Master's thesis
Awards: Dean's Award for an Outstanding Final Thesis

Adaptive Authentication in Keycloak

Bc. Martin Bartoš
Abstract

Keycloak je open-source systém pro správu identit a přístupů, který poskytuje robustní bezpečnostní řešení pro aplikace a služby. Funguje jako centralizovaná platforma pro autentizaci a autorizaci, umožňující organizacím zabezpečit své zdroje a zároveň nabízet Single Sign-On funkcionalitu. Keycloak je široce používán v různých odvětvích, včetně webových aplikací, mikroslužeb a API, na ochranu citlivých …more

Abstract

Keycloak is an open-source identity and access management system that provides robust security solutions for applications and services. It acts as a centralized authentication and authorization platform, enabling organizations to secure their resources while offering Single Sign-On capabilities. Keycloak is widely used in various industries, including web applications, microservices, and APIs, to protect …more

Thesis description
Keycloak is an open-source identity and access management system that provides robust security solutions for applications and services. It acts as a centralized authentication and authorization platform, enabling organizations to secure their resources while offering Single Sign-On (SSO) capabilities. Keycloak is widely used in various industries, including web applications, microservices, and APIs, to protect sensitive data and streamline user access control.

The thesis aims to enhance the security of authentication processes in Keycloak. Traditional static authentication mechanisms, such as username and password, are vulnerable to various security threats, including password breaches, phishing attacks, and unauthorized access. Adaptive authentication might help mitigate these issues.

Adaptive authentication aims to improve the security posture by dynamically adjusting the authentication requirements based on contextual factors. That means the system can adapt its authentication methods and policies in response to changing circumstances.

The structure of the thesis might consist of these points:
  1. Service Provider Interface for the adaptive authentication extensibility.
  2. Basic implementation in Keycloak.
  3. Proof of Concept for a policy engine approach.
  4. Proof of Concept for an artificial intelligence approach.
  5. Integration with a third-party service.
The thesis has been checked:
22/5/2024 08:48, prof. RNDr. Václav Matyáš, M.Sc., Ph.D., UČO 344
Language used
English English
Defence date
20/6/2024
The thesis was defended successfully

Supervisor

prof. RNDr. Václav Matyáš, M.Sc., Ph.D., UČO 344
KPSK FI MU

Reader

Ing. Mgr. et Mgr. Zdeněk Říha, Ph.D., UČO 2514
abs FI MU, PrF MU, ESF MU

Consultant

Mgr. Marek Posolda, UČO 60575
abs FI MU

Masaryk University Faculty of Informatics
Plan
Design and development of software systems
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.