVID). The architecture decouples identity from access permissions and enables instantaneous, short-lived (second-scale) cross-trust-domain credential issuance via OAuth 2.0 Token Exchange. It integrates a gRPC-based proxy with unified RBAC/ABAC policy enforcement, enabling fine-grained, policy-driven authorization. This work introduces the first pipeline-centric dynamic credential proxy design paradigm, bridging a critical engineering gap in applying zero-trust identity models to continuous delivery. Evaluation in production demonstrates sub-500 ms policy enforcement latency, substantial reduction in long-lived credential exposure risk, and significant improvements in audit real-time performance and traceability.

1 citationsRead paper

Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication

Apr 20, 2025

CI/CD systems in enterprises commonly rely on static keys or short-lived credentials for authentication, lacking robust runtime identity assurance—leading to excessive privileges, insufficient isolation, and heightened risk during supply chain attacks. This paper introduces the first zero-trust identity framework specifically designed for CI/CD workloads. It systematically adopts the SPIFFE standard to decouple identity from infrastructure, integrating OpenID Connect–based federated authentication, dynamic SVID issuance, workload attestation, and policy-driven access control. The framework enables automated, job-level identity provisioning, mutual TLS-based authentication, and fine-grained authorization. Evaluated across multi-cloud and hybrid environments, it significantly mitigates risks of credential leakage and lateral movement, delivering a portable, auditable zero-trust identity foundation. By shifting CI/CD security from implicit trust to runtime-verifiable, context-aware interactions, the approach advances the operational paradigm toward verifiable, least-privilege execution.

2 citationsRead paper