Continuous Verification • Adaptive Authorization • End-to-End Encryption
Secure Cloud is a research-oriented cloud security system designed to provide secure file storage and access using the principles of Zero Trust Architecture (ZTA).
Unlike traditional cloud systems that trust users after login, Secure Cloud continuously verifies every access request based on user identity, device trust, roles, attributes, and risk level before allowing access to protected resources.
The system integrates modern security mechanisms including:
- Zero Trust Architecture (NIST SP 800-207)
- AES-256-GCM Encryption
- JWT Authentication
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Risk-Based Authentication (RBA)
- Device Fingerprinting
- Secure Audit Logging
This project was developed as part of a research paper on cloud security.
Traditional cloud systems generally authenticate users only once during login. Once authenticated, users often gain broad access to cloud resources, making systems vulnerable to:
- Unauthorized Access
- Insider Threats
- Credential Theft
- Session Hijacking
- Data Leakage
- Privilege Escalation
- Lateral Movement Attacks
Secure Cloud addresses these challenges by implementing a Zero Trust security model, where every request is verified before access is granted.
Every request is validated through:
- Identity Verification
- Role Validation
- Device Verification
- Context Evaluation
- Risk Assessment
- Continuous Authorization
Supports multiple user roles:
- 👑 Admin
- ✏️ Editor
- 👀 Viewer
- 👤 Guest
Each role has predefined permissions for accessing cloud resources.
Access decisions are made using:
- User Role
- Department
- Time
- Device
- IP Address
- Request Context
- Resource Sensitivity
The system dynamically evaluates login risks based on:
- Unknown Devices
- Suspicious Login Patterns
- Device Fingerprints
- User Context
- Session Information
High-risk requests require additional verification.
Files are encrypted before storage using:
- AES-256-GCM
- Random IV Generation
- Authentication Tags
- Streaming Encryption
- Secure Key Management
Benefits:
- Confidentiality
- Integrity
- Authentication
Users can:
- Upload Files
- Download Files
- Delete Files
- View File Metadata
- Encrypt Files Automatically
- Verify File Integrity
Each login device is identified using:
- Browser Information
- Screen Resolution
- Timezone
- User Agent
- Canvas Fingerprint
This helps detect suspicious device changes.
Every important activity is logged, including:
- Login Attempts
- File Uploads
- Downloads
- Access Requests
- Authorization Decisions
- Security Events
Client
│
▼
Authentication Layer
│
▼
Policy Enforcement Point
│
┌─────────────┼─────────────┐
▼ ▼ ▼
RBAC Engine ABAC Engine Risk Engine
│ │ │
└─────────────┼─────────────┘
▼
Policy Decision Point
│
▼
AES-256-GCM Encryption
│
▼
Cloud Storage
│
▼
MySQL Database
- Intercepts every API request
- Validates authentication
- Enforces security policies
Determines whether access should be:
- Allow
- Deny
- Require Additional Verification
Assigns permissions based on user roles.
Example:
| Role | Upload | Download | Delete |
|---|---|---|---|
| Admin | ✅ | ✅ | ✅ |
| Editor | ✅ | ✅ | ❌ |
| Viewer | ❌ | ✅ | ❌ |
| Guest | ❌ | ❌ | ❌ |
Evaluates multiple attributes:
- User Role
- Device
- Login Time
- Department
- Resource Type
- Access Context
Calculates authentication risk before granting access.
Factors considered:
- New Device
- Multiple Failed Logins
- Suspicious Activity
- Session Behavior
- HTML5
- CSS3
- JavaScript
- Node.js
- Express.js
- MySQL
- JWT
- bcrypt
- Session Management
- AES-256-GCM
- SHA-256
- Zero Trust Policies
- Device Fingerprinting
Secure-Cloud/
│
├── client/
│ ├── css/
│ ├── js/
│ ├── images/
│ └── pages/
│
├── server/
│ ├── config/
│ ├── middleware/
│ ├── routes/
│ ├── controllers/
│ ├── models/
│ ├── services/
│ ├── encryption/
│ └── utils/
│
├── uploads/
├── database/
├── docs/
├── screenshots/
└── README.md
git clone https://github.com/gnanadeep30805/Secure-Cloud.gitcd Secure-Cloudnpm installCreate a .env file.
PORT=5000
DB_HOST=localhost
DB_USER=root
DB_PASSWORD=your_password
DB_NAME=secure_cloud
JWT_SECRET=your_secret_key
AES_SECRET_KEY=your_aes_secret_keynpm startor
npm run devInclude screenshots of:
- Login Page
- Dashboard
- File Upload
- File Encryption
- Access Control
- User Management
- Audit Logs
- Implements Zero Trust Architecture (NIST SP 800-207)
- Continuous Authentication & Authorization
- Hybrid Access Control (RBAC + ABAC + RBA)
- Secure File Encryption using AES-256-GCM
- Device Fingerprinting
- Secure Audit Trail
- Protection against Insider Threats
- Improved Cloud Security Model
- Multi-Factor Authentication (MFA)
- Behavioral Biometrics
- AI-Based Threat Detection
- Blockchain-Based Audit Logs
- Post-Quantum Cryptography (Kyber & Dilithium)
- Fully Homomorphic Encryption (FHE)
- Machine Learning Risk Engine
- Continuous Behavioral Authentication
This project is based on the concepts presented in:
Secure Data Protection for Cloud Computing with Zero Trust Architecture
The implementation follows the security principles defined in NIST SP 800-207 (Zero Trust Architecture) while extending the model with adaptive access control and secure encryption mechanisms.
Contributions are welcome!
-
Fork the repository
-
Create a new feature branch
git checkout -b feature-name- Commit your changes
git commit -m "Added new feature"- Push to GitHub
git push origin feature-name- Create a Pull Request
If you found this project useful, consider giving it a ⭐ Star on GitHub.
It helps others discover the project and motivates further development.
Gnanadeep Yenneti
🎓 Computer Science Student
☁️ Cloud Security Researcher
🔒 Cybersecurity Enthusiast
💻 Full Stack Developer