arXiv · 2510.16067
A Multi-Cloud Framework for Zero-Trust Workload Authentication
Abstract
Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control.
Explore related subjects
Keep this discovery
Saurabh Deochake, Ryan Murphy, Jeremiah Gearheart. 2025-10-17. A Multi-Cloud Framework for Zero-Trust Workload Authentication. https://arxiv.org/abs/2510.16067
Cite the original work for its findings. Save a collection to share your selection of sources.