Performance Trade-Offs in Multi-Tenant IoT–Cloud Security: A Systematic Review of Emerging Technologies
Abstract
1. Introduction
- What are the dominant multi-tenancy security threats at the intersection of IoT and shared cloud layers?
- How do next-generation mitigations (ZTA, AI, Blockchain, PQC) perform when measured against strict IoT resource constraints?
- What architectural shifts, such as edge offloading or hardware isolation, are required to enable future-proof, quantum-resilient multi-tenant deployments?
Contributions
- A Tenant-Centric Threat Taxonomy: We classify threats based on their specific impact on tenant isolation rather than on generic attack vectors such as cross-tenant data leakage or noisy neighbor resource exhaustion in shared environments.
- Intersection Analysis: Unlike general surveys, we evaluate mitigation strategies specifically against IoT constraints (latency, energy, and limited processing power), identifying why standard cloud defenses often fail at the IoT edge.
- Architectural Synthesis: We propose an integrated architectural approach that combines Zero Trust for logical isolation, AI for dynamic threat detection, and PQC for long-term data resilience, mapping these solutions to specific layers of the IoT–Cloud stack (e.g., Edge Gateways vs. End-Devices).
2. Methodology
2.1. Search Strategy and Data Sources
2.2. Inclusion and Exclusion Criteria
- Inclusion: Peer-reviewed journal articles and conference proceedings published between 2020 and 2025 that explicitly address multi-tenancy in IoT–cloud environments and propose concrete security mitigation mechanisms.
- Exclusion: included generic cloud studies without an IoT component, non-peer-reviewed or non-technical works, non-English publications, and studies predating modern containerization paradigms.
2.3. Scope and Limitations of the Review
3. Foundational Architecture and Multi-Tenancy Models
3.1. IoT–Cloud Systems Architecture
3.1.1. Perception Layer
3.1.2. Network Layer
3.1.3. Edge/Fog Layer
3.1.4. Data and Cloud Services Layer
3.1.5. Application Layer
3.2. Multi-Tenant Cloud Systems
3.2.1. Tenant Isolation Mechanisms
Device Isolation
Network Isolation
Resource Isolation
Data Isolation
Application Isolation
4. Critical Analysis of Multi-Tenancy Security
4.1. Multi-Tenancy Security Risks Classification
4.2. Current Mitigation Strategies
4.3. IoT Device Authentication Limitations in Multi-Tenant Cloud Environments
5. Discussion
5.1. Fragmentation of Security Architectures
5.2. The Security-Performance Trade-Off
5.3. Comparative Analysis of Emerging Technologies
5.3.1. Zero Trust Architectures (ZTA)
5.3.2. AI-Driven Threat Detection
5.3.3. Blockchain Integration
5.3.4. Post-Quantum Cryptography (PQC)
5.3.5. Strategic Synthesis
5.4. Feasibility and Implementation Challenges
- Protocol Overhead and Bandwidth Constraints: PQC algorithms, such as CRYSTALS-Kyber, introduce substantial communication overhead due to their larger key and ciphertext sizes (approximately 1.6 KB) [61]. This creates a critical feasibility gap when measured against contemporary radio communication protocols. For example, LoRaWAN typically supports a physical payload maximum transmission unit (MTU) ranging from only 51 to 222 bytes, depending on the data rate. Direct transmission of a 1.6 KB PQC key would require extensive packet fragmentation and multiple transmission windows, leading to significant battery depletion and increased collision risks in the shared radio spectrum. Furthermore, while Bluetooth Low Energy (BLE) and Zigbee offer slightly higher throughput, they still struggle with the “harvest now, decrypt later” resilience gap without hardware acceleration. As a result, the direct deployment of PQC at the IoT end-node layer remains infeasible for many low-power and low-bandwidth applications. This necessitates a tiered architectural approach wherein the intensive cryptographic handshake is delegated to the Edge/Fog layer, which has the high-bandwidth backhaul (e.g., Ethernet or Wi-Fi) requisite for managing PQC-sized artifacts.
- Deployment Cost: Continuous verification under ZTA requires policy enforcement engines, identity management services, and telemetry collection mechanisms that are often unsupported by legacy IoT gateways. Remodifying existing deployments to adapt these components introduces non-trivial infrastructure and operational costs [62]. This limits the economic feasibility of full ZTA adoption in large-scale or cost-sensitive IoT deployments.
- Legacy Interoperability and Operational Complexity: Beyond the direct computational costs, the deployment of next-generation security models faces severe friction from legacy infrastructure. Industrial and smart city ecosystems often rely on long-lived devices that use hard-coded, proprietary protocols that lack native support for dynamic policy enforcement agents or modern identity management. Retrofitting these heterogeneous endpoints for ZTA compliance often demands a prohibitive “rip-and-replace” strategy, creating a migration cost barrier that outweighs the security benefits for many organizations. Moreover, the operational complexity of managing fragmented tooling ecosystems across multi-vendor devices creates a significant administrative bottleneck [63]. These practical limitations reinforce the necessity of the proposed Edge-Gateway architectural shift; by abstracting security enforcement to the gateway layer, organizations can envelop legacy devices in a secure ZTA perimeter without requiring infeasible hardware upgrades at the sensor level.
- Latency: The “verify-then-trust” model intrinsic to ZTA introduces additional round-trip communication and processing delays. For latency-critical IoT applications, such as industrial control systems (ICS) with timing constraints below 10 ms, this added delay can violate real-time requirements [64]. That leads to jitter and system instability.
6. Future Research Roadmap
6.1. Federated Learning at the IoT Edge
6.2. Hardware Enclaves in Fog Computing
6.3. Lightweight Distributed Ledgers at the Gateway
7. Conclusions
Supplementary Materials
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| IoT | Internet of Things |
| PQC | Post-Quantum Cryptography |
| ZTA | Zero Trust Architectures |
| CoAP | Constrained Application Protocol |
| LPWANs | Low-Power Wide Area Networks |
| SSL | Secure Sockets Layer |
| RBAC | Role-Based Access Control |
| VM | virtual machine |
| QoS | Quality of Service |
| VPCs | Virtual Private Clouds |
| ABAC | Attribute-Based Access Control |
| APIs | Application Programming Interfaces |
| TEEs | Trusted Execution Environments |
| DAG | Directed Acyclic Graph |
| ML | Machine Learning |
| TLS | Transport Layer Security |
| MTU | Maximum Transmission Unit |
| DL | Deep Learning |
| MQTT | Message Queuing Telemetry Transport |
| SaaS | Software as a Service |
| IaaS | Infrastructure as a Service |
| AMQP | Advanced Message Queuing Protocol |
| ACLs | Access Control Lists |
| Amazon EC2 | Amazon Elastic Compute Cloud |
| PaaS | Platform as a Service |
| SDN | Software-Defined Networking |
| VPN | Virtual Private Networks |
| VLAN | Virtual Local Area Network |
| DoS | Denial-of-Service |
| SCA | side-channel attacks |
| FL | Federated Learning |
| DLT | Distributed Ledger Technology |
| AI | Artificial Intelligence |
| BLE | Bluetooth Low Energy |
| PKI | Public Key Infrastructure |
| ICS | Industrial Control Systems |
References
- Kuchuk, H.; Malokhvii, E. Integration of Iot With Cloud, Fog, and Edge Computing: A Review. Adv. Inf. Syst. 2024, 8, 65–78. [Google Scholar] [CrossRef] [Scilit]
- Zoting, S.; Aditi, S. Multi-Tenant Data Centers Market Size, Share and Trends 2025 to 2034. 2025. Available online: https://www.precedenceresearch.com/multi-tenant-data-centers-market (accessed on 15 November 2025).
- Hashim, W.; Hussein, N.A.-H.K. Securing Cloud Computing Environments: An Analysis of Multi-Tenancy Vulnerabilities and Countermeasures. SHIFRA 2024, 2024, 8–16. [Google Scholar] [CrossRef] [Scilit]
- Surianarayanan, C.; Chelliah, P.R. Integration of the Internet of Things and Cloud: Security Challenges and Solutions—A Review. Int. J. Cloud Appl. Comput. (IJCAC) 2023, 13, 1–30. [Google Scholar] [CrossRef] [Scilit]
- Almutairi, M.; Sheldon, F.T. IoT–Cloud Integration Security: A Survey of Challenges, Solutions, and Directions. Electronics 2025, 14, 1394. [Google Scholar] [CrossRef] [Scilit]
- Botta, A.; De Donato, W.; Persico, V.; Pescapé, A. Integration of Cloud computing and Internet of Things: A survey. Future Gener. Comput. Syst. 2016, 56, 684–700. [Google Scholar] [CrossRef] [Scilit]
- Gubbi, J.; Buyya, R.; Marusic, S.; Palaniswami, M. Internet of Things (IoT): A vision, architectural elements, and future directions. Future Gener. Comput. Syst. 2013, 29, 1645–1660. [Google Scholar] [CrossRef] [Scilit]
- Mrabet, H.; Belguith, S.; Alhomoud, A.; Jemai, A. A Survey of IoT Security Based on a Layered Architecture of Sensing and Data Analysis. Sensors 2020, 20, 3625. [Google Scholar] [CrossRef] [Scilit]
- Bello, O.; Zeadally, S.; Badra, M. Network layer inter-operation of Device-to-Device communication technologies in Internet of Things (IoT). Ad Hoc Netw. 2017, 57, 52–62. [Google Scholar] [CrossRef] [Scilit]
- Hussain, B.; Elmedany, W.; Sharif, M.S. The Internet of Things Security Issues and Countermeasures in Network Layer: A Systematic Literature Review. In Proceedings of the 2022 International Conference on Data Analytics for Business and Industry (ICDABI), Sakhir, Bahrain, 25–26 October 2022. [Google Scholar]
- Dallaf, A.A.A. Edge Computing in IoT Networks: Enhancing Efficiency, Reducing Latency, and Improving Scalability. Int. J. Adv. Netw. Monit. Control. 2025, 10, 103–115. [Google Scholar] [CrossRef] [Scilit]
- Sarwar, K.; Yongchareon, S.; Yu, J.; ur Rehman, S. Efficient privacy-preserving data replication in fog-enabled IoT. Future Gener. Comput. Syst. 2022, 128, 538–551. [Google Scholar] [CrossRef] [Scilit]
- Mavridis, I.; Karatza, H. Orchestrated sandboxed containers, unikernels, and virtual machines for isolation-enhanced multitenant workloads and serverless computing in cloud. Concurr. Comput. Pract. Exp. 2023, 35, e6365. [Google Scholar] [CrossRef] [Scilit]
- Lynn, T.; Rosati, P.; Lejeune, A.; Emeakaroha, V. A Preliminary Review of Enterprise Serverless Cloud Computing (Function-as-a-Service) Platforms. In Proceedings of the 2017 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), Hong Kong, China, 11–14 December 2017. [Google Scholar]
- Jain, P.; Munjal, Y.; Gera, J.; Gupta, P. Performance Analysis of Various Server Hosting Techniques. Procedia Comput. Sci. 2020, 173, 70–77. [Google Scholar] [CrossRef] [Scilit]
- Van Eyk, E.; Grohmann, J.; Eismann, S.; Bauer, A.; Versluis, L.; Toader, L.; Schmitt, N.; Herbst, N.; Abad, C.L.; Iosup, A. The SPEC-RG Reference Architecture for FaaS: From Microservices and Containers to Serverless Platforms. IEEE Internet Comput. 2019, 23, 7–18. [Google Scholar] [CrossRef] [Scilit]
- Armoogum, S.; Khonje, P. Healthcare Data Storage Options Using Cloud. In The Fusion of Internet of Things, Artificial Intelligence, and Cloud Computing in Health Care; Springer: Cham, Switzerland, 2021. [Google Scholar]
- Hu, Z.; Zhang, H.; Sun, S.; Gao, C.; Li, Y.; Li, X. FDRA: Fully Distributed Routing Architecture for Private Virtual Network in Public Cloud. In Proceedings of the 11th International Symposium on Parallel Architectures, Algorithms and Programming, Shenzhen, China, 28–30 December 2021. [Google Scholar]
- Um, T.W.; Lee, H.; Ryu, W.; Choi, J.K. Dynamic Resource Allocation and Scheduling for Cloud-Based Virtual Content Delivery Networks. ETRI J. 2014, 36, 197–205. [Google Scholar] [CrossRef] [Scilit]
- Zahariadis, T.; Papadakis, A.; Alvarez, F.; Gonzalez, J.; Lopez, F.; Facca, F.; Al-Hazmi, Y. FIWARE Lab: Managing Resources and Services in a Cloud Federation Supporting Future Internet Applications. In Proceedings of the 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, London, UK, 8–11 December 2014. [Google Scholar]
- Zhang, X.; Du, H.T.; Chen, J.Q.; Lin, Y.; Zeng, L.J. Ensure Data Security in Cloud Storage. In Proceedings of the 2011 International Conference on Network Computing and Information Security, Guilin, China, 14–15 May 2011. [Google Scholar]
- Waghchaude, K. A Review on Cloud Computing Security Issues, Applicable Solutions and Implementation. Int. J. Sci. Res. Eng. Manag. 2024, 8, 1–3. [Google Scholar] [CrossRef] [Scilit]
- Sood, S.K. A combined approach to ensure data security in cloud computing. J. Netw. Comput. Appl. 2012, 35, 1831–1838. [Google Scholar] [CrossRef] [Scilit]
- Pal, S.; Khatua, S.; Chaki, N.; Sanyal, S. A New Trusted and Collaborative Agent Based Approach for Ensuring Cloud Security. arXiv 2011, arXiv:1108.4100. [Google Scholar] [CrossRef] [Scilit]
- Gibson, J.; Rondeau, R.; Eveleigh, D.; Tan, Q. Benefits and challenges of three cloud computing service models. In Proceedings of the 2012 4th International Conference on Computational Aspects of Social Networks (CASoN), Sao Carlos, Brazil, 21–23 November 2012. [Google Scholar]
- De Napoli, C.; Forestiero, A.; Fortino, G.; Giordano, A.; Guerrieri, A.; Lagana, D.; Lupi, G.; Mastroianni, C.; Spataro, L. IoT-HC: A Novel IoT Architecture for the Hybrid Cloud. In Proceedings of the 2019 28th International Conference on Computer Communication and Networks (ICCCN), Valencia, Spain, 29 July–1 August 2019. [Google Scholar]
- Yassein, M.B.; Shatnawi, M.Q.; Al-zoubi, D. Application layer protocols for the Internet of Things: A survey. In Proceedings of the 2016 International Conference on Engineering & MIS (ICEMIS), Agadir, Morocco, 22–24 September 2016. [Google Scholar]
- Altayaran, S.; Elmedany, W. Security threats of application programming interface (API’s) in internet of things (IoT) communications. In Proceedings of the 4th Smart Cities Symposium (SCS 2021), Online, 21–23 November 2021. [Google Scholar]
- Ferdows, J.; Mehedi, S.T.; Hossain, A.D.; Shamim, A.A.M.; Rasiq, G.R.I. A Comprehensive Study of IoT Application Layer Security Management. In Proceedings of the 2020 IEEE International Conference for Innovation in Technology (INOCON), Bangluru, India, 6–8 November 2020. [Google Scholar]
- Kaur, K.; Kaur, A.; Gulzar, Y.; Gandhi, V. Unveiling the core of IoT: Comprehensive review on data security challenges and mitigation strategies. Front. Comput. Sci. 2024, 6, 1420680. [Google Scholar] [CrossRef] [Scilit]
- Khan, Y.; Su’ud, M.B.M.; Alam, M.M.; Ahmad, S.F.; Salim, N.A.; Khan, N. Architectural Threats to Security and Privacy: A Challenge for Internet of Things (IoT) Applications. Electronics 2023, 12, 88. [Google Scholar] [CrossRef] [Scilit]
- Banerjee, S.; Parisa, S.K. Secure Multi-Tenancy in Cloud Computing: Challenges and Solutions. Trans. Recent Dev. Ind. IoT 2025, 17. [Google Scholar]
- Sharma, R.K. Multi-Tenant Architectures in Modern Cloud Computing: A Technical Deep Dive. Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol. 2025, 11, 307–317. [Google Scholar] [CrossRef] [Scilit]
- Njeguš, A. Intelligent Software Systems for Multi-Tenant Cloud Environments: Challenges and Solutions. In Proceedings of the Sinteza 2025—International Scientific Conference on Information Technology, Computer Science, and Data Science, Novi Sad, Serbia, 9 May 2025. [Google Scholar]
- Del Piccolo, V.; Amamou, A.; Haddadou, K.; Pujolle, G. A Survey of Network Isolation Solutions for Multi-Tenant Data Centers. IEEE Commun. Surv. Tutor. 2016, 18, 2787–2821. [Google Scholar] [CrossRef] [Scilit]
- Factor, M.; Hadas, D.; Harnama, A.; Har’El, N.; Kolodner, E.K.; Kurmus, A.; Shulman-Peleg, A.; Sorniotti, A. Secure Logical Isolation for Multi-tenancy in cloud storage. In Proceedings of the IEEE Conference on Mass Storage Systems and Technologies, Long Beach, CA, USA, 6–10 May 2013. [Google Scholar]
- Bhattacharyya, S.; Kanka, V.; Mohammed, A.S. Optimizing Resource Isolation Techniques in Multi-Tenant PaaS Architectures Using Kubernetes and Virtualization. J. Artif. Intell. Res. 2021, 1, 197–239. [Google Scholar]
- Basu, M.T.; Sastry, J.K.R. Enhancing Data Security under Multi-Tenancy within Open Stack. Int. J. Adv. Trends Comput. Sci. Eng. 2020, 9, 533–544. [Google Scholar] [CrossRef] [Scilit]
- Kumar, R. Multi-Tenant SaaS Architectures: Design Principles and Security Considerations. J. Softw. Eng. Simul. 2020, 6, 28–41. [Google Scholar] [CrossRef] [Scilit]
- Panguraj, A.R.R. Systematic Approach to Security Testing in Multi-Tenant Cloud Systems. Int. J. Multidiscip. Res. Growth Eval. 2025, 6, 2139–2412. [Google Scholar] [CrossRef] [Scilit]
- Al-Balasmeh, H. Zero Trust Architecture for IoT Device Ecosystems. Int. J. Basic Appl. Sci. 2025, 14, 818–825. [Google Scholar] [CrossRef] [Scilit]
- Saxena, D.; Gupta, I.; Gupta, R.; Singh, A.K.; Wen, X. An AI-Driven VM Threat Prediction Model for Multi-Risks Analysis-Based Cloud Cybersecurity. IEEE Trans. Syst. Man Cybern. Syst. 2023, 53, 6815–6827. [Google Scholar] [CrossRef] [Scilit]
- Yadav, S.; Abidin, S. Enhancing Security in Multi-Tenant Cloud Environments: Threat Detection, Prevention, and Data Breach Mitigation. J. Inf. Syst. Eng. Manag. 2025, 10, 61–72. [Google Scholar] [CrossRef] [Scilit]
- Pandit, A.; Pandit, R. Side-Channel Attacks in Multi-Tenant Cloud Environments: Prevention & Mitigation. Int. J. Innov. Sci. Eng. Manag. 2025, 4, 93–105. [Google Scholar]
- Malikireddy, S.K.R. Securing Multi-Tenant Cloud Environments with Graph-Based Models. Int. J. Sci. Res. Eng. Manag. 2024, 6, 1–21. [Google Scholar] [CrossRef] [Scilit]
- Hariharan, R. Zero Trust Security in Multi-Tenant Cloud Environments. J. Inf. Syst. Eng. Manag. 2025, 10, 623–644. [Google Scholar] [CrossRef] [Scilit]
- Neto, E.C.P.; Dadkhah, S.; Ghorbani, A.A. Collaborative DDoS Detection in Distributed Multi-Tenant IoT using Federated Learning. In Proceedings of the 2022 19th Annual International Conference on Privacy, Security & Trust (PST), Fredericton, NB, Canada, 22–24 August 2022. [Google Scholar]
- Sebestyen, H.; Popescu, D.E.; Zmaranda, R.D. A Literature Review on Security in the Internet of Things: Identifying and Analysing Critical Categories. Computers 2025, 14, 61. [Google Scholar] [CrossRef] [Scilit]
- Dauda, A.; Flauzac, O.; Nolot, F. A Survey on IoT Application Architectures. Sensors 2024, 24, 5320. [Google Scholar] [CrossRef] [Scilit]
- Kyriakidou, C.N.; Papathanasiou, A.M.; Pittaras, I.; Fotiou, N.; Thomas, Y.; Polyzos, G.C. Attribute-Based Access Control Utilizing Verifiable Credentials for Multi-Tenant IoT Systems. In Proceedings of the 2024 IEEE 4th International Conference on Electronic Communications, Internet of Things and Big Data (ICEIB), Taipei, Taiwan, 19–21 April 2024. [Google Scholar]
- Paracha, M.T.; Dubois, D.J.; Vallina-Rodriguez, N.; Choffnes, D. IoTLS: Understanding TLS usage in consumer IoT devices. In Proceedings of the 21st ACM Internet Measurement Conference, Virtual, 2–4 November 2021. [Google Scholar]
- Lazzaro, S.; De Angelis, V.; Mandalari, A.M.; Buccafurri, F. A black-box assessment of authentication and reliability in consumer IoT devices. Pervasive Mob. Comput. 2025, 110, 102045. [Google Scholar] [CrossRef] [Scilit]
- Mahdi, L.H.; Abdullah, A.A. Fortifying Future IoT Security: A Comprehensive Review on Lightweight Post-Quantum Cryptography. Eng. Technol. Appl. Sci. Res. 2025, 15, 21812–21821. [Google Scholar] [CrossRef] [Scilit]
- Awasthi, A. Quantum-Resistant Security for IoT Systems Challenges and Implementation Strategies. Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol. 2025, 11, 671–678. [Google Scholar] [CrossRef] [Scilit]
- Oladimeji, G. A Critical Analysis of Foundations, Challenges and Directions for Zero Trust Security in Cloud Environments. arXiv 2024, arXiv:2411.06139. [Google Scholar] [CrossRef] [Scilit]
- Harth-Kitzerow, C.; Garrido, G.M. Verifying Outsourced Computation in an Edge Computing Marketplace. arXiv 2022, arXiv:2203.12347. [Google Scholar] [CrossRef] [Scilit]
- Donovan, S.; Feamster, N. Alternative Trust Sources: Reducing DNSSEC Signature Verification Operations with TLS. In Proceedings of the 2015 ACM Conference on Special Interest Group on Data Communication, London, UK, 17–21 August 2015. [Google Scholar]
- Zhang, Y.; Wang, X.; Gao, H.; Zhou, Z.; Meng, F.; Zhang, Y.; Su, S. PD3F: A Pluggable and Dynamic DoS-Defense Framework Against Resource Consumption Attacks Targeting Large Language Models. In Proceedings of the Conference on Empirical Methods in Natural Language Processing, Suzhou, China, 4–9 November 2025. [Google Scholar]
- Andriulo, F.C.; Fiore, M.; Mongiello, M.; Traversa, E.; Zizzo, V. Edge Computing and Cloud Computing for Internet of Things: A Review. Informatics 2024, 11, 71. [Google Scholar] [CrossRef] [Scilit]
- Peng, Y.; Jiang, X.; Wang, S.; Xiang, Y.; Xing, L. An Improved Co-Resident Attack Defense Strategy Based on Multi-Level Tenant Classification in Public Cloud Platforms. Electronics 2024, 13, 3273. [Google Scholar] [CrossRef] [Scilit]
- Liu, T.; Ramachandran, G.; Jurdak, R. Towards Quantum Resilient IoT: A Backward-Compatible Approach to Secure BLE Key Exchange Against Quantum Threats. In Proceedings of the International Conference on Internet-of-Things Design and Implementation, Hong Kong, China, 13–16 May 2024. [Google Scholar]
- Mushtaq, S.; Mohsin, M.; Mushtaq, M.M. A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains. Sensors 2025, 25, 6118. [Google Scholar] [CrossRef] [Scilit]
- Roman, R.; Lopez, J.; Mambo, M. Mobile edge computing, Fog et al.: A survey and analysis of security threats and challenges. Future Gener. Comput. Syst. 2018, 78, 680–698. [Google Scholar] [CrossRef] [Scilit]
- Almuseelem, W. Secure Latency-Aware Task Offloading Using Federated Learning and Zero Trust in Edge Computing for IoMT. IEEE Access 2025, 13, 117808–117830. [Google Scholar] [CrossRef] [Scilit]
- Chandu, G.; Karthik, T.; Parag, B. Federated Learning for Distributed IoT Security: A Privacy-Preserving Approach to Intrusion Detection. IEEE Access 2025, 13, 135863–135875. [Google Scholar]
- Belenguer, A.; Navaridas, J.; Pascual, J.A. A review of Federated Learning in Intrusion Detection Systems for IoT. arXiv 2022, arXiv:2204.12443. [Google Scholar] [CrossRef] [Scilit]
- Valadares, D.C.G.; Will, N.C.; Spohn, M.A.; de Souza Santos, D.F.; Perkusich, A.; Gorgonio, K.C. Trusted Execution Environments for Cloud/Fog-based Internet of Things Applications. In Proceedings of the 11th International Conference on Cloud Computing and Services Science (CLOSER 2021), Virtual, 28–30 April 2021; pp. 111–121. [Google Scholar]
- Cherupally, S.R.; Boga, S.; Podili, P.; Kataoka, K. Lightweight and Scalable DAG based distributed ledger for verifying IoT data integrity. In Proceedings of the International Conference on Information Networking, Jeju Island, Republic of Korea, 13–16 January 2021. [Google Scholar]
- Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [Scilit]



| Study | Focus/Approach | Key Contribution | Observations |
|---|---|---|---|
| Hashim et al., 2024 [3] | Tenant isolation & access control | 95% reduction in unauthorized access and eliminated insider privilege escalation. | 12% resource overhead |
| Al-Balasmeh, H., 2025 [41] | Tenant isolation & Zero Trust validation | Confirmed Hashim et al.’s overhead; scalable across 1000 nodes | Lightweight framework |
| Surianarayanan et al., 2023 [4] | Data confidentiality | Exposed leakage risks in shared setups | No mitigation modeling |
| Panguraj et al., 2025 [40] | Resource sharing | Identified inter-tenant leakage paths | No integrated isolation model |
| Kumar et al., 2020 [39] | VM isolation | Simulated weak boundaries | Lacked IoT performance context |
| Kyriakidou et al., 2024 [42] | ABAC + Verifiable credentials | Tenant-level privacy authentication | Added computation overhead |
| Yadav et al., 2025 [43] | Zero Trust analytics | Continuous access validation | Not tested at scale |
| Pandit et al., 2025 [44] | AI anomaly detection | 97.3% accuracy for tenant attacks | Training bias; scalability issue |
| Neto et al., 2022 [47] | Federated DDoS detection | 84.2% accuracy; privacy preserved | Energy overhead |
| Almutairi et al., 2025 [5] | AI & PQC survey | Highlighted framework gaps | No unified integration |
| Malikireddy et al., 2024 [45] | Elasticity testing | Found inadequate dynamic security | No adaptive model proposed |
| Hariharan et al., 2025 [46] | Zero Trust | Continuous verification model | Conceptual; no IoT validation |
| Sebestyen et al., 2025 [48] | Blockchain audit | Immutable audit trails | Scalability constraints |
| Aspect | Previous Works | This Review |
|---|---|---|
| Scope | Earlier studies have largely examined IoT security or cloud security in isolation, with limited attention to the challenges introduced by shared tenancy [3,40]. | Provides a review of security challenges in IoT–cloud multi-tenancy environments. |
| Target Environment | Most works addressed single-tenant or hybrid edge models [39,50]. | Focuses on multi-tenant resource sharing and isolation. |
| Depth of Threat Analysis | Broader surveys have addressed general cloud security threats while offering limited analysis of tenant-specific risks [4,5]. | Classifies tenant-level threats, including data leakage, privilege escalation, and cross-VM attacks. |
| Mitigation Techniques | Emphasized traditional encryption and access control [43,45]. | Introduces adaptive models integrating ZTA, AI-driven detection, blockchain, and PQC. |
| Evaluation Focus | Prior work offered qualitative insights only [44,47]. | Provides comparative evaluation based on scalability, latency, and isolation effectiveness. |
| Gap Analysis | Often lacked systematic categorization [46]. | Delivers structured taxonomy of unresolved issues and testable metrics. |
| Post-Quantum Readiness | PQC rarely examined [3,53]. | Places PQC as a key enabler for quantum-resistant multi-tenant communication. |
| Contribution Type | Mostly descriptive surveys [4,5]. | Provides comparative synthesis and a roadmap for future research directions. |
| Mechanism | Primary Strength | Key IoT Constraint | Best-Fit Deployment |
|---|---|---|---|
| ZTA | Granular access enforcement | Latency and network jitter | Cloud backends, edge gateways |
| AI/ML-Based Detection | Proactive threat identification. | High compute and energy demand | Edge servers (fog layer) |
| Blockchain | Tamper-proof auditability | Storage overhead, scalability | Private or permissioned cloud layers |
| PQC (e.g., CRYSTALS-Kyber) | Long-term data confidentiality. | Increased bandwidth from key sizes | High-value, long-lifecycle data |
| Technology | Metric of Concern | Quantified Technical Impact | Sensor Layer Viability | Edge Layer Viability | Cloud Layer Viability | Deployment Cost |
|---|---|---|---|---|---|---|
| PQC (Kyber) | Bandwidth & MTU | ~1.6 KB public key; LoRaWAN MTU 51–222 bytes. 7–30 packet fragments per exchange | Critical Fail (Exceeds MTU) | High (Ethernet/WiFi) | High | Energy cost (µJ/bit), firmware memory increase (KB), hardware upgrade expenses |
| ZTA | RTT & Processing Delay | Additional RTT per access request; >5–10 ms unacceptable in sub −10 ms ICS | Low (Jitter risks) | Medium/High (PEP placement) | High | Compute scaling operating expenses; policy engine licensing |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Alobaywi, B.; Almutairi, M.G.; Sheldon, F.T. Performance Trade-Offs in Multi-Tenant IoT–Cloud Security: A Systematic Review of Emerging Technologies. IoT 2026, 7, 21. https://doi.org/10.3390/iot7010021
Alobaywi B, Almutairi MG, Sheldon FT. Performance Trade-Offs in Multi-Tenant IoT–Cloud Security: A Systematic Review of Emerging Technologies. IoT. 2026; 7(1):21. https://doi.org/10.3390/iot7010021
Chicago/Turabian StyleAlobaywi, Bader, Mohammed G. Almutairi, and Frederick T. Sheldon. 2026. "Performance Trade-Offs in Multi-Tenant IoT–Cloud Security: A Systematic Review of Emerging Technologies" IoT 7, no. 1: 21. https://doi.org/10.3390/iot7010021
APA StyleAlobaywi, B., Almutairi, M. G., & Sheldon, F. T. (2026). Performance Trade-Offs in Multi-Tenant IoT–Cloud Security: A Systematic Review of Emerging Technologies. IoT, 7(1), 21. https://doi.org/10.3390/iot7010021

