arXiv:2501.01732cs.CRcs.AI2025-01被引 5

为大型企业设计的零信任身份安全架构,兼顾高扩展性与强防护。

Combined Hyper-Extensible Extremely-Secured Zero-Trust CIAM-PAM architecture

  • 融合联邦身份、无密码认证与自适应多因素验证
  • 支持多层角色权限控制与端到端加密,符合严格合规要求
  • 适合面临复杂威胁的大规模企业或需要高安全性的系统

客户身份与访问管理(CIAM)系统在保障企业基础设施安全中至关重要。面对主动持续的网络威胁、人工智能与云计算的发展,以及地理分布广泛的用户群体,亟需向自适应零信任框架演进。本文提出专为大规模企业设计的联合超可扩展极安全零信任(CHEZ)CIAM-PAM架构,通过集成联邦身份管理(私有与公共身份)、无密码认证、自适应多因素认证(MFA)、基于微服务的PEP(策略授权点)、多层基于角色的访问控制(RBAC)及多级信任体系,解决关键安全漏洞。该未来兼容设计还包含端到端数据加密,并可无缝集成先进的AI威胁检测系统,同时满足严格的合规标准。

原文摘要 · Abstract (English)

Customer Identity and Access Management (CIAM) systems play a pivotal role in securing enterprise infrastructures. However, the complexity of implementing these systems requires careful architectural planning to ensure positive Return on Investment (RoI) and avoid costly delays. The proliferation of Active Persistent cyber threats, coupled with advancements in AI, cloud computing, and geographically distributed customer populations, necessitates a paradigm shift towards adaptive and zero-trust security frameworks. This paper introduces the Combined Hyper-Extensible Extremely-Secured Zero-Trust (CHEZ) CIAM-PAM architecture, designed specifically for large-scale enterprises. The CHEZ PL CIAM-PAM framework addresses critical security gaps by integrating federated identity management (private and public identities), password-less authentication, adaptive multi-factor authentication (MFA), microservice-based PEP (Policy Entitlement Point), multi-layer RBAC (Role Based Access Control) and multi-level trust systems. This future-proof design also includes end-to-end data encryption, and seamless integration with state-of-the-art AI-based threat detection systems, while ensuring compliance with stringent regulatory standards.

零信任身份管理安全架构

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。