arXiv · 2504.17759
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
Abstract
This paper introduces the Identity Control Plane (ICP), an architectural framework for enforcing identity-aware Zero Trust access across human users, workloads, and automation systems. The ICP model unifies SPIFFE-based workload identity, OIDC/SAML user identity, and scoped automation credentials via broker-issued transaction tokens. We propose a composable enforcement layer using ABAC policy engines (e.g., OPA, Cedar), aligned with IETF WIMSE drafts and OAuth transaction tokens. The paper includes architectural components, integration patterns, use cases, a comparative analysis with current models, and theorized performance metrics. A FedRAMP and SLSA compliance mapping is also presented. This is a theoretical infrastructure architecture paper intended for security researchers and platform architects. No prior version of this work has been published.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Surya Teja Avirneni. 2025-04-24. Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure. https://arxiv.org/abs/2504.17759
Cite the original work for its findings. Save a collection to share your selection of sources.