Risk-Adaptive CP-ABE for Cloud-IoT using dynamic policies and real-time security enforcement
|
Full Text |
Pdf
|
|
Author |
Tanguturi Tejasree and Shaik Ghouhar Taj
|
|
e-ISSN |
1819-6608 |
|
On Pages
|
525-538
|
|
Volume No. |
21
|
|
Issue No. |
8
|
|
Issue Date |
June 20, 2026
|
|
DOI |
https://doi.org/10.59018/042660
|
|
Keywords |
cloud-IoT security, attribute-based encryption (ABE), ciphertext-policy ABE (CP-ABE), dynamic access control, risk-adaptive security, context-aware policy enforcement, edge computing, real-time policy adaptation.
|
Abstract
Cloud-IoT deployments increasingly require fine-grained access control that can respond to rapidly changing operational contexts, including suspicious access behavior, abnormal time or location, and device trust. This paper proposes a risk-adaptive Ciphertext-Policy Attribute-Based Encryption (CP-ABE) framework in an edge-cloud architecture, where an edge gateway computes a risk score and automatically strengthens or relaxes the encryption policy in real time. In low-risk states, data are encrypted under a baseline policy based on role and department; high-risk contexts trigger stricter, short-lived constraints, including location-zone verification, multi-factor authentication (MFA), and a 15-minute access window. The prototype was evaluated using a topology of 10 IoT nodes, an edge gateway, and cloud storage under brute-force, stolen-credential, and replay attacks. The results show that all 15 attacks were mitigated, corresponding to 100% adaptive defense accuracy, while maintaining practical overhead: 12.1 ms average encryption latency, 21.6 ms average decryption latency, and 59.0625 KB of cloud storage usage.
Back