Self-Sovereign Identity-Enabled Zero Trust Framework with AI-Driven Threat Intelligence for Secure Multi-Cloud Computing
Abstract
With the accelerating deployment and adoption of multi-cloud computing, more and more organizations are exposed to major security threats. On average, a cloud organization is targeted by 1,925 cyberattacks each week, and 80% of cloud organizations are subject to cloud breach incidents annually. Although perimeter-based security is becoming a barrier to securing distributed cloud environments, integrated identity, access, and security management mechanisms that combine identity management, continuous verification, and intelligent threat detection are highly effective in securing multi-cloud computing. In this paper, a Self-Sovereign Identity-Enabled Zero Trust Framework with AI-Driven Threat Intelligence (SSI-ZT-AI) for Secure Multi-Cloud Computing is proposed. This framework comprises three well-matched security layers: (i) a decentralized identity verification layer using Self-Sovereign Identity (SSI)-based DID verification as per W3C Decentralized Identifier (DID) and Verifiable Credentials standards; (ii) a continuous trust assessment layer that performs a Zero Trust Architecture (ZTA)-based continuous verification using context-aware and risk-based scoring based on NIST SP 800-207; and (iii) a real-time threat detection layer that is based on a CNN-LSTM hybrid deep learning model and extracts both spatial and temporal features from network traffic data for intelligent threat detection. The evaluation on the UNSW-NB15 dataset (2,540,047 network flow records with nine different attack types) shows that the proposed SSI-ZT-AI framework for multi-cloud security is able to achieve a detection accuracy of 98.56%, a recall of 99.99%, a precision of 77.05%, an F1-score of 96.02%, and an AUC of 0.9984 with a false positive rate (FPR) of 1.52%. The very high recall value of the framework indicates that it is able to detect almost all the attacks (only 2 out of 14,900 attack samples in the test set were not detected). The integrated processing latency is less than 3 milliseconds, which indicates that the framework can operate in real time. The integrated framework regards identity management, behavior-based risk assessment, and intelligent threat detection as three interdependent security challenges and presents a comprehensive security strategy for securing multi-cloud computing. The very high recall of the proposed framework also makes it well-suited for security-sensitive applications in which the most important requirement is to detect as many attacks as possible.