Journal of Cybersecurity in AI and Quantum Computing

ISSN: Pending Request (Online)Peer ReviewedOpen AccessOpen Access
open accessOpen Access

research

👁️6views

Blockchain-Enabled Zero Trust Architecture for Secure Cloud Computing and Continuous Cybersecurity Risk Auditing Framework Implementation

Volume 2026, Issue 1ISSN: Pending Request (Online)Journal: Journal of Cybersecurity in AI and Quantum Computing
by 

Mohammed Almaiah ORCID profile ;

Santosh Reddy Addula ORCID profile

Mohammed Almaiah : King Abdullah the II IT School, The University of Jordan, Amman 11942, Jordan, JOR

Santosh Reddy Addula: Department of Information Technology, University of the Cumberlands, Williamsburg, Kentucky, USA, USA

PDF logoPDF

Published: 2026/09/02

Pages: 132

Abstract

Traditional cloud security controls tend to treat access, vulnerability exposure, and audit integrity as distinct functions, reducing the ability to be aware of risks on an ongoing basis. In this study, the authors present a blockchain-based zero-trust risk auditing framework for adaptive cloud protection (ACP) called BAZTRA. BAZTRA is a combination of a GBDT-based network-risk estimator and identity, device-posture, provenance, vulnerability, and compliance evidence. The CICIoT2023 corpus, controlled contextual replay, and repeated ten-seed experiments were used to evaluate the following techniques: availability-aware fusion, temporal smoothing, four-state enforcement, EPSS-KEV prioritization, hash chaining, and Merkle-based audit anchoring. Statistical significance was assessed using Friedman and Holm-corrected Wilcoxon tests across repetitions. The selected network-risk estimator achieved 78.96% accuracy, 55.01% macro-F1, 0.964 ROC-AUC, and 0.718 MCC. The complete BAZTRA framework produced 89.44% decision macro-F1, reduced unsafe access to 0.67%, and limited false denial to 0.03%. Ablation confirmed that adaptive enforcement, network evidence, provenance analysis, and availability-aware normalization were the most influential components. Merkle batching reduced effective ledger payload by 98.21% while preserving detection of modification, deletion, reordering, and replay attempts. BAZTRA provides a unified approach to continuous access assessment, vulnerability prioritization, and accountable cloud auditing. Future work will validate the framework on complete multi-source telemetry and a physical multi-peer Hyperledger Fabric deployment.

Keywords

Blockchain-Enabled Zero TrustCloud SecurityContinuous Risk AuditingVulnerability IntelligenceImmutable Audit Trail.

References

  1. Alshammari, S. T., Al-Razgan, M., Alfakih, T., & AlGhamdi, K. A. (2024). Building a comprehensive trust evaluation model to secure cloud services from reputation attacks. IEEE Access, 12, 150754–150775. https://doi.org/10.1109/ACCESS.2024.3471337
  2. Wang, C., Sun, Y., Liu, B., Xue, L., & Guan, X. (2024). Blockchain-based dynamic cloud data integrity auditing via non-leaf node sampling of rank-based Merkle hash tree. IEEE Transactions on Network Science and Engineering, 11(5), 3931-3942. https://doi.org/10.1109/TNSE.2024.3393978
  3. Li, R., Zhou, T., Han, Y., et al. (2025). Integrated protocol for verifiable confidential cloud computing and data integrity auditing. Journal of King Saud University—Computer and Information Sciences, 37, Article 299. https://doi.org/10.1007/s44443-025-00288-9
  4. Nie, S., Ren, J., Wu, R., Han, P., Han, Z., & Wan, W. (2025). Zero-trust access control mechanism based on blockchain and inner-product encryption in the internet of things in a 6g environment. Sensors, 25(2), 550. https://doi.org/10.3390/s25020550
  5. Zhang, J., Zheng, J., Shi, N., Ci, Z., Wang, Y., & Zhu, L. (2025). Toward mitigating APT attacks with zero-trust networks access control model. IEEE Internet of Things Journal, 12(19), 41215–41231. https://doi.org/10.1109/JIOT.2025.3592616
  6. Mostafa, M., Mohamed, E. R., Hanafy, A., Alserhani, F., Alwakid, G. N., Medhat, R., Ezz, M., & Alsirhani, A. (2025). Decentralized identity management in cloud computing: A blockchain-based solution with automatic provisioning techniques. International Journal of Intelligent Systems, Article 2969737. https://doi.org/10.1155/int/2969737
  7. Ghiasvand, E., Ray, S., Iqbal, S., Dadkhah, S., & Ghorbani, A. A. (2024, November). Resilience against APTs: A provenance-based IIoT dataset for cybersecurity research. In International Conference on Mobile and Ubiquitous Systems: Computing, Networking, and Services (pp. 121-144). Cham: Springer Nature Switzerland.
  8. Bailey, P. E., & Leon, T. (2019). A systematic review and meta-analysis of age-related differences in trust. Psychology and aging, 34(5), 674.
  9. Zhang, Y., Xiong, L., Li, F., Niu, X., & Wu, H. (2023). A blockchain-based privacy-preserving auditable authentication scheme with hierarchical access control for mobile cloud computing. Journal of Systems Architecture, 142, Article 102949. https://doi.org/10.1016/j.sysarc.2023.102949
  10. Azbeg, K., Ouchetto, O., & Andaloussi, S. J. (2022). BlockMedCare: A healthcare system based on IoT, Blockchain and IPFS for data management security. Egyptian informatics journal, 23(2), 329-343.
  11. Zhu, L., Wu, Y., Gai, K., & Choo, K. K. R. (2019). Controllable and trustworthy blockchain-based cloud data management. Future generation computer systems, 91, 527-535.
  12. Wang, L., Guan, Z., Chen, Z., & Hu, M. (2023). Enabling integrity and compliance auditing in blockchain-based GDPR-compliant data management. IEEE Internet of Things Journal, 10(23), 20955–20968. https://doi.org/10.1109/JIOT.2023.3285211
  13. Liu, Z., Wang, S., & Liu, Y. (2023). Blockchain-based integrity auditing for shared data in cloud storage with file prediction. Computer Networks, 236, Article 110040. https://doi.org/10.1016/j.comnet.2023.110040
  14. Phiayura, P., & Teerakanok, S. (2023). A comprehensive framework for migrating to zero trust architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3248622
  15. Wen, L., Zhang, L., & Li, J. (2018, November). Application of blockchain technology in data management: advantages and solutions. In International Conference on Big Scientific Data Management (pp. 239-254). Cham: Springer International Publishing.
  16. Liu, Y., Hao, X., Ren, W., Xiong, R., Zhu, T., Choo, K. K. R., & Min, G. (2022). A blockchain-based decentralized, fair and authenticated information sharing scheme in zero trust internet-of-things. IEEE Transactions on Computers, 72(2), 501-512.
  17. Itodo, C., & Ozer, M. (2024). Multivocal literature review on zero-trust security implementation. Computers & Security, 141, Article 103827. https://doi.org/10.1016/j.cose.2024.103827
  18. Ali, Z., Marotta, A., Tiberti, W., Odoardi, O., Cassioli, D., & Di Marco, P. (2025, October). Enhancing IIoT Security: BERT-Driven Intrusion Detection with MLP in Industrial Networks. In 2025 IEEE 11th World Forum on Internet of Things (WF-IoT) (pp. 1-7). IEEE.
  19. Zhu, H., Xue, X., Xu, M., Kim, B.-G., Lyu, X., & Rani, S. (2025). Zero-trust blockchain-enabled secure next-generation healthcare communication network. IEEE Transactions on Network and Service Management, 22(4), 3201–3212. https://doi.org/10.1109/TNSM.2024.3473016
  20. Bradatsch, L., Miroshkin, O., & Kargl, F. (2023). ZTSFC: A service function chaining-enabled zero trust architecture. IEEE Access, 11, 125307–125327. https://doi.org/10.1109/ACCESS.2023.3330706
  21. Punia, A., Gulia, P., Gill, N. S., Ibeke, E., Iwendi, C., & Shukla, P. K. (2024). A systematic review on blockchain-based access control systems in cloud environment. Journal of Cloud Computing, 13(1), 146. https://doi.org/10.1186/s13677-024-00697-7
  22. Xu, Y., Jin, C., Qin, W., Zhao, J., Chen, G., & Zeng, F. (2024). BDACD: Blockchain-based decentralized auditing supporting ciphertext deduplication. Journal of Systems Architecture, 147, Article 103053. https://doi.org/10.1016/j.sysarc.2023.103053
  23. Al-Hawawreh, M., Sitnikova, E., & Aboutorab, N. (2021). X-IIoTID: A connectivity-agnostic and device-agnostic intrusion data set for industrial Internet of Things. IEEE Internet of Things Journal, 9(5), 3962-3977.
  24. Zhang, H., Zhang, Z., & Chen, L. (2025). Toward zero trust in 5G Industrial Internet collaboration systems. Digital Communications and Networks, 11(2), 547–555. https://doi.org/10.1016/j.dcan.2024.03.011
  25. Du, Z., Li, Y., Fu, Y., & Zheng, X. (2024). Blockchain-based access control architecture for multi-domain environments. Pervasive and Mobile Computing, 98, Article 101878. https://doi.org/10.1016/j.pmcj.2024.101878
  26. Ud Din, K., Habib Khan, K., Almogren, A., Zareei, M., & Pérez Díaz, J. A. (2024). Securing the metaverse: A blockchain-enabled zero-trust architecture for virtual environments. IEEE Access, 12, 92337–92347. https://doi.org/10.1109/ACCESS.2024.3423400
  27. Hassan, A., Rauf, A., Shafqat, N., Latif, R., & Khan, H. (2025). ZenGuard a machine learning based zero trust framework for context aware threat mitigation using SIEM SOAR and UEBA. Scientific Reports, 15(1), 35871. https://doi.org/10.1038/s41598-025-20998-4
  28. Fernandez, E. B., & Brazhuk, A. (2024). A critical analysis of Zero Trust Architecture (ZTA). Computer Standards & Interfaces, 89, 103832.
  29. Kumar, R., & Bhatia, M. P. S. (2024). An intelligent optimized secure blockchain mechanism for cloud auditing. Expert Systems with Applications, 255, Part B, Article 124593. https://doi.org/10.1016/j.eswa.2024.124593
  30. Diaz Rivera, J., Muhammad, A., & Song, W.-C. (2024). Securing digital identity in the zero trust architecture: A blockchain approach to privacy-focused multi-factor authentication. IEEE Open Journal of the Communications Society, 5, 2792–2814. https://doi.org/10.1109/OJCOMS.2024.3391728
  31. Abdelmagid, A. M., & Diaz, R. (2025). Zero trust architecture as a risk countermeasure in small–medium enterprises and advanced technology systems. Risk Analysis, 45, 2390–2414. https://doi.org/10.1111/risa.70026
  32. Gatti, G., Valero, J. M. J., Gil Pérez, M., & Basile, C. (2025). Holistic cyber risk assessment in the cloud continuum: A multi-layer, multi-domain approach. IEEE Access, 13, 180593–180612. https://doi.org/10.1109/ACCESS.2025.3622915
  33. Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of zero trust architecture across domains. Sensors, 25(19), Article 6118. https://doi.org/10.3390/s25196118
  34. Song, M., Hua, Z., Zheng, Y., Huang, H., & Jia, X. (2023). Blockchain-based deduplication and integrity auditing over encrypted cloud storage. IEEE Transactions on Dependable and Secure Computing, 20(6), 4928–4945. https://doi.org/10.1109/TDSC.2023.3237221
  35. Dhanapala, S., Bharti, S., McGibney, A., & Rea, S. (2024). Toward a performance-based trustworthy edge-cloud continuum. IEEE Access, 12, 99201–99212. https://doi.org/10.1109/ACCESS.2024.3429197
  36. Li, J., Wu, J., Jiang, L., & Li, J. (2024). Blockchain-based public auditing with deep reinforcement learning for cloud storage. Expert Systems with Applications, 242, Article 122764. https://doi.org/10.1016/j.eswa.2023.122764
  37. Hong, S., Xu, L., Huang, J., Li, H., Hu, H., & Gu, G. (2023). SysFlow: Toward a programmable zero trust framework for system security. IEEE Transactions on Information Forensics and Security, 18, 2794–2809. https://doi.org/10.1109/TIFS.2023.3264152
  38. Li, S., Xu, C., Zhang, Y., Du, Y., & Chen, K. (2023). Blockchain-based transparent integrity auditing and encrypted deduplication for cloud storage. IEEE Transactions on Services Computing, 16(1), 134–146. https://doi.org/10.1109/TSC.2022.3144430
  39. Román-Martínez, J., Calvillo-Arbizu, J., Mayor-Gallego, V. J., Madinabeitia-Luque, G., Estepa-Alonso, A. J., & Estepa-Alonso, R. M. (2023). Blockchain-based service-oriented architecture for consent management, access control, and auditing. IEEE Access, 11, 12727–12741. https://doi.org/10.1109/ACCESS.2023.3242605
  40. Miao, Y., Gai, K., Zhu, L., Choo, K.-K. R., & Vaidya, J. (2024). Blockchain-based shared data integrity auditing and deduplication. IEEE Transactions on Dependable and Secure Computing, 21(4), 3688–3703. https://doi.org/10.1109/TDSC.2023.3335413
  41. Alharbi, A. (2023). Applying access control enabled blockchain (ACE-BC) framework to manage data security in the CIS system. Sensors, 23(6), Article 3020. https://doi.org/10.3390/s23060320
  42. Rivera, J. J. D., Muhammad, A., & Song, W. C. (2024). Securing digital identity in the zero trust architecture: A blockchain approach to privacy-focused multi-factor authentication. IEEE Open Journal of the Communications Society, 5, 2792-2814.
  43. Zichichi, M., D’Angelo, G., Ferretti, S., & Marzolla, M. (2023). Accountable clouds through blockchain. IEEE Access, 11, 48358–48374. https://doi.org/10.1109/ACCESS.2023.3276240
  44. Du, G., Dong, G., Ning, J., Xu, Z., & Yang, R. (2023). A blockchain-assisted certificateless public cloud data integrity auditing scheme. IEEE Access, 11, 123018–123029. https://doi.org/10.1109/ACCESS.2023.3329558
  45. Federici, F., Martintoni, D., & Senni, V. (2023). A zero-trust architecture for remote access in industrial IoT infrastructures. Electronics, 12(3), 566.
  46. Firouzi, A., Dadkhah, S., Maret, S. A., & Ghorbani, A. A. (2025). DataSense: A real-time sensor-based benchmark dataset for attack analysis in IIoT with multi-objective feature selection. Electronics, 14(20), Article 4095. https://doi.org/10.3390/electronics14204095
  47. Javed, S. H., Ahmad, M. B., Asif, M., Akram, W., Mahmood, K., Das, A. K., & Shetty, S. (2023). APT adversarial defence mechanism for industrial IoT enabled cyber-physical system. IEEE Access, 11, 74000-74020.
  48. Neto, E. C. P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., & Ghorbani, A. A. (2023). CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors, 23(13), Article 5941. https://doi.org/10.3390/s23135941