Skip to content
Review Open access

Cloud-Native Identity and Access Management for Enterprise Platforms

Aug 2026 · International Research Journal on Advanced Engineering Hub (IRJAEH) · 0 citations

TL;DR

A four-plane theoretical model can be introduced to separate authentication, authorization reasoning, enforcement, and auditability into four closely coupled but independent evolving planes for the system, providing a unified point of reference for both researchers and practitioners in the field of secure and scalable identity management in today's enterprise world.

Abstract

Cloud-native enterprise architectures have broken out the network perimeter, and now identity has become the front line of defense in the world of security. This review covers the current landscape of cloud-native enterprise identity and access management (IAM) solutions and how the industry has moved beyond a static approach to identity management and perimeter-based security, and is now shifting to dynamic, continually verified access control. A collection of essential research is synthesized covering access-control theory, federated authentication, security of containers and microservices, identity of the service, zero-trust concepts and machine-identity governance. On the basis of this synthesis, we argue that a four-plane theoretical model can be introduced to separate authentication, authorization reasoning, enforcement, and auditability into four closely coupled but independent evolving planes for the system. An illustrative evaluation, gleaned from published benchmarks, illustrates the expected behaviour of this model over 3 dimensions: authorization latency, enforcement overhead and scalability in the face of growth in identities. The results show that the model is viable for realistic enterprise workloads when optimizing policy evaluation and accounting for the overhead of policy enforcement, and provide limits for deployments using latency sensitive and throughput bounded workloads. Finally, the review highlights open challenges and directions for future research, providing a unified point of reference for both researchers and practitioners in the field of secure and scalable identity management in today's enterprise world.

Read PDF

Similar papers

Open access Oct 2026

Zero Trust for SQL Server: A Three-Layer Security Architecture

Enterprise database systems are frequently targeted due to their reliance on perimeter-based, static access control models that lack continuous verification and privilege minimization. This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control (RBAC) with Row-Level Security (RLS) and Just-in-Time (JIT) privilege elevation, and metadata-driven Attribute-Based Access Control (ABAC) through data classification — all without requiring external security middleware. Employing design science and applied experimental methodology, architecture was deployed in a live production environment comprising 589 databases and 132 identities over a 90-day post-implementation period. Chi-square tests of independence with Cramér's V effect size confirmed statistically significant reductions: login misuse declined by 82.1%, malicious authentication attempts by 66.7%, deployment errors by 59.8%, and reporting disruptions by 43.7%. Overprivileged accounts decreased by 84.2%. These results demonstrate that a coordinated, database native Zero Trust pipeline substantially reduces attack surfaces and insider risk in enterprise SQL Server environments. The proposed architecture aligns with globally recognized compliance frameworks, including ISO/IEC 27001 and GDPR, offering a replicable and regulatory-ready deployment model for enterprise environments across diverse jurisdictions.

Maynard Capil, D. Dasig · 0 citations
Review Open access Jul 2026

Security Challenges and Solutions in Cloud Computing Environments

This review examines the major security threats affecting cloud computing environments, including data breaches, account hijacking, insider threats, insecure application programming interfaces (APIs), cloud misconfigurations, distributed denial-of-service (DDoS) attacks, multi-tenancy risks, and regulatory compliance issues.

Amat AL-latif H. Abo-Torkhoma, A. A. H. Abo-torkhoma, G. Ali · 0 citations
Open access 2019

Modern Trends in Multi-Cloud Security Frameworks

The researcher has synthesized academic literature, industry white papers, and standards that have been published before 2024 to arrive at major security trends, such as zero trust architecture and systems, cloud security posture management (CSPM), cloud workload protection systems (CWPP), identity-centric security, confidential computing, policy-as-code, and AI-assisted threat detection.

A. Hassan · 0 citations
Review Open access Jul 2026

PRACTICAL APPROACHES TO SECURE SOFTWARE DESIGN AND PROTECTION OF DISTRIBUTED ENTERPRISE SERVICES

Contemporary enterprise software environments present a security design challenge that perimeter-hardening cannot resolve: distributed architectures expose authentication and authorization state to propagation delays, concurrent updates, and consistency trade-offs that collectively undermine the guarantees a point-of-entry credential mechanism was designed to provide. The article reviews the structural inadequacy of password-based session models in asynchronous multi-service environments, analyzes the post-password authentication ecosystem and its deployment realities, examines zero-trust architecture as an operational design constraint, explores the security semantics of concurrent transaction processing, and evaluates the Adaptive Consistency-Oriented Protocol as a mechanism for aligning performance with security requirements. These contributions are positioned against the broader literature on zero-trust migration, FIDO2 deployment barriers, and DevSecOps pipeline integration

Dmitry Andreevich Kovalev · 0 citations
Review Open access Aug 2026

A Comprehensive Review of User Authentication and Authorization Techniques in Cloud Computing

Cloud computing has emerged as a transformative paradigm for delivering scalable, flexible, and cost-effective computing services over the Internet. As organizations increasingly rely on cloud platforms for data storage, application hosting, and resource management, ensuring secure access to cloud resources has become a critical challenge. Authentication and authorization mechanisms play a fundamental role in protecting cloud environments by verifying user identities and regulating access privileges. This paper presents a comprehensive review of user authentication and authorization techniques in cloud computing. The study examines widely adopted authentication approaches, including password-based, multi-factor, biometric, and behavioral authentication methods, as well as authorization models such as Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Mandatory Access Control (MAC). Furthermore, recent advancements in artificial intelligence-driven authentication, fine-grained access control, graphical authentication systems, and cloud security frameworks are reviewed and analyzed. The findings indicate a significant transition from traditional security mechanisms toward intelligent, adaptive, and context-aware solutions that enhance security, usability, and access management. The review highlights that multi-factor authentication, biometric technologies, behavioral analytics, and attribute-based authorization frameworks offer improved protection against evolving cyber threats and represent promising directions for securing modern cloud computing environments.

C. Patel · 0 citations
Open access Aug 2026

On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)

Remote-access virtual private networks (VPNs) are a key component of enterprise security infrastructures. In practice, the effectiveness of a remote-access VPN is determined not only by cryptographic mechanisms but also by its ability to remain available and recover quickly under realistic operating conditions, which directly affects the operational security guarantees provided by the underlying cryptographic protocols. Enterprise deployments are characterized by heterogeneous client platforms, wireless access networks, and frequent endpoint and network disruptions. In this paper, we execute an exploratory case study of the operation of remote-access VPNs in enterprise environments through an empirical evaluation of WireGuard, OpenVPN, and IPsec. Using a controlled but realistic testbed with a cloud-hosted gateway and heterogeneous client platforms, we evaluate baseline performance as well as behavior under endpoint CPU stress, network impairments, MTU variation, and mobility-related disruptions, reflecting constrained and dynamically changing deployment conditions. The results suggest that VPN operational characteristics are influenced by both protocol design and execution environment. Within the evaluated deployment scenarios, kernel-based implementations generally exhibited higher resilience under endpoint resource contention and faster recovery after disruptions, while layered and virtualized environments exhibited increased variability and sensitivity to network imperfections. These findings underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions.

Rene Forsung, R. Pirmagomedov, A. Mezina et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.