BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Signed\, unsealed\, delivered: A Real‑World Federa
 ted Claims\n   Anti‑Pattern That Broke Authorization at Cloud Scale\n   
 Tags: Cloud Village | Creator Talk/Panel\n   When: Sunday\, Aug 9\, 12:30 
 - 13:10 PDT\n   Where: LVCCW Level 3 W313 (Cloud Village Talks) - [1]Map\n
 \n   Description:\n\n   Authorization decisions in cloud systems are commo
 nly driven by claims\n   embedded in access tokens issued by an identity p
 rovider (IdP). While\n   optional JWT claims can be configured during appl
 ication registration\,\n   these mechanisms are limited to directory‑res
 ident attributes and\n   are insufficient for expressing authoritative\, c
 ontext‑dependent\n   authorization signals that originate outside the Id
 P. As cloud\n   services scale and authorization decisions increasingly de
 pend on\n   external systems and dynamic state\, securely propagating trus
 ted\n   authorization context across service boundaries becomes a systemic
 \n   challenge.\n\n   To address this\, federated claims allow externa
 lly sourced\n   authorization attributes to be incorporated at token issua
 nce time\,\n   preserving a single trust boundary and enabling stateless\,
 \n   cross‑service authorization without centralized state. This talk\n 
   presents a real‑world case study of broken federated\n   claims–ba
 sed authorization in a large production cloud service and\n   exposes a 
 novel anti‑pattern: introducing federated claims without\n   holisticall
 y reasoning about authorization flows can actively regress\n   security. I
 n federated authorization systems\, a signed token is not a\n   decision\,
  it becomes a liability when authority is misplaced.\n\n   In the affected
  system\, an authenticated user was able to tamper with\n   authorization 
 context and obtain a freshly signed JWT asserting\n   attacker‑control
 led scopes. This resulted in arbitrary privilege\n   expansion\, bypassing
  authorization checks\, sensitive‑data\n   protections\, and resource is
 olation across tenants and\n   subscriptions—without breaking cryptograp
 hic primitives\,\n   compromising the IdP\, or exploiting backend services
 .\n\n   This talk distills concrete lessons for architects and security\n 
   engineers designing federated authorization systems\, managed signing\n 
   services\, and stateless authorization models\, demonstrating how\n   sc
 alability optimizations can quietly collapse security guarantees at\n   cl
 oud scale.\n\n   Presentation Outline –\n\n     1. \n\n       Problem St
 atement & Motivation\n\n     2. \n\n       Federated Claims Model – Inte
 nded Design of the system\n\n     3. \n\n       Real‑World Authorization
  Data Flow\n\n     4. \n\n       Vulnerability Deep Dive\n\n     5. \n\n  
      Impact Analysis\n\n     6. \n\n       Fixes & Defensive Lessons\n\n  
    7. \n\n       Generalization & Closing\n\n     8. \n\n       Q&A\n\n   
 SpeakerBio:  Shakul Ramkumar\n\n   Shakul Ramkumar is a Security Engineer 
 in Azure Security team at\n   Microsoft. He has over 7 years of experience
  as a professional in\n   multiple organizations including Microsoft\, App
 le and McAfee. He\n   started his career as a software developer and becam
 e a security\n   professional. Currently\, Shakul focuses on securing Azur
 e cloud\n   services at Microsoft. He is passionate about identifying\n   
 vulnerabilities at scale. His work and research have been recognized\n   t
 hrough a NeurIPS 2020 publication\, reflecting a background that\n   combi
 nes applied research\, engineering rigor\, and a strong focus on\n   scala
 ble security.\n\n   '\n\n   1. #LVCCW_Level3_South\n\n\n
DTEND:20260809T201000Z
DTSTART:20260809T193000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Signed\, unsealed\, delivered: A Real‑World Federated Claims Anti
 ‑Pattern That Broke Authorization at Cloud Scale
END:VEVENT
END:VCALENDAR
