Adaptive Blockchain Based Access Control ABAC for Secure Cloud Data Access: A Comprehensive Approach | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Adaptive Blockchain Based Access Control ABAC for Secure Cloud Data Access: A Comprehensive Approach Mbark ABOUESSAOUAB, Youssef A. Abi, Anass Khannous, Said Bouchkaren This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7409434/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Cloud computing has become a cornerstone for modern enterprises, offering scalable and on-demand resources. However, its centralized architecture poses significant security challenges, especially concerning data access control and integrity. This paper proposes a novel approach that integrates blockchain technology with Attribute-Based Access Control (ABAC) to improve secure, context-aware data access in the cloud. The proposed solution leverages blockchain’s decentralized, immutable infrastructure to store access policies as smart contracts, providing dynamic and fine-grained access control. A middleware layer facilitates the evaluation of access requests, collecting contextual attributes such as time, location, and device type, which are validated against policies stored on the blockchain. The framework ensures traceability, transparency, and scalability while mitigating vulnerabilities associated with traditional Role-Based Access Control (RBAC) systems. Comparative analysis highlights the advantages of the blockchain-based ABAC system over conventional methods, demonstrating its potential to address evolving cloud security challenges. Furthermore, scenarios illustrating unauthorized and authorized access underline the robustness and functionality of the proposed approach. This work lays the foundation for secure and adaptive cloud environments, advancing the adoption of blockchain-based access control mechanisms. Blockchain Cloud computing Smart contracts Cryptographic Middleware Figures Figure 1 Figure 2 Figure 3 Figure 4 INTRODUCTION The adoption of cloud services has transformed data management for businesses, providing scalability, flexibility, and efficiency. Cloud computing has become the cornerstone of digital transformation due to its ability to adapt to changing demands and complexities [ 1 ]. This increased reliance on cloud [ 2 ] threats such as data breaches, denial-of-service (DoS) attacks, and unauthorized Access [ 3 ], which compromise the confidentiality, integrity, and availability of sensitive information. Consequently, companies are looking for more innovative and secure ways to protect their digital assets. Blockchain technology, originally designed for cryptocurrencies [ 4 ], offers great potential for securing cloud systems by solving the problems encountered in traditional centralized setups. The decentralized structure distributes data between different nodes [ 5 ], avoiding single points of failure ,and enhancing system stability. The immutable records of the blockchain add a layer of security, ensuring that data cannot be altered, and its transparency enables actions to be traced, which is essential for compliance and accountability. Blockchain offers a revolutionary solution for access control. By using smart contracts, it applies rules that cannot be changed. The integration of contextual factors such as user roles or access times makes the application of policies more precise and flexible in real time. The decentralized, adaptable model strengthens access control and user identity management [ 6 ], overcoming the limitations of traditional methods. This paper presents a new approach that uses blockchain to address gaps in existing access control systems. Traditionally, systems often rely on static, centralized methods for defining and enforcing access rules, which can lead to inefficiencies and security risks. The system we propose uses blockchain-based Attribute-Based Access Control (ABAC), which offers greater security, flexibility, and responsiveness. By solving today’s access control challenges, this research contributes to the development of more secure, efficient, and effective cloud-based systems. RELATED WORK Recent literature highlights a growing shift toward intelligent, decentralized, and transparent access control mechanisms across various domains. The increasing complexity and sensitivity of data ecosystems—especially in healthcare, finance, and government—have pushed the demand for more context-aware and auditable security solutions. For example, ICT-assisted infrastructures have played a critical role in supporting complex decision-making during the COVID-19 pandemic [ 7 ], enabling the coordination of multi-source data and adaptive control measures. In parallel, artificial intelligence and Industry 4.0 technologies have significantly transformed healthcare systems, introducing data-driven, automated, and resilient operations [ 8 ]. In biomedical and engineering applications, enabling technologies such as cloud computing, blockchain, and IoT are foundational to developing systems that respect user privacy while providing traceable, real-time services. These interdisciplinary advances confirm the rising demand for access control solutions that are not only secure, but also adaptive, auditable, and decentralized. Our proposed framework is aligned with this vision and seeks to extend it within the context of cloud computing. Within the specific domain of cloud security, a range of studies have explored how blockchain technologies enhance data integrity, access control, and system auditability. Gupta and Siddiqui [ 9 ] detail how blockchain’s cryptographic immutability strengthens the trust model of cloud data ecosystems. Similarly, the study “Data Security in Cloud Computing Using Elliptic Curve Cryptography” [ 10 ] demonstrates that ECC can be effectively combined with blockchain to protect cloud data while maintaining computational efficiency. A notable contribution by Tsai and Chou [ 11 ] introduces the cloud@blockchain platform, which combines anonymity, immutability, and smart contracts to support secure file sharing and autonomous access control enforcement. The platform not only protects user identity but also logs access attempts and policy evaluations directly on-chain, improving accountability. The use of smart contracts for operational automation and inter-cloud trust has also gained traction. For instance, Chen et al. [ 12 ] and Ajay & Kumar [ 13 ] propose frameworks where trust and reputation management are embedded in blockchain, allowing cloud users to interact with providers in a transparent, verifiable way. Meanwhile, Awadallah and Samsudin [ 14 ], and Bathen and Jadav [ 15 ], leverage smart contracts to automate Service-Level Agreements (SLAs) across multi-cloud infrastructures. These models reduce manual oversight and promote accountability—but typically rely on static agreements and lack dynamic policy evaluation capabilities needed for real-time access control. Decentralized access control models have also been reinforced through the integration of Attribute-Based Encryption (ABE) and distributed storage systems like IPFS. Bashir and Boucadair [ 16 ]and Ibrahim & Tariq[ 17 ] present hybrid frameworks where blockchain ensures immutable logging while ABE controls attribute-level access. Although promising, many of these architectures treat attribute validation as an off-chain task, limiting their flexibility and real-time responsiveness. To address automation in resource management, Anjangud and Anshu [ 18 ] introduce Saranyu, a decentralized application that orchestrates cloud resource allocation through programmable smart contracts. This approach aligns with our proposed middleware–blockchain architecture that dynamically adapts access based on multiple contextual attributes. From a privacy and identity management perspective, Ghanmi and Alsadig [ 19 ] demonstrate how Decentralized Identifiers (DIDs) can secure interactions between connected medical devices and cloud platforms, offering privacy-preserving identity verification. Similarly, Dudeja and Kaushik [ 20 ] apply blockchain to cloud-based voting systems, using DID concepts to enhance electoral transparency and integrity. Basu and Karmakar [ 21 ] also leverage Ethereum smart contracts to manage the full lifecycle of Virtual Machine Images (VMIs), introducing traceability and tamper-resistance in cloud virtualization processes. Beyond individual solutions, broader reviews such as those by Khanna et al. [ 22 ], Li and Wu [ 23 ], and Keke and Jinnan [ 24 ] explore the general trends and obstacles in blockchain-cloud integration. While these works affirm the potential of Blockchain-as-a-Service (BaaS) for easing adoption and abstracting infrastructure complexity, they often overlook real-time enforcement challenges and the importance of integrating dynamic context-aware policies into access control. In this regard, the work of Dai et al. [ 25 ] is particularly relevant. Their survey on blockchain for edge-enabled IoT systems highlights the importance of decentralized access enforcement in latency-sensitive and distributed architectures. Their findings reinforce the value of combining blockchain and ABAC models in hybrid environments—a concept central to the motivation and design of our proposed system. This table categorizes existing research efforts based on three main areas of focus: (1) blockchain and smart contracts, (2) cryptography and identity management, and (3) sensitive data protection. It includes the relevant references, highlights the technologies used (e.g., ECC, ABE, DIDs, IPFS), and outlines practical use cases such as SLA automation, decentralized authentication, and healthcare data security. The table also evaluates each approach in terms of its contributions to confidentiality and traceability, as well as the limitations encountered, including scalability, standardization needs, and cross-cloud compatibility challenges. This structured summary offers a concise yet informative overview of how various blockchain strategies address different aspects of cloud security. Table 1 Comparative analysis of blockchain-based approaches for securing cloud service Criteria Blockchain and Smart Contracts Cryptography, Identity Management, and Blockchain Blockchain for Sensitive Data Security References [ 11 ]Tsai & Chou, [ 12 ]Chen et al., [ 13 ]Ajay & Kumar, [ 14 ] Awadallah & Samsudin, [ 10 ]for Cloud Security, [ 11 ] Bashir & Boucadair, [ 17 ]Ibrahim & Tariq, [ 18 ]Saranyu, [ 15 ] Dudeja & Kaushik, [ 21 ]Basu & Karmakar [ 15 ]Bathen & Jadav, [ 18 ]Saranyu, [ 22 ]et al., [ 24 ]Keke & Jinnan [ 23 ] Li & Wu [25 ]Dai et al, [ 9 ] Gupta & Siddiqui Technologies Used Blockchain, Smart Contracts, Ethereum, Middleware ECC, ABE, DIDs, Verifiable Credentials Blockchain, IPFS, Smart Contracts, Decentralized Storage Use Cases SLA automation, resource management, policy execution, inter-cloud trust Decentralized identity, secure access delegation, encrypted attribute control Healthcare data protection, voting, VMI lifecycle traceability Confidentiality and Traceability Transparent and autonomous contract enforcement; immutable access logs High confidentiality via ECC & ABE; identity privacy with DIDs Full traceability, tamper-proof data access and storage across cloud systems Limitations Scalability constraints, energy overhead of PoW/PoS, static policies Identity standardization, complexity of cryptographic management Cross-cloud interoperability, latency from decentralized storage systems Blockchain Technology 3.1. Historical Evolution and Key Milestones Blockchain technology was first introduced in 2008 by Satoshi Nakamoto in the whitepaper "Bitcoin: A Peer-to-Peer Electronic Cash System"[ 27 ]. It addressed the double-spending issue in digital currency [ 28 ], enabling secure transactions without intermediaries. Bitcoin’s launch in 2009 marked the first practical use of blockchain, offering a decentralized and trustless system, disrupting traditional finance and showcasing blockchain’s potential beyond digital currencies. In 2015, Ethereum [ 29 ], developed by Vitalik Buterin, expanded blockchain’s functionality with smart contracts—self-executing agreements encoded directly into the blockchain. This innovation enabled decentralized applications (DApps) [ 30 ], opening new possibilities across finance, supply chain, healthcare, and governance. The following image illustrates the historical evolution of blockchain technology, highlighting its major milestones, starting with the creation of Bitcoin in 2008 and progressing to advanced platforms like Ethereum and the introduction of smart contracts. As blockchain evolved, its applications extended beyond cryptocurrencies. Core principles like decentralization, transparency, and immutability addressed challenges across industries. This led to the development of private [ 31 ] [ 32 ]and consortium blockchains [ 33 ], designed to meet the needs of businesses and governments by combining blockchain’s benefits with enhanced control and privacy. 3.2. Key Characteristics of Blockchain Blockchain technology, beyond being a distributed ledger, presents several distinctive features that set it apart from traditional data management systems. These characteristics make it particularly suitable for applications in finance, supply chain management, cloud security, and beyond. The fundamental pillars of blockchain include decentralization, immutability, transparency, enhanced security, resilience, and programmability via smart contracts. 3.2.1. Decentralization Decentralization is a core principle of blockchain technology [ 34 ]. It operates on a distributed network of nodes, each maintaining a full copy of the ledger. This decentralized architecture eliminates the risk of a single point of failure and mitigates threats related to cyberattacks, technical faults, or data corruption. It fosters shared trust by enabling direct transactions between parties without relying on centralized authorities such as banks. This not only reduces transaction costs but also enhances efficiency and system resilience, as each node can continue functioning independently in case of failures elsewhere. 3.2.2. Immutability Immutability ensures that once a transaction is recorded and validated, it cannot be altered or deleted [ 35 ]. Each block contains a cryptographic hash of the previous block, making tampering with data evident and invalidating the chain’s integrity. This feature guarantees data verifiability and security, which is critical in domains requiring rigorous traceability, such as supply chain systems, land registries, and healthcare records. 3.2.3. Transparency Blockchain provides inherent transparency, especially in public blockchain systems where transactions are visible to all participants. This enables real-time auditing and increases system accountability [ 36 ], [ 37 ]. At the same time, blockchain offers pseudonymity, where participants are identified through cryptographic addresses rather than personal identities, balancing transparency with privacy. 3.2.4. Enhanced Security Blockchain incorporates robust cryptographic techniques to protect data integrity and authenticity. Transactions are digitally signed using private keys, ensuring that only authorized users can act on them. Cryptographic hashes link blocks, making unauthorized alterations virtually impossible. Furthermore, consensus mechanisms like Proof of Work (PoW)[ 38 ] and Proof of Stake (PoS) [ 39 ], [ 40 ], validate transactions and secure the network against threats such as double-spending and 51% attacks [ 41 ] [ 42 ]. These features make blockchain a secure foundation for decentralized environments, including IoT networks and cloud infrastructures. 3.2.5. Programmability via Smart Contracts Smart contract programmability is a defining feature of platforms like Ethereum[ 43 ]. These self-executing programs operate automatically when predefined conditions are met, enabling decentralized applications (DApps) to function without human intervention [ 44 ] Decentralized Applications The Blockchain-Empowered Software System. Smart contracts support complex workflows and enforce policy compliance transparently, reducing the need for intermediaries and minimizing the risk of fraud or manual errors. 3.3. Comparison Between Different Types of Blockchain Although blockchain systems share foundational principles decentralization, cryptography, and consensus they are implemented in various forms to meet specific needs. The most common types are public, private, and consortium blockchains, each offering different trade-offs in terms of openness, scalability, and governance. Public blockchains like Bitcoin and Ethereum are permissionless, meaning anyone can participate in the network. While they offer high transparency and robustness, they may not be suitable for applications that require strict confidentiality or compliance with regulatory standards. In contrast, private blockchains restrict access to authorized participants, making them ideal for sectors such as finance and healthcare, where data privacy is critical. Consortium blockchains offer a middle ground by allowing a selected group of organizations to collectively manage the network, promoting collaboration while maintaining data governance. A significant aspect of blockchain evolution is its ability to balance transparency and data protection. Private and consortium blockchains can implement granular access control policies using smart contracts, defining exactly who can access specific data and under what conditions. This feature is particularly relevant in cloud environments that must meet compliance requirements and operate across multiple organizational boundaries. To better understand the operational differences among blockchain types, the table below presents a comparative overview of public, private, and consortium blockchains, evaluating their relevance to cloud-based access control. It highlights key characteristics such as permission models, privacy, and scalability—critical factors when designing security solutions for cloud systems. Table 2 Comparison of blockchain types with respect to access control and data privacy Property Public Blockchain Privat Blockchain Consortium Blockchain Access Control Mechanism Permissionless, anyone can Participate and access data Permissioned, access is Controlled by a central authority Semi decentralized, access is Controlled by a group of entities Data Privacy Low privacy, data is public High privacy, Only authorized participants can access data Medium privacy, Access restricted to consortium members Scalability Limited scalability, slower Transaction speed due to decentralization High scalability, Faster transaction Processing due to centralization Moderate scalability, Depends on the number of Participants and network setup 4. Overview of Cloud Computing Cloud computing is a model for delivering IT services that provides access to a shared pool of configurable computing resources (networks, servers, storage, applications, and services) via the Internet, without the need to own or manage the underlying hardware infrastructure. It is distinguished by its ability to transform access to IT technologies into an on-demand service. In the past, companies had to invest heavily in hardware infrastructure and software to manage their IT operations. This traditional model involved high capital costs, long deployment times, and increased complexity as the infrastructure expanded. 4.1. Cloud Security Threats & Risks Cloud service providers operate within large and complex infrastructures, making them prime targets for a range of advanced security threats. These include data breaches—one of the most significant concerns. Breaches occur when unauthorized parties gain access to sensitive information, either maliciously or by exploiting vulnerabilities. The consequences are considerable: financial losses, regulatory fines, legal liabilities, and a significant erosion of customer trust. Another major challenge is the threat of Distributed Denial-of-Service (DDoS) attacks [ 45 ]. These attacks overwhelm the infrastructure with excessive traffic, rendering services inaccessible to legitimate users. Resulting system downtime can have catastrophic effects on business operations, from halting critical processes to disrupting income streams. Beyond operational disruption, prolonged service unavailability may lead to customer dissatisfaction and reputational damage. Identity and Access Management (IAM) remains a complex and persistent challenge[ 46 ] [ 47 ]. The growing reliance on cloud-based solutions demands robust mechanisms to verify user identities and manage access rights securely and efficiently. 4.2. Traditional Security Approaches To address these risks, cloud service providers have implemented several well-established strategies. One of the key measures is data encryption, which protects sensitive information by rendering it inaccessible without the correct decryption key. Encryption safeguards confidentiality[ 48 ] both during transmission and while data is at rest [ 49 ]. Access management is another essential component. Strict policies, combined with IAM systems [ 50 ], restrict access to authorized users and reduce the likelihood of unauthorized intrusions. This approach can be enhanced by adaptive mechanisms that account for contextual factors such as access time, location, or device type—thereby improving threat resistance. Firewalls remain a core security tool[ 51 ][ 51 ], acting as barriers between trusted internal networks and external threats. They monitor and filter network traffic based on predefined rules. However, while these traditional methods are effective, they are not always sufficient to counter the rapidly evolving threats within cloud environments. More innovative and adaptive solutions, such as blockchain-based frameworks, are needed to meet the growing security demands. 4.3. Cloud Computing Security Needs 4.3.1. Data Integrity Cloud computing provides a cost-effective alternative for data storage, allowing users to access and manage data remotely. However, this raises critical concerns about data integrity [ 52 ] [ 53 ]. Without direct control over physical infrastructure, users cannot always verify whether their data has been altered or corrupted. Ensuring that stored data remains reliable and unmodified is a major challenge. To address this, robust technologies such as blockchain and advanced verification protocols are necessary. These tools can enhance trust and accountability in cloud environments by providing verifiable records and user-controlled visibility over stored data. 4.3.2. Data Sharing In cloud systems, where resources are shared among multiple users, unauthorized data access poses a serious risk [ 54 ]. Data owners must address vulnerabilities that could lead to unintended exposure. Encryption is a foundational strategy—making data unreadable to unauthorized parties, even if accessed. Secure data transmission is also vital. It requires careful planning regarding when and where data is encrypted and decrypted. An often overlooked but critical component is key management. Without robust key distribution and handling procedures, even encrypted data can be compromised. Secure key management is essential to ensure reliable long-term protection. 4.3.3. Data Auditing Security concerns around data auditability continue to hinder cloud adoption. Users must regularly verify outsourced data to ensure its integrity. However, frequent audits and communication with cloud providers can be resource-intensive. Solutions such as remote public auditing allow third-party auditors (TPAs) to verify data on behalf of users. While this reduces the burden, it also introduces centralized trust risks. A dishonest or negligent TPA may incorrectly report audit results, potentially leading to undetected data corruption. This highlights the need for more trustworthy, decentralized auditing mechanisms. 4.3.4. Access Control and Authentication Authentication and access control mechanisms [ 55 ]are vital for verifying the legitimacy of all participants in cloud environments—whether users or service providers. Weak identity verification opens the door to security breaches [ 56 ]. Moreover, poor access control can negatively affect other functions, such as authorization and auditing. Traditional access control systems typically rely on centralized management entities, which create points of vulnerability. These systems often lack transparency, traceability, immutability, and strong governance mechanisms. Thus, more decentralized and context-aware access control models are essential. 5.1 Overview of Existing Solutions Recent studies on the integration of blockchain into cloud computing have addressed key challenges in security, identity management, and operational transparency. The literature broadly supports the potential of blockchain to enhance data protection, decentralized access control, and auditability in cloud environments. Security Enhancement through Blockchain Blockchain improves data security by enabling tamper-proof records and decentralized enforcement mechanisms. Approaches leveraging homomorphic encryption allow for computations on encrypted data, ensuring confidentiality. Additionally, attribute-based encryption (ABE) is employed to control access based on user-specific attributes, enhancing availability while preserving integrity. Blockchain-Based Access Control Several models implement attribute-based access control (ABAC) using blockchain smart contracts to define and enforce fine-grained policies. These contracts automate decision-making processes and ensure that all access requests and outcomes are transparently and immutably recorded, which strengthens accountability and regulatory compliance. Decentralized Identity Management Decentralized identifiers (DIDs) provide a blockchain-enabled alternative to centralized identity providers [ 57 ] [ 58 ]. This enhances user control over personal data, facilitates privacy-preserving authentication, and adapts well to dynamic and federated cloud environments. Cross-Provider Security and Interoperability Smart contracts allow the definition of interaction rules between multiple cloud service providers, fostering trust, transparency, and dynamic security configurations. Blockchain enables automated and verifiable enforcement of inter-provider agreements and compliance with service-level policies. Secure Cloud Data Storage and Processing The use of blockchain with decentralized storage systems like InterPlanetary File System IPFS ensures data availability and integrity. Smart contracts manage access and processing workflows across heterogeneous cloud environments. Security models combine encryption techniques with blockchain validation mechanisms to protect data during storage, transmission, and computation phases. To synthesize the reviewed literature and highlight key research trends, this subsection presents a comparative classification of blockchain-based solutions proposed for cloud environments. The classification focuses on five dominant categories identified in the literature: security integration, decentralized access control, identity management, multi-cloud provider security, and secure storage and processing. Table 3 below summarizes the primary objectives, technologies used, benefits, and limitations of each approach. This synthesis provides a comprehensive understanding of how blockchain is currently being leveraged to enhance cloud infrastructures and where the current approaches still fall short. Table 3 Classification of Existing Blockchain-Based Solutions in Cloud Environments Approach Primary Objective Technologies Used Advantages Limitations Security Integration Ensure data integrity, confidentiality, and availability Blockchain, Homomorphic Encryption, ABE Tamper-proof records, secure encrypted computation, fine-grained access Potential latency and scalability issues Access Control via Blockchain Decentralized and auditable access control Smart Contracts, ABAC, CP-ABE Automated enforcement, immutability, regulatory compliance Complex implementation and policy updates Decentralized Identity (DID) Trustless identity management Blockchain, Decentralized Identifiers (DIDs) User control, privacy preservation, adaptive verification Lack of standardization and limited adoption Cross-Provider Security Secure interactions across multiple cloud providers Smart Contracts, Blockchain Federation Transparency, enforceable policies, trust enhancement Interoperability challenges and varying APIs between providers Secure Data Storage & Processing Eliminate third-party dependence for storage & computing IPFS, Smart Contracts, Blockchain, ABE Decentralization, resilience, secure access and auditability Variable performance, resource overhead, and integration complexity 5.2 Identified Gaps and Limitations Despite extensive progress in integrating blockchain into cloud environments, several critical challenges persist that hinder full realization of its potential. Blockchain consensus mechanisms, while securing data integrity, often introduce scalability issues due to limited transaction throughput and resource-intensive operations. Energy consumption, particularly with Proof-of-Work (PoW), raises sustainability concerns, although alternatives like Proof-of-Stake (PoS) are still evolving and not without trade-offs. Interoperability remains a major barrier, as diverse APIs, standards, and service-level agreements (SLAs) across cloud providers complicate seamless integration. Furthermore, the complexity of deploying and managing smart contracts and decentralized infrastructure presents a steep learning curve for many organizations, especially smaller entities lacking technical expertise. Additionally, existing solutions have been mostly tested in controlled environments, which limits insights into their behavior under real-world cloud conditions, where performance, heterogeneity, and user behavior vary significantly. Finally, legal and regulatory constraints such as compliance with data protection laws like GDPR [ 59 ] conflict with the immutable nature of blockchain, posing challenges for lawful data erasure or correction. These combined limitations reveal the inadequacy of current blockchain-based approaches in supporting dynamic, context-aware, and scalable access control in cloud environments. To address these challenges, the next section presents our proposed adaptive ABAC framework integrated with blockchain technologies 5.3. Motivation for Using Blockchain in Data Access within the Cloud Integrating blockchain technology into cloud environments for managing data access represents a significant advancement in addressing key security challenges and reinforcing existing mechanisms. This approach not only capitalizes on blockchain's inherent strengths but also introduces innovative solutions tailored to modern cloud complexities. 5.3.1. Enhanced Security and Immutability Traditional cloud systems often rely on centralized access control mechanisms, making them susceptible to unauthorized modifications and single points of failure. In contrast, the decentralized and immutable ledger provided by blockchain ensures that access policies and audit logs are tamper-proof, thereby offering robust data security. This transition to a decentralized model enables organizations to maintain transparent and trustworthy audit trails. Such immutable logging is especially crucial in sectors where regulatory compliance and accountability are mandatory, as it guarantees that records cannot be altered or forged by malicious actors. 5.3.2. Decentralized Access Management Centralized systems pose inherent risks due to their reliance on a single point of control. Blockchain technology addresses this issue by distributing governance across a decentralized network [ 60 ], significantly enhancing system resilience. Through the use of smart contracts, blockchain enforces access control policies dynamically and autonomously, eliminating the need for centralized intermediaries. These contracts are triggered by predefined conditions—such as user role or time of access—ensuring precision, adaptability, and automated enforcement. Moreover, blockchain’s immutable architecture enables transparent and verifiable tracking of all access activities, which strengthens trust and supports compliance with security standards. This decentralized model effectively mitigates the limitations of traditional centralized access management approaches. 5.3.3. Fine-Grained and Dynamic Access Control Implementing precise, attribute-based access levels remains a challenge in many conventional systems. When integrated with blockchain and attribute-based encryption (ABE) mechanisms, access control becomes fine-grained, dynamic, and context-sensitive. This allows organizations to define flexible, secure permissions that automatically adapt to operational changes and evolving security needs. Multi-Cloud Interoperability: As enterprises increasingly operate across multiple cloud providers, each with distinct APIs and service-level agreements (SLAs) [ 61 ], synchronizing access policies becomes a complex task. Blockchain offers a unified and consistent framework for cross-platform access control, streamlining policy harmonization in heterogeneous cloud ecosystems. Mitigation of Unauthorized Access: Unauthorized access is a persistent threat in centralized architectures. Blockchain enhances authentication mechanisms through cryptographic consensus protocols, significantly reducing exposure to such risks. Features like decentralized identity verification and tamper-proof logging further reinforce trust and transparency in access control operations. Innovative Framework for Enhanced Access Control 6.1. Introduction and Context The rapid progression in the adoption of cloud services has transformed data management, but has introduced significant security challenges [ 62 ], particularly when it comes to controlling access to sensitive data. Conventionally centralized mechanisms, while functional, are vulnerable to single points of failure, lack transparency and struggle to adapt dynamically to changing access requirements. With blockchain technology, a decentralized, transparent and immutable infrastructure solves these problems. Blockchain, by eliminating single points of control, improves system resilience, guarantees auditability through transparent access logs, and enables dynamic policy enforcement through smart contracts. The proposed approach integrates Attribute-Based Access Control (ABAC) into the blockchain using middleware. ABAC’s flexibility, based on user, resource, and environmental attributes, combined with blockchain’s strengths, provides secure, scalable, and fine-grained access management. Middleware ensures seamless integration, enabling cloud providers to enhance security, meet compliance standards, and foster client trust while overcoming the limitations of centralized systems. ABAC introduces a decentralized and adaptive framework for access control that combines blockchain technology, middleware, and smart contracts. This figure highlights the core security-enhancing features of the proposed approach. These include decentralized access control via blockchain, context-aware decision-making through middleware, immutability of access logs using smart contracts, and fine-grained attribute-based policy enforcement. The integration of these components ensures a secure, transparent, and adaptable access control system for cloud environments. Each feature is aligned with the framework’s goals of eliminating central points of failure, enhancing traceability, and responding dynamically to changing access contexts. 6.2. Architecture model proposal for access control in cloud environments The model is organized into three key layers, providing secure, adaptable, and dynamic access control in cloud environments. These layers work to assess and enforce access policies based on predefined attributes and contextual information. The following is an overview of the three main layers: 6.2.1. Blockchain Layer The blockchain layer is the foundation of the proposed access control system, leveraging blockchain’s decentralized and immutable nature to enhance security and transparency. This layer is responsible for: Policies for access control are encoded in smart contracts using a set of predefined rules and conditions. These may include attributes such as user role, access time, device type and location. Smart contracts ensure that the rules governing data access are immutable and transparently enforceable. Maintaining Immutable Logs of Access Requests and Decisions: corresponding decision are recorded immutably on the blockchain. This ensures a comprehensive audit trail, promoting accountability and enabling compliance with regulatory requirements. 6.2.2. Middleware Layer The middleware layer acts as a critical intermediary, facilitating seamless interaction between the cloud services and the blockchain. Its primary roles include: Evaluating Access Requests: When a user or system initiates an access request, the middleware evaluates the request by checking user attributes, roles, or conditions defined in the policies stored on the blockchain. This ensures decisions are dynamic and context-aware, filtering out invalid requests early and reducing the blockchain’s workload. Decision implementation: Following evaluation, the middleware interacts with the blockchain to retrieve the appropriate access control decision and ensure that it is applied quickly and accurately. 6.2.3. Cloud Data Layer The Data Layer in a cloud environment serves as the Foundation where user information is securely stored and managed. By working in with the blockchain and middleware, it ensures a robust framework for data management. This layer is characterized by: Encrypted data storage: user data is stored in an encrypted format within the cloud data layer to protect it from unauthorized access and guarantee data confidentiality and transform sensitive information into unreadable ciphertext to make it inaccessible, even if unauthorized parties manage to bypass other security measures. Access verification: the cloud data layer responds to access requests only after receiving validation from the middleware. This multi-level verification mechanism ensures that only authorized entities can access the data, effectively mitigating the risks associated with unauthorized access or data breaches. In addition, the inclusion of real-time authentication measures ensures that access requests are continually checked and validated against changing security contexts. 6.3. Framework Implementation proposed approach consists of three main components: policy definition, middleware operations and smart contract logic. Each of these components plays a crucial role in ensuring secure, efficient and context-aware access control in the cloud environment. 6.3.1. Policy Definition Access control policies are implemented through smart contracts, which act as self-executing rules embedded within the blockchain. These policies are designed to be dynamic and context-aware, ensuring that access decisions are not only secure but also adaptable to real-world scenarios. A policy might specify that a user can access sensitive data only during specific hours (9 AM to 5 PM), from a registered device (a company-issued laptop), and based on their assigned role (a manager or an intern). For instance, the policies encompass several contextual attributes: Access Time: Identifies specific periods of time during which access to resources is allowed ensuring that resources are availaible only during approved periods, reducing the risk of unauthorized access outside of working hours. Device type: Restricts access based on the type of device used, ensuring both compatibility and security. User role: Enables access to be granted or denied on the basis of predefined roles and tasks assigned to the user. 6.3.2. Middleware Operations The middleware layer acts as a bridge between the users, the cloud infrastructure and the blockchain, ensuring seamless integration and secure access, preserving the integrity and efficiency of the entire system. - Request evaluation: The Middleware layer is responsible for capturing access requests initiated by users or applications. When the middleware layer receives a request, it meticulously evaluates it against the predefined access control policies built into the blockchain’s smart contracts. - Context Validation: To enhance security, the middleware gathers contextual information such as time of access, device type, and user role, to ensures that the access requests align with the defined policies. IP Address: Confirms the geographical origin of the request. Geolocation: Validates that the request is coming from an approved region. Other Contextual Attributes: Assesses other conditions defined in the smart contract policies. - Decision Enforcement: Once a decision is made based on the evaluation and validation processes, the middleware relays the result to the cloud system. For approved requests, the middleware ensures the cloud system grants the necessary access; for denied requests, the action is blocked and logged. 6.3.3. Smart Contract Logic Smart contracts represent the core decision-making unit of the proposed approach, executing access control policies autonomously without requiring human intervention. These contracts are designed to evaluate access requests in Realtime, using a combination of contextual attributes 6.4. Unified Access Control Workflow in the Proposed Blockchain-Based Approach To demonstrate the strength and functionality of our approach for securing data access in the cloud, this scenario combines two distinct cases. In the first case, an unauthorized user attempts to access confidential data from an unregistered mobile device outside of approved hours. The middleware collects contextual details such as the user’s location, time of access, and device type. It identifies that the GPS location is unapproved, the access occurs outside of permitted hours, and the device is not registered. This information is sent to the blockchain, where a smart contract evaluates it against predefined policies. As the policies prohibit access under these conditions, the request is denied, and the attempt is immutably logged. In the second case, a registered user requests access to sensitive data during approved working hours using a verified device. The middleware confirms that the location is authorized, the time is within the permitted range, and the device is secure and registered. This request is also sent to the blockchain, where the smart contract verifies that all conditions are met. The request is approved, the decision is logged immutably, and the cloud system is notified to grant access The diagram highlights the role of each component user, middleware, blockchain, and cloud storage and demonstrates how contextual, real-time access control is enforced securely and transparently. User : The individual attempting to access a confidential document or resource stored in the cloud. Middleware Layer : The central intermediary between the user, the blockchain, and the cloud storage system, plays a pivotal role in gathering contextual information, ensures access requests are thoroughly vetted before being forwarded to the blockchain. Blockchain (Smart Contract ): The decentralized and immutable system for storing access control policies and evaluating requests based on predefined rules (e.g., granting access only during approved hours or from authorized devices) ensures that access policies are transparently and immutably enforced via smart contracts. Cloud Data Layer : The actual storage system where sensitive and encrypted user data resides, ensures data remains secure and inaccessible without proper authorization. The blockchain strategy addresses the critical challenges of securing access to data in cloud environments. Combining attribute-based access control (ABAC) with an intermediate layer and blockchain, we ensure a dynamic, fine-grained and context-sensitive security mechanism. This design not only improves the granularity of access control, but also addresses common weaknesses of traditional centralized systems. One of the keys benefits of this approach is the use of blockchain to store immutable logs and enforce smart contract-based access policies. This provides the transparency, accountability and unforgeable enforcement of rules that are essential for compliance and security in cloud ecosystems. One of the key benefits of this approach is the use of blockchain to store immutable logs and enforce smart contract-based access policies. This provides the transparency, accountability and unforgeable enforcement of rules that are essential for compliance and security in cloud ecosystems. In additional, the middleware layer acts as a critical intermediary, providing real-time evaluation of access requests based on dynamic contextual attributes such as time, location and device type. This contextual awareness improves the system’s ability to adapt to complex real-world scenarios. Including a data layer in the cloud, where sensitive information is stored in an encrypted format, provides additional protection against unauthorized access. By demanding verification of the blockchain before granting access, this approach minimizes risks such as data breaches. 6.5. Performance Evaluation Scenario To illustrate the practical applicability and dynamic behavior of the proposed blockchain-based ABAC framework, we simulated a realistic scenario involving multiple user access attempts under varying contextual conditions. This evaluation highlights the system’s ability to accurately enforce fine-grained access policies in real time and demonstrates its scalability, responsiveness, and auditability The simulation models a cloud infrastructure integrated with our proposed architecture, composed of the following elements: A smart contract deployed on a private Ethereum blockchain that encodes the access control policies; A middleware layer, implemented in Python, that collects contextual attributes from access requests and interacts with the blockchain to evaluate them; A cloud data storage layer that processes access decisions and delivers or denies content based on the results. The middleware collects and transmits real-time contextual attributes, including: user_role (e.g., employee, guest), device_type (e.g., laptop, smartphone), access_time (e.g., 10:30), location_ip (used to validate origin). These attributes are packaged as a request and sent to the blockchain, where the smart contract evaluates them against predefined access policies. Policy Logic and Enforcement The access policy enforced by the smart contract is designed to reflect real-world enterprise access control requirements. It integrates multiple dynamic contextual attributes and applies a multi-condition validation mechanism before reaching an access decision. The logic implemented in the smart contract ensures that only requests satisfying all policy constraints are granted access to cloud resources. The policy rules are defined as follows: User Role Verification: Access is limited to users whose role is explicitly set as employee. This condition ensures that guests, external collaborators, or unauthorized roles are systematically denied, even if other attributes are valid. Temporal Constraint: Access is restricted to business hours, specifically from 08:00 to 18:00 (system time). This prevents access during off-hours, mitigating risks of insider threats or unauthorized activities during non-working periods. Device Authentication: The requesting device must correspond to a known and authorized device, identified through a hashed hardware fingerprint. These device hashes are pre-registered on-chain by an administrator using a dedicated function (registerDevice()). This constraint ensures that access cannot be performed from untrusted or compromised endpoints, even by valid users. Network Location Check: The IP address from which the access request originates must fall within a predefined corporate subnet range. This rule serves to prevent access from external, potentially insecure networks, enforcing location-based restrictions. The smart contract contains two core functions: verifyAccess(), which receives the contextual attributes from the middleware, evaluates them against the stored access policy, and returns a decision (true for grant, false for deny); logAccessAttempt(), which emits an event containing the attributes, the decision, and a timestamp, ensuring permanent and tamper-proof logging on the blockchain ledger. This on-chain enforcement model eliminates reliance on traditional, centralized Policy Decision Points (PDPs) and ensures both transparency and immutability. By executing attribute verification within the smart contract itself, the framework guarantees that no access request can bypass evaluation, and no policy manipulation can occur without authorization. This model significantly enhances trust, auditability, and resistance to tampering, making it well-suited for sensitive enterprise cloud environments. The image illustrates the complete access control process: a user submits an access request with contextual attributes (role, device, time, location); the middleware collects and forwards these attributes to the blockchain; a smart contract evaluates them against encoded policies; the decision (grant or deny) is returned to the cloud storage system, which enforces it by either delivering or blocking the requested content. Evaluation Results Four representative access attempts were simulated to cover both valid and invalid conditions. The outcomes are summarized below Table 1 Policy-Based Access Decision Outcomes in Simulated Scenarios Case Description Role Time Device Location Access Decision Response Time 1 Valid user with correct context Employee 10:30 Registered PC Internal Network Granted 130 ms 2 Invalid device used by valid user Employee 11:00 Unknown Device Internal Network Denied 127 ms 3 Valid user outside authorized hours Employee 21:00 Registered PC Internal Network Denied 125 ms 4 Unauthorized user with invalid context Guest 15:00 Unknown Device Public Wi-Fi Denied 133 ms Discussion Following the evaluation scenario, the results confirm that the proposed blockchain-based ABAC framework is both theoretically sound and practically effective. The framework successfully evaluated access requests based on multiple dynamic attributes—such as user role, device identity, access time, and location—and enforced access policies with high accuracy. The embedded smart contracts consistently denied access when one or more contextual parameters were invalid and granted access only when all predefined conditions were satisfied. This reinforces the precision and robustness of the attribute-based decision logic implemented in the blockchain layer. In terms of performance, access decisions were executed within a narrow response time window of 125 to 133 milliseconds, regardless of the scenario complexity. These variations are attributed to the number of attributes assessed, the internal decision flow within the smart contract, and minimal fluctuations in middleware processing. Nonetheless, the system consistently delivered access decisions within an acceptable threshold (< 150 ms), confirming its responsiveness and real-time applicability—an essential criterion for enterprise environments such as healthcare, finance, or industrial control systems. A major strength of the proposed framework lies in its capacity to ensure end-to-end auditability. Each access attempt—successful or denied—is immutably recorded on the blockchain ledger, providing a tamper-proof, transparent audit trail. This feature enhances system accountability and supports regulatory compliance, forensic investigation, and operational transparency. Beyond these technical benefits, the inclusion of a middleware layer plays a pivotal role in managing dynamic attributes and offloading processing from the blockchain, contributing to system efficiency and scalability. The framework addresses the limitations of traditional Role-Based Access Control (RBAC) by enabling fine-grained, context-aware, and decentralized access control, thereby eliminating dependence on centralized decision points and reducing the risk of single-point failures. 6.6. Results: Overcoming Limitations in Cloud Access Control By incorporating blockchain into the ABAC framework, we can provide a more secure environment for cloud services, allowing for decentralized and tamper-proof storage of access policies, thus optimizing scalability and adaptability without compromising security. This model is highly dynamic and context-aware, since real-time changes of the access rules and attributes can be incorporated avoiding central point failures and improving resilience. Blockchain also allows for seamless interoperability between multi-cloud environments, making it easier to manage complex access control scenarios while ensuring security and compliance across heterogeneous cloud platforms. 6.6.1. Eliminating Centralized Weak Points Blockchain technology revolutionizes traditional access control systems by decentralizing the storage of policies and decision-making processes, effectively eliminating single points of failure and enhancing resilience against attacks. This decentralized architecture also improves transparency, as all access decisions and policy updates are immutably recorded on the blockchain, creating robust audit trails that facilitate trust-building and compliance with regulatory requirements. By integrating blockchain, organizations can establish secure and adaptable access control systems that address modern security challenges effectively. 6.6.2. Enhancing Contextual Adaptability Existing access control models face significant challenges in incorporating real-time contextual attributes such as user location, device status, or network conditions. These limitations hinder their ability to effectively and accurately address security needs in dynamic environments. The proposed approach addresses these shortcomings by dynamically integrating environmental attributes into the decision-making process. By considering these contextual factors, access policies can be adapted in real-time, ensuring more precise and situationally appropriate control. This innovation enhances data security by clearly defining access conditions. As a result, users can access resources only when specific criteria are met, significantly reducing the risk of unauthorized or inappropriate access. 6.6.3. Improving Policy Transparency and Auditability In traditional systems, access logs are often stored in centralized repositories, making them vulnerable to tampering, accidental deletion, or malicious attacks. This centralization undermines the reliability and integrity of records, making it challenging to trace critical events effectively. By integrating blockchain technology, access logs are stored in a decentralized and immutable ledger. Every access attempt, whether successful or denied, is permanently recorded in a manner that cannot be altered or erased. This ensures complete transparency and provides an unchangeable audit trail. This approach enables comprehensive and proactive analysis of events due to the integrity of the recorded data. It also improves compliance with regulatory requirements and improves forensic investigations in the event of a security breach, fostering increased trust between stakeholders. 6.6.4. Facilitating Interoperability Current access control solutions often lack the flexibility to operate seamlessly in diverse cloud environments. The integration of blockchain with modular APIs and middleware ensures compatibility with existing cloud infrastructures, allowing gradual and non-disruptive adoption of the new system. The table below highlights the core distinctions between traditional BAC systems and the proposed blockchain-integrated ABAC framework. It compares both models across five critical aspects: decision criteria, flexibility, context awareness, management structure, and traceability. While BAC relies on static user roles and centralized control, blockchain-based ABAC introduces dynamic, context-sensitive access decisions using attributes such as time, location, and device type. It also leverages decentralized smart contracts for policy enforcement and guarantees tamper-proof audit logs via blockchain immutability. CONCLUSION AND FUTURE WORK This research presented an adaptive access control framework that integrates blockchain technology with Attribute-Based Access Control (ABAC) to provide secure, decentralized, and context-aware data access in cloud environments. By leveraging the immutability and transparency of blockchain smart contracts, the framework decentralizes policy enforcement and eliminates reliance on a centralized authority. At the same time, the middleware layer dynamically collects contextual attributes such as user role, device type, access time, and IP address, which are then evaluated in real time by the blockchain-based policy engine. Through a simulation environment, the proposed system demonstrated its technical feasibility and responsiveness. All access decisions were processed with low latency—ranging from 125 to 133 milliseconds—demonstrating compatibility with real-time cloud applications. The smart contract accurately enforced attribute-based policies, and each decision was immutably logged on-chain, ensuring auditability and traceability. The implementation highlights the potential for secure, automated, and transparent access management in dynamic and distributed systems. However, the current work is not without limitations. The evaluation was conducted in a simulated private Ethereum environment, and the system has yet to be tested at scale across real-world multi-cloud platforms. Additionally, the current policy model is static and manually configured, lacking mechanisms for autonomous adaptation or anomaly detection. Interoperability with diverse cloud service APIs, performance under high-load conditions, and integration with privacy and compliance frameworks (GDPR, HIPAA) remain unaddressed challenges. Future work will address these limitations by deploying the framework across heterogeneous cloud platforms (AWS, Azure, GCP) to evaluate performance, interoperability, and scalability. We also plan to incorporate AI-driven policy generation and dynamic attribute weighting to support self-learning access control decisions. Furthermore, exploring support for decentralized identity systems such as Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) could strengthen the system’s capacity for privacy-preserving and user-centric authentication. Regulatory compliance features, including consent management and audit support, will also be integrated to ensure legal viability in sensitive domains such as healthcare, finance, and government services. Declarations AVAILABILITY OF DATA AND MATERIALS The datasets generated and/or analyzed during the current study are available from the corresponding author upon reasonable request. At this time, no publicly archived datasets are associated with this research. All relevant configurations, access policies, and simulation parameters used in the proof-of-concept implementation can be shared with interested researchers upon justified inquiry for academic or collaborative purposes. FUNDING This research did not receive any specific grant from funding agencies in the public, commercial, or not-for-profit sectors. The work was conducted independently by the authors without external financial support. CONFLICT OF INTEREST The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper. ACKNOWLEDGEMENTS The authors would like to thank the editorial team and anonymous reviewers for their insightful comments, which significantly helped improve the quality and clarity of this manuscript. Their constructive feedback was instrumental throughout the revision process. References « Enterprise cloud service architectures.pdf ». B. Cusack et E. Ghazizadeh, « Evaluating single sign-on security failure in cloud services », Business Horizons , vol. 59, n o 6, p. 605‑614, nov. 2016, doi: 10.1016/j.bushor.2016.08.002. F. Doelitzscher, C. Reich, M. Knahl, et N. Clarke, « Incident Detection for Cloud Environments », 2011. M. F. Shahzad, S. Xu, W. M. Lim, M. F. Hasnain, et S. Nusrat, « Cryptocurrency awareness, acceptance, and adoption: the role of trust as a cornerstone », Humanit Soc Sci Commun , vol. 11, n o 1, p. 4, janv. 2024, doi: 10.1057/s41599-023-02528-7. A. Beikverdi et JooSeok Song, « Trend of centralization in Bitcoin’s distributed network », in 2015 IEEE/ACIS 16th International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD) , Takamatsu: IEEE, juin 2015, p. 1‑6. doi: 10.1109/SNPD.2015.7176229. U. Habiba, R. Masood, M. A. Shibli, et M. A. Niazi, « Cloud identity management security issues & solutions: a taxonomy », Complex Adapt Syst Model , vol. 2, n o 1, p. 5, déc. 2014, doi: 10.1186/s40294-014-0005-9. S. K. Sood, K. S. Rawat, et D. Kumar, « Scientometric analysis of ICT-assisted intelligent control systems response to COVID-19 pandemic », Neural Comput & Applic , vol. 35, n o 26, p. 18829‑18849, sept. 2023, doi: 10.1007/s00521-023-08788-3. S. K. Sood, K. S. Rawat, et D. Kumar, « A visual review of artificial intelligence and Industry 4.0 in healthcare », Computers and Electrical Engineering , vol. 101, p. 107948, juill. 2022, doi: 10.1016/j.compeleceng.2022.107948. A. Gupta, S. T. Siddiqui, S. Alam, et M. Shuaib, « Cloud Computing Security using Blockchain », vol. 6, n o 6, 2019. M. Y. Shakor, M. I. Khaleel, M. Safran, S. Alfarhood, et M. Zhu, « Dynamic AES Encryption and Blockchain Key Management: A Novel Solution for Cloud Data Security », IEEE Access , vol. 12, p. 26334‑26343, 2024, doi: 10.1109/ACCESS.2024.3351119. W.-Y. Tsai, T.-C. Chou, J.-L. Chen, Y.-W. Ma, et C.-J. Huang, « Blockchain as a Platform for Secure Cloud Computing Services », in 2020 22nd International Conference on Advanced Communication Technology (ICACT) , Phoenix Park, PyeongChang,, Korea (South): IEEE, févr. 2020, p. 155‑158. doi: 10.23919/ICACT48636.2020.9061435. S. Xie, Z. Zheng, W. Chen, J. Wu, H.-N. Dai, et M. Imran, « Blockchain for cloud exchange: A survey », Computers & Electrical Engineering , vol. 81, p. 106526, janv. 2020, doi: 10.1016/j.compeleceng.2019.106526. A. Kumar, K. Abhishek, P. Nerurkar, M. R. Ghalib, A. Shankar, et X. Cheng, « Secure smart contracts for cloud‐based manufacturing using Ethereum blockchain », Trans Emerging Tel Tech , vol. 33, n o 4, p. e4129, avr. 2022, doi: 10.1002/ett.4129. R. Awadallah, A. Samsudin, J. S. Teh, et M. Almazrooie, « An Integrated Architecture for Maintaining Security in Cloud Computing Based on Blockchain », IEEE Access , vol. 9, p. 69513‑69526, 2021, doi: 10.1109/ACCESS.2021.3077123. « Bathen et Jadav - 2022 - Smart Contracts in the Cloud.pdf ». L. Yan, L. Ge, Z. Wang, G. Zhang, J. Xu, et Z. Hu, « Access control scheme based on blockchain and attribute-based searchable encryption in cloud environment », J Cloud Comp , vol. 12, n o 1, p. 61, avr. 2023, doi: 10.1186/s13677-023-00444-4. I. T. Javed, F. Alharbi, T. Margaria, N. Crespi, et K. N. Qureshi, « PETchain: A Blockchain-Based Privacy Enhancing Technology », IEEE Access , vol. 9, p. 41129‑41143, 2021, doi: 10.1109/ACCESS.2021.3064896. S. Nayak, N. C. Narendra, A. Shukla, et J. Kempf, « Saranyu: Using Smart Contracts and Blockchain for Cloud Tenant Management », in 2018 IEEE 11th International Conference on Cloud Computing (CLOUD) , San Francisco, CA, USA: IEEE, juill. 2018, p. 857‑861. doi: 10.1109/CLOUD.2018.00121. H. Daniyal et A. Chinwalla, « Blockchain Security Solutions for Ensuring Medical Device Integrity in Cloud Environments ». H. Dudeja, J. Kaushik, et Shalu, « Cloud Based Voting System Using Blockchain Technology », in 2023 5th International Conference on Advances in Computing, Communication Control and Networking (ICAC3N) , Greater Noida, India: IEEE, déc. 2023, p. 1392‑1396. doi: 10.1109/ICAC3N60023.2023.10541707. S. Basu, S. Karmakar, et D. Bera, « Securing Cloud Virtual Machine Image Using Ethereum Blockchain »:, International Journal of Information Security and Privacy , vol. 16, n o 1, p. 1‑22, avr. 2022, doi: 10.4018/IJISP.295868. A. Khanna, A. Sah, V. Bolshev, A. Burgio, V. Panchenko, et M. Jasiński, « Blockchain–Cloud Integration: A Survey », Sensors , vol. 22, n o 14, p. 5238, juill. 2022, doi: 10.3390/s22145238. W. Li, J. Wu, J. Cao, N. Chen, Q. Zhang, et R. Buyya, « Blockchain-based trust management in cloud computing systems: a taxonomy, review and future directions », J Cloud Comp , vol. 10, n o 1, p. 35, juin 2021, doi: 10.1186/s13677-021-00247-5. K. Gai, J. Guo, L. Zhu, et S. Yu, « Blockchain Meets Cloud Computing: A Survey », IEEE Commun. Surv. Tutorials , vol. 22, n o 3, p. 2009‑2030, 2020, doi: 10.1109/COMST.2020.2989392. « Dai et al. - 2019 - Blockchain for Internet of Things A Survey.pdf ». M. Z. Hasan, M. Z. Hussain, Z. Mubarak, A. A. Siddiqui, A. M. Qureshi, et I. Ismail, « Data security and Integrity in Cloud Computing », in 2023 International Conference for Advancement in Technology (ICONAT) , Goa, India: IEEE, janv. 2023, p. 1‑5. doi: 10.1109/ICONAT57137.2023.10080440. S. Nakamoto, « Bitcoin: A Peer-to-Peer Electronic Cash System ». Y. Qi, Z. Yang, Y. Luo, Y. Huang, et X. Li, « Blockchain-Based Light-Weighted Provable Data Possession for Low Performance Devices », Computers, Materials & Continua , vol. 73, n o 2, p. 2205‑2221, 2022, doi: 10.32604/cmc.2022.027939. D. C. Youvan, « Navigating the Evolution of Ethereum: Vitalik Buterin’s Vision for DeFi, Governance, and Scalability », 2024, doi: 10.13140/RG.2.2.14861.35044. Y. Yu, « Analysis of POW in Bitcoin and POS in Peercoin », vol. 39, 2023. X. Huang et D. Huang, « Performance Analysis of Blockchain Consensus Algorithm in Unmanned Aerial Vehicle Ad Hoc Networks », Drones , vol. 9, n o 5, p. 334, avr. 2025, doi: 10.3390/drones9050334. « performance-analysis-private.pdf ». O. Dib, K.-L. Brousmiche, A. Durand, E. Thea, et E. B. Hamida, « Consortium Blockchains: Overview, Applications and Challenges », 2018. J. Zarrin, H. Wen Phang, L. Babu Saheer, et B. Zarrin, « Blockchain for decentralization of internet: prospects, trends, and challenges », Cluster Comput , vol. 24, n o 4, p. 2841‑2866, déc. 2021, doi: 10.1007/s10586-021-03301-8. H. S. Kim et K. Wang, « Immutability Measure for Different Blockchain Structures », in 2018 IEEE 39th Sarnoff Symposium , Newark, NJ, USA: IEEE, sept. 2018, p. 1‑6. doi: 10.1109/SARNOF.2018.8720496. K. G. Gokoglan et S. Cetin, « Blockchain technology and its impact on audit activities », Pressacademia , p. 2, juin 2022, doi: 10.17261/Pressacademia.2022.1567. B. Ş. Alkan, « Real-Time Blockchain Accounting System As A New Paradigm », 2021. M. H. Miraz, P. S. Excell, et K. Sobayel, « Evaluation of Green Alternatives for Blockchain Proof-of-Work (PoW) Approach », AETiC , vol. 5, n o 4, p. 54‑59, oct. 2021, doi: 10.33166/AETiC.2021.04.005. American International University- Bangladesh, Department of Computer Science, Dhaka-1229, Bangladesh, S. Fahim, S. Katibur Rahman, et S. Mahmood, « Blockchain: A Comparative Study of Consensus Algorithms PoW, PoS, PoA, PoV », IJMSC , vol. 9, n o 3, p. 46‑57, août 2023, doi: 10.5815/ijmsc.2023.03.04. C. Lepore, M. Ceria, A. Visconti, U. P. Rao, K. A. Shah, et L. Zanolini, « A Survey on Blockchain Consensus with a Performance Comparison of PoW, PoS and Pure PoS », Mathematics , vol. 8, n o 10, p. 1782, oct. 2020, doi: 10.3390/math8101782. S. Mahmood Babur, S. Ur Rehman Khan, J. Yang, Y.-L. Chen, C. Soon Ku, et L. Yee Por, « Preventing 51% Attack by Using Consecutive Block Limits in Bitcoin », IEEE Access , vol. 12, p. 77852‑77869, 2024, doi: 10.1109/ACCESS.2024.3407521. K. Nicolas et Y. Wang, « A novel double spending attack countermeasure in blockchain », in 2019 IEEE 10th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON) , New York City, NY, USA: IEEE, oct. 2019, p. 0383‑0388. doi: 10.1109/UEMCON47517.2019.8992991. Z. Wang, H. Jin, W. Dai, K.-K. R. Choo, et D. Zou, « Ethereum smart contract security research: survey and future research opportunities », Front. Comput. Sci. , vol. 15, n o 2, p. 152802, avr. 2021, doi: 10.1007/s11704-020-9284-9. W. Cai, Z. Wang, J. B. Ernst, Z. Hong, C. Feng, et V. C. M. Leung, « Decentralized Applications: The Blockchain-Empowered Software System », IEEE Access , vol. 6, p. 53019‑53033, 2018, doi: 10.1109/ACCESS.2018.2870644. S. Naiem, M. Marie, A. E. Khedr, et A. M. Idrees, « DISTRIBUTED DENIAL OF SERVICES ATTACKS AND THEIR PREVENTION IN CLOUD SERVICES », . Vol. , n o 4, 2022. « Advanced_Authentication_Mechanisms_for_I.pdf ». Pratik Jain, « Identity and Access Management in the Cloud », Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol , vol. 11, n o 2, p. 1528‑1535, mars 2025, doi: 10.32628/CSEIT25112523. J. Stanly Jayaprakash, K. Balasubramanian, R. Sulaiman, M. Kamrul Hasan, B. D. Parameshachari, et C. Iwendi, « Cloud Data Encryption and Authentication Based on Enhanced Merkle Hash Tree Method », Computers, Materials & Continua , vol. 72, n o 1, p. 519‑534, 2022, doi: 10.32604/cmc.2022.021269. R. Akter, Md. A. R. Khan, F. Rahman, S. J. Soheli, et N. J. Suha, « RSA and AES Based Hybrid Encryption Technique for Enhancing Data Security in Cloud Computing », International Journal of Computational and Applied Mathematics & Computer Science , vol. 3, p. 60‑71, oct. 2023, doi: 10.37394/232028.2023.3.8. I. Indu, P. M. R. Anand, et V. Bhaskar, « Identity and access management in cloud environment: Mechanisms and challenges », Engineering Science and Technology, an International Journal , vol. 21, n o 4, p. 574‑588, août 2018, doi: 10.1016/j.jestch.2018.05.010. J. Sun, Y. Zeng, G. Shi, W. Li, et Z. Li, « The Research for Virtualization Network Security on Cloud Computing », in Proceedings of the 2018 2nd International Conference on Artificial Intelligence: Technologies and Applications (ICAITA 2018) , Chengdu, China: Atlantis Press, 2018. doi: 10.2991/icaita-18.2018.37. « Hasan et al. - 2023 - Data security and Integrity in Cloud Computing.pdf ». N. Thakur et A. K. Sharma, « Data Integrity Techniques in Cloud Computing: An Analysis », IJARCSSE , vol. 7, n o 8, p. 121, août 2017, doi: 10.23956/ijarcsse.v7i8.36. N. Mohammad, « The Impact of Cloud Computing on Cybersecurity Threat Hunting and Threat Intelligence Sharing Data Security Data Sharing and Collaboration ». A. J. Choudhury, P. Kumar, M. Sain, H. Lim, et H. Jae-Lee, « A Strong User Authentication Framework for Cloud Computing », in 2011 IEEE Asia-Pacific Services Computing Conference , Jeju, Korea (South): IEEE, déc. 2011, p. 110‑115. doi: 10.1109/APSCC.2011.14. « Weak identity verification.pdf ». Gobika S. et Vaishnavi N., « Blockchain Based Identity Management System », Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol , vol. 11, n o 2, p. 1413‑1420, mars 2025, doi: 10.32628/CSEIT25112471. A. Thorve, M. Shirole, P. Jain, C. Santhumayor, et S. Sarode, « Decentralized Identity Management Using Blockchain », in 2022 4th International Conference on Advances in Computing, Communication Control and Networking (ICAC3N) , Greater Noida, India: IEEE, déc. 2022, p. 1985‑1991. doi: 10.1109/ICAC3N56670.2022.10074477. « GDPR Compliant Blockchains–A Systematic Literature Review.pdf ». N. M. Noor, N. A. M. Razali, N. A. Malizan, K. K. Ishak, M. Wook, et N. A. Hasbullah, « Decentralized Access Control using Blockchain Technology for Application in Smart Farming », IJACSA , vol. 13, n o 9, 2022, doi: 10.14569/IJACSA.2022.0130993. H. A. H. Hadi Al Kim et S. Barua, « Service Level Agreement (SLA) for Cloud Computing Compilation with Common and New Formats », int.jour.sci.res.mana , vol. 6, n o 04, avr. 2018, doi: 10.18535/ijsrm/v6i4.ec01. A. S. Priya et S. Sangeetha, « Security Challenges and Solutions in Cloud Computing Environments », INTERNATIONAL ADVANCED RESEARCH JOURNAL IN SCIENCE, ENGINEERING AND TECHNOLOGY , vol. 11, n o 3, mars 2024, doi: 10.17148/IARJSET.2024.11311. Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7409434","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":509075642,"identity":"60c6ca3a-13fd-46c2-b337-869c2cf69b9b","order_by":0,"name":"Mbark ABOUESSAOUAB","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABCklEQVRIiWNgGAWjYDACCQYGxgaGA3B+Aj+YLCBFi2QDiDQgRYsBmI1Hi+7s5mcfZ9TckTM43v74w8c2uzzj86sTPzwwYJDnFzuAVYvZnWPGMzcce2ZscOaMmeTMtuRisxtvN0sAHWY4c3YCdi03EowZH7AdTtxwI4eNmbeNOXHbjbMbQFoSDG7j0pL+mfHBP6CW+88ff+Ztq0/cPOPs5h/4teQYM25sA9nCYCDNC2Lw927Db8udM8WMM/ueGUueyTGTnHHueLHEDd5tFgkGErj9crt9M2PPtztyfMePP/7woaw6j7//7OabPyps5PmlsWvBAiTAKiWIVQ4C/AdIUT0KRsEoGAUjAAAASeFuLVxo+VoAAAAASUVORK5CYII=","orcid":"","institution":"Abdelmalel Essaadi University National School of Applied Sciences","correspondingAuthor":true,"prefix":"","firstName":"Mbark","middleName":"","lastName":"ABOUESSAOUAB","suffix":""},{"id":509075643,"identity":"8ea238b3-2ea2-48e0-b2c4-ede4e5a4e65d","order_by":1,"name":"Youssef A. Abi","email":"","orcid":"","institution":"Abdelmalel Essaadi University National School of Applied Sciences","correspondingAuthor":false,"prefix":"","firstName":"Youssef","middleName":"A.","lastName":"Abi","suffix":""},{"id":509075644,"identity":"c6eeedb5-f54d-4e23-8bc5-63ab22dd4f2e","order_by":2,"name":"Anass Khannous","email":"","orcid":"","institution":"Abdelmalel Essaadi University National School of Applied Sciences","correspondingAuthor":false,"prefix":"","firstName":"Anass","middleName":"","lastName":"Khannous","suffix":""},{"id":509075648,"identity":"cff65784-fd3b-4224-ad84-d9987dd06b5f","order_by":3,"name":"Said Bouchkaren","email":"","orcid":"","institution":"Abdelmalel Essaadi University National School of Applied Sciences","correspondingAuthor":false,"prefix":"","firstName":"Said","middleName":"","lastName":"Bouchkaren","suffix":""}],"badges":[],"createdAt":"2025-08-19 14:08:27","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-7409434/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7409434/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":90502364,"identity":"ced0ebc7-ba07-4b94-a119-c1bd14b9f261","added_by":"auto","created_at":"2025-09-03 11:56:40","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":527427,"visible":true,"origin":"","legend":"\u003cp\u003eHistorical Evolution of blockchain\u003c/p\u003e","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-7409434/v1/cde2a99b062d155a47a16411.png"},{"id":90502362,"identity":"2d428893-7b02-4196-90fb-31531aa6a20e","added_by":"auto","created_at":"2025-09-03 11:56:40","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":247744,"visible":true,"origin":"","legend":"\u003cp\u003eKey Features of Approach for Secure Data Access in the Cloud\u003c/p\u003e","description":"","filename":"floatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-7409434/v1/fa7e1d40493b302bb1860eef.png"},{"id":90502365,"identity":"5a996679-32f6-4e8a-b544-ac5e792b1932","added_by":"auto","created_at":"2025-09-03 11:56:40","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":548942,"visible":true,"origin":"","legend":"\u003cp\u003eSecure Data Access Workflow with Blockchain Integration\u003c/p\u003e","description":"","filename":"floatimage3.png","url":"https://assets-eu.researchsquare.com/files/rs-7409434/v1/30b8633b667cad92f18f8c6e.png"},{"id":90502827,"identity":"d6d243a0-da0f-41ab-a825-85094c70018e","added_by":"auto","created_at":"2025-09-03 12:04:40","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":228977,"visible":true,"origin":"","legend":"\u003cp\u003eDetailed flowchart of the simulation scenario for the blockchain-based ABAC framework.\u003c/p\u003e","description":"","filename":"floatimage4.png","url":"https://assets-eu.researchsquare.com/files/rs-7409434/v1/9690dec9e8ce77e553ae454c.png"},{"id":96708084,"identity":"6e289a70-1c56-4914-a9ca-13c9dae27d4e","added_by":"auto","created_at":"2025-11-25 09:56:13","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":3098033,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7409434/v1/c0f6f493-b368-487d-a03b-0c3b68ba9fdd.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Adaptive Blockchain Based Access Control ABAC for Secure Cloud Data Access: A Comprehensive Approach","fulltext":[{"header":"INTRODUCTION","content":"\u003cp\u003eThe adoption of cloud services has transformed data management for businesses, providing scalability, flexibility, and efficiency. Cloud computing has become the cornerstone of digital transformation due to its ability to adapt to changing demands and complexities [\u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e1\u003c/span\u003e]. This increased reliance on cloud [\u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2\u003c/span\u003e] threats such as data breaches, denial-of-service (DoS) attacks, and unauthorized Access [\u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e3\u003c/span\u003e], which compromise the confidentiality, integrity, and availability of sensitive information. Consequently, companies are looking for more innovative and secure ways to protect their digital assets.\u003c/p\u003e\u003cp\u003eBlockchain technology, originally designed for cryptocurrencies [\u003cspan citationid=\"CR4\" class=\"CitationRef\"\u003e4\u003c/span\u003e], offers great potential for securing cloud systems by solving the problems encountered in traditional centralized setups. The decentralized structure distributes data between different nodes [\u003cspan citationid=\"CR5\" class=\"CitationRef\"\u003e5\u003c/span\u003e], avoiding single points of failure ,and enhancing system stability. The immutable records of the blockchain add a layer of security, ensuring that data cannot be altered, and its transparency enables actions to be traced, which is essential for compliance and accountability.\u003c/p\u003e\u003cp\u003eBlockchain offers a revolutionary solution for access control. By using smart contracts, it applies rules that cannot be changed. The integration of contextual factors such as user roles or access times makes the application of policies more precise and flexible in real time. The decentralized, adaptable model strengthens access control and user identity management [\u003cspan citationid=\"CR6\" class=\"CitationRef\"\u003e6\u003c/span\u003e], overcoming the limitations of traditional methods.\u003c/p\u003e\u003cp\u003eThis paper presents a new approach that uses blockchain to address gaps in existing access control systems. Traditionally, systems often rely on static, centralized methods for defining and enforcing access rules, which can lead to inefficiencies and security risks. The system we propose uses blockchain-based Attribute-Based Access Control (ABAC), which offers greater security, flexibility, and responsiveness. By solving today\u0026rsquo;s access control challenges, this research contributes to the development of more secure, efficient, and effective cloud-based systems.\u003c/p\u003e"},{"header":"RELATED WORK","content":"\u003cp\u003eRecent literature highlights a growing shift toward intelligent, decentralized, and transparent access control mechanisms across various domains. The increasing complexity and sensitivity of data ecosystems\u0026mdash;especially in healthcare, finance, and government\u0026mdash;have pushed the demand for more context-aware and auditable security solutions.\u003c/p\u003e\u003cp\u003eFor example, ICT-assisted infrastructures have played a critical role in supporting complex decision-making during the COVID-19 pandemic [\u003cspan citationid=\"CR7\" class=\"CitationRef\"\u003e7\u003c/span\u003e], enabling the coordination of multi-source data and adaptive control measures. In parallel, artificial intelligence and Industry 4.0 technologies have significantly transformed healthcare systems, introducing data-driven, automated, and resilient operations [\u003cspan citationid=\"CR8\" class=\"CitationRef\"\u003e8\u003c/span\u003e]. In biomedical and engineering applications, enabling technologies such as cloud computing, blockchain, and IoT are foundational to developing systems that respect user privacy while providing traceable, real-time services. These interdisciplinary advances confirm the rising demand for access control solutions that are not only secure, but also adaptive, auditable, and decentralized. Our proposed framework is aligned with this vision and seeks to extend it within the context of cloud computing.\u003c/p\u003e\u003cp\u003eWithin the specific domain of cloud security, a range of studies have explored how blockchain technologies enhance data integrity, access control, and system auditability. Gupta and Siddiqui [\u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e9\u003c/span\u003e] detail how blockchain\u0026rsquo;s cryptographic immutability strengthens the trust model of cloud data ecosystems. Similarly, the study \u0026ldquo;Data Security in Cloud Computing Using Elliptic Curve Cryptography\u0026rdquo; [\u003cspan citationid=\"CR10\" class=\"CitationRef\"\u003e10\u003c/span\u003e] demonstrates that ECC can be effectively combined with blockchain to protect cloud data while maintaining computational efficiency.\u003c/p\u003e\u003cp\u003eA notable contribution by Tsai and Chou [\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e] introduces the cloud@blockchain platform, which combines anonymity, immutability, and smart contracts to support secure file sharing and autonomous access control enforcement. The platform not only protects user identity but also logs access attempts and policy evaluations directly on-chain, improving accountability.\u003c/p\u003e\u003cp\u003eThe use of smart contracts for operational automation and inter-cloud trust has also gained traction. For instance, Chen et al. [\u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e12\u003c/span\u003e] and Ajay \u0026amp; Kumar [\u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e13\u003c/span\u003e] propose frameworks where trust and reputation management are embedded in blockchain, allowing cloud users to interact with providers in a transparent, verifiable way. Meanwhile, Awadallah and Samsudin [\u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e14\u003c/span\u003e], and Bathen and Jadav [\u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e15\u003c/span\u003e], leverage smart contracts to automate Service-Level Agreements (SLAs) across multi-cloud infrastructures. These models reduce manual oversight and promote accountability\u0026mdash;but typically rely on static agreements and lack dynamic policy evaluation capabilities needed for real-time access control.\u003c/p\u003e\u003cp\u003eDecentralized access control models have also been reinforced through the integration of Attribute-Based Encryption (ABE) and distributed storage systems like IPFS. Bashir and Boucadair [\u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e16\u003c/span\u003e]and Ibrahim \u0026amp; Tariq[\u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e17\u003c/span\u003e] present hybrid frameworks where blockchain ensures immutable logging while ABE controls attribute-level access. Although promising, many of these architectures treat attribute validation as an off-chain task, limiting their flexibility and real-time responsiveness.\u003c/p\u003e\u003cp\u003eTo address automation in resource management, Anjangud and Anshu [\u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e18\u003c/span\u003e] introduce Saranyu, a decentralized application that orchestrates cloud resource allocation through programmable smart contracts. This approach aligns with our proposed middleware\u0026ndash;blockchain architecture that dynamically adapts access based on multiple contextual attributes.\u003c/p\u003e\u003cp\u003eFrom a privacy and identity management perspective, Ghanmi and Alsadig [\u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e19\u003c/span\u003e] demonstrate how Decentralized Identifiers (DIDs) can secure interactions between connected medical devices and cloud platforms, offering privacy-preserving identity verification. Similarly, Dudeja and Kaushik [\u003cspan citationid=\"CR20\" class=\"CitationRef\"\u003e20\u003c/span\u003e] apply blockchain to cloud-based voting systems, using DID concepts to enhance electoral transparency and integrity. Basu and Karmakar [\u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e21\u003c/span\u003e] also leverage Ethereum smart contracts to manage the full lifecycle of Virtual Machine Images (VMIs), introducing traceability and tamper-resistance in cloud virtualization processes.\u003c/p\u003e\u003cp\u003eBeyond individual solutions, broader reviews such as those by Khanna et al. [\u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e22\u003c/span\u003e], Li and Wu [\u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e23\u003c/span\u003e], and Keke and Jinnan [\u003cspan citationid=\"CR24\" class=\"CitationRef\"\u003e24\u003c/span\u003e] explore the general trends and obstacles in blockchain-cloud integration. While these works affirm the potential of Blockchain-as-a-Service (BaaS) for easing adoption and abstracting infrastructure complexity, they often overlook real-time enforcement challenges and the importance of integrating dynamic context-aware policies into access control.\u003c/p\u003e\u003cp\u003eIn this regard, the work of Dai et al. [\u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e25\u003c/span\u003e] is particularly relevant. Their survey on blockchain for edge-enabled IoT systems highlights the importance of decentralized access enforcement in latency-sensitive and distributed architectures. Their findings reinforce the value of combining blockchain and ABAC models in hybrid environments\u0026mdash;a concept central to the motivation and design of our proposed system.\u003c/p\u003e\u003cp\u003eThis table categorizes existing research efforts based on three main areas of focus: (1) blockchain and smart contracts, (2) cryptography and identity management, and (3) sensitive data protection. It includes the relevant references, highlights the technologies used (e.g., ECC, ABE, DIDs, IPFS), and outlines practical use cases such as SLA automation, decentralized authentication, and healthcare data security. The table also evaluates each approach in terms of its contributions to confidentiality and traceability, as well as the limitations encountered, including scalability, standardization needs, and cross-cloud compatibility challenges. This structured summary offers a concise yet informative overview of how various blockchain strategies address different aspects of cloud security.\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab1\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eComparative analysis of blockchain-based approaches for securing cloud service\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"4\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eCriteria\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eBlockchain and Smart Contracts\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eCryptography, Identity Management, and Blockchain\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eBlockchain for Sensitive Data Security\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\" morerows=\"1\" rowspan=\"2\"\u003e\u003cp\u003e\u003cb\u003eReferences\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e[\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e]Tsai \u0026amp; Chou, [\u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e12\u003c/span\u003e]Chen et al., [\u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e13\u003c/span\u003e]Ajay \u0026amp; Kumar, [\u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e14\u003c/span\u003e] Awadallah \u0026amp; Samsudin,\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e[\u003cspan citationid=\"CR10\" class=\"CitationRef\"\u003e10\u003c/span\u003e]for Cloud Security, [\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e] Bashir \u0026amp; Boucadair,\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e[\u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e17\u003c/span\u003e]Ibrahim \u0026amp; Tariq, [\u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e18\u003c/span\u003e]Saranyu, [\u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e15\u003c/span\u003e] Dudeja \u0026amp; Kaushik, [\u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e21\u003c/span\u003e]Basu \u0026amp; Karmakar\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e[\u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e15\u003c/span\u003e]Bathen \u0026amp; Jadav, [\u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e18\u003c/span\u003e]Saranyu, [\u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e22\u003c/span\u003e]et al., [\u003cspan citationid=\"CR24\" class=\"CitationRef\"\u003e24\u003c/span\u003e]Keke \u0026amp; Jinnan\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e[\u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e23\u003c/span\u003e] Li \u0026amp; Wu\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e[25 ]Dai et al, [\u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e9\u003c/span\u003e] Gupta \u0026amp; Siddiqui\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eTechnologies Used\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eBlockchain, Smart Contracts, Ethereum, Middleware\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eECC, ABE, DIDs, Verifiable Credentials\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eBlockchain, IPFS, Smart Contracts, Decentralized Storage\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eUse Cases\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eSLA automation, resource management, policy execution, inter-cloud trust\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eDecentralized identity, secure access delegation, encrypted attribute control\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eHealthcare data protection, voting, VMI lifecycle traceability\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eConfidentiality and Traceability\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eTransparent and autonomous contract enforcement; immutable access logs\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eHigh confidentiality via ECC \u0026amp; ABE; identity privacy with DIDs\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eFull traceability, tamper-proof data access and storage across cloud systems\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eLimitations\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eScalability constraints, energy overhead of PoW/PoS, static policies\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eIdentity standardization, complexity of cryptographic management\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eCross-cloud interoperability, latency from decentralized storage systems\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e"},{"header":"Blockchain Technology","content":"\u003cdiv id=\"Sec4\" class=\"Section2\"\u003e\u003ch2\u003e3.1. Historical Evolution and Key Milestones\u003c/h2\u003e\u003cp\u003eBlockchain technology was first introduced in 2008 by Satoshi Nakamoto in the whitepaper \"Bitcoin: A Peer-to-Peer Electronic Cash System\"[\u003cspan citationid=\"CR27\" class=\"CitationRef\"\u003e27\u003c/span\u003e]. It addressed the double-spending issue in digital currency [\u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e28\u003c/span\u003e], enabling secure transactions without intermediaries. Bitcoin\u0026rsquo;s launch in 2009 marked the first practical use of blockchain, offering a decentralized and trustless system, disrupting traditional finance and showcasing blockchain\u0026rsquo;s potential beyond digital currencies.\u003c/p\u003e\u003cp\u003eIn 2015, Ethereum [\u003cspan citationid=\"CR29\" class=\"CitationRef\"\u003e29\u003c/span\u003e], developed by Vitalik Buterin, expanded blockchain\u0026rsquo;s functionality with smart contracts\u0026mdash;self-executing agreements encoded directly into the blockchain. This innovation enabled decentralized applications (DApps) [\u003cspan citationid=\"CR30\" class=\"CitationRef\"\u003e30\u003c/span\u003e], opening new possibilities across finance, supply chain, healthcare, and governance.\u003c/p\u003e\u003cp\u003eThe following image illustrates the historical evolution of blockchain technology, highlighting its major milestones, starting with the creation of Bitcoin in 2008 and progressing to advanced platforms like Ethereum and the introduction of smart contracts. As blockchain evolved, its applications extended beyond cryptocurrencies. Core principles like decentralization, transparency, and immutability addressed challenges across industries. This led to the development of private [\u003cspan citationid=\"CR31\" class=\"CitationRef\"\u003e31\u003c/span\u003e] [\u003cspan citationid=\"CR32\" class=\"CitationRef\"\u003e32\u003c/span\u003e]and consortium blockchains [\u003cspan citationid=\"CR33\" class=\"CitationRef\"\u003e33\u003c/span\u003e], designed to meet the needs of businesses and governments by combining blockchain\u0026rsquo;s benefits with enhanced control and privacy.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec5\" class=\"Section2\"\u003e\u003ch2\u003e3.2. Key Characteristics of Blockchain\u003c/h2\u003e\u003cp\u003eBlockchain technology, beyond being a distributed ledger, presents several distinctive features that set it apart from traditional data management systems. These characteristics make it particularly suitable for applications in finance, supply chain management, cloud security, and beyond. The fundamental pillars of blockchain include decentralization, immutability, transparency, enhanced security, resilience, and programmability via smart contracts.\u003c/p\u003e\u003cdiv id=\"Sec6\" class=\"Section3\"\u003e\u003ch2\u003e3.2.1. Decentralization\u003c/h2\u003e\u003cp\u003eDecentralization is a core principle of blockchain technology [\u003cspan citationid=\"CR34\" class=\"CitationRef\"\u003e34\u003c/span\u003e]. It operates on a distributed network of nodes, each maintaining a full copy of the ledger. This decentralized architecture eliminates the risk of a single point of failure and mitigates threats related to cyberattacks, technical faults, or data corruption. It fosters shared trust by enabling direct transactions between parties without relying on centralized authorities such as banks. This not only reduces transaction costs but also enhances efficiency and system resilience, as each node can continue functioning independently in case of failures elsewhere.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec7\" class=\"Section3\"\u003e\u003ch2\u003e3.2.2. Immutability\u003c/h2\u003e\u003cp\u003eImmutability ensures that once a transaction is recorded and validated, it cannot be altered or deleted [\u003cspan citationid=\"CR35\" class=\"CitationRef\"\u003e35\u003c/span\u003e]. Each block contains a cryptographic hash of the previous block, making tampering with data evident and invalidating the chain\u0026rsquo;s integrity. This feature guarantees data verifiability and security, which is critical in domains requiring rigorous traceability, such as supply chain systems, land registries, and healthcare records.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec8\" class=\"Section3\"\u003e\u003ch2\u003e3.2.3. Transparency\u003c/h2\u003e\u003cp\u003eBlockchain provides inherent transparency, especially in public blockchain systems where transactions are visible to all participants. This enables real-time auditing and increases system accountability [\u003cspan citationid=\"CR36\" class=\"CitationRef\"\u003e36\u003c/span\u003e], [\u003cspan citationid=\"CR37\" class=\"CitationRef\"\u003e37\u003c/span\u003e]. At the same time, blockchain offers pseudonymity, where participants are identified through cryptographic addresses rather than personal identities, balancing transparency with privacy.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec9\" class=\"Section3\"\u003e\u003ch2\u003e3.2.4. Enhanced Security\u003c/h2\u003e\u003cp\u003eBlockchain incorporates robust cryptographic techniques to protect data integrity and authenticity. Transactions are digitally signed using private keys, ensuring that only authorized users can act on them. Cryptographic hashes link blocks, making unauthorized alterations virtually impossible. Furthermore, consensus mechanisms like Proof of Work (PoW)[\u003cspan citationid=\"CR38\" class=\"CitationRef\"\u003e38\u003c/span\u003e] and Proof of Stake (PoS) [\u003cspan citationid=\"CR39\" class=\"CitationRef\"\u003e39\u003c/span\u003e], [\u003cspan citationid=\"CR40\" class=\"CitationRef\"\u003e40\u003c/span\u003e], validate transactions and secure the network against threats such as double-spending and 51% attacks [\u003cspan citationid=\"CR41\" class=\"CitationRef\"\u003e41\u003c/span\u003e] [\u003cspan citationid=\"CR42\" class=\"CitationRef\"\u003e42\u003c/span\u003e]. These features make blockchain a secure foundation for decentralized environments, including IoT networks and cloud infrastructures.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec10\" class=\"Section3\"\u003e\u003ch2\u003e3.2.5. Programmability via Smart Contracts\u003c/h2\u003e\u003cp\u003eSmart contract programmability is a defining feature of platforms like Ethereum[\u003cspan citationid=\"CR43\" class=\"CitationRef\"\u003e43\u003c/span\u003e]. These self-executing programs operate automatically when predefined conditions are met, enabling decentralized applications (DApps) to function without human intervention [\u003cspan citationid=\"CR44\" class=\"CitationRef\"\u003e44\u003c/span\u003e] Decentralized Applications The Blockchain-Empowered Software System. Smart contracts support complex workflows and enforce policy compliance transparently, reducing the need for intermediaries and minimizing the risk of fraud or manual errors.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec11\" class=\"Section2\"\u003e\u003ch2\u003e3.3. Comparison Between Different Types of Blockchain\u003c/h2\u003e\u003cp\u003eAlthough blockchain systems share foundational principles decentralization, cryptography, and consensus they are implemented in various forms to meet specific needs. The most common types are public, private, and consortium blockchains, each offering different trade-offs in terms of openness, scalability, and governance.\u003c/p\u003e\u003cp\u003ePublic blockchains like Bitcoin and Ethereum are permissionless, meaning anyone can participate in the network. While they offer high transparency and robustness, they may not be suitable for applications that require strict confidentiality or compliance with regulatory standards. In contrast, private blockchains restrict access to authorized participants, making them ideal for sectors such as finance and healthcare, where data privacy is critical. Consortium blockchains offer a middle ground by allowing a selected group of organizations to collectively manage the network, promoting collaboration while maintaining data governance.\u003c/p\u003e\u003cp\u003eA significant aspect of blockchain evolution is its ability to balance transparency and data protection. Private and consortium blockchains can implement granular access control policies using smart contracts, defining exactly who can access specific data and under what conditions. This feature is particularly relevant in cloud environments that must meet compliance requirements and operate across multiple organizational boundaries.\u003c/p\u003e\u003cp\u003eTo better understand the operational differences among blockchain types, the table below presents a comparative overview of public, private, and consortium blockchains, evaluating their relevance to cloud-based access control. It highlights key characteristics such as permission models, privacy, and scalability\u0026mdash;critical factors when designing security solutions for cloud systems.\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab2\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eComparison of blockchain types with respect to access control and data privacy\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"4\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eProperty\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003ePublic Blockchain\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003ePrivat Blockchain\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConsortium Blockchain\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eAccess Control Mechanism\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003ePermissionless, anyone can\u003c/p\u003e\u003cp\u003eParticipate and access data\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003ePermissioned, access is\u003c/p\u003e\u003cp\u003eControlled by a central\u003c/p\u003e\u003cp\u003eauthority\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eSemi decentralized, access is\u003c/p\u003e\u003cp\u003eControlled by a group of entities\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eData Privacy\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eLow privacy, data is public\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eHigh privacy,\u003c/p\u003e\u003cp\u003eOnly authorized participants\u003c/p\u003e\u003cp\u003ecan access data\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eMedium privacy,\u003c/p\u003e\u003cp\u003eAccess restricted to consortium members\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eScalability\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eLimited scalability, slower\u003c/p\u003e\u003cp\u003eTransaction speed\u003c/p\u003e\u003cp\u003edue to decentralization\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eHigh scalability,\u003c/p\u003e\u003cp\u003eFaster transaction\u003c/p\u003e\u003cp\u003eProcessing due to centralization\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eModerate scalability,\u003c/p\u003e\u003cp\u003eDepends on the number of\u003c/p\u003e\u003cp\u003eParticipants and network\u003c/p\u003e\u003cp\u003esetup\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\n\u003ch3\u003e4. Overview of Cloud Computing\u003c/h3\u003e\n\u003cp\u003eCloud computing is a model for delivering IT services that provides access to a shared pool of configurable computing resources (networks, servers, storage, applications, and services) via the Internet, without the need to own or manage the underlying hardware infrastructure. It is distinguished by its ability to transform access to IT technologies into an on-demand service. In the past, companies had to invest heavily in hardware infrastructure and software to manage their IT operations. This traditional model involved high capital costs, long deployment times, and increased complexity as the infrastructure expanded.\u003c/p\u003e\u003cdiv id=\"Sec13\" class=\"Section2\"\u003e\u003ch2\u003e4.1. Cloud Security Threats \u0026amp; Risks\u003c/h2\u003e\u003cp\u003eCloud service providers operate within large and complex infrastructures, making them prime targets for a range of advanced security threats. These include data breaches\u0026mdash;one of the most significant concerns. Breaches occur when unauthorized parties gain access to sensitive information, either maliciously or by exploiting vulnerabilities. The consequences are considerable: financial losses, regulatory fines, legal liabilities, and a significant erosion of customer trust.\u003c/p\u003e\u003cp\u003eAnother major challenge is the threat of Distributed Denial-of-Service (DDoS) attacks [\u003cspan citationid=\"CR45\" class=\"CitationRef\"\u003e45\u003c/span\u003e]. These attacks overwhelm the infrastructure with excessive traffic, rendering services inaccessible to legitimate users. Resulting system downtime can have catastrophic effects on business operations, from halting critical processes to disrupting income streams. Beyond operational disruption, prolonged service unavailability may lead to customer dissatisfaction and reputational damage.\u003c/p\u003e\u003cp\u003eIdentity and Access Management (IAM) remains a complex and persistent challenge[\u003cspan citationid=\"CR46\" class=\"CitationRef\"\u003e46\u003c/span\u003e] [\u003cspan citationid=\"CR47\" class=\"CitationRef\"\u003e47\u003c/span\u003e]. The growing reliance on cloud-based solutions demands robust mechanisms to verify user identities and manage access rights securely and efficiently.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec14\" class=\"Section2\"\u003e\u003ch2\u003e4.2. Traditional Security Approaches\u003c/h2\u003e\u003cp\u003eTo address these risks, cloud service providers have implemented several well-established strategies. One of the key measures is data encryption, which protects sensitive information by rendering it inaccessible without the correct decryption key. Encryption safeguards confidentiality[\u003cspan citationid=\"CR48\" class=\"CitationRef\"\u003e48\u003c/span\u003e] both during transmission and while data is at rest [\u003cspan citationid=\"CR49\" class=\"CitationRef\"\u003e49\u003c/span\u003e].\u003c/p\u003e\u003cp\u003eAccess management is another essential component. Strict policies, combined with IAM systems [\u003cspan citationid=\"CR50\" class=\"CitationRef\"\u003e50\u003c/span\u003e], restrict access to authorized users and reduce the likelihood of unauthorized intrusions. This approach can be enhanced by adaptive mechanisms that account for contextual factors such as access time, location, or device type\u0026mdash;thereby improving threat resistance.\u003c/p\u003e\u003cp\u003eFirewalls remain a core security tool[\u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e51\u003c/span\u003e][\u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e51\u003c/span\u003e], acting as barriers between trusted internal networks and external threats. They monitor and filter network traffic based on predefined rules. However, while these traditional methods are effective, they are not always sufficient to counter the rapidly evolving threats within cloud environments. More innovative and adaptive solutions, such as blockchain-based frameworks, are needed to meet the growing security demands.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec15\" class=\"Section2\"\u003e\u003ch2\u003e4.3. Cloud Computing Security Needs\u003c/h2\u003e\u003cdiv id=\"Sec16\" class=\"Section3\"\u003e\u003ch2\u003e4.3.1. Data Integrity\u003c/h2\u003e\u003cp\u003eCloud computing provides a cost-effective alternative for data storage, allowing users to access and manage data remotely. However, this raises critical concerns about data integrity [\u003cspan citationid=\"CR52\" class=\"CitationRef\"\u003e52\u003c/span\u003e] [\u003cspan citationid=\"CR53\" class=\"CitationRef\"\u003e53\u003c/span\u003e]. Without direct control over physical infrastructure, users cannot always verify whether their data has been altered or corrupted. Ensuring that stored data remains reliable and unmodified is a major challenge.\u003c/p\u003e\u003cp\u003eTo address this, robust technologies such as blockchain and advanced verification protocols are necessary. These tools can enhance trust and accountability in cloud environments by providing verifiable records and user-controlled visibility over stored data.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec17\" class=\"Section3\"\u003e\u003ch2\u003e4.3.2. Data Sharing\u003c/h2\u003e\u003cp\u003eIn cloud systems, where resources are shared among multiple users, unauthorized data access poses a serious risk [\u003cspan citationid=\"CR54\" class=\"CitationRef\"\u003e54\u003c/span\u003e]. Data owners must address vulnerabilities that could lead to unintended exposure. Encryption is a foundational strategy\u0026mdash;making data unreadable to unauthorized parties, even if accessed.\u003c/p\u003e\u003cp\u003eSecure data transmission is also vital. It requires careful planning regarding when and where data is encrypted and decrypted. An often overlooked but critical component is key management. Without robust key distribution and handling procedures, even encrypted data can be compromised. Secure key management is essential to ensure reliable long-term protection.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec18\" class=\"Section3\"\u003e\u003ch2\u003e4.3.3. Data Auditing\u003c/h2\u003e\u003cp\u003eSecurity concerns around data auditability continue to hinder cloud adoption. Users must regularly verify outsourced data to ensure its integrity. However, frequent audits and communication with cloud providers can be resource-intensive.\u003c/p\u003e\u003cp\u003eSolutions such as remote public auditing allow third-party auditors (TPAs) to verify data on behalf of users. While this reduces the burden, it also introduces centralized trust risks. A dishonest or negligent TPA may incorrectly report audit results, potentially leading to undetected data corruption. This highlights the need for more trustworthy, decentralized auditing mechanisms.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec19\" class=\"Section3\"\u003e\u003ch2\u003e4.3.4. Access Control and Authentication\u003c/h2\u003e\u003cp\u003eAuthentication and access control mechanisms [\u003cspan citationid=\"CR55\" class=\"CitationRef\"\u003e55\u003c/span\u003e]are vital for verifying the legitimacy of all participants in cloud environments\u0026mdash;whether users or service providers. Weak identity verification opens the door to security breaches [\u003cspan citationid=\"CR56\" class=\"CitationRef\"\u003e56\u003c/span\u003e]. Moreover, poor access control can negatively affect other functions, such as authorization and auditing.\u003c/p\u003e\u003cp\u003eTraditional access control systems typically rely on centralized management entities, which create points of vulnerability. These systems often lack transparency, traceability, immutability, and strong governance mechanisms. Thus, more decentralized and context-aware access control models are essential.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec20\" class=\"Section2\"\u003e\u003ch2\u003e5.1 Overview of Existing Solutions\u003c/h2\u003e\u003cp\u003eRecent studies on the integration of blockchain into cloud computing have addressed key challenges in security, identity management, and operational transparency. The literature broadly supports the potential of blockchain to enhance data protection, decentralized access control, and auditability in cloud environments.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eSecurity Enhancement through Blockchain\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eBlockchain improves data security by enabling tamper-proof records and decentralized enforcement mechanisms. Approaches leveraging homomorphic encryption allow for computations on encrypted data, ensuring confidentiality. Additionally, attribute-based encryption (ABE) is employed to control access based on user-specific attributes, enhancing availability while preserving integrity.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eBlockchain-Based Access Control\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eSeveral models implement attribute-based access control (ABAC) using blockchain smart contracts to define and enforce fine-grained policies. These contracts automate decision-making processes and ensure that all access requests and outcomes are transparently and immutably recorded, which strengthens accountability and regulatory compliance.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eDecentralized Identity Management\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eDecentralized identifiers (DIDs) provide a blockchain-enabled alternative to centralized identity providers [\u003cspan citationid=\"CR57\" class=\"CitationRef\"\u003e57\u003c/span\u003e] [\u003cspan citationid=\"CR58\" class=\"CitationRef\"\u003e58\u003c/span\u003e]. This enhances user control over personal data, facilitates privacy-preserving authentication, and adapts well to dynamic and federated cloud environments.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eCross-Provider Security and Interoperability\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eSmart contracts allow the definition of interaction rules between multiple cloud service providers, fostering trust, transparency, and dynamic security configurations. Blockchain enables automated and verifiable enforcement of inter-provider agreements and compliance with service-level policies.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eSecure Cloud Data Storage and Processing\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThe use of blockchain with decentralized storage systems like InterPlanetary File System IPFS ensures data availability and integrity. Smart contracts manage access and processing workflows across heterogeneous cloud environments. Security models combine encryption techniques with blockchain validation mechanisms to protect data during storage, transmission, and computation phases.\u003c/p\u003e\u003cp\u003eTo synthesize the reviewed literature and highlight key research trends, this subsection presents a comparative classification of blockchain-based solutions proposed for cloud environments. The classification focuses on five dominant categories identified in the literature: security integration, decentralized access control, identity management, multi-cloud provider security, and secure storage and processing.\u003c/p\u003e\u003cp\u003eTable\u0026nbsp;\u003cspan refid=\"Tab3\" class=\"InternalRef\"\u003e3\u003c/span\u003e below summarizes the primary objectives, technologies used, benefits, and limitations of each approach. This synthesis provides a comprehensive understanding of how blockchain is currently being leveraged to enhance cloud infrastructures and where the current approaches still fall short.\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab3\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eClassification of Existing Blockchain-Based Solutions in Cloud Environments\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"5\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eApproach\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003ePrimary Objective\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eTechnologies Used\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eAdvantages\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c5\"\u003e\u003cp\u003eLimitations\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eSecurity Integration\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eEnsure data integrity, confidentiality, and availability\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eBlockchain, Homomorphic Encryption, ABE\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eTamper-proof records, secure encrypted computation, fine-grained access\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003ePotential latency and scalability issues\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eAccess Control via Blockchain\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eDecentralized and auditable access control\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eSmart Contracts, ABAC, CP-ABE\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eAutomated enforcement, immutability, regulatory compliance\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eComplex implementation and policy updates\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eDecentralized Identity (DID)\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eTrustless identity management\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eBlockchain, Decentralized Identifiers (DIDs)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eUser control, privacy preservation, adaptive verification\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eLack of standardization and limited adoption\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eCross-Provider Security\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eSecure interactions across multiple cloud providers\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eSmart Contracts, Blockchain Federation\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eTransparency, enforceable policies, trust enhancement\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eInteroperability challenges and varying APIs between providers\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e\u003cb\u003eSecure Data Storage \u0026amp; Processing\u003c/b\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eEliminate third-party dependence for storage \u0026amp; computing\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eIPFS, Smart Contracts, Blockchain, ABE\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eDecentralization, resilience, secure access and auditability\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eVariable performance, resource overhead, and integration complexity\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec21\" class=\"Section2\"\u003e\u003ch2\u003e5.2 Identified Gaps and Limitations\u003c/h2\u003e\u003cp\u003eDespite extensive progress in integrating blockchain into cloud environments, several critical challenges persist that hinder full realization of its potential. Blockchain consensus mechanisms, while securing data integrity, often introduce scalability issues due to limited transaction throughput and resource-intensive operations. Energy consumption, particularly with Proof-of-Work (PoW), raises sustainability concerns, although alternatives like Proof-of-Stake (PoS) are still evolving and not without trade-offs. Interoperability remains a major barrier, as diverse APIs, standards, and service-level agreements (SLAs) across cloud providers complicate seamless integration. Furthermore, the complexity of deploying and managing smart contracts and decentralized infrastructure presents a steep learning curve for many organizations, especially smaller entities lacking technical expertise. Additionally, existing solutions have been mostly tested in controlled environments, which limits insights into their behavior under real-world cloud conditions, where performance, heterogeneity, and user behavior vary significantly. Finally, legal and regulatory constraints such as compliance with data protection laws like GDPR [\u003cspan citationid=\"CR59\" class=\"CitationRef\"\u003e59\u003c/span\u003e] conflict with the immutable nature of blockchain, posing challenges for lawful data erasure or correction. These combined limitations reveal the inadequacy of current blockchain-based approaches in supporting dynamic, context-aware, and scalable access control in cloud environments. To address these challenges, the next section presents our proposed adaptive ABAC framework integrated with blockchain technologies\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec22\" class=\"Section2\"\u003e\u003ch2\u003e5.3. Motivation for Using Blockchain in Data Access within the Cloud\u003c/h2\u003e\u003cp\u003eIntegrating blockchain technology into cloud environments for managing data access represents a significant advancement in addressing key security challenges and reinforcing existing mechanisms. This approach not only capitalizes on blockchain's inherent strengths but also introduces innovative solutions tailored to modern cloud complexities.\u003c/p\u003e\u003cdiv id=\"Sec23\" class=\"Section3\"\u003e\u003ch2\u003e5.3.1. Enhanced Security and Immutability\u003c/h2\u003e\u003cp\u003eTraditional cloud systems often rely on centralized access control mechanisms, making them susceptible to unauthorized modifications and single points of failure. In contrast, the decentralized and immutable ledger provided by blockchain ensures that access policies and audit logs are tamper-proof, thereby offering robust data security. This transition to a decentralized model enables organizations to maintain transparent and trustworthy audit trails. Such immutable logging is especially crucial in sectors where regulatory compliance and accountability are mandatory, as it guarantees that records cannot be altered or forged by malicious actors.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec24\" class=\"Section3\"\u003e\u003ch2\u003e5.3.2. Decentralized Access Management\u003c/h2\u003e\u003cp\u003eCentralized systems pose inherent risks due to their reliance on a single point of control. Blockchain technology addresses this issue by distributing governance across a decentralized network [\u003cspan citationid=\"CR60\" class=\"CitationRef\"\u003e60\u003c/span\u003e], significantly enhancing system resilience. Through the use of smart contracts, blockchain enforces access control policies dynamically and autonomously, eliminating the need for centralized intermediaries. These contracts are triggered by predefined conditions\u0026mdash;such as user role or time of access\u0026mdash;ensuring precision, adaptability, and automated enforcement. Moreover, blockchain\u0026rsquo;s immutable architecture enables transparent and verifiable tracking of all access activities, which strengthens trust and supports compliance with security standards. This decentralized model effectively mitigates the limitations of traditional centralized access management approaches.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec25\" class=\"Section3\"\u003e\u003ch2\u003e5.3.3. Fine-Grained and Dynamic Access Control\u003c/h2\u003e\u003cp\u003eImplementing precise, attribute-based access levels remains a challenge in many conventional systems. When integrated with blockchain and attribute-based encryption (ABE) mechanisms, access control becomes fine-grained, dynamic, and context-sensitive. This allows organizations to define flexible, secure permissions that automatically adapt to operational changes and evolving security needs.\u003c/p\u003e\u003cp\u003eMulti-Cloud Interoperability: As enterprises increasingly operate across multiple cloud providers, each with distinct APIs and service-level agreements (SLAs) [\u003cspan citationid=\"CR61\" class=\"CitationRef\"\u003e61\u003c/span\u003e], synchronizing access policies becomes a complex task. Blockchain offers a unified and consistent framework for cross-platform access control, streamlining policy harmonization in heterogeneous cloud ecosystems.\u003c/p\u003e\u003cp\u003eMitigation of Unauthorized Access: Unauthorized access is a persistent threat in centralized architectures. Blockchain enhances authentication mechanisms through cryptographic consensus protocols, significantly reducing exposure to such risks. Features like decentralized identity verification and tamper-proof logging further reinforce trust and transparency in access control operations.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\n\u003ch3\u003eInnovative Framework for Enhanced Access Control\u003c/h3\u003e\n\u003cdiv id=\"Sec27\" class=\"Section2\"\u003e\u003ch2\u003e6.1. Introduction and Context\u003c/h2\u003e\u003cp\u003eThe rapid progression in the adoption of cloud services has transformed data management, but has introduced significant security challenges [\u003cspan citationid=\"CR62\" class=\"CitationRef\"\u003e62\u003c/span\u003e], particularly when it comes to controlling access to sensitive data. Conventionally centralized mechanisms, while functional, are vulnerable to single points of failure, lack transparency and struggle to adapt dynamically to changing access requirements. With blockchain technology, a decentralized, transparent and immutable infrastructure solves these problems. Blockchain, by eliminating single points of control, improves system resilience, guarantees auditability through transparent access logs, and enables dynamic policy enforcement through smart contracts. The proposed approach integrates Attribute-Based Access Control (ABAC) into the blockchain using middleware. ABAC\u0026rsquo;s flexibility, based on user, resource, and environmental attributes, combined with blockchain\u0026rsquo;s strengths, provides secure, scalable, and fine-grained access management. Middleware ensures seamless integration, enabling cloud providers to enhance security, meet compliance standards, and foster client trust while overcoming the limitations of centralized systems. ABAC introduces a decentralized and adaptive framework for access control that combines blockchain technology, middleware, and smart contracts.\u003c/p\u003e\u003cp\u003eThis figure highlights the core security-enhancing features of the proposed approach. These include decentralized access control via blockchain, context-aware decision-making through middleware, immutability of access logs using smart contracts, and fine-grained attribute-based policy enforcement. The integration of these components ensures a secure, transparent, and adaptable access control system for cloud environments. Each feature is aligned with the framework\u0026rsquo;s goals of eliminating central points of failure, enhancing traceability, and responding dynamically to changing access contexts.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec28\" class=\"Section2\"\u003e\u003ch2\u003e6.2. Architecture model proposal for access control in cloud environments\u003c/h2\u003e\u003cp\u003eThe model is organized into three key layers, providing secure, adaptable, and dynamic access control in cloud environments. These layers work to assess and enforce access policies based on predefined attributes and contextual information. The following is an overview of the three main layers:\u003c/p\u003e\u003cdiv id=\"Sec29\" class=\"Section3\"\u003e\u003ch2\u003e6.2.1. Blockchain Layer\u003c/h2\u003e\u003cp\u003eThe blockchain layer is the foundation of the proposed access control system, leveraging blockchain\u0026rsquo;s decentralized and immutable nature to enhance security and transparency. This layer is responsible for:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003ePolicies for access control are encoded in smart contracts using a set of predefined rules and conditions. These may include attributes such as user role, access time, device type and location. Smart contracts ensure that the rules governing data access are immutable and transparently enforceable.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eMaintaining Immutable Logs of Access Requests and Decisions: corresponding decision are recorded immutably on the blockchain. This ensures a comprehensive audit trail, promoting accountability and enabling compliance with regulatory requirements.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec30\" class=\"Section3\"\u003e\u003ch2\u003e6.2.2. Middleware Layer\u003c/h2\u003e\u003cp\u003eThe middleware layer acts as a critical intermediary, facilitating seamless interaction between the cloud services and the blockchain. Its primary roles include:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eEvaluating Access Requests: When a user or system initiates an access request, the middleware evaluates the request by checking user attributes, roles, or conditions defined in the policies stored on the blockchain. This ensures decisions are dynamic and context-aware, filtering out invalid requests early and reducing the blockchain\u0026rsquo;s workload.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eDecision implementation: Following evaluation, the middleware interacts with the blockchain to retrieve the appropriate access control decision and ensure that it is applied quickly and accurately.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec31\" class=\"Section3\"\u003e\u003ch2\u003e6.2.3. Cloud Data Layer\u003c/h2\u003e\u003cp\u003eThe Data Layer in a cloud environment serves as the Foundation where user information is securely stored and managed. By working in with the blockchain and middleware, it ensures a robust framework for data management. This layer is characterized by:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eEncrypted data storage: user data is stored in an encrypted format within the cloud data layer to protect it from unauthorized access and guarantee data confidentiality and transform sensitive information into unreadable ciphertext to make it inaccessible, even if unauthorized parties manage to bypass other security measures.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eAccess verification: the cloud data layer responds to access requests only after receiving validation from the middleware. This multi-level verification mechanism ensures that only authorized entities can access the data, effectively mitigating the risks associated with unauthorized access or data breaches. In addition, the inclusion of real-time authentication measures ensures that access requests are continually checked and validated against changing security contexts.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec32\" class=\"Section2\"\u003e\u003ch2\u003e6.3. Framework Implementation\u003c/h2\u003e\u003cp\u003eproposed approach consists of three main components: policy definition, middleware operations and smart contract logic. Each of these components plays a crucial role in ensuring secure, efficient and context-aware access control in the cloud environment.\u003c/p\u003e\u003cdiv id=\"Sec33\" class=\"Section3\"\u003e\u003ch2\u003e6.3.1. Policy Definition\u003c/h2\u003e\u003cp\u003eAccess control policies are implemented through smart contracts, which act as self-executing rules embedded within the blockchain. These policies are designed to be dynamic and context-aware, ensuring that access decisions are not only secure but also adaptable to real-world scenarios. A policy might specify that a user can access sensitive data only during specific hours (9 AM to 5 PM), from a registered device (a company-issued laptop), and based on their assigned role (a manager or an intern). For instance, the policies encompass several contextual attributes:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eAccess Time: Identifies specific periods of time during which access to resources is allowed ensuring that resources are availaible only during approved periods, reducing the risk of unauthorized access outside of working hours.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eDevice type: Restricts access based on the type of device used, ensuring both compatibility and security.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eUser role: Enables access to be granted or denied on the basis of predefined roles and tasks assigned to the user.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec34\" class=\"Section3\"\u003e\u003ch2\u003e6.3.2. Middleware Operations\u003c/h2\u003e\u003cp\u003eThe middleware layer acts as a bridge between the users, the cloud infrastructure and the blockchain, ensuring seamless integration and secure access, preserving the integrity and efficiency of the entire system.\u003c/p\u003e\u003cp\u003e- Request evaluation: The Middleware layer is responsible for capturing access requests initiated by users or applications. When the middleware layer receives a request, it meticulously evaluates it against the predefined access control policies built into the blockchain\u0026rsquo;s smart contracts.\u003c/p\u003e\n\u003cp\u003e- Context Validation: To enhance security, the middleware gathers contextual information such as time of access, device type, and user role, to ensures that the access requests align with the defined policies.\u003c/p\u003e\n\u003cul\u003e\n \u003cli\u003eIP Address: Confirms the geographical origin of the request.\u003c/li\u003e\n \u003cli\u003eGeolocation: Validates that the request is coming from an approved region.\u003c/li\u003e\n \u003cli\u003eOther Contextual Attributes: Assesses other conditions defined in the smart contract policies.\u003c/li\u003e\n\u003c/ul\u003e\u003cp\u003e- Decision Enforcement: Once a decision is made based on the evaluation and validation processes, the middleware relays the result to the cloud system. For approved requests, the middleware ensures the cloud system grants the necessary access; for denied requests, the action is blocked and logged.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec35\" class=\"Section3\"\u003e\u003ch2\u003e6.3.3. Smart Contract Logic\u003c/h2\u003e\u003cp\u003eSmart contracts represent the core decision-making unit of the proposed approach, executing access control policies autonomously without requiring human intervention. These contracts are designed to evaluate access requests in Realtime, using a combination of contextual attributes\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec36\" class=\"Section2\"\u003e\u003ch2\u003e6.4. Unified Access Control Workflow in the Proposed Blockchain-Based Approach\u003c/h2\u003e\u003cp\u003eTo demonstrate the strength and functionality of our approach for securing data access in the cloud, this scenario combines two distinct cases. In the first case, an unauthorized user attempts to access confidential data from an unregistered mobile device outside of approved hours. The middleware collects contextual details such as the user\u0026rsquo;s location, time of access, and device type. It identifies that the GPS location is unapproved, the access occurs outside of permitted hours, and the device is not registered. This information is sent to the blockchain, where a smart contract evaluates it against predefined policies. As the policies prohibit access under these conditions, the request is denied, and the attempt is immutably logged. In the second case, a registered user requests access to sensitive data during approved working hours using a verified device. The middleware confirms that the location is authorized, the time is within the permitted range, and the device is secure and registered. This request is also sent to the blockchain, where the smart contract verifies that all conditions are met. The request is approved, the decision is logged immutably, and the cloud system is notified to grant access\u003c/p\u003e\u003cp\u003eThe diagram highlights the role of each component user, middleware, blockchain, and cloud storage and demonstrates how contextual, real-time access control is enforced securely and transparently.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eUser\u003c/b\u003e: The individual attempting to access a confidential document or resource stored in the cloud.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eMiddleware Layer\u003c/b\u003e: The central intermediary between the user, the blockchain, and the cloud storage system, plays a pivotal role in gathering contextual information, ensures access requests are thoroughly vetted before being forwarded to the blockchain.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eBlockchain (Smart Contract\u003c/b\u003e): The decentralized and immutable system for storing access control policies and evaluating requests based on predefined rules (e.g., granting access only during approved hours or from authorized devices) ensures that access policies are transparently and immutably enforced via smart contracts.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eCloud Data Layer\u003c/b\u003e: The actual storage system where sensitive and encrypted user data resides, ensures data remains secure and inaccessible without proper authorization.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eThe blockchain strategy addresses the critical challenges of securing access to data in cloud environments. Combining attribute-based access control (ABAC) with an intermediate layer and blockchain, we ensure a dynamic, fine-grained and context-sensitive security mechanism. This design not only improves the granularity of access control, but also addresses common weaknesses of traditional centralized systems. One of the keys benefits of this approach is the use of blockchain to store immutable logs and enforce smart contract-based access policies. This provides the transparency, accountability and unforgeable enforcement of rules that are essential for compliance and security in cloud ecosystems. One of the key benefits of this approach is the use of blockchain to store immutable logs and enforce smart contract-based access policies. This provides the transparency, accountability and unforgeable enforcement of rules that are essential for compliance and security in cloud ecosystems. In additional, the middleware layer acts as a critical intermediary, providing real-time evaluation of access requests based on dynamic contextual attributes such as time, location and device type. This contextual awareness improves the system\u0026rsquo;s ability to adapt to complex real-world scenarios. Including a data layer in the cloud, where sensitive\u003c/p\u003e\u003cp\u003einformation is stored in an encrypted format, provides additional protection against unauthorized access. By demanding verification of the blockchain before granting access, this approach minimizes risks such as data breaches.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec37\" class=\"Section2\"\u003e\u003ch2\u003e6.5. Performance Evaluation Scenario\u003c/h2\u003e\u003cp\u003eTo illustrate the practical applicability and dynamic behavior of the proposed blockchain-based ABAC framework, we simulated a realistic scenario involving multiple user access attempts under varying contextual conditions. This evaluation highlights the system\u0026rsquo;s ability to accurately enforce fine-grained access policies in real time and demonstrates its scalability, responsiveness, and auditability\u003c/p\u003e\u003cp\u003eThe simulation models a cloud infrastructure integrated with our proposed architecture, composed of the following elements:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eA smart contract deployed on a private Ethereum blockchain that encodes the access control policies;\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eA middleware layer, implemented in Python, that collects contextual attributes from access requests and interacts with the blockchain to evaluate them;\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eA cloud data storage layer that processes access decisions and delivers or denies content based on the results.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThe middleware collects and transmits real-time contextual attributes, including:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003euser_role (e.g., employee, guest),\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003edevice_type (e.g., laptop, smartphone),\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eaccess_time (e.g., 10:30),\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003elocation_ip (used to validate origin).\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThese attributes are packaged as a request and sent to the blockchain, where the smart contract evaluates them against predefined access policies.\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePolicy Logic and Enforcement\u003c/b\u003e\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThe access policy enforced by the smart contract is designed to reflect real-world enterprise access control requirements. It integrates multiple dynamic contextual attributes and applies a multi-condition validation mechanism before reaching an access decision. The logic implemented in the smart contract ensures that only requests satisfying all policy constraints are granted access to cloud resources.\u003c/p\u003e\u003cp\u003eThe policy rules are defined as follows:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eUser Role Verification: Access is limited to users whose role is explicitly set as employee. This condition ensures that guests, external collaborators, or unauthorized roles are systematically denied, even if other attributes are valid.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eTemporal Constraint: Access is restricted to business hours, specifically from 08:00 to 18:00 (system time). This prevents access during off-hours, mitigating risks of insider threats or unauthorized activities during non-working periods.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eDevice Authentication: The requesting device must correspond to a known and authorized device, identified through a hashed hardware fingerprint. These device hashes are pre-registered on-chain by an administrator using a dedicated function (registerDevice()). This constraint ensures that access cannot be performed from untrusted or compromised endpoints, even by valid users.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eNetwork Location Check: The IP address from which the access request originates must fall within a predefined corporate subnet range. This rule serves to prevent access from external, potentially insecure networks, enforcing location-based restrictions.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThe smart contract contains two core functions:\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003everifyAccess(), which receives the contextual attributes from the middleware, evaluates them against the stored access policy, and returns a decision (true for grant, false for deny);\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003elogAccessAttempt(), which emits an event containing the attributes, the decision, and a timestamp, ensuring permanent and tamper-proof logging on the blockchain ledger.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eThis on-chain enforcement model eliminates reliance on traditional, centralized Policy Decision Points (PDPs) and ensures both transparency and immutability. By executing attribute verification within the smart contract itself, the framework guarantees that no access request can bypass evaluation, and no policy manipulation can occur without authorization. This model significantly enhances trust, auditability, and resistance to tampering, making it well-suited for sensitive enterprise cloud environments.\u003c/p\u003e\u003cp\u003eThe image illustrates the complete access control process: a user submits an access request with contextual attributes (role, device, time, location); the middleware collects and forwards these attributes to the blockchain; a smart contract evaluates them against encoded policies; the decision (grant or deny) is returned to the cloud storage system, which enforces it by either delivering or blocking the requested content.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eEvaluation Results\u003c/b\u003e\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cp\u003eFour representative access attempts were simulated to cover both valid and invalid conditions. The outcomes are summarized below\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab4\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003ePolicy-Based Access Decision Outcomes in Simulated Scenarios\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"8\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c6\" colnum=\"6\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c7\" colnum=\"7\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c8\" colnum=\"8\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eCase\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eDescription\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eRole\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eTime\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c5\"\u003e\u003cp\u003eDevice\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c6\"\u003e\u003cp\u003eLocation\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c7\"\u003e\u003cp\u003eAccess Decision\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c8\"\u003e\u003cp\u003eResponse Time\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eValid user with correct context\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eEmployee\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e10:30\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eRegistered PC\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c6\"\u003e\u003cp\u003eInternal Network\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c7\"\u003e\u003cp\u003eGranted\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c8\"\u003e\u003cp\u003e130 ms\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e2\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eInvalid device used by valid user\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eEmployee\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e11:00\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eUnknown Device\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c6\"\u003e\u003cp\u003eInternal Network\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c7\"\u003e\u003cp\u003eDenied\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c8\"\u003e\u003cp\u003e127 ms\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e3\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eValid user outside authorized hours\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eEmployee\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e21:00\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eRegistered PC\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c6\"\u003e\u003cp\u003eInternal Network\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c7\"\u003e\u003cp\u003eDenied\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c8\"\u003e\u003cp\u003e125 ms\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e4\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eUnauthorized user with invalid context\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eGuest\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e15:00\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003eUnknown Device\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c6\"\u003e\u003cp\u003ePublic Wi-Fi\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c7\"\u003e\u003cp\u003eDenied\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c8\"\u003e\u003cp\u003e133 ms\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e"},{"header":" Discussion","content":"\u003cp\u003eFollowing the evaluation scenario, the results confirm that the proposed blockchain-based ABAC framework is both theoretically sound and practically effective. The framework successfully evaluated access requests based on multiple dynamic attributes\u0026mdash;such as user role, device identity, access time, and location\u0026mdash;and enforced access policies with high accuracy. The embedded smart contracts consistently denied access when one or more contextual parameters were invalid and granted access only when all predefined conditions were satisfied. This reinforces the precision and robustness of the attribute-based decision logic implemented in the blockchain layer.\u003c/p\u003e\u003cp\u003eIn terms of performance, access decisions were executed within a narrow response time window of 125 to 133 milliseconds, regardless of the scenario complexity. These variations are attributed to the number of attributes assessed, the internal decision flow within the smart contract, and minimal fluctuations in middleware processing. Nonetheless, the system consistently delivered access decisions within an acceptable threshold (\u0026lt;\u0026thinsp;150 ms), confirming its responsiveness and real-time applicability\u0026mdash;an essential criterion for enterprise environments such as healthcare, finance, or industrial control systems.\u003c/p\u003e\u003cp\u003eA major strength of the proposed framework lies in its capacity to ensure end-to-end auditability. Each access attempt\u0026mdash;successful or denied\u0026mdash;is immutably recorded on the blockchain ledger, providing a tamper-proof, transparent audit trail. This feature enhances system accountability and supports regulatory compliance, forensic investigation, and operational transparency.\u003c/p\u003e\u003cp\u003eBeyond these technical benefits, the inclusion of a middleware layer plays a pivotal role in managing dynamic attributes and offloading processing from the blockchain, contributing to system efficiency and scalability. The framework addresses the limitations of traditional Role-Based Access Control (RBAC) by enabling fine-grained, context-aware, and decentralized access control, thereby eliminating dependence on centralized decision points and reducing the risk of single-point failures.\u003c/p\u003e\u003cdiv id=\"Sec39\" class=\"Section2\"\u003e\u003ch2\u003e6.6. Results: Overcoming Limitations in Cloud Access Control\u003c/h2\u003e\u003cp\u003eBy incorporating blockchain into the ABAC framework, we can provide a more secure environment for cloud services, allowing for decentralized and tamper-proof storage of access policies, thus optimizing scalability and adaptability without compromising security. This model is highly dynamic and context-aware, since real-time changes of the access rules and attributes can be incorporated avoiding central point failures and improving resilience. Blockchain also allows for seamless interoperability between multi-cloud environments, making it easier to manage complex access control scenarios while ensuring security and compliance across heterogeneous cloud platforms.\u003c/p\u003e\u003cdiv id=\"Sec40\" class=\"Section3\"\u003e\u003ch2\u003e6.6.1. Eliminating Centralized Weak Points\u003c/h2\u003e\u003cp\u003eBlockchain technology revolutionizes traditional access control systems by decentralizing the storage of policies and decision-making processes, effectively eliminating single points of failure and enhancing resilience against attacks. This decentralized architecture also improves transparency, as all access decisions and policy updates are immutably recorded on the blockchain, creating robust audit trails that facilitate trust-building and compliance with regulatory requirements. By integrating blockchain, organizations can establish secure and adaptable access control systems that address modern security challenges effectively.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec41\" class=\"Section3\"\u003e\u003ch2\u003e6.6.2. Enhancing Contextual Adaptability\u003c/h2\u003e\u003cp\u003eExisting access control models face significant challenges in incorporating real-time contextual attributes such as user location, device status, or network conditions. These limitations hinder their ability to effectively and accurately address security needs in dynamic environments. The proposed approach addresses these shortcomings by dynamically integrating environmental attributes into the decision-making process. By considering these contextual factors, access policies can be adapted in real-time, ensuring more precise and situationally appropriate control. This innovation enhances data security by clearly defining access conditions. As a result, users can access resources only when specific criteria are met, significantly reducing the risk of unauthorized or inappropriate access.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec42\" class=\"Section3\"\u003e\u003ch2\u003e6.6.3. Improving Policy Transparency and Auditability\u003c/h2\u003e\u003cp\u003eIn traditional systems, access logs are often stored in centralized repositories, making them vulnerable to tampering, accidental deletion, or malicious attacks. This centralization undermines the reliability and integrity of records, making it challenging to trace critical events effectively. By integrating blockchain technology, access logs are stored in a decentralized and immutable ledger. Every access attempt, whether successful or denied, is permanently recorded in a manner that cannot be altered or erased. This ensures complete transparency and provides an unchangeable audit trail. This approach enables comprehensive and proactive analysis of events due to the integrity of the recorded data. It also improves compliance with regulatory requirements and improves forensic investigations in the event of a security breach, fostering increased trust between stakeholders.\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec43\" class=\"Section3\"\u003e\u003ch2\u003e6.6.4. Facilitating Interoperability\u003c/h2\u003e\u003cp\u003eCurrent access control solutions often lack the flexibility to operate seamlessly in diverse cloud environments. The integration of blockchain with modular APIs and middleware ensures compatibility with existing cloud infrastructures, allowing gradual and non-disruptive adoption of the new system.\u003c/p\u003e\u003cp\u003eThe table below highlights the core distinctions between traditional BAC systems and the proposed blockchain-integrated ABAC framework. It compares both models across five critical aspects: decision criteria, flexibility, context awareness, management structure, and traceability. While BAC relies on static user roles and centralized control, blockchain-based ABAC introduces dynamic, context-sensitive access decisions using attributes such as time, location, and device type. It also leverages decentralized smart contracts for policy enforcement and guarantees tamper-proof audit logs via blockchain immutability.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e"},{"header":"CONCLUSION AND FUTURE WORK","content":"\u003cp\u003eThis research presented an adaptive access control framework that integrates blockchain technology with Attribute-Based Access Control (ABAC) to provide secure, decentralized, and context-aware data access in cloud environments. By leveraging the immutability and transparency of blockchain smart contracts, the framework decentralizes policy enforcement and eliminates reliance on a centralized authority. At the same time, the middleware layer dynamically collects contextual attributes such as user role, device type, access time, and IP address, which are then evaluated in real time by the blockchain-based policy engine.\u003c/p\u003e\u003cp\u003eThrough a simulation environment, the proposed system demonstrated its technical feasibility and responsiveness. All access decisions were processed with low latency\u0026mdash;ranging from 125 to 133 milliseconds\u0026mdash;demonstrating compatibility with real-time cloud applications. The smart contract accurately enforced attribute-based policies, and each decision was immutably logged on-chain, ensuring auditability and traceability. The implementation highlights the potential for secure, automated, and transparent access management in dynamic and distributed systems. However, the current work is not without limitations. The evaluation was conducted in a simulated private Ethereum environment, and the system has yet to be tested at scale across real-world multi-cloud platforms. Additionally, the current policy model is static and manually configured, lacking mechanisms for autonomous adaptation or anomaly detection. Interoperability with diverse cloud service APIs, performance under high-load conditions, and integration with privacy and compliance frameworks (GDPR, HIPAA) remain unaddressed challenges.\u003c/p\u003e\u003cp\u003eFuture work will address these limitations by deploying the framework across heterogeneous cloud platforms (AWS, Azure, GCP) to evaluate performance, interoperability, and scalability. We also plan to incorporate AI-driven policy generation and dynamic attribute weighting to support self-learning access control decisions. Furthermore, exploring support for decentralized identity systems such as Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) could strengthen the system\u0026rsquo;s capacity for privacy-preserving and user-centric authentication. Regulatory compliance features, including consent management and audit support, will also be integrated to ensure legal viability in sensitive domains such as healthcare, finance, and government services.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eAVAILABILITY OF DATA AND MATERIALS\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe datasets generated and/or analyzed during the current study are available from the corresponding author upon reasonable request. At this time, no publicly archived datasets are associated with this research. All relevant configurations, access policies, and simulation parameters used in the proof-of-concept implementation can be shared with interested researchers upon justified inquiry for academic or collaborative purposes.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFUNDING\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis research did not receive any specific grant from funding agencies in the public, commercial, or not-for-profit sectors. The work was conducted independently by the authors without external financial support.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eCONFLICT OF INTEREST\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eACKNOWLEDGEMENTS\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe authors would like to thank the editorial team and anonymous reviewers for their insightful comments, which significantly helped improve the quality and clarity of this manuscript. Their constructive feedback was instrumental throughout the revision process.\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003e\u0026laquo; Enterprise cloud service architectures.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eB. Cusack et E. Ghazizadeh, \u0026laquo; Evaluating single sign-on security failure in cloud services \u0026raquo;, \u003cem\u003eBusiness Horizons\u003c/em\u003e, vol. 59, n\u003csup\u003eo\u003c/sup\u003e 6, p. 605‑614, nov. 2016, doi: 10.1016/j.bushor.2016.08.002.\u003c/li\u003e\n\u003cli\u003eF. Doelitzscher, C. Reich, M. Knahl, et N. Clarke, \u0026laquo; Incident Detection for Cloud Environments \u0026raquo;, 2011.\u003c/li\u003e\n\u003cli\u003eM. F. Shahzad, S. Xu, W. M. Lim, M. F. Hasnain, et S. Nusrat, \u0026laquo; Cryptocurrency awareness, acceptance, and adoption: the role of trust as a cornerstone \u0026raquo;, \u003cem\u003eHumanit Soc Sci Commun\u003c/em\u003e, vol. 11, n\u003csup\u003eo\u003c/sup\u003e 1, p. 4, janv. 2024, doi: 10.1057/s41599-023-02528-7.\u003c/li\u003e\n\u003cli\u003eA. Beikverdi et JooSeok Song, \u0026laquo; Trend of centralization in Bitcoin\u0026rsquo;s distributed network \u0026raquo;, in \u003cem\u003e2015 IEEE/ACIS 16th International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)\u003c/em\u003e, Takamatsu: IEEE, juin 2015, p. 1‑6. doi: 10.1109/SNPD.2015.7176229.\u003c/li\u003e\n\u003cli\u003eU. Habiba, R. Masood, M. A. Shibli, et M. A. Niazi, \u0026laquo; Cloud identity management security issues \u0026amp; solutions: a taxonomy \u0026raquo;, \u003cem\u003eComplex Adapt Syst Model\u003c/em\u003e, vol. 2, n\u003csup\u003eo\u003c/sup\u003e 1, p. 5, d\u0026eacute;c. 2014, doi: 10.1186/s40294-014-0005-9.\u003c/li\u003e\n\u003cli\u003eS. K. Sood, K. S. Rawat, et D. Kumar, \u0026laquo; Scientometric analysis of ICT-assisted intelligent control systems response to COVID-19 pandemic \u0026raquo;, \u003cem\u003eNeural Comput \u0026amp; Applic\u003c/em\u003e, vol. 35, n\u003csup\u003eo\u003c/sup\u003e 26, p. 18829‑18849, sept. 2023, doi: 10.1007/s00521-023-08788-3.\u003c/li\u003e\n\u003cli\u003eS. K. Sood, K. S. Rawat, et D. Kumar, \u0026laquo; A visual review of artificial intelligence and Industry 4.0 in healthcare \u0026raquo;, \u003cem\u003eComputers and Electrical Engineering\u003c/em\u003e, vol. 101, p. 107948, juill. 2022, doi: 10.1016/j.compeleceng.2022.107948.\u003c/li\u003e\n\u003cli\u003eA. Gupta, S. T. Siddiqui, S. Alam, et M. Shuaib, \u0026laquo; Cloud Computing Security using Blockchain \u0026raquo;, vol. 6, n\u003csup\u003eo\u003c/sup\u003e 6, 2019.\u003c/li\u003e\n\u003cli\u003eM. Y. Shakor, M. I. Khaleel, M. Safran, S. Alfarhood, et M. Zhu, \u0026laquo; Dynamic AES Encryption and Blockchain Key Management: A Novel Solution for Cloud Data Security \u0026raquo;, \u003cem\u003eIEEE Access\u003c/em\u003e, vol. 12, p. 26334‑26343, 2024, doi: 10.1109/ACCESS.2024.3351119.\u003c/li\u003e\n\u003cli\u003eW.-Y. Tsai, T.-C. Chou, J.-L. Chen, Y.-W. Ma, et C.-J. Huang, \u0026laquo; Blockchain as a Platform for Secure Cloud Computing Services \u0026raquo;, in \u003cem\u003e2020 22nd International Conference on Advanced Communication Technology (ICACT)\u003c/em\u003e, Phoenix Park, PyeongChang,, Korea (South): IEEE, f\u0026eacute;vr. 2020, p. 155‑158. doi: 10.23919/ICACT48636.2020.9061435.\u003c/li\u003e\n\u003cli\u003eS. Xie, Z. Zheng, W. Chen, J. Wu, H.-N. Dai, et M. Imran, \u0026laquo; Blockchain for cloud exchange: A survey \u0026raquo;, \u003cem\u003eComputers \u0026amp; Electrical Engineering\u003c/em\u003e, vol. 81, p. 106526, janv. 2020, doi: 10.1016/j.compeleceng.2019.106526.\u003c/li\u003e\n\u003cli\u003eA. Kumar, K. Abhishek, P. Nerurkar, M. R. Ghalib, A. Shankar, et X. Cheng, \u0026laquo; Secure smart contracts for cloud‐based manufacturing using Ethereum blockchain \u0026raquo;, \u003cem\u003eTrans Emerging Tel Tech\u003c/em\u003e, vol. 33, n\u003csup\u003eo\u003c/sup\u003e 4, p. e4129, avr. 2022, doi: 10.1002/ett.4129.\u003c/li\u003e\n\u003cli\u003eR. Awadallah, A. Samsudin, J. S. Teh, et M. Almazrooie, \u0026laquo; An Integrated Architecture for Maintaining Security in Cloud Computing Based on Blockchain \u0026raquo;, \u003cem\u003eIEEE Access\u003c/em\u003e, vol. 9, p. 69513‑69526, 2021, doi: 10.1109/ACCESS.2021.3077123.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; Bathen et Jadav - 2022 - Smart Contracts in the Cloud.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eL. Yan, L. Ge, Z. Wang, G. Zhang, J. Xu, et Z. Hu, \u0026laquo; Access control scheme based on blockchain and attribute-based searchable encryption in cloud environment \u0026raquo;, \u003cem\u003eJ Cloud Comp\u003c/em\u003e, vol. 12, n\u003csup\u003eo\u003c/sup\u003e 1, p. 61, avr. 2023, doi: 10.1186/s13677-023-00444-4.\u003c/li\u003e\n\u003cli\u003eI. T. Javed, F. Alharbi, T. Margaria, N. Crespi, et K. N. Qureshi, \u0026laquo; PETchain: A Blockchain-Based Privacy Enhancing Technology \u0026raquo;, \u003cem\u003eIEEE Access\u003c/em\u003e, vol. 9, p. 41129‑41143, 2021, doi: 10.1109/ACCESS.2021.3064896.\u003c/li\u003e\n\u003cli\u003eS. Nayak, N. C. Narendra, A. Shukla, et J. Kempf, \u0026laquo; Saranyu: Using Smart Contracts and Blockchain for Cloud Tenant Management \u0026raquo;, in \u003cem\u003e2018 IEEE 11th International Conference on Cloud Computing (CLOUD)\u003c/em\u003e, San Francisco, CA, USA: IEEE, juill. 2018, p. 857‑861. doi: 10.1109/CLOUD.2018.00121.\u003c/li\u003e\n\u003cli\u003eH. Daniyal et A. Chinwalla, \u0026laquo; Blockchain Security Solutions for Ensuring Medical Device Integrity in Cloud Environments \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eH. Dudeja, J. Kaushik, et Shalu, \u0026laquo; Cloud Based Voting System Using Blockchain Technology \u0026raquo;, in \u003cem\u003e2023 5th International Conference on Advances in Computing, Communication Control and Networking (ICAC3N)\u003c/em\u003e, Greater Noida, India: IEEE, d\u0026eacute;c. 2023, p. 1392‑1396. doi: 10.1109/ICAC3N60023.2023.10541707.\u003c/li\u003e\n\u003cli\u003eS. Basu, S. Karmakar, et D. Bera, \u0026laquo; Securing Cloud Virtual Machine Image Using Ethereum Blockchain \u0026raquo;:, \u003cem\u003eInternational Journal of Information Security and Privacy\u003c/em\u003e, vol. 16, n\u003csup\u003eo\u003c/sup\u003e 1, p. 1‑22, avr. 2022, doi: 10.4018/IJISP.295868.\u003c/li\u003e\n\u003cli\u003eA. Khanna, A. Sah, V. Bolshev, A. Burgio, V. Panchenko, et M. Jasiński, \u0026laquo; Blockchain\u0026ndash;Cloud Integration: A Survey \u0026raquo;, \u003cem\u003eSensors\u003c/em\u003e, vol. 22, n\u003csup\u003eo\u003c/sup\u003e 14, p. 5238, juill. 2022, doi: 10.3390/s22145238.\u003c/li\u003e\n\u003cli\u003eW. Li, J. Wu, J. Cao, N. Chen, Q. Zhang, et R. Buyya, \u0026laquo; Blockchain-based trust management in cloud computing systems: a taxonomy, review and future directions \u0026raquo;, \u003cem\u003eJ Cloud Comp\u003c/em\u003e, vol. 10, n\u003csup\u003eo\u003c/sup\u003e 1, p. 35, juin 2021, doi: 10.1186/s13677-021-00247-5.\u003c/li\u003e\n\u003cli\u003eK. Gai, J. Guo, L. Zhu, et S. Yu, \u0026laquo; Blockchain Meets Cloud Computing: A Survey \u0026raquo;, \u003cem\u003eIEEE Commun. Surv. Tutorials\u003c/em\u003e, vol. 22, n\u003csup\u003eo\u003c/sup\u003e 3, p. 2009‑2030, 2020, doi: 10.1109/COMST.2020.2989392.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; Dai et al. - 2019 - Blockchain for Internet of Things A Survey.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eM. Z. Hasan, M. Z. Hussain, Z. Mubarak, A. A. Siddiqui, A. M. Qureshi, et I. Ismail, \u0026laquo; Data security and Integrity in Cloud Computing \u0026raquo;, in \u003cem\u003e2023 International Conference for Advancement in Technology (ICONAT)\u003c/em\u003e, Goa, India: IEEE, janv. 2023, p. 1‑5. doi: 10.1109/ICONAT57137.2023.10080440.\u003c/li\u003e\n\u003cli\u003eS. Nakamoto, \u0026laquo; Bitcoin: A Peer-to-Peer Electronic Cash System \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eY. Qi, Z. Yang, Y. Luo, Y. Huang, et X. Li, \u0026laquo; Blockchain-Based Light-Weighted Provable Data Possession for Low Performance Devices \u0026raquo;, \u003cem\u003eComputers, Materials \u0026amp; Continua\u003c/em\u003e, vol. 73, n\u003csup\u003eo\u003c/sup\u003e 2, p. 2205‑2221, 2022, doi: 10.32604/cmc.2022.027939.\u003c/li\u003e\n\u003cli\u003eD. C. Youvan, \u0026laquo; Navigating the Evolution of Ethereum: Vitalik Buterin\u0026rsquo;s Vision for DeFi, Governance, and Scalability \u0026raquo;, 2024, doi: 10.13140/RG.2.2.14861.35044.\u003c/li\u003e\n\u003cli\u003eY. Yu, \u0026laquo; Analysis of POW in Bitcoin and POS in Peercoin \u0026raquo;, vol. 39, 2023.\u003c/li\u003e\n\u003cli\u003eX. Huang et D. Huang, \u0026laquo; Performance Analysis of Blockchain Consensus Algorithm in Unmanned Aerial Vehicle Ad Hoc Networks \u0026raquo;, \u003cem\u003eDrones\u003c/em\u003e, vol. 9, n\u003csup\u003eo\u003c/sup\u003e 5, p. 334, avr. 2025, doi: 10.3390/drones9050334.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; performance-analysis-private.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eO. Dib, K.-L. Brousmiche, A. Durand, E. Thea, et E. B. Hamida, \u0026laquo; Consortium Blockchains: Overview, Applications and Challenges \u0026raquo;, 2018.\u003c/li\u003e\n\u003cli\u003eJ. Zarrin, H. Wen Phang, L. Babu Saheer, et B. Zarrin, \u0026laquo; Blockchain for decentralization of internet: prospects, trends, and challenges \u0026raquo;, \u003cem\u003eCluster Comput\u003c/em\u003e, vol. 24, n\u003csup\u003eo\u003c/sup\u003e 4, p. 2841‑2866, d\u0026eacute;c. 2021, doi: 10.1007/s10586-021-03301-8.\u003c/li\u003e\n\u003cli\u003eH. S. Kim et K. Wang, \u0026laquo; Immutability Measure for Different Blockchain Structures \u0026raquo;, in \u003cem\u003e2018 IEEE 39th Sarnoff Symposium\u003c/em\u003e, Newark, NJ, USA: IEEE, sept. 2018, p. 1‑6. doi: 10.1109/SARNOF.2018.8720496.\u003c/li\u003e\n\u003cli\u003eK. G. Gokoglan et S. Cetin, \u0026laquo; Blockchain technology and its impact on audit activities \u0026raquo;, \u003cem\u003ePressacademia\u003c/em\u003e, p. 2, juin 2022, doi: 10.17261/Pressacademia.2022.1567.\u003c/li\u003e\n\u003cli\u003eB. Ş. Alkan, \u0026laquo; Real-Time Blockchain Accounting System As A New Paradigm \u0026raquo;, 2021.\u003c/li\u003e\n\u003cli\u003eM. H. Miraz, P. S. Excell, et K. Sobayel, \u0026laquo; Evaluation of Green Alternatives for Blockchain Proof-of-Work (PoW) Approach \u0026raquo;, \u003cem\u003eAETiC\u003c/em\u003e, vol. 5, n\u003csup\u003eo\u003c/sup\u003e 4, p. 54‑59, oct. 2021, doi: 10.33166/AETiC.2021.04.005.\u003c/li\u003e\n\u003cli\u003eAmerican International University- Bangladesh, Department of Computer Science, Dhaka-1229, Bangladesh, S. Fahim, S. Katibur Rahman, et S. Mahmood, \u0026laquo; Blockchain: A Comparative Study of Consensus Algorithms PoW, PoS, PoA, PoV \u0026raquo;, \u003cem\u003eIJMSC\u003c/em\u003e, vol. 9, n\u003csup\u003eo\u003c/sup\u003e 3, p. 46‑57, ao\u0026ucirc;t 2023, doi: 10.5815/ijmsc.2023.03.04.\u003c/li\u003e\n\u003cli\u003eC. Lepore, M. Ceria, A. Visconti, U. P. Rao, K. A. Shah, et L. Zanolini, \u0026laquo; A Survey on Blockchain Consensus with a Performance Comparison of PoW, PoS and Pure PoS \u0026raquo;, \u003cem\u003eMathematics\u003c/em\u003e, vol. 8, n\u003csup\u003eo\u003c/sup\u003e 10, p. 1782, oct. 2020, doi: 10.3390/math8101782.\u003c/li\u003e\n\u003cli\u003eS. Mahmood Babur, S. Ur Rehman Khan, J. Yang, Y.-L. Chen, C. Soon Ku, et L. Yee Por, \u0026laquo; Preventing 51% Attack by Using Consecutive Block Limits in Bitcoin \u0026raquo;, \u003cem\u003eIEEE Access\u003c/em\u003e, vol. 12, p. 77852‑77869, 2024, doi: 10.1109/ACCESS.2024.3407521.\u003c/li\u003e\n\u003cli\u003eK. Nicolas et Y. Wang, \u0026laquo; A novel double spending attack countermeasure in blockchain \u0026raquo;, in \u003cem\u003e2019 IEEE 10th Annual Ubiquitous Computing, Electronics \u0026amp; Mobile Communication Conference (UEMCON)\u003c/em\u003e, New York City, NY, USA: IEEE, oct. 2019, p. 0383‑0388. doi: 10.1109/UEMCON47517.2019.8992991.\u003c/li\u003e\n\u003cli\u003eZ. Wang, H. Jin, W. Dai, K.-K. R. Choo, et D. Zou, \u0026laquo; Ethereum smart contract security research: survey and future research opportunities \u0026raquo;, \u003cem\u003eFront. Comput. Sci.\u003c/em\u003e, vol. 15, n\u003csup\u003eo\u003c/sup\u003e 2, p. 152802, avr. 2021, doi: 10.1007/s11704-020-9284-9.\u003c/li\u003e\n\u003cli\u003eW. Cai, Z. Wang, J. B. Ernst, Z. Hong, C. Feng, et V. C. M. Leung, \u0026laquo; Decentralized Applications: The Blockchain-Empowered Software System \u0026raquo;, \u003cem\u003eIEEE Access\u003c/em\u003e, vol. 6, p. 53019‑53033, 2018, doi: 10.1109/ACCESS.2018.2870644.\u003c/li\u003e\n\u003cli\u003eS. Naiem, M. Marie, A. E. Khedr, et A. M. Idrees, \u0026laquo; DISTRIBUTED DENIAL OF SERVICES ATTACKS AND THEIR PREVENTION IN CLOUD SERVICES \u0026raquo;, . \u003cem\u003eVol.\u003c/em\u003e, n\u003csup\u003eo\u003c/sup\u003e 4, 2022.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; Advanced_Authentication_Mechanisms_for_I.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003ePratik Jain, \u0026laquo; Identity and Access Management in the Cloud \u0026raquo;, \u003cem\u003eInt. J. Sci. Res. Comput. Sci. Eng. Inf. Technol\u003c/em\u003e, vol. 11, n\u003csup\u003eo\u003c/sup\u003e 2, p. 1528‑1535, mars 2025, doi: 10.32628/CSEIT25112523.\u003c/li\u003e\n\u003cli\u003eJ. Stanly Jayaprakash, K. Balasubramanian, R. Sulaiman, M. Kamrul Hasan, B. D. Parameshachari, et C. Iwendi, \u0026laquo; Cloud Data Encryption and Authentication Based on Enhanced Merkle Hash Tree Method \u0026raquo;, \u003cem\u003eComputers, Materials \u0026amp; Continua\u003c/em\u003e, vol. 72, n\u003csup\u003eo\u003c/sup\u003e 1, p. 519‑534, 2022, doi: 10.32604/cmc.2022.021269.\u003c/li\u003e\n\u003cli\u003eR. Akter, Md. A. R. Khan, F. Rahman, S. J. Soheli, et N. J. Suha, \u0026laquo; RSA and AES Based Hybrid Encryption Technique for Enhancing Data Security in Cloud Computing \u0026raquo;, \u003cem\u003eInternational Journal of Computational and Applied Mathematics \u0026amp; Computer Science\u003c/em\u003e, vol. 3, p. 60‑71, oct. 2023, doi: 10.37394/232028.2023.3.8.\u003c/li\u003e\n\u003cli\u003eI. Indu, P. M. R. Anand, et V. Bhaskar, \u0026laquo; Identity and access management in cloud environment: Mechanisms and challenges \u0026raquo;, \u003cem\u003eEngineering Science and Technology, an International Journal\u003c/em\u003e, vol. 21, n\u003csup\u003eo\u003c/sup\u003e 4, p. 574‑588, ao\u0026ucirc;t 2018, doi: 10.1016/j.jestch.2018.05.010.\u003c/li\u003e\n\u003cli\u003eJ. Sun, Y. Zeng, G. Shi, W. Li, et Z. Li, \u0026laquo; The Research for Virtualization Network Security on Cloud Computing \u0026raquo;, in \u003cem\u003eProceedings of the 2018 2nd International Conference on Artificial Intelligence: Technologies and Applications (ICAITA 2018)\u003c/em\u003e, Chengdu, China: Atlantis Press, 2018. doi: 10.2991/icaita-18.2018.37.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; Hasan et al. - 2023 - Data security and Integrity in Cloud Computing.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eN. Thakur et A. K. Sharma, \u0026laquo; Data Integrity Techniques in Cloud Computing: An Analysis \u0026raquo;, \u003cem\u003eIJARCSSE\u003c/em\u003e, vol. 7, n\u003csup\u003eo\u003c/sup\u003e 8, p. 121, ao\u0026ucirc;t 2017, doi: 10.23956/ijarcsse.v7i8.36.\u003c/li\u003e\n\u003cli\u003eN. Mohammad, \u0026laquo; The Impact of Cloud Computing on Cybersecurity Threat Hunting and Threat Intelligence Sharing Data Security Data Sharing and Collaboration \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eA. J. Choudhury, P. Kumar, M. Sain, H. Lim, et H. Jae-Lee, \u0026laquo; A Strong User Authentication Framework for Cloud Computing \u0026raquo;, in \u003cem\u003e2011 IEEE Asia-Pacific Services Computing Conference\u003c/em\u003e, Jeju, Korea (South): IEEE, d\u0026eacute;c. 2011, p. 110‑115. doi: 10.1109/APSCC.2011.14.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; Weak identity verification.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eGobika S. et Vaishnavi N., \u0026laquo; Blockchain Based Identity Management System \u0026raquo;, \u003cem\u003eInt. J. Sci. Res. Comput. Sci. Eng. Inf. Technol\u003c/em\u003e, vol. 11, n\u003csup\u003eo\u003c/sup\u003e 2, p. 1413‑1420, mars 2025, doi: 10.32628/CSEIT25112471.\u003c/li\u003e\n\u003cli\u003eA. Thorve, M. Shirole, P. Jain, C. Santhumayor, et S. Sarode, \u0026laquo; Decentralized Identity Management Using Blockchain \u0026raquo;, in \u003cem\u003e2022 4th International Conference on Advances in Computing, Communication Control and Networking (ICAC3N)\u003c/em\u003e, Greater Noida, India: IEEE, d\u0026eacute;c. 2022, p. 1985‑1991. doi: 10.1109/ICAC3N56670.2022.10074477.\u003c/li\u003e\n\u003cli\u003e\u0026laquo; GDPR Compliant Blockchains\u0026ndash;A Systematic Literature Review.pdf \u0026raquo;.\u003c/li\u003e\n\u003cli\u003eN. M. Noor, N. A. M. Razali, N. A. Malizan, K. K. Ishak, M. Wook, et N. A. Hasbullah, \u0026laquo; Decentralized Access Control using Blockchain Technology for Application in Smart Farming \u0026raquo;, \u003cem\u003eIJACSA\u003c/em\u003e, vol. 13, n\u003csup\u003eo\u003c/sup\u003e 9, 2022, doi: 10.14569/IJACSA.2022.0130993.\u003c/li\u003e\n\u003cli\u003eH. A. H. Hadi Al Kim et S. Barua, \u0026laquo; Service Level Agreement (SLA) for Cloud Computing Compilation with Common and New Formats \u0026raquo;, \u003cem\u003eint.jour.sci.res.mana\u003c/em\u003e, vol. 6, n\u003csup\u003eo\u003c/sup\u003e 04, avr. 2018, doi: 10.18535/ijsrm/v6i4.ec01.\u003c/li\u003e\n\u003cli\u003eA. S. Priya et S. Sangeetha, \u0026laquo; Security Challenges and Solutions in Cloud Computing Environments \u0026raquo;, \u003cem\u003eINTERNATIONAL ADVANCED RESEARCH JOURNAL IN SCIENCE, ENGINEERING AND TECHNOLOGY\u003c/em\u003e, vol. 11, n\u003csup\u003eo\u003c/sup\u003e 3, mars 2024, doi: 10.17148/IARJSET.2024.11311.\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Blockchain, Cloud computing, Smart contracts, Cryptographic, Middleware","lastPublishedDoi":"10.21203/rs.3.rs-7409434/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7409434/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eCloud computing has become a cornerstone for modern enterprises, offering scalable and on-demand resources. However, its centralized architecture poses significant security challenges, especially concerning data access control and integrity. This paper proposes a novel approach that integrates blockchain technology with Attribute-Based Access Control (ABAC) to improve secure, context-aware data access in the cloud. The proposed solution leverages blockchain\u0026rsquo;s decentralized, immutable infrastructure to store access policies as smart contracts, providing dynamic and fine-grained access control. A middleware layer facilitates the evaluation of access requests, collecting contextual attributes such as time, location, and device type, which are validated against policies stored on the blockchain. The framework ensures traceability, transparency, and scalability while mitigating vulnerabilities associated with traditional Role-Based Access Control (RBAC) systems. Comparative analysis highlights the advantages of the blockchain-based ABAC system over conventional methods, demonstrating its potential to address evolving cloud security challenges. Furthermore, scenarios illustrating unauthorized and authorized access underline the robustness and functionality of the proposed approach. This work lays the foundation for secure and adaptive cloud environments, advancing the adoption of blockchain-based access control mechanisms.\u003c/p\u003e","manuscriptTitle":"Adaptive Blockchain Based Access Control ABAC for Secure Cloud Data Access: A Comprehensive Approach","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-09-03 11:56:35","doi":"10.21203/rs.3.rs-7409434/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"ed16f3e9-fc88-4445-a3fe-811d84c295d8","owner":[],"postedDate":"September 3rd, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-11-23T11:23:18+00:00","versionOfRecord":[],"versionCreatedAt":"2025-09-03 11:56:35","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7409434","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7409434","identity":"rs-7409434","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.