Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control.
翻译:静态、长期有效的工作负载认证凭证会带来不可接受的安全风险,违背零信任原则。本文提出一种基于工作负载身份联盟与OpenID Connect的多云无密钥认证框架。该方法采用经密码学验证的临时令牌,使工作负载无需持久私钥即可完成认证,有效缓解凭证窃取风险。我们在企业级Kubernetes环境中验证了该框架,其显著缩减了攻击面。该模型提供了跨异构云平台统一管理工作负载身份的解决方案,为未来实现基于属性的强健访问控制奠定了基础。