[Paper Review] A Reliable User Authentication and Data Protection Model in Cloud Computing Environments
This paper proposes a dual-encryption user authentication and data protection model in cloud computing using AES (symmetric) in cloud servers and RSA (asymmetric) in an independent middleware agent. The model enhances resistance to attacks and unpredictable events through dual encryption and isolated trust, demonstrating improved reliability over existing approaches in theoretical evaluation.
Security issues are the most challenging problems in cloud computing environments as an emerging technology. Regarding to this importance, an efficient and reliable user authentication and data protection model has been presented in this paper to increase the rate of reliability cloud-based environments. Accordingly, two encryption procedures have been established in an independent middleware (Agent) to perform the process of user authentication, access control, and data protection in cloud servers. AES has been used as a symmetric cryptography algorithm in cloud servers and RSA has been used as an asymmetric cryptography algorithm in Agent servers. The theoretical evaluation of the proposed model shows that the ability of resistance in face with possible attacks and unpredictable events has been enhanced considerably in comparison with similar models because of using dual encryption and an independent middleware during user authentication and data protection procedures.
Motivation & Objective
- To address critical security challenges in cloud computing environments, particularly in user authentication and data protection.
- To improve system reliability by reducing vulnerability to attacks and unpredictable events.
- To design a secure, scalable architecture that separates authentication and encryption logic from cloud servers.
- To leverage both symmetric and asymmetric cryptography for layered protection in cloud-based systems.
- To evaluate the model's resilience against common threats through theoretical analysis.
Proposed method
- The system employs an independent middleware (Agent) to handle user authentication and access control, isolating sensitive operations from cloud servers.
- AES (Advanced Encryption Standard) is used as the symmetric encryption algorithm within cloud servers for efficient data protection.
- RSA (Rivest–Shamir–Adleman) is implemented in the Agent servers for asymmetric key management and secure key exchange.
- Dual encryption is applied during authentication and data protection processes, combining AES and RSA for enhanced security.
- The middleware acts as a trusted intermediary, managing user credentials and access decisions without exposing them to the cloud infrastructure.
- Theoretical evaluation assesses resistance to common attacks, including man-in-the-middle and replay attacks, based on cryptographic strength and architectural isolation.
Experimental results
Research questions
- RQ1How can user authentication and data protection be made more reliable in cloud computing environments?
- RQ2What role does an independent middleware play in enhancing security and trust in cloud-based systems?
- RQ3How does dual encryption (AES + RSA) improve resistance to cryptographic attacks compared to single-encryption models?
- RQ4To what extent does architectural isolation of authentication logic reduce exposure to threats?
- RQ5What theoretical improvements in resilience can be achieved through the proposed model?
Key findings
- The proposed model significantly enhances resistance to potential attacks and unpredictable events due to the use of dual encryption and an isolated middleware architecture.
- Theoretical evaluation confirms improved security properties, including stronger confidentiality and integrity guarantees during authentication and data transfer.
- The separation of authentication logic into a dedicated, independent Agent reduces the attack surface of the cloud infrastructure.
- The integration of AES for performance and RSA for key management provides a balanced approach to efficiency and security.
- The model demonstrates a higher level of reliability compared to similar existing models, as validated through theoretical analysis of cryptographic resilience.
- The architecture effectively mitigates risks associated with key exposure and unauthorized access by centralizing trust in the middleware.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.