<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">60836</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.060836</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Enhanced Triple Layered Approach for Mitigating Security Risks in Cloud</article-title>
<alt-title alt-title-type="left-running-head">Enhanced Triple Layered Approach for Mitigating Security Risks in Cloud</alt-title>
<alt-title alt-title-type="right-running-head">Enhanced Triple Layered Approach for Mitigating Security Risks in Cloud</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Kumar</surname><given-names>Tajinder</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Sharma</surname><given-names>Purushottam</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><email>purushottam@galgotiasuniversity.edu.in</email></contrib>
<contrib id="author-3" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Cheng</surname><given-names>Xiaochun</given-names></name><xref ref-type="aff" rid="aff-3">3</xref><email>xiaochun.cheng@swansea.ac.uk</email></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Lalar</surname><given-names>Sachin</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Kumar</surname><given-names>Shubham</given-names></name><xref ref-type="aff" rid="aff-5">5</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Bansal</surname><given-names>Sandhya</given-names></name><xref ref-type="aff" rid="aff-6">6</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Computer Science &#x0026; Engineering Department, Jai Parkash Mukand Lal Innovative Engineering &#x0026; Technology Institute</institution>, <addr-line>Radaur, 135133, Haryana</addr-line>, <country>India</country></aff>
<aff id="aff-2"><label>2</label><institution>School of Computer Science &#x0026; Engineering, Galgotias University</institution>, <addr-line>Greater Noida, 203201, Uttar Pradesh</addr-line>, <country>India</country></aff>
<aff id="aff-3"><label>3</label><institution>Computer Science Department, Bay Campus Fabian Way, Swansea University</institution>, <addr-line>Swansea, SA1 8EN</addr-line>, <country>UK</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Engineering and Technology, Gurugram University</institution>, <addr-line>Gurugram, 122003</addr-line>, <country>India</country></aff>
<aff id="aff-5"><label>5</label><institution>Presidency School of Computer Science, Presidency University</institution>, <addr-line>Bangalore, 560089</addr-line>, <country>India</country></aff>
<aff id="aff-6"><label>6</label><institution>Maharishi Markendeshwar Engineering College, Maharishi Markandeshwar (Deemed to be) University</institution>, <addr-line>Mullana, Ambala, 133203</addr-line>, <country>India</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Authors: Purushottam Sharma. Email: <email>purushottam@galgotiasuniversity.edu.in</email>; Xiaochun Cheng. Email: <email>xiaochun.cheng@swansea.ac.uk</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>26</day><month>03</month><year>2025</year>
</pub-date>
<volume>83</volume>
<issue>1</issue>
<fpage>719</fpage>
<lpage>738</lpage>
<history>
<date date-type="received">
<day>11</day>
<month>11</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>10</day>
<month>2</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_60836.pdf"></self-uri>
<abstract>
<p>With cloud computing, large chunks of data can be handled at a small cost. However, there are some reservations regarding the security and privacy of cloud data stored. For solving these issues and enhancing cloud computing security, this research provides a Three-Layered Security Access model (TLSA) aligned to an intrusion detection mechanism, access control mechanism, and data encryption system. The TLSA underlines the need for the protection of sensitive data. This proposed approach starts with Layer 1 data encryption using the Advanced Encryption Standard (AES). For data transfer and storage, this encryption guarantees the data&#x2019;s authenticity and secrecy. Surprisingly, the solution employs the AES encryption algorithm to secure essential data before storing them in the Cloud to minimize unauthorized access. Role-based access control (RBAC) implements the second strategic level, which ensures specific personnel access certain data and resources. In RBAC, each user is allowed a specific role and Permission. This implies that permitted users can access some data stored in the Cloud. This layer assists in filtering granular access to data, reducing the risk that undesired data will be discovered during the process. Layer 3 deals with intrusion detection systems (IDS), which detect and quickly deal with malicious actions and intrusion attempts. The proposed TLSA security model of e-commerce includes conventional levels of security, such as encryption and access control, and encloses an insight intrusion detection system. This method offers integrated solutions for most typical security issues of cloud computing, including data secrecy, method of access, and threats. An extensive performance test was carried out to confirm the efficiency of the proposed three-tier security method. Comparisons have been made with state-of-art techniques, including DES, RSA, and DUAL-RSA, keeping into account Accuracy, QILV, F-Measure, Sensitivity, MSE, PSNR, SSIM, and computation time, encryption time, and decryption time. The proposed TLSA method provides an accuracy of 89.23%, F-Measure of 0.876, and SSIM of 0.8564 at a computation time of 5.7 s. A comparison with existing methods shows the better performance of the proposed method, thus confirming the enhanced ability to address security issues in cloud computing.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Cloud security: data encryption</kwd>
<kwd>AES</kwd>
<kwd>access control</kwd>
<kwd>intrusion detection systems (IDS)</kwd>
<kwd>role-based access control (RBAC)</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>UKRI EPSRC</funding-source>
<award-id>EP/W020408/1</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Doctoral Training Centre at Swansea University</funding-source>
<award-id>RS718</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>As regards conventional local storage, cloud computing provides greater flexibility, affordability, and access to data. The character of data storage in cloud computing differs is unique since it does not involve the use of major facilities but can be charged based on the volume of use. Moreover, the Cloud information can be accessed anywhere, making the system more flexible and proficient for traversing divisional teams. The improved reliability of Cloud data depends on several methods, including the use of encryption levels and authorized restrictions. It not only helps to protect from various threats such as data breaches, malware attacks, and several unauthorized access attempts, but it also enhances the system&#x2019;s immunity against virus attacks. The biggest threats to cloud-stored data are the threat of access by unauthorized personnel, data leakage, and data loss. The proposed TLSA model mitigates these challenges by providing a layered security wall comprising encryption mechanisms and intrusion detection systems to deal with these threats. The three-tier strategy improves scalability and redundancy by integrating the concept of redundancy and fault tolerance in improving cloud infrastructure [<xref ref-type="bibr" rid="ref-1">1</xref>].</p>
<p>Moreover, integrating RBAC enhances access management&#x2019;s usefulness as it accurately controls user rights. In the age where many industrial systems are getting connected to the Internet, they are prone to many security threats. Security devices such as intrusion detection systems (IDSs) are becoming important in defending industrial infrastructures against identified malicious activities. Several studies on IDS that integrated signature-based and anomaly-based systems showed that the latter was more efficient [<xref ref-type="bibr" rid="ref-2">2</xref>]. When IDS is implemented at the third network layer, it is feasible to identify and prevent dangerous activities. The three-tier strategy also promotes compliance with safety regulations and laws in the workplace. It can show that an organization is committed to protecting an individual&#x2019;s data and following policy regulation standards prescribed by specific industry bodies by having several layers of protection.</p>
<sec id="s1_1">
<label>1.1</label>
<title>Overview of Cloud Computing and Its Security Challenges</title>
<p>Cloud computing allows businesses to rapidly and smoothly get the right of entry to computing assets that include networks, applications, services, servers, and storage. Nevertheless, the significant advantages of cloud computing are scalability, cost-effectiveness, flexibility, and others. These concepts lead to security issues that need to be resolved to protect the privacy integrity and availability of resources and data [<xref ref-type="bibr" rid="ref-3">3</xref>].
<list list-type="bullet">
<list-item>
<p>Data Protection and Privacy: This poses a challenge in cloud computing due to the latent risks associated with unauthorized access, data breaches, or data loss when data is managed on remote servers managed by cloud service providers (CSP).</p></list-item>
<list-item>
<p>Identity and Access Management: Managing security requires managing user identities and restricting access to cloud resources. Reducing the risk of illegitimate access and unauthorized privilege escalation requires sound identity and access management best practices, such as strong user authentication, flexible RBAC, and constant access auditing [<xref ref-type="bibr" rid="ref-4">4</xref>].</p></list-item>
<list-item>
<p>Data Encryption: To improve security and reduce the chances of being accessed and attacked by unauthorized persons, data is encrypted and stored in the Cloud. However, its usage has certain drawbacks&#x2014;sometimes, it is complicated to regulate encryption keys and guarantee safe representations of keys.</p></list-item>
<list-item>
<p>Cloud Application Security: It is important to avoid threats that attackers can exploit. It is best to use tight means of authentication and authorization in cloud applications to avoid cases of illegitimate access [<xref ref-type="bibr" rid="ref-5">5</xref>].</p></list-item>
</list></p>
<p>To address these cloud security concerns, organizations must complete their cloud security initiatives with the risk assessment and management approach. As cloud computing progresses, tackling the problem of cloud security and promoting a safe environment demands integration between enterprises and cloud service providers.</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Importance of Secure Algorithms for Cloud Security</title>
<p>For organizations to ensure their measures work, secure algorithms must first be in place. From the study of literature, the following main arguments underline the importance of current secure algorithms for cloud security:
<list list-type="bullet">
<list-item>
<p>Confidentiality and Data Protection: The secure technologies of Elliptic Curve Cryptography, RSA, and Advanced Encryption Standard (AES) can be used to show the importance of data security in cloud computing [<xref ref-type="bibr" rid="ref-6">6</xref>].</p></list-item>
<list-item>
<p>Authentication and Access Control: Other means to verify the identity of the users, and get access to the cloud services via tight measures include secure protocols such as Transport Layer Security (TLS) and digital signatures [<xref ref-type="bibr" rid="ref-7">7</xref>].</p></list-item>
<list-item>
<p>Key Management: Due to secure algorithms, activities that include key creation, distribution, storage, and revocation are easily simplified. According to papers, intense key management is required to ensure encryption keys are processed safely in the Cloud and prevent unauthorized access [<xref ref-type="bibr" rid="ref-8">8</xref>].</p></list-item>
<list-item>
<p>Intrusion Detection and Prevention: IDS/IPS employs strong algorithms to detect and prevent security threats or threats in the cloud environment [<xref ref-type="bibr" rid="ref-9">9</xref>].</p></list-item>
<list-item>
<p>Performance and Efficiency: Thus, aspects such as the performance and efficacy of present-day secure algorithms in cloud systems are more relevant. It also includes performance, computational complexity, encryption/decryption time, and resources [<xref ref-type="bibr" rid="ref-10">10</xref>].</p></list-item>
</list></p>
</sec>
<sec id="s1_3">
<label>1.3</label>
<title>Data Integrity and Privacy in Cloud Computing</title>
<p>Maintenance of data quality, consistency, and reliability plays a significant role in cloud computing. To maintain data integrity, issues such as unwanted modifications, tampering, and value checking, must be considered. Implement certain security features like authentication, authorization, and auditing to guard data integrity and privacy in cloud resources [<xref ref-type="bibr" rid="ref-9">9</xref>&#x2013;<xref ref-type="bibr" rid="ref-12">12</xref>]. In case, the sharing of resources is important, data privacy takes a serious hit in the cloud-computing environment. Accessing of sensitive information by unwanted entities is prevented by the execution of technologies such as data anonymization, data masking, and data encryption [<xref ref-type="bibr" rid="ref-13">13</xref>&#x2013;<xref ref-type="bibr" rid="ref-15">15</xref>]. SSL/TLS and all the other data transfer security protocols are a must if data is to be protected from leakage and interference during transfer. Legal requirements are crucial while dealing with data to ensure the correct procedure is followed. This helps to meet the set legal measures such as GDPR or HIPAA compliance. Cloud providers must retain transparency and accountability to provide insight into data processing, and security measures the customers implement. Measures of data backup and data recovery are important to maintain the data&#x2019;s integrity and security. In case of data loss [<xref ref-type="bibr" rid="ref-16">16</xref>] or system failure, it&#x2019;s crucial to maintain business operations [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>].</p>
</sec>
<sec id="s1_4">
<label>1.4</label>
<title>Purpose and Objectives of the Paper</title>
<p>How companies handle data is significant and has been transformed through cloud computing. Cloud computing technology is an excellent approach to delivering the highest scalable, cost-efficient, and flexible computing with the help of remote servers and diffused computing ingredients. In order to maintain the confidentiality, integrity, and availability of information, many security aspects concerning the use of cloud services [<xref ref-type="bibr" rid="ref-19">19</xref>] have to be considered. One of the main problems of cloud computing is data security. The threat of data vulnerability has become a significant problem in cloud computing. Cloud providers share security certifications, security incident response efficiency, and open security policies, and they have a reasonably significant role in implementing the security of their platforms and services [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>]. Although cloud computing offers advantages, like being cost-efficient, productive, and reliable, organizations must always watch out for threats and protect their data and systems [<xref ref-type="bibr" rid="ref-21">21</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>]. However, to make the best use of cloud technology&#x2019;s opportunities, businesses must recognize several features specific to the cloud environment and provide reliable protection for sensitive information [<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>].</p>
<p>The subsequent sections encompass the remaining content of this paper: This paper examines the security research in the context of cloud computing in <xref ref-type="sec" rid="s2">Section 2</xref>. <xref ref-type="sec" rid="s3">Section 3</xref> describes the nature of the dataset utilized in the study and the feature extraction and pre-processing step of the presented method. The following section describes the prediction method of stroke. <xref ref-type="sec" rid="s5">Section 5</xref> performs the comparative study of the evaluation parameters of the proposed method against the baseline methods. The last section contains the conclusion.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>Personal computing and organizational use, and the collaborative network and hybrid cloud distribution model, as depicted in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, are demonstrated. Attention is paid to access control methods, including mandatory access control, role-based access control, and discretionary access control [<xref ref-type="bibr" rid="ref-25">25</xref>]. The proposed approach is used for availability and integrity&#x2014;to provide users with easy access and efficient performance execution while ensuring confidentiality.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Overview of cloud computing</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-1.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-1">Fig. 1</xref> explains the Cloud Concept by analyzing the Overview of Cloud Computing. It concentrates on providing computing resources, especially servers, storage, and applications, as services are accessible through the Internet. Three approaches to cloud computing, known as IaaS, PaaS, and SaaS service delivery models, explain cloud computing. Authors in [<xref ref-type="bibr" rid="ref-25">25</xref>] propose a revolutionary Cryptographic Role Engineering (CRE) approach to solve security issues in organizations. In contrast with the previous encryption models that employ El-Gamal, Baillier, and Benaloh techniques in [<xref ref-type="bibr" rid="ref-26">26</xref>], the introduced model utilizes SPHE for both the encryption of data and the computation of the encrypted data, enhancing security. In a cloud context that improves access control and database privacy, SPHE is implemented in conjunction with a role-based user policy. This model is deployed in an Amazon Web Service environment of Elastic Beanstalks (EB). In [<xref ref-type="bibr" rid="ref-27">27</xref>], authors take a closer look at cloud computing opportunities besides Virtual Reality, Augmented Reality, and Metaverse. As the requirement for computation rises, the data owners shift towards the remote server to obtain computation. However, having multiple tenants on the same Cloud brings issues with access to unauthorized personnel and probing of the networks. H-IDS is the host-based intrusion detection system proposed in [<xref ref-type="bibr" rid="ref-28">28</xref>] to protect virtual machines in cloud computing. The NSL-KDD dataset is used to train and test the model, and simulation proves satisfactory for approximately 97.51% of attack detection against normal states.</p>
<p>In this work [<xref ref-type="bibr" rid="ref-29">29</xref>], the authors present the IBET model of Identity-Based Encryption Transformation to address the key difficulty of sharing encrypted data with a more extensive audience than the intended recipients. This IBET model perfectly integrates Identity Based Encryption (IBE) and Broadcast Encryption (IBBE) methods. For addressing data security in cloud-based applications, the paper presents a proposed cryptographic model called Autonomous Path Identity-Based Broadcast Proxy Re-Encryption (APIB-BPRE) but in a different setting. Evaluating and comparing APIB-BPRE reveals that it is effectively applied to practical engineering problems. In [<xref ref-type="bibr" rid="ref-30">30</xref>], authors enhance the security of data stored in cloud storage systems using trust models in conjunction with cryptographic role-based access control (RBAC) schemes. Considering inheritance and role hierarchy, these trust models enable owners and roles to assess each user&#x2019;s and role&#x2019;s trustworthiness inside the RBAC system.</p>
<p>The research gap lacks a holistic security framework that addresses data encryption, access control, and intrusion detection in cloud computing environments. While some papers discuss Role-Based Access Control (RBAC), there is a research gap in the comprehensive coverage of user roles and permissions, especially in dynamically changing cloud environments. The proposed research addresses the challenges of evolving user roles and permissions in the realm of cloud security. This research introduces a comprehensive three-tier security framework that focuses on enhancing cloud computing security through the integration of Advanced Encryption Standard (AES)-based encryption, Role-Based Access Control (RBAC), and Intrusion Detection Systems (IDS). Motivated by the imperative need to fortify cloud data security, our proposed method employs AES as the cornerstone for first-layer data encryption.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Working of Proposed Method TLSA</title>
<sec id="s3_1">
<label>3.1</label>
<title>Components and Layers of the Algorithm</title>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>First Layer: Data Encryption</title>
<p>AES strengthens data authenticity and secrecy, meaning the encryption algorithm is computationally secure from brute force attacks. These are encryption features: data at rest and data in transit so that the wrong people cannot intercept or modify the various forms of information. AES also opts for fast data encryption and decryption rate, which is important for large-scale cloud applications. Its features encrypt data at rest and in transit, making it impossible for the wrong force to breach the information. This layer focuses on protecting data using encryption methods such as asymmetric encryption (such as RSA) or symmetric encryption (such as AES). This technology converts the original data into an encrypted version while maintaining confidentiality through mathematical operations and encryption algorithms. Efficient key management is essential for secure encryption. The algorithm includes mechanisms to generate encryption keys and securely transmit them to authorized parties. Key management strategies are employed to safeguard the integrity and confidentiality of cryptographic keys.</p>
</sec>
<sec id="s3_1_2">
<label>3.1.2</label>
<title>Second Layer: Access Control</title>
<p>Depending on their roles and responsibilities, the user can access cloud resources through this layer, which controls and manages this access. RBAC provides a versatile and scalable method for creating and implementing access controls. Depending on user roles and the permissions associated with those roles, the algorithm combines RBAC techniques to grant or restrict access privileges. Trusted authentication techniques such as username/password, biometric authentication, or multi-factor authentication are implemented to confirm the identity of users accessing the cloud environment. Authorization techniques, such as attribute-based access control (ABAC) and access control lists (ACL), define the extent of access granted to authorized users.</p>
</sec>
<sec id="s3_1_3">
<label>3.1.3</label>
<title>Third Layer: Intrusion Detection and Prevention</title>
<p>Before presenting the proposed methods, the paper conducts a comprehensive review of related work in the field of Intrusion Detection. Some concerns for traditional machine learning and deep learning models are the lack of labeled data and the disparity in data distribution that characterizes ICNs. DTL is a potential solution to transfer knowledge from pre-trained models to target tasks with little training data. The paper introduces IDS types (anomaly, signature, and hybrid) and overviews potential issues that arise during their application to ICNs. A schematic block diagram of the proposed method, the Three-Layered Security Access (TLSA) Model, is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Block diagram of TLSA</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-2.tif"/>
</fig>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Algorithm of Proposed Method&#x2014;TLSA</title>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>First Layer: Data Encryption</title>
<p>Encryption Techniques and Algorithms Used: This layer employs the AES encryption algorithm, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, a symmetric key cryptographic algorithm widely used for secure data encryption. It starts with adding the first round key, known as the round key (0). Much about a decision point, it looks into a question as to whether the current round, &#x2018;i&#x2019;, is equal to the total number of rounds, &#x201C;Nr.&#x201D; If not, the encryption process will take three steps. However, despite the Data Encryption Standard (DES) comprising 16 rounds of operation, four primary operations bear mentioning: sub bytes, shift rows, mix columns, and ultimately, adding the round key. If yes, only two operations are performed, sub-byte and shift rows, and then the last round key (round key (Nr)) is added. The final step is the output of the ciphertext, often referred to as the encrypted result. The complete Algorithmic details are given in <xref ref-type="app" rid="app1">Appendix A</xref> as 3.3.1.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Advanced encryption system</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-3.tif"/>
</fig>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Second Layer: Access Control&#x2014;RBAC (Role-Based Access Control)</title>
<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates Role-Based Access Control (RBAC) in access control. The process ensures that only those employees with the right roles will request the proper Permission to connect to the system.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Second layer: access control&#x2014;role-based access control (RBAC)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-4.tif"/>
</fig>
<p>In this model, the user authenticates to affirm his identity and authorize his or her access with roles. It then verifies the user&#x2019;s position and his or her authorization level. This enables to allow or deny him or her, the given resource. Such an approach forms the system to ensure that only authorized users can run jobs and are considered appropriate by their status. RBAC is a broadly used access control model that grants users permissions based on their assigned roles, as shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>. The RBAC implementation includes multiple steps, as shown in <xref ref-type="app" rid="app1">Appendix A</xref>, which are 3.3.2.</p>
</sec>
<sec id="s3_2_3">
<label>3.2.3</label>
<title>Third Layer: Intrusion Detection Systems (IDS)</title>
<p>Intrusion Detection Systems (IDS) Implementation: IDS are security mechanisms that detect and respond to potential intrusions or malicious activities, as shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>. The IDS implementation includes multiple steps, as shown in <xref ref-type="app" rid="app1">Appendix A</xref>, such as 3.3.3.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Third layer: intrusion detection systems (IDS)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-5.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Evaluation and Performance Analysis</title>
<sec id="s4_1">
<label>4.1</label>
<title>Experimental Setup</title>
<p>The experimental setup specification used for implementation and performance evaluation configured to specific parameters/conditions given in <xref ref-type="sec" rid="s4_1">Section 4.1</xref>. Experimental setup configuration given in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Detail of experimental setup</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Category</th>
<th align="center">Details</th>
</tr>
</thead>
<tbody>
<tr>
<td></td>
<td><bold>CPU:</bold> Intel Xeon E5-2678 v3 (12 Cores, 24 Threads)</td>
</tr>
<tr>
<td><bold>Hardware specifications</bold></td>
<td><bold>RAM:</bold> 32 GB DDR4</td>
</tr>
<tr>
<td></td>
<td><bold>Storage:</bold> 1 TB SSD (NVMe) for faster I/O operations</td>
</tr>
<tr>
<td></td>
<td><bold>Platform:</bold> AWS EC2 Instances</td>
</tr>
<tr>
<td></td>
<td><bold>Region:</bold> US-East (N. Virginia)</td>
</tr>
<tr>
<td><bold>Cloud platform setup</bold></td>
<td><bold>Instance type:</bold> m5.xlarge (4 vCPUs, 16 GB RAM)</td>
</tr>
<tr>
<td></td>
<td><bold>Virtualization:</bold> Xen/AMI-based virtualization</td>
</tr>
<tr>
<td></td>
<td><bold>Security configurations:</bold> VPC, Subnets, Security Groups, and IAM Roles for access control</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Performance Metrics</title>
<p>The performance metrics are often used to evaluate the quality and effectiveness of various algorithms. The following performance metrics are used in this paper:
<list list-type="bullet">
<list-item>
<p>SSIM (Structural Similarity Index): It measures the structural similarity between images. It assesses how well the structural information in an image is preserved after processing.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>I</mml:mi><mml:mi>M</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mi>x</mml:mi><mml:mi>y</mml:mi><mml:mo>+</mml:mo><mml:mi>C</mml:mi><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mi>x</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mi>y</mml:mi><mml:mo>+</mml:mo><mml:mi>C</mml:mi><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>C</mml:mi><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>C</mml:mi><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:math></disp-formula>
In <xref ref-type="disp-formula" rid="eqn-1">(1)</xref>, <italic>x</italic>, <italic>y</italic> are the input and processed images, <italic>&#x03BC;x</italic>, <italic>&#x03BC;y</italic> are the means of <italic>x</italic> and <italic>y</italic>, Standard deviations of <italic>x</italic> and <italic>y</italic> is <italic>&#x03C3;x</italic>, <italic>&#x03C3;y</italic>, Covariance of <italic>x</italic> and <italic>y</italic> is <italic>&#x03C3;xy</italic>, <italic>C</italic>1 and <italic>C</italic>2 are constants to stabilize the division.</p></list-item>
<list-item>
<p>QILV (Quality Index of Luminance and Visibility): QILV is a metric that assesses the quality and visibility of important features in an image.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>Q</mml:mi><mml:mi>I</mml:mi><mml:mi>L</mml:mi><mml:mi>V</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mi>x</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mi>y</mml:mi><mml:mo>+</mml:mo><mml:mi>k</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mi>k</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mfrac></mml:math></disp-formula>
In <xref ref-type="disp-formula" rid="eqn-2">(2)</xref>, <italic>x</italic> and <italic>y</italic> are the input and processed images, means of <italic>x</italic> and <italic>y</italic> are <italic>&#x03BC;x</italic> and <italic>&#x03BC;y</italic>, <italic>k</italic> is a constant.</p></list-item>
<list-item>
<p>Precision (%): Precision is a metric used in classification tasks. The percentage of total expected positive cases is measured precisely by the percentage of expected positive cases.
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mrow><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">F</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo>+</mml:mo><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></disp-formula></p></list-item>
<list-item>
<p>Sensitivity (%): Sensitivity is the ratio between accurately predicted positive cases and the total number of positive cases that occurred.
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">y</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo>+</mml:mo><mml:mi mathvariant="normal">F</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">N</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">g</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></disp-formula></p></list-item>
<list-item>
<p>F-Measure (%): The harmonic mean of Sensitivity and precision is known as F-measure. Classification functions use it to find a trade-off between recall and precision.
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mrow><mml:mi mathvariant="normal">F</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mo>+</mml:mo><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></disp-formula></p></list-item>
<list-item>
<p>PSNR (Peak Signal-to-Noise Ratio): PSNR is a statistic used to evaluate the quality of image noise reduction or compression. Calculates the ratio between the highest possible signal strength and the strength of the signal causing noise.
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>P</mml:mi><mml:mi>S</mml:mi><mml:mi>N</mml:mi><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mn>10</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mn>10</mml:mn><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mi>M</mml:mi><mml:mi>a</mml:mi><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>M</mml:mi><mml:mi>S</mml:mi><mml:mi>E</mml:mi></mml:mrow></mml:mfrac><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
In <xref ref-type="disp-formula" rid="eqn-6">(6)</xref>, the maximum pixel value, typically 255 for 8-bit images, is denoted by <italic>Max</italic>.</p></list-item>
<list-item>
<p>MSE (Mean Squared Error): MSE measures the mean squared difference between the pixel values of the original and processed image.
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">E</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi mathvariant="normal">N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi mathvariant="normal">&#x03A3;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">y</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:math></disp-formula>
In <xref ref-type="disp-formula" rid="eqn-7">(7)</xref>, the total number of pixels is N. The pixel values of the original and processed image at a given location are represented by x and y.</p></list-item>
<list-item>
<p>Accuracy (%): A classification statistic called accuracy calculates the proportion of accurately predicted occurrences to all instances.
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mrow><mml:mi mathvariant="normal">A</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">y</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></disp-formula></p></list-item>
<list-item>
<p>Computation Time (s): Computation time measures how long a specific operation or algorithm takes to process the data, typically in seconds.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Performance Analysis of the Algorithm</title>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> shows the time it takes to perform encryption using different encryption algorithms for various key sizes. As the key size increases to 10 bits, TLSA and DES remain the fastest, but their encryption times have increased significantly. RSA and DUAL-RSA, asymmetric encryption algorithms, show a much more significant increase in encryption time than symmetric algorithms like TLSA and DES. TLSA, using a 50-bit key, completes the encryption process in 2.86 s, while DES takes 2.93 s, DUAL-RSA 3.23 s, and RSA 4.87 s.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Encryption time comparison</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-6.tif"/>
</fig>
<p>The comparison reveals that symmetric encryption methods such as DES and TLSA outperform asymmetric encryption algorithms such as DUAL-RSA and RSA, especially with large key sizes. In addition, the encryption time of RSA and DUAL-RSA is significantly affected by the key size, making them slower than TLSA and DES for larger key sizes.</p>
<p>For minimum key sizes, TLSA&#x2014;Proposed method, DES, RSA, and DUAL-RSA all decrypt the data in <xref ref-type="fig" rid="fig-7">Fig. 7</xref> in about 0.05 s, which means they are all fast and have comparable decryption speeds. Although TLSA and DES are relatively fast compared to RSA and DUAL-RSA, decryption times increase as the key size approaches 10 bits. TLSA and DUAL-RSA emerged as the slowest decryption options, with TLSA requiring 2.89 s and DUAL-RSA 5.07 s. RSA follows with 4.99 s, but DES is the fastest with 1.98 s. Even with a key size of 100 bits, TLSA decryption is still somewhat slow, taking 4.7 s. The comparison indicates that symmetric encryption algorithms like DES and TLSA tend to be faster for decryption than asymmetric encryption algorithms like RSA DUAL-RSA [<xref ref-type="bibr" rid="ref-31">31</xref>]. As the key size increases, the decryption times for all algorithms also increase, but the relative performance remains consistent.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Decryption time comparison</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-7.tif"/>
</fig>
<p>To compare the performance of different encryption methods, several parameters have been employed to measure different aspects of encryption from [<xref ref-type="bibr" rid="ref-32">32</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>]. F-Measure considers both precision and recall to measure encryption reliability where there is an imbalance of the data. Sensitivity evaluates the encryption method and how well it identifies all the important data that needs to be encrypted. MSE measures the level of encrypted and original data. According to the current research, the data quality after decryption using PSNR is studied. Validating SSIM focuses on checking perceived similarity in encryption output. Computation Time gives the time taken to perform the encryption in a given method.</p>
<p><xref ref-type="table" rid="table-2">Table 2</xref> compares different encryption methods based on various evaluation metrics. DUAL-RSA performs well across various metrics, balancing quality, accuracy, and speed well. TLSA and DES also perform reasonably well, while RSA lags in quality and accuracy. <xref ref-type="table" rid="table-3">Table 3</xref> compares access control models based on layer 2 of the proposed method.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Performance analysis of encryption methods</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Methods</th>
<th>Accuracy (%)</th>
<th>QILV</th>
<th>F-Measure (%)</th>
<th>Sensitivity (%)</th>
<th>MAP</th>
<th>PSNR (dB)</th>
<th>SSIM</th>
<th>Computation time (s)</th>
</tr>
</thead>
<tbody>
<tr>
<td>DES</td>
<td>92.55</td>
<td>0.8456</td>
<td>0.879</td>
<td>0.865</td>
<td>3.4</td>
<td>66.52</td>
<td>0.8431</td>
<td>5.2</td>
</tr>
<tr>
<td>TLSA</td>
<td>89.23</td>
<td>0.9042</td>
<td>0.876</td>
<td>0.853</td>
<td>3.5</td>
<td>65.32</td>
<td>0.8564</td>
<td>5.7</td>
</tr>
<tr>
<td>RSA</td>
<td>82.65</td>
<td>0.8992</td>
<td>0.848</td>
<td>0.826</td>
<td>3.9</td>
<td>62.12</td>
<td>0.8241</td>
<td>6.5</td>
</tr>
<tr>
<td>DUAL-RSA</td>
<td>93.48</td>
<td>0.9098</td>
<td>0.912</td>
<td>0.894</td>
<td>3.2</td>
<td>68.23</td>
<td>0.8896</td>
<td>3.5</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Comparison of access control models</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th align="center">Access control model</th>
<th align="center">Access granted</th>
<th align="center">Access permissions</th>
<th align="center">Security implications</th>
<th align="center">Examples</th>
</tr>
</thead>
<tbody>
<tr>
<td>DAC</td>
<td>Based on the user&#x2019;s identification</td>
<td>The access control list defines permissions.</td>
<td>Simple to attack and exploit</td>
<td>Old versions of Windows/UNIX</td>
</tr>
<tr>
<td>MAC</td>
<td>System administrator</td>
<td>The administrator has complete control over altering an object&#x2019;s and the user&#x2019;s security clearance.</td>
<td>Vulnerable to exploit</td>
<td>Military applications</td>
</tr>
<tr>
<td>RBAC</td>
<td>Depending on the role that a system administrator has allocated to a user</td>
<td>An administrator grants a user a position with predetermined system privileges and rights. Once given a role, a user can only access system resources and carry out the tasks listed in the assigned role. Additionally, the system administrator centrally oversees the tasks assigned to users.</td>
<td>Compared to the MAC and DAC variants, they are more secure and durable</td>
<td>Microsoft Azure, Google Cloud, Most of the enterprise applications</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6">
<label>6</label>
<title>Scalability Testing</title>
<p>The scalability test of the Triple Layered Approach for Mitigating Security Risks in the Cloud shows how the system responds to workloads of 100, 1000, and 10,000 users in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, which shows trends. From 500 users, latency increases steeply from 50 to 350 ms in <xref ref-type="fig" rid="fig-8">Fig. 8a</xref>, suggesting system bottlenecks for higher workload levels. It becomes apparent that computational requirements have increased from 100 to 10,000 users, from consuming 30% of the CPU to 85% in <xref ref-type="fig" rid="fig-8">Fig. 8b</xref>. Likewise, memory usage in <xref ref-type="fig" rid="fig-8">Fig. 8c</xref> increases from 40% to 95% due to the growing need for memory-bound operations in the system. The error rate also increases from 0.5% at 100 users to 3.8% at 10,000 users in <xref ref-type="fig" rid="fig-8">Fig. 8d</xref>, which indicates that the system&#x2019;s reliability is affected when the system is under pressure. It also underlines current trends to focus on resource management in general and performance in particular, as well as the determination of system thresholds for large-scale workloads.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Scalability test of the triple layered approach for mitigating security risks for 100, 1000, and 10,000 users</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-8.tif"/>
</fig>
</sec>
<sec id="s7">
<label>7</label>
<title>Conclusion</title>
<p>Focusing on data encryption, access management, and intrusion detection systems (IDS), a three-layer secure technique is proposed for cloud security in this paper. This technology uses IDS for intrusion detection, RBAC to control access, and Advanced Encryption Standard (AES) to encrypt data. AES encryption protects Sensitive data during storage and transmission in the Cloud. AES, a well-known and trusted encryption technology, maintains the security and integrity of data while reducing the possibility of illegal access. RBAC, the second layer of the algorithm, provides a systematic method for access control. RBAC secures specific data in the Cloud by allocating roles and specifying pertinent permissions, limiting access to only permitted ones. This layer improves security by imposing stringent access controls based on roles and responsibilities. The intrusion detection system (IDS), which examines network traffic and system records for security breaches and malicious activities, is the attribute of the third layer of the algorithm. This three-layer security algorithm deals with security concerns related to cloud computing, successfully guarding against hostile actions, illegal access, and data breaches.</p>
<p>When the proposed method, TLSA, was compared against the current approaches&#x2014;DES, RSA, and DUAL-RSA&#x2014;it produced impressive results on several performance criteria. Notably, the suggested approach performs better in accuracy, Sensitivity, F-Measure, MSE, signal maximum, QILV, SSIM, PSNR, computation time, and accuracy. The proposed method performed the best, DUAL-RSA, and has the greatest SSIM of 0.8896, indicating that the encoded data&#x2019;s structural similarity is optimally preserved. Moreover, it has the greatest QILV (0.9098), demonstrating its exceptional visual coding performance. The DUAL-RSA&#x2019;s dependability is further supported by precision and sensitivity tests, which show that it has the lowest rates of false positives (87.9%) and false negatives (89.4%), with the greatest F-Measure (91.2%). Together with its efficiency, our suggested technique has an accuracy rate of 93.48%, which makes it a complete and practical solution for cloud computing security. A weakness of the proposed method of enhancing data security is that the DUAL-RSA algorithm forms the core part of the three-layer security system. As can be observed, the average response time of DUAL-RSA is higher than that of TLSA and DES. However, its computation complexity makes its overhead relatively high for a resource-constrained environment. Moreover, the choice of one particular cryptographic technique could restrain innovation and portability to modern cryptographical methods or risks. This could become troublesome, especially in environments where the cloud setup is dynamic, scalable, and agile.</p>
</sec>
</body>
<back>
<ack>
<p>This work was supported by UKRI EPSRC Grant funded Doctoral Training Centre at Swansea University, through PhD project RS718 on Explainable AI.
Authors also have been supported by UKRI EPSRC Grant EP/W020408/1 Project SPRITE+ 2: The Security, Privacy, Identity and Trust Engagement Network plus (phase 2).
The authors acknowledge above financial support.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors have been funded by UKRI EPSRC Grant EP/W020408/1 Project SPRITE+ 2: The Security, Privacy, Identity and Trust Engagement Network plus (phase 2) for this study.
The authors also have been funded by PhD project RS718 on Explainable AI through UKRI EPSRC Grant funded Doctoral Training Centre at Swansea University.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Conceptualization, Tajinder Kumar and Purushottam Sharma; methodology, Xiaochun Cheng; software, Sachin Lalar; validation, Xiaochun Cheng, Purushottam Sharma and Shubham Kumar; formal analysis, Tajinder Kumar; investigation, Tajinder Kumar and Purushottam Sharma; resources, Xiaochun Cheng; data curation, Purushottam Sharma; writing&#x2014;original draft preparation, Tajinder Kumar; writing&#x2014;review and editing, Sachin Lalar and Purushottam Sharma; visualization, Sandhya Bansal; supervision, Sandhya Bansal; project administration, Purushottam Sharma; funding acquisition, Xiaochun Cheng. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The studies are conducted on already available data and materials for which consent is not required.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<app-group id="apg-1">
<app id="app1"><label>Appendix</label><title>A</title>
<p><bold>Algorithms details:</bold></p>
<p><bold>Section 3.3.1:</bold></p>
<p><bold>Advanced Encryption Algorithm:</bold> The round keys are generated form the initial encryption key using the Key Expansion algorithm of AES. Initial round which take the plaintext and an XOR is done between the plaintext and first round key. In each round it has SubBytes (byte substitution using the S-Box), ShiftRows (cyclic shifts in row wise), MixColumns (column mixing for diffusion) and AddRoundKey (XOR with round key).</p>
<p>Key Expansion Algorithm: KeyExpansion expands the key from its initial size (128, 192, or 256 bits). SubWord, RotWord, and Rcon are helper functions used for transformations and round constant application.</p>
<fig id="fig-9">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-9.tif"/>
</fig>
<p>Initial Round Algorithm: Initial Round performs an initial XOR operation between the first round key and the input data block.</p>
<fig id="fig-10">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-10.tif"/>
</fig>
<p>SubBytes Algorithm: SubBytes performs a byte-level substitution operation using a predefined substitution table (S-Box). SubByte(byte) replaces a byte with a corresponding value from the S-Box.</p>
<fig id="fig-11">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-11.tif"/>
</fig>
<p>ShiftRows Algorithm: ShiftRows cyclically shifts the bytes in each row of the data block to the left based on their row index.</p>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-12.tif"/>
</fig>
<p>MixColumns Algorithm: MixColumns Algorithm performs a matrix multiplication operation on each column of the data block using a predefined matrix.</p>
<fig id="fig-13">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-13.tif"/>
</fig>
<p>AddRoundKey Algorithm: AddRoundKey performs an XOR operation between the round key and the current state.</p>
<fig id="fig-14">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-14.tif"/>
</fig>
<fig id="fig-15">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-15.tif"/>
</fig>
<p><bold>Section 3.3.2</bold></p>
<p>User and Role Management: AssignRole(user, Roles) is a helper function that assigns a role to a user based on defined rules and policies. It assigns roles to users based on predefined rules and policies.</p>
<fig id="fig-16">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-16.tif"/>
</fig>
<p><list list-type="simple">
<list-item><label>1.</label><p>Permission Assignment: AssignPermission(role, Permissions) is a helper function that assigns specific permissions to a role. It assigns permissions to roles based on predefined rules and policies.</p></list-item>
</list></p>
<fig id="fig-17">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-17.tif"/>
</fig>
<p><list list-type="simple">
<list-item><label>2.</label><p>Authorization: Authorization relies on the mappings from UserRoles and RolePermissions. It verifies whether a user has the necessary permissions to access a specific resource. Authorization relies on the mappings from UserRoles and RolePermissions. Authentication Mechanisms are used to verify the identity of the user prior to granting access.</p></list-item>
</list></p>
<fig id="fig-18">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-18.tif"/>
</fig>
<fig id="fig-19">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-19.tif"/>
</fig>
<p><bold>Section 3.3.3:</bold></p>
<p>System Monitoring: It Monitors system events to detect potential intrusions or anomalies and generates alerts. AnalyzeEvents(Events) is called to analyze events and identify potential issues.</p>
<fig id="fig-20">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-20.tif"/>
</fig>
<p>Event Analysis: It analyzes each system event to detect potential intrusions or anomalies and generates appropriate alerts. IsIntrusion(event) determines if a specific event indicates a potential intrusion or anomaly. GenerateAlert(event) creates an alert when an intrusion or anomaly is detected.</p>
<fig id="fig-21">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-21.tif"/>
</fig>
<p>Triple Layer Secure Algorithm:</p>
<fig id="fig-22">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_60836-fig-22.tif"/>
</fig>
</app>
</app-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ghosh Ray</surname> <given-names>I</given-names></string-name>, <string-name><surname>Rahulamathavan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Rajarajan</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A new lightweight symmetric searchable encryption scheme for string identification</article-title>. <source>IEEE Trans Cloud Comput</source>. <year>2020</year>;<volume>8</volume>(<issue>3</issue>):<fpage>672</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCC.2018.2820014</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kheddar</surname> <given-names>H</given-names></string-name>, <string-name><surname>Himeur</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Awad</surname> <given-names>AI</given-names></string-name></person-group>. <article-title>Deep transfer learning for intrusion detection in industrial control networks: a comprehensive review</article-title>. <source>J Netw Comput Appl</source>. <year>2023</year>;<volume>220</volume>(<issue>10</issue>):<fpage>103760</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jnca.2023.103760</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Barnes</surname> <given-names>R</given-names></string-name>, <string-name><surname>Bhargavan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lipp</surname> <given-names>B</given-names></string-name>, <string-name><surname>Wood</surname> <given-names>CA</given-names></string-name></person-group>. <article-title>Hybrid public key encryption</article-title>.<source>Internet Research Task Force (IRTF)</source>; <year>2022</year>. doi:<pub-id pub-id-type="doi">10.17487/RFC9180</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mihailescu</surname> <given-names>MI</given-names></string-name>, <string-name><surname>Nita</surname> <given-names>SL</given-names></string-name></person-group>. <article-title>A searchable encryption scheme with biometric authentication and authorization for cloud environments</article-title>. <source>Cryptography</source>. <year>2022</year>;<volume>6</volume>(<issue>1</issue>):<fpage>8</fpage>. doi:<pub-id pub-id-type="doi">10.3390/cryptography6010008</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bauspie&#x00DF;</surname> <given-names>P</given-names></string-name>, <string-name><surname>Kolberg</surname> <given-names>J</given-names></string-name>, <string-name><surname>Drozdowski</surname> <given-names>P</given-names></string-name>, <string-name><surname>Rathgeb</surname> <given-names>C</given-names></string-name>, <string-name><surname>Busch</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Privacy-preserving preselection for protected biometric identification using public-key encryption with keyword search</article-title>. <source>IEEE Trans Ind Inform.</source>. <year>2023</year>;<volume>19</volume>(<issue>5</issue>):<fpage>6972</fpage>&#x2013;<lpage>81</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TII.2022.3199944</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Seth</surname> <given-names>B</given-names></string-name>, <string-name><surname>Dalal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jaglan</surname> <given-names>V</given-names></string-name>, <string-name><surname>Le</surname> <given-names>DN</given-names></string-name>, <string-name><surname>Mohan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Srivastava</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Integrating encryption techniques for secure data storage in the cloud</article-title>. <source>Trans Emerging Tel Tech</source>. <year>2022</year>;<volume>33</volume>(<issue>4</issue>):<fpage>e4108</fpage>. doi:<pub-id pub-id-type="doi">10.1002/ett.4108</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khoda Parast</surname> <given-names>F</given-names></string-name>, <string-name><surname>Sindhav</surname> <given-names>C</given-names></string-name>, <string-name><surname>Nikam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Izadi Yekta</surname> <given-names>H</given-names></string-name>, <string-name><surname>Kent</surname> <given-names>KB</given-names></string-name>, <string-name><surname>Hakak</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Cloud computing security: a survey of service-based models</article-title>. <source>Comput Secur</source>. <year>2022</year>;<volume>114</volume>(<issue>1</issue>):<fpage>102580</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102580</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>T</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>T</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Towards differential access control and privacy-preserving for secure media data sharing in the cloud</article-title>. <source>Comput Secur</source>. <year>2022</year>;<volume>113</volume>(<issue>1</issue>):<fpage>102553</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102553</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Khan</surname> <given-names>JA</given-names></string-name></person-group>. <chapter-title>Role-based access control (RBAC) and attribute-based access control (ABAC)</chapter-title>. In: <source>Improving security, privacy, and trust in cloud computing</source>. <publisher-loc>Hershey, PA, USA</publisher-loc>: <publisher-name>IGI Global</publisher-name>; <year>2024</year>. p. <fpage>113</fpage>&#x2013;<lpage>26</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rao</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Prasad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bera</surname> <given-names>S</given-names></string-name>, <string-name><surname>Das</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Susilo</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Boolean searchable attribute-based signcryption with search results self-verifiability mechanism for data storage and retrieval in clouds</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2024</year>;<volume>17</volume>(<issue>4</issue>):<fpage>1382</fpage>&#x2013;<lpage>99</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TSC.2023.3327816</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chenam</surname> <given-names>VB</given-names></string-name>, <string-name><surname>Ali</surname> <given-names>ST</given-names></string-name></person-group>. <article-title>A designated cloud server-based multi-user certificateless public key authenticated encryption with conjunctive keyword search against IKGA</article-title>. <source>Comput Stand Interfaces</source>. <year>2022</year>;<volume>81</volume>(<issue>4</issue>):<fpage>103603</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.csi.2021.103603</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>N</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>J</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Mohan</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Privacy-preserving multi-keyword hybrid search over encrypted data in cloud</article-title>. <source>J Ambient Intell Humaniz Comput</source>. <year>2024</year>;<volume>15</volume>(<issue>1</issue>):<fpage>261</fpage>&#x2013;<lpage>74</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s12652-022-03889-8</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kousalya</surname> <given-names>A</given-names></string-name>, <string-name><surname>Baik</surname> <given-names>NK</given-names></string-name></person-group>. <article-title>Enhance cloud security and effectiveness using improved RSA-based RBAC with XACML technique</article-title>. <source>Int J Intell Netw</source>. <year>2023</year>;<volume>4</volume>(<issue>7</issue>):<fpage>62</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ijin.2023.03.003</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Joshi</surname> <given-names>NS</given-names></string-name>, <string-name><surname>Sambrekar</surname> <given-names>KP</given-names></string-name></person-group>. <article-title>Privacy-preserving and ranked search using advanced multi-keyword scheme over the encrypted cloud environment</article-title>. <source>J Electr Syst</source>. <year>2024</year>;<volume>20</volume>(<issue>1s</issue>):<fpage>353</fpage>&#x2013;<lpage>65</lpage>. doi:<pub-id pub-id-type="doi">10.52783/jes.776</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Varri</surname> <given-names>US</given-names></string-name>, <string-name><surname>Mallick</surname> <given-names>D</given-names></string-name>, <string-name><surname>Das</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Hossain</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Park</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Rodrigues</surname> <given-names>JJPC</given-names></string-name></person-group>. <article-title>TL-ABKS: traceable and lightweight attribute-based keyword search in edge-cloud assisted IoT environment</article-title>. <source>Alex Eng J</source>. <year>2024</year>;<volume>107</volume>(<issue>101</issue>):<fpage>757</fpage>&#x2013;<lpage>69</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.aej.2024.09.030</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rao</surname> <given-names>KR</given-names></string-name>, <string-name><surname>Ray</surname> <given-names>IG</given-names></string-name>, <string-name><surname>Asif</surname> <given-names>W</given-names></string-name>, <string-name><surname>Nayak</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rajarajan</surname> <given-names>M</given-names></string-name></person-group>. <article-title>R-PEKS: RBAC enabled PEKS for secure access of cloud data</article-title>. <source>IEEE Access</source>. <year>2019</year>;<volume>7</volume>:<fpage>133274</fpage>&#x2013;<lpage>89</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2019.2941560</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Javadpour</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ja&#x2019;fari</surname> <given-names>F</given-names></string-name>, <string-name><surname>Taleb</surname> <given-names>T</given-names></string-name>, <string-name><surname>Benza&#x00EF;d</surname> <given-names>C</given-names></string-name>, <string-name><surname>Bin</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Encryption as a service (EaaS): introducing the full-cloud-fog architecture for enhanced performance and security</article-title>. <source>IEEE Internet Things J</source>. <year>2024</year>;<volume>11</volume>(<issue>24</issue>):<fpage>39744</fpage>&#x2013;<lpage>66</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2024.3450192</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Verma</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Blockchain-based privacy preservation framework for healthcare data in cloud environment</article-title>. <source>J Exp Theor Artif Intell</source>. <year>2024</year>;<volume>36</volume>(<issue>1</issue>):<fpage>147</fpage>&#x2013;<lpage>60</lpage>. doi:<pub-id pub-id-type="doi">10.1080/0952813X.2022.2135611</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>T</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Identity-based integrity auditing scheme with sensitive information hiding for proxy-server-assisted cloud storage applications</article-title>. <source>IEEE Internet Things J</source>. <year>2024</year>;<fpage>1</fpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2024.3491315</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Femminella</surname> <given-names>M</given-names></string-name>, <string-name><surname>Palmucci</surname> <given-names>M</given-names></string-name>, <string-name><surname>Reali</surname> <given-names>G</given-names></string-name>, <string-name><surname>Rengo</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Attribute-based management of secure Kubernetes cloud bursting</article-title>. <source>IEEE Open J Commun Soc</source>. <year>2024</year>;<volume>5</volume>:<fpage>1276</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1109/OJCOMS.2024.3367461</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Meng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Du</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>C</given-names></string-name></person-group>. <article-title>ECMO: an efficient and confidential outsourcing protocol for medical data</article-title>. <source>IEEE Open J Comput Soc</source>. <year>2024</year>;<volume>6</volume>:<fpage>37</fpage>&#x2013;<lpage>48</lpage>. doi:<pub-id pub-id-type="doi">10.1109/OJCS.2024.3506114</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Arundathi</surname> <given-names>JS</given-names></string-name>, <string-name><surname>Satyanarayana</surname> <given-names>KV</given-names></string-name></person-group>. <article-title>A secure and efficient framework for multi-user encrypted cloud databases supporting single and multiple keyword searches</article-title>. <source>Int J Adv Comput Sci Appl</source>. <year>2024</year>;<volume>15</volume>(<issue>9</issue>):<fpage>537</fpage>&#x2013;<lpage>46</lpage>. doi:<pub-id pub-id-type="doi">10.14569/issn.2156-5570</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bhansali</surname> <given-names>PK</given-names></string-name>, <string-name><surname>Hiran</surname> <given-names>D</given-names></string-name>, <string-name><surname>Kothari</surname> <given-names>H</given-names></string-name>, <string-name><surname>Gulati</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Cloud-based secure data storage and access control for Internet of medical things using federated learning</article-title>. <source>Int J Pervasive Comput Commun</source>. <year>2024</year>;<volume>20</volume>(<issue>2</issue>):<fpage>228</fpage>&#x2013;<lpage>39</lpage>. doi:<pub-id pub-id-type="doi">10.1108/IJPCC-02-2022-0041</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saha</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chowdhury</surname> <given-names>C</given-names></string-name>, <string-name><surname>Neogy</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A novel two phase data sensitivity based access control framework for healthcare data</article-title>. <source>Multimed Tools Appl</source>. <year>2024</year>;<volume>83</volume>(<issue>3</issue>):<fpage>8867</fpage>&#x2013;<lpage>92</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11042-023-15427-5</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Samala</surname> <given-names>AD</given-names></string-name>, <string-name><surname>Rawas</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Transforming healthcare data management: a blockchain-based cloud EHR system for enhanced security and interoperability</article-title>. <source>Int J Onl Eng</source>. <year>2024</year>;<volume>20</volume>(<issue>2</issue>):<fpage>46</fpage>&#x2013;<lpage>60</lpage>. doi:<pub-id pub-id-type="doi">10.3991/ijoe.v20i02.45693</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Besharati</surname> <given-names>E</given-names></string-name>, <string-name><surname>Naderan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Namjoo</surname> <given-names>E</given-names></string-name></person-group>. <article-title>LR-HIDS: logistic regression host-based intrusion detection system for cloud environments</article-title>. <source>J Ambient Intell Humaniz Comput</source>. <year>2019</year>;<volume>10</volume>(<issue>9</issue>):<fpage>3669</fpage>&#x2013;<lpage>92</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s12652-018-1093-8</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Autonomous path identity-based broadcast proxy re-encryption for data sharing in clouds</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>(<issue>1</issue>):<fpage>87322</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2022.3200084</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kheddar</surname> <given-names>H</given-names></string-name>, <string-name><surname>Dawoud</surname> <given-names>DW</given-names></string-name>, <string-name><surname>Awad</surname> <given-names>AI</given-names></string-name>, <string-name><surname>Himeur</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MK</given-names></string-name></person-group>. <article-title>Reinforcement-learning-based intrusion detection in communication networks: a review</article-title>. <source>IEEE Commun Surv Tutor</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.1109/COMST.2024.3484491</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xie</surname> <given-names>M</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Hong</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wei</surname> <given-names>G</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>A novel verifiable Chinese multi-keyword fuzzy rank searchable encryption scheme in cloud environments</article-title>. <source>Future Gener Comput Syst</source>. <year>2024</year>;<volume>153</volume>(<issue>3</issue>):<fpage>287</fpage>&#x2013;<lpage>300</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2023.11.017</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Agarwal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>P</given-names></string-name>, <string-name><surname>Alshehri</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mohamed</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Alfarraj</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Classification model for accuracy and intrusion detection using machine learning approach</article-title>. <source>PeerJ Comput Sci</source>. <year>2021</year>;<volume>7</volume>(<issue>3</issue>):<fpage>e437</fpage>. doi:<pub-id pub-id-type="doi">10.7717/peerj-cs.437</pub-id>; <pub-id pub-id-type="pmid">33954233</pub-id></mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Deng</surname> <given-names>H</given-names></string-name>, <string-name><surname>Qin</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Guan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Deng</surname> <given-names>RH</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Identity-based encryption transformation for flexible sharing of encrypted data in public cloud</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2020</year>;<volume>15</volume>:<fpage>3168</fpage>&#x2013;<lpage>80</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2020.2985532</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saxena</surname> <given-names>UR</given-names></string-name>, <string-name><surname>Alam</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Role-based access using partial homomorphic encryption for securing cloud data</article-title>. <source>Int J Syst Assur Eng Manag</source>. <year>2023</year>;<volume>14</volume>(<issue>3</issue>):<fpage>950</fpage>&#x2013;<lpage>66</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s13198-023-01896-2</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A lattice-based searchable encryption scheme with multi-user authorization for the certificateless cloud computing environment</article-title>. <source>Trans Emerging Tel Tech</source>. <year>2024</year>;<volume>35</volume>(<issue>4</issue>):<fpage>e4960</fpage>. doi:<pub-id pub-id-type="doi">10.1002/ett.4960</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>