This document outlines the work carried out by Davide Vigolo during the 320-hour internship at Athesys S.r.l. (Padua) from May 11 to July 10, 2026. The purpose of the project was the study, design, implementation, and testing of the security event receiver module for the Monokee platform, based on the OpenID Shared Signals Framework (SSF) specification. The integration of this framework allows Monokee to receive and manage security events issued by third-party systems (such as Identity Providers), steering the system towards a "Zero Trust" architecture. The activity included a detailed examination of the SSF specification and associated RFCs, followed by an accurate analysis of the requirements necessary for the integration and utilization of the aforementioned module. Subsequently, the work proceeded with the design, development, and code testing of the microservice. Furthermore, a significant portion of the work was dedicated to the optimization of event processing, a fundamental step to enable the platform to efficiently support the high volume of generated events.

Questo documento illustra il lavoro svolto da Davide Vigolo durante lo stage di 320 ore presso Athesys S.r.l. (Padova) dall'11 maggio al 10 luglio 2026. Scopo del progetto è stato lo studio, la progettazione, la realizzazione e il testing del modulo di ricezione degli eventi di sicurezza per la piattaforma Monokee, basato sulla specifica OpenID Shared Signals Framework (SSF). L'integrazione di questo framework consente a Monokee di ricevere e gestire eventi di sicurezza emessi da sistemi terzi (come gli Identity Provider), orientando il sistema verso un'architettura "Zero Trust". L'attività ha compreso un esame dettagliato della specifica SSF e delle RFC associate, seguito da un'accurata analisi dei requisiti necessari all'integrazione e all'utilizzo del suddetto modulo. Si è poi passati alla progettazione del microservizio, allo sviluppo e al collaudo del codice. Una parte rilevante del lavoro è stata inoltre dedicata all'ottimizzazione dell'elaborazione degli eventi, un passaggio fondamentale per consentire alla piattaforma di supportare efficientemente l'elevato volume di eventi generati.

Sicurezza Zero Trust in tempo reale: un modulo per OpenID Shared Signals Framework in una piattaforma IAM

VIGOLO, DAVIDE
2025/2026

Abstract

This document outlines the work carried out by Davide Vigolo during the 320-hour internship at Athesys S.r.l. (Padua) from May 11 to July 10, 2026. The purpose of the project was the study, design, implementation, and testing of the security event receiver module for the Monokee platform, based on the OpenID Shared Signals Framework (SSF) specification. The integration of this framework allows Monokee to receive and manage security events issued by third-party systems (such as Identity Providers), steering the system towards a "Zero Trust" architecture. The activity included a detailed examination of the SSF specification and associated RFCs, followed by an accurate analysis of the requirements necessary for the integration and utilization of the aforementioned module. Subsequently, the work proceeded with the design, development, and code testing of the microservice. Furthermore, a significant portion of the work was dedicated to the optimization of event processing, a fundamental step to enable the platform to efficiently support the high volume of generated events.
2025
Real-time Zero Trust Security: A Module for OpenID Shared Signals Framework in an IAM Platform
Questo documento illustra il lavoro svolto da Davide Vigolo durante lo stage di 320 ore presso Athesys S.r.l. (Padova) dall'11 maggio al 10 luglio 2026. Scopo del progetto è stato lo studio, la progettazione, la realizzazione e il testing del modulo di ricezione degli eventi di sicurezza per la piattaforma Monokee, basato sulla specifica OpenID Shared Signals Framework (SSF). L'integrazione di questo framework consente a Monokee di ricevere e gestire eventi di sicurezza emessi da sistemi terzi (come gli Identity Provider), orientando il sistema verso un'architettura "Zero Trust". L'attività ha compreso un esame dettagliato della specifica SSF e delle RFC associate, seguito da un'accurata analisi dei requisiti necessari all'integrazione e all'utilizzo del suddetto modulo. Si è poi passati alla progettazione del microservizio, allo sviluppo e al collaudo del codice. Una parte rilevante del lavoro è stata inoltre dedicata all'ottimizzazione dell'elaborazione degli eventi, un passaggio fondamentale per consentire alla piattaforma di supportare efficientemente l'elevato volume di eventi generati.
IAM
Zero Trust
Security Events
Shared Signals
File in questo prodotto:
File Dimensione Formato  
openid_ssf_vigolo_davide.pdf

accesso aperto

Dimensione 9.88 MB
Formato Adobe PDF
9.88 MB Adobe PDF Visualizza/Apri

The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12608/116532