Implementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)
| bracu.degree.level | Undergraduate | |
| bracu.type.group | Student Works | |
| datacite.rights | Open Access | |
| dc.contributor.advisor | Ferdous, Md Sadek | |
| dc.contributor.author | Islam, MD Monzurul | |
| dc.contributor.author | Zahin, Jaima | |
| dc.contributor.author | Swaccho, Aditya Das | |
| dc.contributor.author | Ahsan, Salfi | |
| dc.contributor.author | Hasan, Mahtab Uddin Al | |
| dc.contributor.department | Department of Computer Science and Engineering | |
| dc.date.accessioned | 2026-04-16T07:59:54Z | |
| dc.date.available | 2026-04-16T07:59:54Z | |
| dc.date.copyright | 2026 | |
| dc.date.copyright | 2026 | |
| dc.date.issued | 2026-01 | |
| dc.description | Cataloged from PDF version of thesis. | |
| dc.description | Includes bibliographical references (pages 60-63). | |
| dc.description | This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2026. | en_US |
| dc.description.abstract | In an era defined by dynamic cyber threats, old perimeter-style security models are becoming increasingly obsolete. Federated Identity Systems (FIS), where users au thenticate across multiple domains based on a single identity provider (IdP), offer convenience but are accompanied by significant security threats, including token theft, IdP compromise, and static session validation. At the same time, Zero Trust Architecture (ZTA) has emerged as a strong framework that applies continuous ver ification and least-privilege access regardless of user location or network trust. This research proposes a comprehensive solution for deploying the Zero Trust approach to Federated Identity Systems, which adjusts authentication needs based on real-time risk evaluations. It integrates Adaptive Multi-Factor Authentication (MFA) and hardware attestation, like TPM (Trusted Platform Module), to detect and register devices that establish trust, ensuring that compromised and untrusted devices do not enter the federation. The system designs and deploys a safe, privacy-preserving federated identity system utilizing OpenID Connect and dynamic policy verifica tion. After threat modeling, requirements analysis, and performance testing, the proposed system demonstrates increased protection against identity-based attacks and remains user-friendly and interoperable. Combining device trust, which is sup ported by hardware and adaptive authentication with contextual risk assessment, this architecture provides a comprehensive trust model that helps to mitigate threats of credential abuse, device spoofing, and token misuse. The approach increases se curity in federated environments and minimizes friction among users to provide an effective, scalable secure digital identity solution. | en_US |
| dc.description.degree | Bachelor of Science in Computer Science | |
| dc.description.statementofresponsibility | MD Monzurul Islam | |
| dc.description.statementofresponsibility | Jaima Zahin | |
| dc.description.statementofresponsibility | Aditya Das Swaccho | |
| dc.description.statementofresponsibility | Salfi Ahsan | |
| dc.description.statementofresponsibility | Mahtab Uddin Al Hasan | |
| dc.identifier.other | ID 22101124 | |
| dc.identifier.other | ID 22101129 | |
| dc.identifier.other | ID 24141269 | |
| dc.identifier.other | ID 22101142 | |
| dc.identifier.other | ID 24141273 | |
| dc.identifier.uri | http://hdl.handle.net/10361/27905 | |
| dc.language.iso | en | en_US |
| dc.publisher | BRAC University | en_US |
| dc.rights | BRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. | |
| dc.subject | Zero trust architecture | en_US |
| dc.subject | Federated identity system | en_US |
| dc.subject | Federated identity system | en_US |
| dc.subject | Multi-factor authentication | en_US |
| dc.subject | Trusted Platform Module | en_US |
| dc.subject | Performance evaluation | en_US |
| dc.subject.lcsh | Sustainable architecture. | |
| dc.subject.lcsh | Computer networks--Security measures. | |
| dc.title | Implementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA) | en_US |
| dc.type | Thesis | en_US |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- 22101124, 22101129, 24141269, 22101142, 24141273_CSE.pdf
- Size:
- 1.13 MB
- Format:
- Adobe Portable Document Format
- Description:
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description: