Enhanced Secure Storage Architecture for IAAS Cloud Environments
Authors
Research and Innovation Centre, Agency for Information and Communication Technology (AGETIC), Bamako, Mali (Mali)
Ouedraogo Paloute Karim Charlemagne
Higher School of Computer Science, University Nazi Boni, Bobo-Dioulasso, Burkina Faso (Mali)
Ouedraogo Yann Christian Florian
Higher School of Computer Science, University Nazi Boni, Bobo-Dioulasso, Burkina Faso (Mali)
Research and Innovation Centre, Agency for Information and Communication Technology (AGETIC), Bamako, Mali (Mali)
Article Information
DOI: 10.51583/IJLTEMAS.2026.150700103
Subject Category: Cloud Security
Volume/Issue: 15/7 | Page No: 1321-1331
Publication Timeline
Submitted: 2026-08-01
Accepted: 2026-08-06
Published: 2026-08-18
Abstract
The growing adoption of Cloud Computing has profoundly transformed the management of IT infrastructures by providing flexible, scalable, and on-demand accessible resources. Among the various cloud computing service models, Infrastructure as a Service (IaaS) enables organizations to outsource their computing, networking, and storage resources to cloud providers. However, this outsourcing raises significant security concerns, particularly regarding the confidentiality, integrity, and availability of stored data. This paper presents an analytical study of storage security techniques in IaaS environments and examines the main threats that may affect data hosted in the cloud, including unauthorized access, misconfigurations, insider threats, and cyber attacks. Particular attention is given to cryptographic mechanisms used to protect data, including symmetric, asymmetric, and hybrid encryption techniques, as well as client-side and server-side encryption approaches. Based on this analysis, an enhanced secure storage architecture is proposed. This architecture relies on three main techniques: client-side data encryption using AES-256, encryption key protection through RSA, and the use of a Key Management System (KMS). It also incorporates secure communication protocols and enhanced authentication mechanisms. The objective is to ensure effective data protection while preserving the advantages provided by cloud infrastructures. The results of this study highlight the importance of combining robust encryption techniques, secure key management, and appropriate access control mechanisms to strengthen trust in cloud storage solutions. Finally, emerging approaches such as homomorphic encryption and Zero Trust architectures are presented as promising directions for future developments in cloud security.
Keywords
Cloud Computing, Infrastructure as a Service (IaaS), Cloud Storage Security, Data Encryption, AES-256, RSA, Key Management System (KMS), Zero Trust Architecture.
Downloads
References
1. P. Mell et T. Grance, « The NIST Definition of Cloud Computing », National Institute of Standards and Technology, Gaithersburg, MD, Special Publication (NIST SP) 800‑145, sept. 2011. doi: 10.6028/NIST.SP.800-145. [Google Scholar] [Crossref]
2. P. Yang, N. Xiong, et J. Ren, « Data Security and Privacy Protection for Cloud Storage: A Survey », IEEE Access, vol. 8, p. 131723‑131740, 2020, doi: 10.1109/ACCESS.2020.3009876. [Google Scholar] [Crossref]
3. « Threat Landscape | ENISA ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape [Google Scholar] [Crossref]
4. « Top Threats to Cloud Computing 2024 | CSA ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2024 [Google Scholar] [Crossref]
5. « Cloud Security Threats: Top Threats and 3 Mitigation Strategies », Exabeam. Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.exabeam.com/explainers/cloud-security/cloud-security-threats-top-threats-and-3-mitigation-strategies/ [Google Scholar] [Crossref]
6. N. I. of S. and Technology, « Advanced Encryption Standard (AES) », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 197, mai 2023. doi: 10.6028/NIST.FIPS.197-upd1. [Google Scholar] [Crossref]
7. « RSA and Elliptic Curve Encryption System »:, Int. J. Inf. Secur. Priv., vol. 18, no 1, janv. 2024, doi: 10.4018/IJISP.340728. [Google Scholar] [Crossref]
8. M. R. Khan et al., « Analysis of Elliptic Curve Cryptography & RSA », J. ICT Stand., p. 355‑378, nov. 2023, doi: 10.13052/jicts2245-800X.1142. [Google Scholar] [Crossref]
9. « Using server-side encryption with AWS KMS keys (SSE-KMS) - Amazon Simple Storage Service ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: [Google Scholar] [Crossref]
10. https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html [Google Scholar] [Crossref]
11. K. Munjal et R. Bhatia, « A systematic review of homomorphic encryption and its contributions in healthcare industry », Complex Intell. Syst., p. 1‑28, mai 2022, doi: 10.1007/s40747-022-00756-z. [Google Scholar] [Crossref]
12. J. S. Rauthan, « Homomorphic Encryption in Healthcare Industry Applications for Protecting Data Privacy », 7 janvier 2025, arXiv: arXiv:2501.04058. doi: 10.48550/arXiv.2501.04058. [Google Scholar] [Crossref]
13. « Protecting data with server-side encryption - Amazon Simple Storage Service ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: [Google Scholar] [Crossref]
14. https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html [Google Scholar] [Crossref]
15. S. Rose, O. Borchert, S. Mitchell, et S. Connelly, « Zero Trust Architecture », National Institute of Standards and Technology, NIST Special Publication (SP) 800-207, août 2020. doi: [Google Scholar] [Crossref]
16. 10.6028/NIST.SP.800-207. [Google Scholar] [Crossref]
17. « Cybersecurity Framework », NIST, nov. 2013, Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.nist.gov/cyberframework [Google Scholar] [Crossref]
18. M. Dworkin, « Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC », National Institute of Standards and Technology, NIST Special Publication (SP) 800-38D, nov. 2007. doi: 10.6028/NIST.SP.800-38D. [Google Scholar] [Crossref]
19. « (PDF) IDENTITY AND ACCESS MANAGEMENT (IAM) IN CLOUD SECURITY FRAMEWORKS », ResearchGate. Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.researchgate.net/publication/391270909_IDENTITY_AND_ACCESS_MANAGEMENT_IAM_IN_CLOUD_SECURITY_FRAMEWORKS [Google Scholar] [Crossref]
20. I. T. L. Computer Security Division, « Key Management Guidelines - Key Management | CSRC | CSRC », CSRC | NIST. Consulté le: 15 juin 2026. [En ligne]. Disponible sur: [Google Scholar] [Crossref]
21. https://csrc.nist.gov/projects/key-management/key-management-guidelines [Google Scholar] [Crossref]
22. E. Barker, « Recommendation for Key Management: Part 1 – General », National Institute of Standards and Technology, NIST Special Publication (SP) 800-57 Part 1 Rev. 5, mai 2020. doi: 10.6028/NIST.SP.800-57pt1r5. [Google Scholar] [Crossref]
23. garrodonnell, « How to generate & transfer HSM-protected keys – BYOK – Azure Key Vault ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://learn.microsoft.com/en-us/azure/key-vault/keys/hsm-protected-keys-byok [Google Scholar] [Crossref]
24. « Customer-managed encryption keys (CMEK) | Cloud Key Management Service », Google Cloud Documentation. Consulté le: 15 juin 2026. [En ligne]. Disponible sur: [Google Scholar] [Crossref]
25. https://docs.cloud.google.com/kms/docs/cmek [Google Scholar] [Crossref]
26. msmbaldwin, « Azure encryption overview ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://learn.microsoft.com/en-us/azure/security/fundamentals/encryption-overview [Google Scholar] [Crossref]
27. « Customer-managed encryption keys | Cloud Storage », Google Cloud Documentation. Consulté le: 15 juin 2026. [En ligne]. Disponible sur: [Google Scholar] [Crossref]
28. https://docs.cloud.google.com/storage/docs/encryption/customer-managed-keys [Google Scholar] [Crossref]
29. « Cross-Border Data Sharing Under the CLOUD Act ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://www.congress.gov/crs-product/R45173 [Google Scholar] [Crossref]
30. « Demystifying AWS KMS key operations, bring your own key (BYOK), custom key store, and ciphertext portability | AWS Security Blog ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://aws.amazon.com/blogs/security/demystifying-kms-keys-operations-bring-your-own-key-byok-custom-key-store-and-ciphertext-portability/ [Google Scholar] [Crossref]
31. « Cloud HSM vs KMS: What’s Best for Enterprise Security? », Fortanix. Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://www.fortanix.com/blog/cloud-hsm-vs-kms-which-is-right-for-your-enterprise-data-security-strategy [Google Scholar] [Crossref]
32. N. I. of S. and Technology, « Module-Lattice-Based Key-Encapsulation Mechanism Standard », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 203, août 2024. doi: 10.6028/NIST.FIPS.203. [Google Scholar] [Crossref]
33. N. I. of S. and Technology, « Module-Lattice-Based Digital Signature Standard », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 204, août 2024. doi: 10.6028/NIST.FIPS.204. [Google Scholar] [Crossref]