IAM & Zero Trust
Cyber Security
Identity & Access Management (MFA, SSO, RBAC)
TOTP Multi-Factor Authentication, NIST password policies, session concurrency limits, and enterprise SSO.
Aarkam’s Identity & Access Management (IAM) tier enforces stringent enterprise security controls aligned with NCA ECC-2:2024 §2-2, NIST SP 800-63B, and ISO/IEC 27001:2022.
1. Multi-Factor Authentication (MFA / TOTP)
Aarkam enforces hardware or software TOTP Multi-Factor Authentication across all administrative and tenant-privileged access:
- Algorithm: RFC 6238 Time-Based One-Time Password (TOTP)
- Time Step: 30 seconds with 1-step drift tolerance
- Enrollment: Secure QR-code provisioning with encrypted shared secrets for Microsoft Authenticator, Google Authenticator, and hardware YubiKeys.
- Service Implementation: Implemented in
IMfaServiceand required prior to generating API tokens or accessing administrative panels.
2. Password Governance & NIST Compliance
User authentication enforces strict cryptographic hygiene in AarkamPersistenceModule:
| Policy | Setting | Standard Compliance |
|---|---|---|
| Minimum Length | 12 Characters | NIST SP 800-63B / NCA ECC |
| Character Complexity | Upper, Lower, Numeric, Special | NCA ECC-2:2024 §2-2 |
| Account Lockout | 15 Minutes after 5 Failed Attempts | Prevent Brute-Force Password Spraying |
| Password History | 120-Day History Validator (PasswordHistoryValidator) |
Prohibits Reusing Previous 5 Passwords |
| Password Expiration | Maximum 90-Day Lifespan | Automated Expiration Enforcement |
3. Session Security & Concurrency Controls
To prevent unauthorized concurrent session hijacking, Aarkam.IO restricts session lifetimes:
- Concurrent Session Limits:
LoginByUserNameOrEmailHandlerrestricts accounts to a maximum of 3 concurrent sessions. Logging into a 4th session automatically prunes and invalidates the oldest session. - Instant Revocation on Credential Change:
ChangePasswordRequestHandlerimmediately revokes all active JWT Refresh Tokens across all devices when an account password or MFA status changes. - HMAC Signed JWTs: Session tokens are signed using HMAC-SHA256 with automated token rotation upon each refresh request.
4. Enterprise SSO Federation
Aarkam integrates into existing enterprise identity providers via standard federated protocols:
- OpenID Connect (OIDC): Native integration with Microsoft Entra ID (Azure AD), Okta, and Ping Identity.
- SAML 2.0: Support for on-premises Active Directory Federation Services (AD FS) and government identity gateways.
Aarkam Sovereign Data Fabric — https://aarkam.io
Aarkam Wiki • Enterprise Technical Documentation