Token-Based Identity Model Using OpenID Connect For Unmanaged Systems

Yesudian Rajkumar John Koilpillai, Rajesh Kumar · 2023

According to recent advancements in the cloud and identity domains, there is a drive to remove outdated technologies like Virtual Private Networks (VPNs) and promote Zero Trust Paradigms (ZTP). However, there is a lot of resistance to implementing ZTP among businesses. VPN presents challenges when the user base expands across the boundary, the applications are on-premises, and SaaS requires a hybrid model. Also, when we look deeply into the currently available technologies in Zero Trust, a tight bonding of the user to the device is missing. That is, the enterprise prefers to access its SaaS applications and on-premises applications through the systems that have been issued to it. However, the reality is that there are cases where enterprises would like their employees to bring their own devices (BYOD). In such cases, the challenge for the administrator is how to trust this new device. This paper discusses the issues associated with some of the current VPN techniques. And in the interim, it suggests special ways to incorporate tokens and device parameters to truly believe that the user is a member of an enterprise and grant exclusive access to enterprise applications in the hybrid model

Read the paper · More papers on PaperTik