Blockchain-Enabled Zero Trust Architecture for Secure Cloud Computing and Continuous Cybersecurity Risk Auditing Framework Implementation
Mohammed Almaiah : King Abdullah the II IT School, The University of Jordan, Amman 11942, Jordan, JOR
Santosh Reddy Addula: Department of Information Technology, University of the Cumberlands, Williamsburg, Kentucky, USA, USA
Published: 2026/09/02
Pages: 1–32
Abstract
Traditional cloud security controls tend to treat access, vulnerability exposure, and audit integrity as distinct functions, reducing the ability to be aware of risks on an ongoing basis. In this study, the authors present a blockchain-based zero-trust risk auditing framework for adaptive cloud protection (ACP) called BAZTRA. BAZTRA is a combination of a GBDT-based network-risk estimator and identity, device-posture, provenance, vulnerability, and compliance evidence. The CICIoT2023 corpus, controlled contextual replay, and repeated ten-seed experiments were used to evaluate the following techniques: availability-aware fusion, temporal smoothing, four-state enforcement, EPSS-KEV prioritization, hash chaining, and Merkle-based audit anchoring. Statistical significance was assessed using Friedman and Holm-corrected Wilcoxon tests across repetitions. The selected network-risk estimator achieved 78.96% accuracy, 55.01% macro-F1, 0.964 ROC-AUC, and 0.718 MCC. The complete BAZTRA framework produced 89.44% decision macro-F1, reduced unsafe access to 0.67%, and limited false denial to 0.03%. Ablation confirmed that adaptive enforcement, network evidence, provenance analysis, and availability-aware normalization were the most influential components. Merkle batching reduced effective ledger payload by 98.21% while preserving detection of modification, deletion, reordering, and replay attempts. BAZTRA provides a unified approach to continuous access assessment, vulnerability prioritization, and accountable cloud auditing. Future work will validate the framework on complete multi-source telemetry and a physical multi-peer Hyperledger Fabric deployment.
Keywords
Blockchain-Enabled Zero Trust Architecture for Secure Cloud Computing and Continuous Cybersecurity Risk Auditing Framework Implementation is licensed under CC BY 4.0
References
- Alshammari, S. T., Al-Razgan, M., Alfakih, T., & AlGhamdi, K. A. (2024). Building a comprehensive trust evaluation model to secure cloud services from reputation attacks. IEEE Access, 12, 150754–150775. https://doi.org/10.1109/ACCESS.2024.3471337
- Wang, C., Sun, Y., Liu, B., Xue, L., & Guan, X. (2024). Blockchain-based dynamic cloud data integrity auditing via non-leaf node sampling of rank-based Merkle hash tree. IEEE Transactions on Network Science and Engineering, 11(5), 3931-3942. https://doi.org/10.1109/TNSE.2024.3393978
- Li, R., Zhou, T., Han, Y., et al. (2025). Integrated protocol for verifiable confidential cloud computing and data integrity auditing. Journal of King Saud University—Computer and Information Sciences, 37, Article 299. https://doi.org/10.1007/s44443-025-00288-9
- Nie, S., Ren, J., Wu, R., Han, P., Han, Z., & Wan, W. (2025). Zero-trust access control mechanism based on blockchain and inner-product encryption in the internet of things in a 6g environment. Sensors, 25(2), 550. https://doi.org/10.3390/s25020550
- Zhang, J., Zheng, J., Shi, N., Ci, Z., Wang, Y., & Zhu, L. (2025). Toward mitigating APT attacks with zero-trust networks access control model. IEEE Internet of Things Journal, 12(19), 41215–41231. https://doi.org/10.1109/JIOT.2025.3592616
- Mostafa, M., Mohamed, E. R., Hanafy, A., Alserhani, F., Alwakid, G. N., Medhat, R., Ezz, M., & Alsirhani, A. (2025). Decentralized identity management in cloud computing: A blockchain-based solution with automatic provisioning techniques. International Journal of Intelligent Systems, Article 2969737. https://doi.org/10.1155/int/2969737
- Ghiasvand, E., Ray, S., Iqbal, S., Dadkhah, S., & Ghorbani, A. A. (2024, November). Resilience against APTs: A provenance-based IIoT dataset for cybersecurity research. In International Conference on Mobile and Ubiquitous Systems: Computing, Networking, and Services (pp. 121-144). Cham: Springer Nature Switzerland.
- Bailey, P. E., & Leon, T. (2019). A systematic review and meta-analysis of age-related differences in trust. Psychology and aging, 34(5), 674.
- Zhang, Y., Xiong, L., Li, F., Niu, X., & Wu, H. (2023). A blockchain-based privacy-preserving auditable authentication scheme with hierarchical access control for mobile cloud computing. Journal of Systems Architecture, 142, Article 102949. https://doi.org/10.1016/j.sysarc.2023.102949
- Azbeg, K., Ouchetto, O., & Andaloussi, S. J. (2022). BlockMedCare: A healthcare system based on IoT, Blockchain and IPFS for data management security. Egyptian informatics journal, 23(2), 329-343.
- Zhu, L., Wu, Y., Gai, K., & Choo, K. K. R. (2019). Controllable and trustworthy blockchain-based cloud data management. Future generation computer systems, 91, 527-535.
- Wang, L., Guan, Z., Chen, Z., & Hu, M. (2023). Enabling integrity and compliance auditing in blockchain-based GDPR-compliant data management. IEEE Internet of Things Journal, 10(23), 20955–20968. https://doi.org/10.1109/JIOT.2023.3285211
- Liu, Z., Wang, S., & Liu, Y. (2023). Blockchain-based integrity auditing for shared data in cloud storage with file prediction. Computer Networks, 236, Article 110040. https://doi.org/10.1016/j.comnet.2023.110040
- Phiayura, P., & Teerakanok, S. (2023). A comprehensive framework for migrating to zero trust architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3248622
- Wen, L., Zhang, L., & Li, J. (2018, November). Application of blockchain technology in data management: advantages and solutions. In International Conference on Big Scientific Data Management (pp. 239-254). Cham: Springer International Publishing.
- Liu, Y., Hao, X., Ren, W., Xiong, R., Zhu, T., Choo, K. K. R., & Min, G. (2022). A blockchain-based decentralized, fair and authenticated information sharing scheme in zero trust internet-of-things. IEEE Transactions on Computers, 72(2), 501-512.
- Itodo, C., & Ozer, M. (2024). Multivocal literature review on zero-trust security implementation. Computers & Security, 141, Article 103827. https://doi.org/10.1016/j.cose.2024.103827
- Ali, Z., Marotta, A., Tiberti, W., Odoardi, O., Cassioli, D., & Di Marco, P. (2025, October). Enhancing IIoT Security: BERT-Driven Intrusion Detection with MLP in Industrial Networks. In 2025 IEEE 11th World Forum on Internet of Things (WF-IoT) (pp. 1-7). IEEE.
- Zhu, H., Xue, X., Xu, M., Kim, B.-G., Lyu, X., & Rani, S. (2025). Zero-trust blockchain-enabled secure next-generation healthcare communication network. IEEE Transactions on Network and Service Management, 22(4), 3201–3212. https://doi.org/10.1109/TNSM.2024.3473016
- Bradatsch, L., Miroshkin, O., & Kargl, F. (2023). ZTSFC: A service function chaining-enabled zero trust architecture. IEEE Access, 11, 125307–125327. https://doi.org/10.1109/ACCESS.2023.3330706
- Punia, A., Gulia, P., Gill, N. S., Ibeke, E., Iwendi, C., & Shukla, P. K. (2024). A systematic review on blockchain-based access control systems in cloud environment. Journal of Cloud Computing, 13(1), 146. https://doi.org/10.1186/s13677-024-00697-7
- Xu, Y., Jin, C., Qin, W., Zhao, J., Chen, G., & Zeng, F. (2024). BDACD: Blockchain-based decentralized auditing supporting ciphertext deduplication. Journal of Systems Architecture, 147, Article 103053. https://doi.org/10.1016/j.sysarc.2023.103053
- Al-Hawawreh, M., Sitnikova, E., & Aboutorab, N. (2021). X-IIoTID: A connectivity-agnostic and device-agnostic intrusion data set for industrial Internet of Things. IEEE Internet of Things Journal, 9(5), 3962-3977.
- Zhang, H., Zhang, Z., & Chen, L. (2025). Toward zero trust in 5G Industrial Internet collaboration systems. Digital Communications and Networks, 11(2), 547–555. https://doi.org/10.1016/j.dcan.2024.03.011
- Du, Z., Li, Y., Fu, Y., & Zheng, X. (2024). Blockchain-based access control architecture for multi-domain environments. Pervasive and Mobile Computing, 98, Article 101878. https://doi.org/10.1016/j.pmcj.2024.101878
- Ud Din, K., Habib Khan, K., Almogren, A., Zareei, M., & Pérez Díaz, J. A. (2024). Securing the metaverse: A blockchain-enabled zero-trust architecture for virtual environments. IEEE Access, 12, 92337–92347. https://doi.org/10.1109/ACCESS.2024.3423400
- Hassan, A., Rauf, A., Shafqat, N., Latif, R., & Khan, H. (2025). ZenGuard a machine learning based zero trust framework for context aware threat mitigation using SIEM SOAR and UEBA. Scientific Reports, 15(1), 35871. https://doi.org/10.1038/s41598-025-20998-4
- Fernandez, E. B., & Brazhuk, A. (2024). A critical analysis of Zero Trust Architecture (ZTA). Computer Standards & Interfaces, 89, 103832.
- Kumar, R., & Bhatia, M. P. S. (2024). An intelligent optimized secure blockchain mechanism for cloud auditing. Expert Systems with Applications, 255, Part B, Article 124593. https://doi.org/10.1016/j.eswa.2024.124593
- Diaz Rivera, J., Muhammad, A., & Song, W.-C. (2024). Securing digital identity in the zero trust architecture: A blockchain approach to privacy-focused multi-factor authentication. IEEE Open Journal of the Communications Society, 5, 2792–2814. https://doi.org/10.1109/OJCOMS.2024.3391728
- Abdelmagid, A. M., & Diaz, R. (2025). Zero trust architecture as a risk countermeasure in small–medium enterprises and advanced technology systems. Risk Analysis, 45, 2390–2414. https://doi.org/10.1111/risa.70026
- Gatti, G., Valero, J. M. J., Gil Pérez, M., & Basile, C. (2025). Holistic cyber risk assessment in the cloud continuum: A multi-layer, multi-domain approach. IEEE Access, 13, 180593–180612. https://doi.org/10.1109/ACCESS.2025.3622915
- Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of zero trust architecture across domains. Sensors, 25(19), Article 6118. https://doi.org/10.3390/s25196118
- Song, M., Hua, Z., Zheng, Y., Huang, H., & Jia, X. (2023). Blockchain-based deduplication and integrity auditing over encrypted cloud storage. IEEE Transactions on Dependable and Secure Computing, 20(6), 4928–4945. https://doi.org/10.1109/TDSC.2023.3237221
- Dhanapala, S., Bharti, S., McGibney, A., & Rea, S. (2024). Toward a performance-based trustworthy edge-cloud continuum. IEEE Access, 12, 99201–99212. https://doi.org/10.1109/ACCESS.2024.3429197
- Li, J., Wu, J., Jiang, L., & Li, J. (2024). Blockchain-based public auditing with deep reinforcement learning for cloud storage. Expert Systems with Applications, 242, Article 122764. https://doi.org/10.1016/j.eswa.2023.122764
- Hong, S., Xu, L., Huang, J., Li, H., Hu, H., & Gu, G. (2023). SysFlow: Toward a programmable zero trust framework for system security. IEEE Transactions on Information Forensics and Security, 18, 2794–2809. https://doi.org/10.1109/TIFS.2023.3264152
- Li, S., Xu, C., Zhang, Y., Du, Y., & Chen, K. (2023). Blockchain-based transparent integrity auditing and encrypted deduplication for cloud storage. IEEE Transactions on Services Computing, 16(1), 134–146. https://doi.org/10.1109/TSC.2022.3144430
- Román-Martínez, J., Calvillo-Arbizu, J., Mayor-Gallego, V. J., Madinabeitia-Luque, G., Estepa-Alonso, A. J., & Estepa-Alonso, R. M. (2023). Blockchain-based service-oriented architecture for consent management, access control, and auditing. IEEE Access, 11, 12727–12741. https://doi.org/10.1109/ACCESS.2023.3242605
- Miao, Y., Gai, K., Zhu, L., Choo, K.-K. R., & Vaidya, J. (2024). Blockchain-based shared data integrity auditing and deduplication. IEEE Transactions on Dependable and Secure Computing, 21(4), 3688–3703. https://doi.org/10.1109/TDSC.2023.3335413
- Alharbi, A. (2023). Applying access control enabled blockchain (ACE-BC) framework to manage data security in the CIS system. Sensors, 23(6), Article 3020. https://doi.org/10.3390/s23060320
- Rivera, J. J. D., Muhammad, A., & Song, W. C. (2024). Securing digital identity in the zero trust architecture: A blockchain approach to privacy-focused multi-factor authentication. IEEE Open Journal of the Communications Society, 5, 2792-2814.
- Zichichi, M., D’Angelo, G., Ferretti, S., & Marzolla, M. (2023). Accountable clouds through blockchain. IEEE Access, 11, 48358–48374. https://doi.org/10.1109/ACCESS.2023.3276240
- Du, G., Dong, G., Ning, J., Xu, Z., & Yang, R. (2023). A blockchain-assisted certificateless public cloud data integrity auditing scheme. IEEE Access, 11, 123018–123029. https://doi.org/10.1109/ACCESS.2023.3329558
- Federici, F., Martintoni, D., & Senni, V. (2023). A zero-trust architecture for remote access in industrial IoT infrastructures. Electronics, 12(3), 566.
- Firouzi, A., Dadkhah, S., Maret, S. A., & Ghorbani, A. A. (2025). DataSense: A real-time sensor-based benchmark dataset for attack analysis in IIoT with multi-objective feature selection. Electronics, 14(20), Article 4095. https://doi.org/10.3390/electronics14204095
- Javed, S. H., Ahmad, M. B., Asif, M., Akram, W., Mahmood, K., Das, A. K., & Shetty, S. (2023). APT adversarial defence mechanism for industrial IoT enabled cyber-physical system. IEEE Access, 11, 74000-74020.
- Neto, E. C. P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., & Ghorbani, A. A. (2023). CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors, 23(13), Article 5941. https://doi.org/10.3390/s23135941