Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (1,213)

Search Parameters:
Keywords = cloud computing security

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
18 pages, 1353 KB  
Article
Secure Adaptive Resource Orchestration for Cloud Management with Deep Reinforcement Learning: An Extended Evaluation on Real Traces
by Usaid Alibrahem, Priyadarsi Nanda and Hoang Dinh
Electronics 2026, 15(17), 3916; https://doi.org/10.3390/electronics15173916 (registering DOI) - 31 Aug 2026
Abstract
Cloud platforms must hold utilisation and latency targets while demand shifts and attack traffic arrive together. Reactive threshold scaling meets neither pressure, and an autoscaler blind to attacks funds the load an adversary requested. Recent work shows adversaries can drive this loop into [...] Read more.
Cloud platforms must hold utilisation and latency targets while demand shifts and attack traffic arrive together. Reactive threshold scaling meets neither pressure, and an autoscaler blind to attacks funds the load an adversary requested. Recent work shows adversaries can drive this loop into economic denial of sustainability, so the controller sits inside the attack surface. No prior orchestrator couples workload forecasting, unsupervised anomaly detection and learned scaling in one loop, and none reports multi-seed significance testing. This article extends SARO, presented at IMCOM 2026, to close that gap. We formalise the problem as a Markov decision process with a corrected multi-objective reward, and replace the tabular agent with SARO-DQN, a continuous-state controller trained by three-step Double Q-learning. Across ten held-out days and five seeds, SARO-DQN reaches the highest composite reward (200.1 ± 16.5) and the highest utilisation (68.2%) against eight alternatives, and every reward difference is significant under Welch tests (p<0.05). Ablations attribute 23.6 reward points to the detector (p=1.4×106) and 8.9 to the forecast (p=0.016). On UNSW-NB15, the detector attains an AUC of 0.888. Two principles follow. Detectors must consume exogenous traffic-shape signals, and detector and policy must be trained as a coupled system. Full article
Show Figures

Figure 1

7 pages, 1262 KB  
Editorial
Cloud–Edge Intelligence for the Industrial Internet of Things: Security, Digital Twins, and Resource-Aware Computing
by Muhammad Kazim, Stefan Kuhn and Mujeeb Ur Rehman
Big Data Cogn. Comput. 2026, 10(9), 286; https://doi.org/10.3390/bdcc10090286 - 26 Aug 2026
Viewed by 127
Abstract
The Industrial Internet of Things (IIoT) is reshaping the relationship between physical industrial processes and digital computing infrastructures [...] Full article
(This article belongs to the Special Issue Application of Cloud Computing in Industrial Internet of Things)
Show Figures

Figure 1

24 pages, 1226 KB  
Article
Practical Verifiable Multi-Key Searchable Encryption with Optimal Overhead
by Yaping Su, Binghang Wang, Yanjie Xiang, Wenting Li and Jing Lu
Mathematics 2026, 14(17), 3042; https://doi.org/10.3390/math14173042 - 24 Aug 2026
Viewed by 133
Abstract
Multi-Key Searchable Encryption (MKSE) enables data owners (DOs) to outsource their data to a cloud server (CS) while supporting fine-grained data sharing with other authorized users. Most existing MKSE schemes can protect data users’ (DUs’) search query privacy against collusion attacks between malicious [...] Read more.
Multi-Key Searchable Encryption (MKSE) enables data owners (DOs) to outsource their data to a cloud server (CS) while supporting fine-grained data sharing with other authorized users. Most existing MKSE schemes can protect data users’ (DUs’) search query privacy against collusion attacks between malicious DOs and the CS. However, the CS is not fully trusted and may maliciously return forged or incomplete search results. To address this issue, Verifiable MKSE (VMKSE) is proposed by leveraging Garbled Bloom Filter (GBF), which can support verifiability even when the search results are empty. Unfortunately, due to the massive native storage redundancy of GBF, the storage and computational overhead of verification evidence generated in the sharing phase increases as the number of shared documents grows. Therefore, in this paper, we present a novel VMKSE scheme (VMKSE-BFF) by adopting BFF, which can simultaneously support verifiability of and secure data sharing in a multi-user setting. We provide a comparison with the existing VMKSE schemes. Experimental results on a real-world dataset show a significant performance improvement of VMKSE-BFF. Full article
Show Figures

Figure 1

34 pages, 2336 KB  
Article
An Integrated University Digital Transformation Model Combining IT Governance, Interoperability, Cloud Security Assessment and Data Analytics: The UTMACH Case in Ecuador
by Jennifer Célleri-Pacheco, Fernanda Tusa Jumbo, Oswaldo Chuquirima Camacho, Santiago Rodríguez Yánez and Javier Andrade-Garda
Future Internet 2026, 18(8), 443; https://doi.org/10.3390/fi18080443 - 20 Aug 2026
Viewed by 285
Abstract
Digital transformation in higher education requires integrated designs connecting strategy, governance, infrastructure, interoperability, applications, cybersecurity, accessibility, analytics, and continuous improvement. This study analyzes the Integrated University Digital Transformation Model implemented at Universidad Técnica de Machala, Ecuador, between 2023 and April 2026. A qualitative [...] Read more.
Digital transformation in higher education requires integrated designs connecting strategy, governance, infrastructure, interoperability, applications, cybersecurity, accessibility, analytics, and continuous improvement. This study analyzes the Integrated University Digital Transformation Model implemented at Universidad Técnica de Machala, Ecuador, between 2023 and April 2026. A qualitative embedded case study with a design-science orientation examined institutional documents, technical records, governance evidence, cloud migration reports, interoperability mechanisms, system descriptions, analytics outputs, and cloud security assessment records through thematic analysis, process tracing, and artifact evaluation. Findings showed alignment between the Strategic Information Technology Plan and institutional planning; formal IT governance and information security structures; an API- and microservices-based architecture; a staged migration of 52 institutional servers in four operational lots, with documented post-migration monitoring indicating 99.85% average server uptime and no critical incidents attributable to the migration during the monitored period; an automated and traceable admission allocation process within a broader portfolio of integrated academic–administrative systems; and dashboards supporting evidence-informed decisions. MMGSI-Cloud complemented the architecture by assessing governance capabilities, identifying improvement priorities, and linking findings to an institutional roadmap. The case indicates that university digital transformation is strengthened when technological implementation is integrated with formal governance, systematic assessment, evidence-based planning, and institutional accountability. Full article
Show Figures

Graphical abstract

15 pages, 390 KB  
Systematic Review
Edge Intelligence in the IoT Era: A Review of Architectural Paradigms
by Marco Fiore and Francesca Lanera
Electronics 2026, 15(16), 3689; https://doi.org/10.3390/electronics15163689 - 18 Aug 2026
Viewed by 175
Abstract
The exponential growth of the Internet of Things (IoT) has generated massive data streams traditionally processed by centralized cloud architectures, which increasingly face latency, bandwidth, and privacy limitations. Shifting artificial intelligence to resource-constrained edge nodes, known as TinyML, offers a robust decentralized alternative, [...] Read more.
The exponential growth of the Internet of Things (IoT) has generated massive data streams traditionally processed by centralized cloud architectures, which increasingly face latency, bandwidth, and privacy limitations. Shifting artificial intelligence to resource-constrained edge nodes, known as TinyML, offers a robust decentralized alternative, though it introduces severe memory, compute, and energy bottlenecks. To map this transition, a systematic literature review was conducted following PRISMA guidelines, analyzing peer-reviewed studies published between 2021 and 2026 across major databases. The analysis identifies primary architectural paradigms and evaluates the efficacy of state-of-the-art model compression techniques, such as quantization, pruning, and knowledge distillation. Furthermore, the findings reveal that hardware–software co-design and custom neural accelerators are crucial for overcoming operational bottlenecks, while also highlighting persistent security and privacy challenges in on-device learning. Ultimately, while deploying complex models on microcontrollers is increasingly viable, achieving optimal performance demands holistic optimization strategies. This review synthesizes current research gaps and provides a strategic roadmap to guide future interdisciplinary efforts toward resilient, energy-efficient, and secure next-generation intelligent edge systems. Full article
(This article belongs to the Special Issue Advanced Computer Science and Intelligent Systems Innovations)
Show Figures

Figure 1

25 pages, 6470 KB  
Article
A Blockchain-Enabled Security Framework for Cloud-Based Sensor Systems with Deep Learning-Driven Attack Classification
by Naveed Ahmad, Yue Cao and William Liu
Sensors 2026, 26(16), 5198; https://doi.org/10.3390/s26165198 - 17 Aug 2026
Viewed by 272
Abstract
Cloud-integrated sensor and Internet of Things (IoT) systems enable scalable data storage, processing, and intelligent monitoring, but their distributed nature exposes network-flow and host-level data to unauthorized access, tampering, and cyberattacks. This study proposes a Weighted Symmetric Hashed Blockchain (WSHB) framework that integrates [...] Read more.
Cloud-integrated sensor and Internet of Things (IoT) systems enable scalable data storage, processing, and intelligent monitoring, but their distributed nature exposes network-flow and host-level data to unauthorized access, tampering, and cyberattacks. This study proposes a Weighted Symmetric Hashed Blockchain (WSHB) framework that integrates mutual-information-based feature weighting, deep-learning-based attack classification, AES-256-GCM authenticated encryption, cryptographic hashing, and permissioned-ledger logging. The framework was evaluated independently using HIKARI-2021 for network-based intrusion detection and ADFA-LD for host-based intrusion detection. A transparent comparative evaluation was conducted against LSTM and CNN–RNN baselines using identical data splits, preprocessing settings, input representations, hyperparameter-search budget, and repeated initialization seeds. The proposed WSHB-DNN classifier achieved macro-F1 scores of 0.6837 on HIKARI-2021 and 0.7914 on ADFA-LD, showing the strongest overall classification performance among the evaluated models. The cryptographic and permissioned-ledger components provide confidentiality protection, record-level authentication, integrity verification, and tamper-evident logging for confirmed attack-event records. These results demonstrate the potential of WSHB as a reproducible framework for attack classification and secure event logging in cloud-integrated sensor environments. Full article
(This article belongs to the Collection Intelligent Security Sensors in Cloud Computing)
Show Figures

Figure 1

40 pages, 1067 KB  
Review
Trustworthy AI-Powered Intrusion Detection for the Internet of Medical Things (IoMT): A Review
by Jahidul Islam, Dristi Datta and Fowzia Akhter
Sensors 2026, 26(16), 5182; https://doi.org/10.3390/s26165182 - 16 Aug 2026
Viewed by 374
Abstract
The Internet of Medical Things (IoMT) is transforming healthcare through continuous patient monitoring, telemedicine, cloud–edge services, and Healthcare 5.0. However, the rapid growth of interconnected medical devices has expanded the healthcare cyberattack surface, making intelligent intrusion detection essential for protecting sensitive medical data [...] Read more.
The Internet of Medical Things (IoMT) is transforming healthcare through continuous patient monitoring, telemedicine, cloud–edge services, and Healthcare 5.0. However, the rapid growth of interconnected medical devices has expanded the healthcare cyberattack surface, making intelligent intrusion detection essential for protecting sensitive medical data and ensuring resilient clinical operations. Existing reviews examine specific aspects of AI-powered intrusion detection but rarely provide a deployment-oriented synthesis linking technical performance with operational and clinical requirements. This review critically examines Artificial Intelligence (AI)-powered Intrusion Detection Systems (IDSs) for IoMT across six analytical dimensions: detection performance, explainability, privacy preservation, computational efficiency, benchmarking practices, and cross-dataset generalization. This structured narrative review adopted the PRISMA 2020 framework to ensure transparent record identification, screening, and reporting, with evidence synthesized qualitatively rather than through quantitative meta-analysis. A total of 5127 records published between 2021 and 2026 were screened, resulting in 24 primary studies supported by 115 complementary studies. The findings show that machine learning, deep learning, hybrid AI, Explainable Artificial Intelligence (XAI), Federated Learning (FL), blockchain-assisted security, and edge intelligence have significantly advanced IoMT intrusion detection. However, despite benchmark accuracies often exceeding 95%, deployment remains constrained by dataset dependency, weak cross-dataset generalization, computational overhead, limited explainability, fragmented benchmarking, and insufficient operational validation. This review identifies deployment readiness, rather than predictive accuracy alone, as the principal challenge for next-generation healthcare cybersecurity and provides a practical framework for developing trustworthy, interoperable, privacy-preserving, and deployment-ready IoMT cybersecurity architectures supported by standardized evaluation protocols. Full article
(This article belongs to the Section Internet of Things)
Show Figures

Figure 1

25 pages, 23619 KB  
Article
Lightweight Homomorphic Pixel Scrambling for Privacy-Preserving Image Fusion
by Tieyu Zhao
Electronics 2026, 15(16), 3637; https://doi.org/10.3390/electronics15163637 - 15 Aug 2026
Viewed by 157
Abstract
Image fusion integrates complementary multi-source visual information, yet plaintext fusion poses severe privacy risks. Conventional lattice-based homomorphic encryption enables ciphertext computation but incurs substantial computational overhead and exhibits poor compatibility with image fusion tasks. This work investigates lightweight privacy-preserving image fusion built upon [...] Read more.
Image fusion integrates complementary multi-source visual information, yet plaintext fusion poses severe privacy risks. Conventional lattice-based homomorphic encryption enables ciphertext computation but incurs substantial computational overhead and exhibits poor compatibility with image fusion tasks. This work investigates lightweight privacy-preserving image fusion built upon pixel scrambling. Any pixel-scrambling technique that only rearranges pixel coordinates without modifying pixel values inherently satisfies the homomorphic properties required for pixel-level spatial fusion. In this paper, we adopt full-size random permutation matrix scrambling as a representative pixel-disordering method for systematic theoretical and experimental verification. The scheme generates a secret key matching the resolution of test images; it merely reorders pixel positions while preserving all original intensity values, allowing direct cipher-domain fusion that yields distortion-free outputs for averaging, weighted averaging, maximum-value and minimum-value fusion rules. Free from intricate lattice calculations and ciphertext expansion, the proposed lightweight framework achieves an optimal trade-off among security, computational efficiency and fusion quality for cloud computing scenarios. Full article
Show Figures

Figure 1

20 pages, 2712 KB  
Article
An Algebra for Two-Layer Cloud Filtering: Detecting Redundancy, Shadowing, and Dominance Anomalies Across Stateless Network ACLs and Stateful Security Groups
by Thawatchai Chomsiri and Suwichai Phunsa
Future Internet 2026, 18(8), 426; https://doi.org/10.3390/fi18080426 - 11 Aug 2026
Viewed by 229
Abstract
Traffic inside a cloud Virtual Private Cloud (VPC) is filtered by two layers with fundamentally different semantics: a stateless, ordered, first-match Network ACL (NACL) and a stateful, unordered, allow-only Security Group (SG). Existing analyzers decide point-to-point reachability using satisfiability solvers, Datalog engines, or [...] Read more.
Traffic inside a cloud Virtual Private Cloud (VPC) is filtered by two layers with fundamentally different semantics: a stateless, ordered, first-match Network ACL (NACL) and a stateful, unordered, allow-only Security Group (SG). Existing analyzers decide point-to-point reachability using satisfiability solvers, Datalog engines, or binary decision diagrams, but do not identify, at the rule level, which rules are dead, redundant, or dominated, nor explain why. We provide a closed-form set algebra over the two layers. Representing each rule field by its boundaries makes a rule a hyper-rectangle and a layer a union of boxes; the effective admitted region Φ = A(N) ∩ A(G) is then a finite union of disjoint boxes computable from rule endpoints alone. We define a taxonomy of single- and cross-layer anomalies—shadowed NACL rules, dead SG rules, Φ-redundant rules, Φ-ineffective NACL allows, and layer disagreement—characterize each by a decidable region predicate, and prove an exact iff-condition for SG Φ-redundancy. A boundary-only detection algorithm is sound and complete for the exactly decidable anomaly classes, running in O((k + t)^d) time for fixed dimension d, and the disjoint box decomposition of Φ gives a minimal anomaly-free form that is unique up to merging adjacent coplanar boxes. A single-file implementation matches brute force on millions of packets, staying orders of magnitude below the worst-case bound; the parametric model extends unchanged to IPv6 and ICMP. Full article
(This article belongs to the Collection Information Systems Security)
Show Figures

Figure 1

37 pages, 16235 KB  
Article
Privacy-Preserving and Quantum-Resilient Blockchain Infrastructures for MuReQua Federated Micro Data Centers
by Gerardo Iovane
Electronics 2026, 15(16), 3575; https://doi.org/10.3390/electronics15163575 - 11 Aug 2026
Viewed by 262
Abstract
The rapid growth of AI-driven workloads, IoT ecosystems, and distributed digital services has exposed fundamental limitations in existing cloud and edge infrastructures, particularly in guaranteeing robust data privacy under emerging quantum threats. Current blockchain-based systems provide integrity and decentralization but rely predominantly on [...] Read more.
The rapid growth of AI-driven workloads, IoT ecosystems, and distributed digital services has exposed fundamental limitations in existing cloud and edge infrastructures, particularly in guaranteeing robust data privacy under emerging quantum threats. Current blockchain-based systems provide integrity and decentralization but rely predominantly on computational cryptography and access-control mechanisms, leaving them vulnerable to future quantum adversaries and large-scale inference attacks. In this paper, we introduce Data Communities as a novel paradigm for privacy-preserving, blockchain-enabled cooperative digital infrastructures, formalized within the Cooperative Digital Infrastructure (CDI) framework. Our approach integrates three complementary privacy protection layers: (i) MuReQua, a quantum-resilient blockchain consensus mechanism leveraging CQKD for cryptographic robustness against Shor-type attacks; (ii) DeSSE, an information-theoretically secure distributed storage model based on n × m fragmentation, ensuring zero information leakage below reconstruction thresholds; and (iii) a multi-tier data sovereignty model (C0–C3) enforcing policy-driven data locality and regulatory compliance across federated nodes. We formalize privacy guarantees through an adversarial model encompassing classical, quantum, insider, and governance-level threats, and demonstrate that the proposed architecture achieves information-theoretic confidentiality, forward secrecy, and attack-resilient distributed governance. A privacy leakage analysis shows that the probability of data reconstruction under sub-threshold compromise is identical to zero, outperforming conventional blockchain storage models based on encryption alone. Simulation and case study results indicate that Data Communities achieve up to 99.999% service availability, 55% reduction in external data exposure, and 22–35% carbon-aware optimization, while maintaining strict privacy guarantees across distributed environments. Compared with existing blockchain systems (e.g., Ethereum, Hyperledger Fabric), the proposed framework shifts privacy protection from access-control and pseudonymity to structural, information-theoretic privacy by design. Overall, the results establish Data Communities as a scalable and quantum-resilient foundation for next-generation privacy-preserving blockchain infrastructures, bridging distributed AI, secure storage, and cooperative governance under a unified formal model. Full article
(This article belongs to the Special Issue Data Privacy Protection in Blockchain Systems)
Show Figures

Figure 1

27 pages, 2976 KB  
Article
SLAVUL: A Novel Ontology-Driven Approach for Integrating Cloud SLA Security Knowledge and Vulnerability Intelligence
by Ozgu Can and Sena Yakut
Symmetry 2026, 18(8), 1337; https://doi.org/10.3390/sym18081337 - 8 Aug 2026
Viewed by 333
Abstract
Cloud Service Level Agreements (SLAs) define security obligations, remediation commitments, and compliance requirements between cloud service providers and customers. SLAs define the performance standards and expectations between service providers and users. Therefore, it is an essential element in cloud computing. However, SLA documents [...] Read more.
Cloud Service Level Agreements (SLAs) define security obligations, remediation commitments, and compliance requirements between cloud service providers and customers. SLAs define the performance standards and expectations between service providers and users. Therefore, it is an essential element in cloud computing. However, SLA documents are typically represented in unstructured natural language and lack semantic integration with operational vulnerability management processes. Meanwhile, cloud security platforms continuously generate vulnerability intelligence containing security findings, severity levels, and remediation information. The lack of semantic interoperability between SLA-defined security obligations and vulnerability intelligence limits automated security governance, compliance assessment, and vulnerability management in cloud environments. To address these challenges, this study proposes an integrated semantic approach that enables the representation, integration, and reasoning of SLA-derived security knowledge and cloud vulnerability intelligence within a unified ontology model. The proposed solution combines automated knowledge acquisition from SLA documents, the development of an SLA Security Ontology and a Vulnerability Ontology, ontology alignment techniques, and Semantic Web Rule Language (SWRL)-based reasoning mechanisms to support automated vulnerability management, remediation commitment assignment, and consistency verification. Further, the proposed approach is evaluated using real-world SLA documents and vulnerability information. Experimental results demonstrate that the developed reasoning mechanism successfully identifies logical inconsistencies in 73% of the evaluated SLA cases. The analysis further reveals that the undetected cases correspond to contractually incorrect yet logically consistent outputs, highlighting the complementary role of human validation in ontology-driven security management. As a result, the study demonstrates that ontology engineering and rule-based semantic reasoning can effectively bridge the gap between contractual security obligations and operational vulnerability intelligence. Therefore, the proposed approach provides a foundation for automated vulnerability management, SLA compliance assessment, and semantically aware cloud security governance. Full article
(This article belongs to the Section B: Mathematics)
Show Figures

Figure 1

43 pages, 1129 KB  
Article
A Reliability-Aware Edge–Cloud Framework for Early Intrusion Detection in IoT Networks
by Siraj Azam, Farheen Naaz and Mikail Mohammed Salim
Electronics 2026, 15(16), 3506; https://doi.org/10.3390/electronics15163506 - 7 Aug 2026
Viewed by 277
Abstract
Gateway-resident intrusion detection can act before IoT traffic reaches cloud services, but early decisions are based on incomplete flow prefixes. This paper presents a reliability-aware edge–cloud framework that treats early detection as a sequential routing problem. At each checkpoint, a lightweight gated recurrent [...] Read more.
Gateway-resident intrusion detection can act before IoT traffic reaches cloud services, but early decisions are based on incomplete flow prefixes. This paper presents a reliability-aware edge–cloud framework that treats early detection as a sequential routing problem. At each checkpoint, a lightweight gated recurrent unit (GRU) maps causal packet-prefix features to a malicious-probability estimate. Temperature scaling, asymmetric benign and malicious thresholds, and an eight-packet minimum-evidence gate determine whether a flow exits locally, remains under observation, or is sent for cloud refinement. Short and unresolved flows are classified by regularized logistic regression using a compact 97-feature causal representation. The edge model contains 19,777 parameters, and each cloud submission carries 388 bytes of float32 features. The principal evaluation uses all 309 CIC-IoT-2023 PCAP files under four outer PCAP-disjoint folds, with separate edge-training, calibration, cloud-development, and final-test roles. Across 2,286,754 pooled out-of-fold flows with 88.54% malicious prevalence, the framework resolves 422,190 flows at the edge and routes 1,864,564 for cloud refinement, reducing cloud submissions by 18.46%. The final policy attains 4.47% FPR, 1.89% FNR, 96.82% balanced accuracy, and 98.76% F1 score. Observation-budget analysis identifies 32 packets as a corpus-specific compromise, whereas controlled delays in post-eight-packet information expose the limits of short-prefix detection. On the balanced CICIDS2017 test set, in-domain development attains 97.03% balanced accuracy; zero-shot transfer falls to 86.30%, and target-calibration-only adaptation improves it to 91.65%. Ablation results identify the minimum-evidence gate and cloud-refinement stage as the main reliability controls. Benign false alarms, delayed post-eight-packet information, cross-dataset shift, and scenario/file-level labels remain the principal limitations. Full article
Show Figures

Figure 1

39 pages, 3356 KB  
Article
Smart Pasture Management for Optimizing Grazing Capacity and Herbage Production
by Maria P. Koidou, Maria Kleanthi Tseliou, Christos L. Stergiou, Vasileios A. Memos, Konstantinos G. Zaralis and Konstantinos E. Psannis
Appl. Sci. 2026, 16(15), 7826; https://doi.org/10.3390/app16157826 - 6 Aug 2026
Viewed by 317
Abstract
Grassland and pasture management increasingly requires timely and reliable decision support to address changing environmental conditions, optimize grazing capacity, and improve herbage production. Although digital technologies such as the Internet of Things (IoT), Cloud Computing, Digital Twins, Artificial Intelligence (AI) and Machine Learning [...] Read more.
Grassland and pasture management increasingly requires timely and reliable decision support to address changing environmental conditions, optimize grazing capacity, and improve herbage production. Although digital technologies such as the Internet of Things (IoT), Cloud Computing, Digital Twins, Artificial Intelligence (AI) and Machine Learning (ML) have been widely adopted, they are often implemented as isolated solutions rather than as an integrated management framework. This paper proposes a cloud-based smart grazing framework that combines field monitoring, biomass forecasting, digital twin monitoring, and stocking optimization within a unified architecture. The framework includes two interconnected algorithms: the first supports the operational grazing management cycle through IoT sensing, biomass forecasting, digital twin monitoring, and stocking optimization, while the second enables secure ML training and model updating for biomass prediction, livestock health assessment, and grazing behavior analysis. To ensure data integrity with low computational overhead, the framework employs SHA-256 hash-based verification rather than a full blockchain implementation. The proposed architecture provides a practical approach for integrating monitoring, prediction, and secure data management to support sustainable grazing management. Full article
(This article belongs to the Special Issue Internet of Things (IoT) and Blockchain Applications)
Show Figures

Figure 1

26 pages, 699 KB  
Article
Secure PUF-ASCON-Based Gateway-Assisted D2D Authentication for Resource-Constrained Smart-Manufacturing IIoT Devices
by Alanoud Subahi
Mathematics 2026, 14(15), 2800; https://doi.org/10.3390/math14152800 - 4 Aug 2026
Viewed by 220
Abstract
Smart-manufacturing Industrial Internet of Things (IIoT) deployments increasingly depend on low-latency device-to-device (D2D) communication among resource-constrained, physically exposed field devices. This setting makes mutual authentication and session-key establishment difficult: public-key-intensive or cloud-dependent schemes add overhead, availability dependence, and single points of failure, while [...] Read more.
Smart-manufacturing Industrial Internet of Things (IIoT) deployments increasingly depend on low-latency device-to-device (D2D) communication among resource-constrained, physically exposed field devices. This setting makes mutual authentication and session-key establishment difficult: public-key-intensive or cloud-dependent schemes add overhead, availability dependence, and single points of failure, while weak PUF-based designs may expose challenge-response pairs (CRPs) to replay, disclosure, and modeling attacks. This paper proposes PASMAP, a lightweight PUF-ASCON mutual authentication protocol for gateway-assisted D2D communication in smart-manufacturing IIoT. PASMAP combines SRAM-PUF key reconstruction, fuzzy-extractor helper data, hash- and XOR-based obfuscation, and ASCON authenticated encryption with associated data (AEAD) to protect hardware-rooted identities, hide raw PUF responses, and establish fresh session keys for post-authentication data exchange under an explicitly trusted local-gateway model. The protocol is evaluated against physical, protocol-level, and insider threats, including cloning, tampering, replay, man-in-the-middle, CRP disclosure, PUF modeling, stolen-verifier, and known-key attacks. A real-or-random (ROR) analysis bounds the adversary’s session-key advantage using hash collisions, PUF-response prediction, online guessing, and ASCON AEAD security. A mixed-platform evaluation based on ESP32 primitive timings for the edge devices and desktop timings for the resource-rich gateway yields an estimated total computation cost of 4.762 ms. The initiator and responder require 2.006 ms/264.79 μJ and 2.679 ms/353.63 μJ of computational energy, respectively, while the five-message exchange carries 4704 bits. These results indicate low computational overhead under the stated benchmark and power-model assumptions. However, the protocol totals are operation-count-based estimates, the PUF and fuzzy-extractor operations are simulated, and the energy model excludes several platform- and communication-dependent costs. A complete embedded implementation is therefore required to validate end-to-end latency, memory use, energy consumption, communication-stack overhead, SRAM-PUF reliability, and fuzzy-extractor performance. Full article
(This article belongs to the Special Issue Cryptography, Data Security, and Cloud Computing)
Show Figures

Figure 1

48 pages, 9266 KB  
Article
SDAP-K: A Kerberos-Assisted Secure Data Auditing Protocol for Cloud Storage
by Thangavel Murugan, Nasurudeen Ahamed Noor Mohamed Badusha, Priyan Malarvizhi Kumar and Varalakshmi Perumal
Future Internet 2026, 18(8), 411; https://doi.org/10.3390/fi18080411 - 3 Aug 2026
Viewed by 281
Abstract
Cloud storage services have become a fundamental component of modern computing infrastructures, enabling scalable and cost-effective data management. However, outsourcing data to remote cloud servers introduces significant security challenges, particularly in ensuring data integrity, secure access control, and efficient auditing of stored information. [...] Read more.
Cloud storage services have become a fundamental component of modern computing infrastructures, enabling scalable and cost-effective data management. However, outsourcing data to remote cloud servers introduces significant security challenges, particularly in ensuring data integrity, secure access control, and efficient auditing of stored information. Existing cloud auditing schemes primarily focus on integrity verification and often rely on trusted third-party auditors, leading to additional trust assumptions, communication overhead, and metadata management complexity. To address these limitations, this research presents a Kerberos-Assisted Secure Data Auditing Protocol (SDAP-K) that integrates authenticated service exchange with lightweight integrity verification for outsourced cloud storage. The proposed framework employs Kerberos-based mutual authentication and ticket-driven access control to establish secure communication among the Data Owner, Authentication Server, Metadata Server, and Cloud Data Server. To verify storage correctness, an N-ary hash tree with the Modified Murmur hash algorithm is used to enable efficient file- and block-level auditing without requiring a trusted third-party auditor. The framework further incorporates metadata-assisted auditing, dynamic data operations, and an error localization and recovery mechanism that identifies and restores corrupted data blocks. Security analysis demonstrates that the proposed protocol mitigates unauthorized access, replay attacks, impersonation attempts, and malicious data modification. Experimental results indicate that SDAP-K reduces storage execution time by 18.6%, retrieval time by 24.3%, update time by 21.8%, file-level auditing overhead by 31.5%, and block-level auditing latency by 36.2% compared with state-of-the-art research, while eliminating the need for a trusted third-party auditor. The results indicate that the proposed framework offers a practical, lightweight, and reliable solution for secure cloud data auditing in enterprise cloud storage environments. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Graphical abstract

Back to TopTop