Secure Identity Governance Architecture for Cloud-Native Enterprise Platforms in Regulated Industries

Authors

  • Aravind Yedmala

Keywords:

Access Control, Auditability, Cloud-Native Security, Identity Governance, Workload Identity, Zero Trust Architecture

Abstract

Regulated enterprises are moving core business functions onto distributed, application programming interface (API) driven platforms, and in such platforms an access decision is no longer made once at a point of login. Each microservice, batch job, and cloud workload evaluates whether a caller is the identity it claims to be and whether that identity is permitted to perform the requested action. Strong authentication alone does not establish why access was granted, whether it remains appropriate, who approved it, or when it was last reviewed, and these are the questions a regulated organization is required to answer. This article develops a vendor-neutral reference architecture for cloud-native identity governance by synthesizing normative standards, primary protocol specifications, and peer-reviewed research on cloud-native access control. Unlike Zero Trust guidance, which specifies how a request is verified, and conventional identity and access management, which specifies how a credential is issued, the architecture’s distinguishing claim is a governance plane that holds entitlement and lifecycle state independently of the authorization plane that issues tokens-a separation that makes an entitlement reviewable, recertifiable, and revocable without touching the credentials that carry it. The architecture organizes identity governance into six planes and three flows connecting them, situates role-based and attribute-based access control, OAuth 2.0, OpenID Connect, JSON Web Token validation, policy decision and enforcement points, API gateway controls, service mesh authentication, and workload identity federation via SPIFFE/SPIRE within that structure, and traces one entitlement end to end-from approval through enforcement to scheduled review and revocation-as a worked illustration of the model. A discrete-event simulation, built for this article and reported with its parameters and code, estimates policy-evaluation overhead and revocation-propagation latency under stated assumptions; it is a simulation of the model’s behavior, not a measurement of a deployed system, and is reported on that basis. Four contributions are offered: the plane separation itself; a layered authorization model distinguishing authentication from role, organization, object, action, and field-level authorization; the treatment of workload identity as a governed lifecycle rather than an authentication mechanism; and worked applications to healthcare, financial services, and insurance settings. The model is intended to support the production of compliance evidence; it does not by itself establish regulatory compliance, which depends on organizational processes and controls beyond the technical architecture.

Downloads

Download data is not yet available.

References

S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero trust architecture,” Nat. Inst. Standards Technol., Gaithersburg, MD, USA, NIST Special Publication 800-207, Aug. 2020, doi: 10.6028/NIST.SP.800-207.

R. Chandramouli and Z. Butcher, “A zero trust architecture model for access control in cloud-native applications in multi-location environments,” Nat. Inst. Standards Technol., Gaithersburg, MD, USA, NIST Special Publication 800-207A, Sep. 2023, doi: 10.6028/NIST.SP.800-207A.

D. Temoshok, Y.-Y. Choong, R. Galluzzo, C. LaSalle, A. Regenscheid, D. Proud-Madruga, S. Gupta, and N. Lefkovitz, “Digital identity guidelines,” Nat. Inst. Standards Technol., Gaithersburg, MD, USA, NIST Special Publication 800-63-4, Jul. 2025, doi: 10.6028/NIST.SP.800-63-4.

V. C. Hu, D. Ferraiolo, R. Kuhn, A. Schnitzer, K. Sandlin, R. Miller, and K. Scarfone, “Guide to attribute based access control (ABAC) definition and considerations,” Nat. Inst. Standards Technol., Gaithersburg, MD, USA, NIST Special Publication 800-162, Jan. 2014, includes updates as of Aug. 2, 2019, doi: 10.6028/NIST.SP.800-162.

T. Lodderstedt, J. Bradley, A. Labunets, and D. Fett, “Best current practice for OAuth 2.0 security,” Internet Engineering Task Force, RFC 9700 (BCP 240), Jan. 2025, doi: 10.17487/RFC9700.

N. Sakimura, J. Bradley, M. Jones, B. de Medeiros, and C. Mortimore, “OpenID Connect Core 1.0 incorporating errata set 2,” OpenID Foundation, final specification, Dec. 2023. [Online]. Available: https://openid.net/specs/openid-connect-core-1_0.html (accessed Aug. 4, 2026).

M. Jones, J. Bradley, and N. Sakimura, “JSON Web Token (JWT),” Internet Engineering Task Force, RFC 7519, May 2015, doi: 10.17487/RFC7519.

Y. Sheffer, D. Hardt, and M. Jones, “JSON Web Token best current practices,” Internet Engineering Task Force, RFC 8725 (BCP 225), Feb. 2020, doi: 10.17487/RFC8725.

M. Jones, A. Nadalin, B. Campbell, Ed., J. Bradley, and C. Mortimore, “OAuth 2.0 token exchange,” Internet Engineering Task Force, RFC 8693, Jan. 2020, doi: 10.17487/RFC8693.

OWASP Foundation, “OWASP API Security Top 10 – 2023,” 2023. [Online]. Available: https://owasp.org/API-Security/editions/2023/en/0x00-header/ (accessed Aug. 4, 2026).

SPIFFE Project, “SPIFFE identity and verifiable identity document,” The SPIFFE Standard, v1.15.2. [Online]. Available: https://spiffe.io/docs/latest/spiffe-specs/spiffe-id/ (accessed Aug. 4, 2026).

SPIFFE Project, “SPIFFE Workload API,” The SPIFFE Standard, v1.15.2. [Online]. Available: https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/ (accessed Aug. 4, 2026).

SPIFFE Project, “SPIRE concepts,” SPIRE Documentation, v1.15.2. [Online]. Available: https://spiffe.io/docs/latest/spire-about/spire-concepts/ (accessed Aug. 4, 2026).

Kubernetes Authors, “Managing service accounts,” Kubernetes Documentation. [Online]. Available: https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/ (accessed Aug. 4, 2026).

N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero trust architecture (ZTA): A comprehensive survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022, doi: 10.1109/ACCESS.2022.3174679.

Y. He, D. Huang, L. Chen, Y. Ni, and X. Ma, “A survey on zero trust architecture: Challenges and future trends,” Wireless Commun. Mobile Comput., vol. 2022, art. no. 6476274, Jun. 2022, doi: 10.1155/2022/6476274.

M. S. I. Shamim, F. A. Bhuiyan, and A. Rahman, “XI commandments of Kubernetes security: A systematization of knowledge related to Kubernetes security practices,” in Proc. IEEE Secure Develop. Conf. (SecDev), Atlanta, GA, USA, Sep. 2020, pp. 58–64, doi: 10.1109/SecDev45635.2020.00025.

E. Falcão, M. Silva, A. Luz, and A. Brito, “Supporting confidential workloads in SPIRE,” in Proc. IEEE 14th Int. Conf. Cloud Comput. Technol. Sci. (CloudCom), Bangkok, Thailand, Dec. 2022, pp. 186–193, doi: 10.1109/CloudCom55334.2022.00035.

M. S. Rahaman, S. N. Tisha, E. Song, and T. Cerny, “Access control design practice and solutions in cloud-native architecture: A systematic mapping study,” Sensors, vol. 23, no. 7, art. no. 3413, Mar. 2023, doi: 10.3390/s23073413.

P. Haindl, P. Kochberger, and M. Sveggen, “A systematic literature review of inter-service security threats and mitigation strategies in microservice architectures,” IEEE Access, vol. 12, pp. 90252–90286, 2024, doi: 10.1109/ACCESS.2024.3406500.

Downloads

Published

25.08.2026

How to Cite

Aravind Yedmala. (2026). Secure Identity Governance Architecture for Cloud-Native Enterprise Platforms in Regulated Industries. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 2292–2297. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/8522

Issue

Section

Research Article