Enhancing Cloud Security in Sri Lanka's Banking Sector: An Empirical Study on Authorization and Authentication Mechanisms Cloud-Native Approach for Secure Banking Access
The increasing adoption of cloud computing within the banking and financial industry has introduced significant challenges related to secure authentication, authorization, and identity management, particularly in highly regulated environments such as Sri Lanka. This paper explores the application of cloud-based authentication and access control mechanisms using Microsoft Azure to address these challenges. Cloud-native architecture is proposed that integrates Azure Kubernetes Service, Azure Functions, Azure API Management, and Azure Active Directory B2C to deliver a scalable, resilient, and secure user authentication platform. The proposed solution addresses critical identity and access management concerns, including session management, account lockout enforcement, password recovery workflows, user registration and login processes, auditing and logging, role-based access control (RBAC), multi-factor authentication (MFA), and the protection of secure API endpoints. The architecture is designed to meet industry requirements for secure account provisioning, flexible access control policies, and robust protection of sensitive financial data. Empirical findings demonstrate the system's ability to integrate effectively with heterogeneous and legacy IT environments commonly found in financial institutions, while simplifying identity and access management (IAM) operations and supporting regulatory compliance. Despite these advantages, several practical limitations are identified, including architectural complexity, continuous monitoring and maintenance requirements, usability constraints, and the dynamic nature of regulatory and compliance frameworks. The paper further outlines future enhancement opportunities, such as the incorporation of advanced threat detection techniques, adaptive and risk-based MFA mechanisms, and more mature cloud-native security models. Overall, the proposed solution provides practical value to financial institutions by mitigating authentication and authorization weaknesses in cloud environments, offering an efficient and scalable identity service platform that enhances operational efficiency, regulatory compliance, and cybersecurity resilience in the face of evolving digital threats.
Read more