Skip to content
Open access

Self-Sovereign Identity-Enabled Zero Trust Framework with AI-Driven Threat Intelligence for Secure Multi-Cloud Computing

Sep 2026 · University of Thi-Qar journal for engineering sciences · 0 citations · 6 references

Abstract

With the accelerating deployment and adoption of multi-cloud computing, more and more organizations are exposed to major security threats. On average, a cloud organization is targeted by 1,925 cyberattacks each week, and 80% of cloud organizations are subject to cloud breach incidents annually. Although perimeter-based security is becoming a barrier to securing distributed cloud environments, integrated identity, access, and security management mechanisms that combine identity management, continuous verification, and intelligent threat detection are highly effective in securing multi-cloud computing. In this paper, a Self-Sovereign Identity-Enabled Zero Trust Framework with AI-Driven Threat Intelligence (SSI-ZT-AI) for Secure Multi-Cloud Computing is proposed. This framework comprises three well-matched security layers: (i) a decentralized identity verification layer using Self-Sovereign Identity (SSI)-based DID verification as per W3C Decentralized Identifier (DID) and Verifiable Credentials standards; (ii) a continuous trust assessment layer that performs a Zero Trust Architecture (ZTA)-based continuous verification using context-aware and risk-based scoring based on NIST SP 800-207; and (iii) a real-time threat detection layer that is based on a CNN-LSTM hybrid deep learning model and extracts both spatial and temporal features from network traffic data for intelligent threat detection. The evaluation on the UNSW-NB15 dataset (2,540,047 network flow records with nine different attack types) shows that the proposed SSI-ZT-AI framework for multi-cloud security is able to achieve a detection accuracy of 98.56%, a recall of 99.99%, a precision of 77.05%, an F1-score of 96.02%, and an AUC of 0.9984 with a false positive rate (FPR) of 1.52%. The very high recall value of the framework indicates that it is able to detect almost all the attacks (only 2 out of 14,900 attack samples in the test set were not detected). The integrated processing latency is less than 3 milliseconds, which indicates that the framework can operate in real time. The integrated framework regards identity management, behavior-based risk assessment, and intelligent threat detection as three interdependent security challenges and presents a comprehensive security strategy for securing multi-cloud computing. The very high recall of the proposed framework also makes it well-suited for security-sensitive applications in which the most important requirement is to detect as many attacks as possible.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.