WorkloadIdentityAuthenticationLevels


title: “draft-hurst-workloadidentityauthlevels” category: info

docname: draft-hurst-workloadidentityauthlevels-latest submissiontype: IETF # also: “independent”, “editorial”, “IAB”, or “IRTF” number: date: 2024-11-05 consensus: true v: 3

area: ART

workgroup: WIMSE

keyword:

author: - fullname: Ryan Hurst organization: SPIRL email: ryan@spirl.com - fullname: Jean-François ‘Jeff’ Lombardo organization: AWS email: jeffsec@amazon.com

normative:

informative:

— abstract

This draft introduces the Workload Authentication Maturity Level (WAML) framework that enables organizations to assess their current workload authentication mechanisms and progressively strengthen their security posture.

— middle

Introduction

The Workload Authentication Maturity Levels (WAML) framework provides a structured approach for organizations to systematically assess and enhance their authentication mechanisms. By offering standardized criteria and incremental levels of improvement, WAML allows organizations to progressively strengthen their security posture, ensuring that their authentication systems are resilient against evolving threats.

Conventions and Definitions

{::boilerplate bcp14-tagged}

Workload Identity Authentication Levels

Level 0: No Authentication

Description:

Characteristics:

Examples:

No access control or reliance on IP addresses, combined with allow lists and block lists for access control.

Level 1: Deploy Time Shared-Secret Based Authentication

Description:

Manual deploy time of simple passwords, shared secrets and API keys without lifecycle management

Characteristics:

Examples:

Deploy-time shared secrets.

Level 2: Deploy-Time Credential Based Authentication

Description:

Static asymmetric key-based authentication and symmetric credential management systems that are deployed during setup.

Characteristics:

Examples:

Kerberos key tabs, long-lived tokens.

Level 3: Automated Authentication with Static Credentials

Description:

Automated authentication using static credentials and improved logging.

Characteristics:

Examples:

Automated API key distribution, long-lived certificates managed through automation tools.

Level 4: Dynamic Authentication with Renewable Credentials

Description:

Dynamic authentication using renewable credentials with moderate automation.

Characteristics:

Examples:

Short-lived tokens issued and renewed automatically, dynamic certificates.

Level 5: Zero-Trust Principles with Context-Aware Authentication

Description:

Implementation of zero-trust principles with context-aware authentication.

Characteristics:

Examples:

Ephemeral certificates, workload identities validated against behavioral baselines.

Level 6: Full Zero-Trust Implementation with End-to-End Security

Description:

Characteristics:

Examples:

Security Considerations

TODO Security

IANA Considerations

This document has no IANA actions.

— back

Acknowledgments

TODO acknowledge.