Welcome to the upgraded BRAC University Institutional Repository. We are currently organizing collections after a recent system upgrade. Homepage category counters may temporarily show lower numbers while syncing, but over 27,000 repository items remain safe and accessible. Please use the search bar to find theses, scholarly outputs, and institutional documents.

Implementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)

bracu.degree.levelUndergraduate
bracu.type.groupStudent Works
datacite.rightsOpen Access
dc.contributor.advisorFerdous, Md Sadek
dc.contributor.authorIslam, MD Monzurul
dc.contributor.authorZahin, Jaima
dc.contributor.authorSwaccho, Aditya Das
dc.contributor.authorAhsan, Salfi
dc.contributor.authorHasan, Mahtab Uddin Al
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-04-16T07:59:54Z
dc.date.available2026-04-16T07:59:54Z
dc.date.copyright2026
dc.date.copyright2026
dc.date.issued2026-01
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 60-63).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2026.en_US
dc.description.abstractIn an era defined by dynamic cyber threats, old perimeter-style security models are becoming increasingly obsolete. Federated Identity Systems (FIS), where users au thenticate across multiple domains based on a single identity provider (IdP), offer convenience but are accompanied by significant security threats, including token theft, IdP compromise, and static session validation. At the same time, Zero Trust Architecture (ZTA) has emerged as a strong framework that applies continuous ver ification and least-privilege access regardless of user location or network trust. This research proposes a comprehensive solution for deploying the Zero Trust approach to Federated Identity Systems, which adjusts authentication needs based on real-time risk evaluations. It integrates Adaptive Multi-Factor Authentication (MFA) and hardware attestation, like TPM (Trusted Platform Module), to detect and register devices that establish trust, ensuring that compromised and untrusted devices do not enter the federation. The system designs and deploys a safe, privacy-preserving federated identity system utilizing OpenID Connect and dynamic policy verifica tion. After threat modeling, requirements analysis, and performance testing, the proposed system demonstrates increased protection against identity-based attacks and remains user-friendly and interoperable. Combining device trust, which is sup ported by hardware and adaptive authentication with contextual risk assessment, this architecture provides a comprehensive trust model that helps to mitigate threats of credential abuse, device spoofing, and token misuse. The approach increases se curity in federated environments and minimizes friction among users to provide an effective, scalable secure digital identity solution.en_US
dc.description.degreeBachelor of Science in Computer Science
dc.description.statementofresponsibilityMD Monzurul Islam
dc.description.statementofresponsibilityJaima Zahin
dc.description.statementofresponsibilityAditya Das Swaccho
dc.description.statementofresponsibilitySalfi Ahsan
dc.description.statementofresponsibilityMahtab Uddin Al Hasan
dc.identifier.otherID 22101124
dc.identifier.otherID 22101129
dc.identifier.otherID 24141269
dc.identifier.otherID 22101142
dc.identifier.otherID 24141273
dc.identifier.urihttp://hdl.handle.net/10361/27905
dc.language.isoenen_US
dc.publisherBRAC Universityen_US
dc.rightsBRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission.
dc.subjectZero trust architectureen_US
dc.subjectFederated identity systemen_US
dc.subjectFederated identity systemen_US
dc.subjectMulti-factor authenticationen_US
dc.subjectTrusted Platform Moduleen_US
dc.subjectPerformance evaluationen_US
dc.subject.lcshSustainable architecture.
dc.subject.lcshComputer networks--Security measures.
dc.titleImplementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)en_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
22101124, 22101129, 24141269, 22101142, 24141273_CSE.pdf
Size:
1.13 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: