Implementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)

dc.contributor.advisorFerdous, Md Sadek
dc.contributor.authorIslam, MD Monzurul
dc.contributor.authorZahin, Jaima
dc.contributor.authorSwaccho, Aditya Das
dc.contributor.authorAhsan, Salfi
dc.contributor.authorHasan, Mahtab Uddin Al
dc.date.accessioned2026-04-16T07:59:54Z
dc.date.available2026-04-16T07:59:54Z
dc.date.issued2026-01
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 60-63).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2026.
dc.description.abstractIn an era defined by dynamic cyber threats, old perimeter-style security models are becoming increasingly obsolete. Federated Identity Systems (FIS), where users au thenticate across multiple domains based on a single identity provider (IdP), offer convenience but are accompanied by significant security threats, including token theft, IdP compromise, and static session validation. At the same time, Zero Trust Architecture (ZTA) has emerged as a strong framework that applies continuous ver ification and least-privilege access regardless of user location or network trust. This research proposes a comprehensive solution for deploying the Zero Trust approach to Federated Identity Systems, which adjusts authentication needs based on real-time risk evaluations. It integrates Adaptive Multi-Factor Authentication (MFA) and hardware attestation, like TPM (Trusted Platform Module), to detect and register devices that establish trust, ensuring that compromised and untrusted devices do not enter the federation. The system designs and deploys a safe, privacy-preserving federated identity system utilizing OpenID Connect and dynamic policy verifica tion. After threat modeling, requirements analysis, and performance testing, the proposed system demonstrates increased protection against identity-based attacks and remains user-friendly and interoperable. Combining device trust, which is sup ported by hardware and adaptive authentication with contextual risk assessment, this architecture provides a comprehensive trust model that helps to mitigate threats of credential abuse, device spoofing, and token misuse. The approach increases se curity in federated environments and minimizes friction among users to provide an effective, scalable secure digital identity solution.
dc.identifier.otherID 22101124
dc.identifier.otherID 22101129
dc.identifier.otherID 24141269
dc.identifier.otherID 22101142
dc.identifier.otherID 24141273
dc.identifier.otherhttps://dspace.bracu.ac.bd/server/api/core/items/8215a926-7abc-45cf-bd51-68eb2c2044a9
dc.identifier.urihttp://hdl.handle.net/10361/27905
dc.language.isoen
dc.publisherBRAC University
dc.sourceBRAC University Institutional Repository
dc.subjectZero trust architecture
dc.subjectFederated identity system
dc.subjectFederated identity system
dc.subjectMulti-factor authentication
dc.subjectTrusted Platform Module
dc.subjectPerformance evaluation
dc.titleImplementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
22101124, 22101129, 24141269, 22101142, 24141273_CSE.pdf
Size:
1.13 MB
Format:
Adobe Portable Document Format