Open Access

A Comprehensive Review of User Authentication and Authorization Techniques in Cloud Computing

4 Associate Professor, CSE, Geetanjali Institute of Technical Studies, India

Abstract

Cloud computing has emerged as a transformative paradigm for delivering scalable, flexible, and cost-effective computing services over the Internet. As organizations increasingly rely on cloud platforms for data storage, application hosting, and resource management, ensuring secure access to cloud resources has become a critical challenge. Authentication and authorization mechanisms play a fundamental role in protecting cloud environments by verifying user identities and regulating access privileges. This paper presents a comprehensive review of user authentication and authorization techniques in cloud computing. The study examines widely adopted authentication approaches, including password-based, multi-factor, biometric, and behavioral authentication methods, as well as authorization models such as Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Mandatory Access Control (MAC). Furthermore, recent advancements in artificial intelligence-driven authentication, fine-grained access control, graphical authentication systems, and cloud security frameworks are reviewed and analyzed. The findings indicate a significant transition from traditional security mechanisms toward intelligent, adaptive, and context-aware solutions that enhance security, usability, and access management. The review highlights that multi-factor authentication, biometric technologies, behavioral analytics, and attribute-based authorization frameworks offer improved protection against evolving cyber threats and represent promising directions for securing modern cloud computing environments.

Keywords

References

B. Uzoma and B. Okhuoya, “A Research On Cloud Computing,” 2022.
J. B. Mehta, “AI-Driven Test Engineering for Cloud-Native Systems,” Int. J. Data Sci. IoT Manag. Syst., vol. 5, no. 1, Jan. 2026, doi: 10.64751/ijdim.2026.v5i1.297.
E. Dritsas and M. Trigka, “A Survey on the Applications of Cloud Computing in the Industrial Internet of Things,” Big Data Cogn. Comput., vol. 9, no. 2, 2025, doi: 10.3390/bdcc9020044.
J. B. Mehta, “Autonomous Patch Validation For Zero-Day Exploits In Enterprise Clouds,” Int. J. Appl. Math., vol. 38, no. 4s, pp. 1270–1285, Oct. 2025, doi: 10.12732/ijam.v38i4s.685.
M. Parikh, A. A. Soni, S. M. Shah, and A. R. Jha, “Big Data Workload Profiling for Energy-Aware Cloud Resource Management,” in 2026 International Conference on Data Analytics for Sustainability and Engineering Technology (DASET 2026)), Track: Big Data and Machine Learning Applications, IEEE, Ed., arXiv preprint arXiv, 2026, pp. 01–07, januray. doi: 10.48550/arXiv.2601.11935.
A. M. Mostafa et al., “Strengthening Cloud Security: An Innovative Multi-Factor Multi-Layer Authentication Framework for Cloud User Authentication,” Appl. Sci., vol. 13, no. 19, 2023, doi: 10.3390/app131910871.
R. Lingam, S. Nagi, M. Chigurupati, and B. T. Myneni, “Resilient DevSecOps: Self-Healing Cloud-Native Systems via SRE-Driven AI Threat Detection and Response,” in 2026 International Conference on Smart Futuristic Technology, IEEE, Jan. 2026, pp. 1–6. doi: 10.1109/ICSFT66733.2026.11508049.
M. Kumar and M. K. Shah, “AI-Driven DDoS Detection for Network Security: A Performance Analysis of Machine-Deep Learning Methods on Network Traffic Data,” in 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC), Houston, TX, USA: IEEE, Feb. 2026, pp. 1–6. doi: 10.1109/ICAIC67076.2026.11395710.
R. K. Gadiraju, “Cloud-Native AI Platforms for Scalable Enterprise Machine Learning: Architecture, Challenges, and Best Practices,” Int. J. ofINTELLIGENT Syst. Appl. INENGINEERING, vol. 9, no. 4, pp. 481–492, October, 2021.
M. S. Rahaman, S. N. Tisha, E. Song, and T. Cerny, “Access Control Design Practice and Solutions in Cloud-Native Architecture: A Systematic Mapping Study,” Sensors, vol. 23, no. 7, 2023, doi: 10.3390/s23073413.
A. Mohammad, “Distributed Authentication and Authorization Models in Cloud Computing Systems: A Literature Review,” J. Cybersecurity Priv., vol. 2, no. 1, pp. 107–123, 2022, doi: 10.3390/jcp2010008.
D. Chandra Jadala, “Authentication and Authorization Mechanism for Cloud Security,” Int. J. Eng. Adv. Technol., vol. 8, no. 6, pp. 2072–2078, Aug. 2019, doi: 10.35940/ijeat.F8473.088619.
A. Joon, B. K. R. Janumpally, A. Gogineni, and P. Chatterjee, “Efficient Large-Scale Intrusion Identification and Prevention in Distributed Cloud Networks Using Artificial Intelligence,” in 2025 5th International Conference on Intelligent Technologies (CONIT), HUBBALI, India: IEEE, 2025, pp. 1–8, September. doi: 10.1109/CONIT65521.2025.11167760.
V. Mohan and s Sathyanathan, “Research in Cloud Computing-An Overview,” Int. J. Distrib. Cloud Comput., vol. 3, 2015, doi: 10.21863/ijdcc/2015.3.1.002.
H. N. Dholariya, “Regulatory-Grade Autonomous Data Modernization: The RAMA Framework for Compliance-Aware AI-Native Cloud Architectures,” J. Comput. Anal. Appl., vol. 35, no. 1, pp. 883–898, Jan, Jan. 2026, doi: 10.48047/jocaaa.2026.35.01.40.
M. Humayun, M. Niazi, M. F. Almufareh, N. Z. Jhanjhi, S. Mahmood, and M. Alshayeb, “Software-as-a-Service Security Challenges and Best Practices: A Multivocal Literature Review,” Appl. Sci., vol. 12, no. 8, p. 3953, Apr. 2022, doi: 10.3390/app12083953.
Y. Alghofaili, A. Albattah, N. Alrajeh, M. A. Rassam, and B. A. S. Al-rimy, “Secure Cloud Infrastructure: A Survey on Issues, Current Solutions, and Open Challenges,” Appl. Sci., vol. 11, no. 19, 2021, doi: 10.3390/app11199005.
R. K. Gadiraju, “Artificial Intelligence for Resource Optimization in Cloud Computing Environments,” J. Electr. Syst., vol. 20, no. 6, pp. 3164–3174, March, 2024.
K. H. Hong and B. M. Lee, “A Deep Learning-Based Password Security Evaluation Model,” Appl. Sci., vol. 12, no. 5, 2022, doi: 10.3390/app12052404.
S. Zaman, S. Raheel, T. Jamil, and M. Zalisham, “A Text based Authentication Scheme for Improving Security of Textual Passwords,” Int. J. Adv. Comput. Sci. Appl., vol. 8, 2017, doi: 10.14569/IJACSA.2017.080771.
A. Almulhem, “A graphical password authentication system,” in 2011 World Congress on Internet Security (WorldCIS-2011), IEEE, Feb. 2011, pp. 223–225. doi: 10.1109/WorldCIS17046.2011.5749855.
S. Das, B. Wang, Z. Tingle, and L. J. Camp, “Evaluating User Perception of Multi-Factor Authentication: {A} Systematic Review,” CoRR, vol. abs/1908.0, 2019.
J. Williamson and K. Curran, “Best Practice in Multi-factor Authentication,” Semicond. Sci. Inf. Devices, vol. 3, 2021, doi: 10.30564/ssid.v3i1.3152.
A. Ometov, S. Bezzateev, N. Mäkitalo, S. Andreev, T. Mikkonen, and Y. Koucheryavy, “Multi-Factor Authentication: A Survey,” Cryptography, vol. 2, no. 1, 2018, doi: 10.3390/cryptography2010001.
H. Ramcharan, “The Effective Integration of Multi-Factor Authentication (MFA) with Zero Trust Security,” Am. J. Math. Comput. Model., vol. 10, pp. 1–5, 2025, doi: 10.11648/j.ajmcm.20251001.11.
K. Modi and L. Devaraj, “Advancements in Biometric Technology with Artificial Intelligence,” 2023.
I. Alsaadi, “Physiological Biometric Authentication Systems, Advantages, Disadvantages And Future Development: A Review,” Int. J. Sci. Technol. Res., vol. Volume 4, 2015.
C. Wang, H. Tang, H. Zhu, J. Zheng, and C. Jiang, “Behavioral authentication for security and safety,” Secur. Saf., vol. 3, 2024, doi: 10.1051/sands/2024003.
M. L. Shuwandy et al., “A Robust Behavioral Biometrics Framework for Smartphone Authentication via Hybrid Machine Learning and TOPSIS,” J. Cybersecurity Priv., vol. 5, no. 2, 2025, doi: 10.3390/jcp5020020.
J. Singh, S. Rani, and V. Kumar, “Role-Based Access Control (RBAC) Enabled Secure and Efficient Data Processing Framework for IoT Networks,” Int. J. Commun. Networks Inf. Secur., Aug. 2024, doi: 10.17762/ijcnis.v16i2.6697.
D. Servos and S. Osborn, “Current Research and Open Problems in Attribute-Based Access Control,” ACM Comput. Surv., vol. 49, 2017, doi: 10.1145/3007204.
S. Kosunalp and S. Acik, “Medium Access Control Layer for Internet of Things Edge-Side Network Using Carrier-Sense Multiple Access Protocol,” Eng. Proc., vol. 70, no. 1, 2024, doi: 10.3390/engproc2024070001.
T. Ali, M. Al-Khalidi, and R. Al-Zaidi, “Information Security Risk Assessment Methods in Cloud Computing: Comprehensive Review,” J. Comput. Inf. Syst., vol. 66, no. 1, pp. 123–150, Jan. 2026, doi: 10.1080/08874417.2024.2329985.
P. Pandey, “AI-Enabled Multi-Factor Authentication (MFA) Systems for Private and Public Cloud Security,” in 2025 International Conference on Electronics and Renewable Systems (ICEARS), IEEE, Feb. 2025, pp. 886–889. doi: 10.1109/ICEARS64219.2025.10941462.
M. Z. Khan, K. U. Nisa, M. T. Quasim, M. A. Khalifa, and M. M. Mobarak, “Cloud-based Data Protection: A Framework for Authorizing Data Movement,” in 2024 International Conference on Expert Clouds and Applications (ICOECA), IEEE, Apr. 2024, pp. 271–275. doi: 10.1109/ICOECA62351.2024.00057.
Z. Cheng, X. Ding, H. Wan, and K. Liu, “Aplication and Practice of Data Authorization and Access Technology in Multi-tenant Environment,” in 2024 9th International Symposium on Computer and Information Processing Technology (ISCIPT), IEEE, May 2024, pp. 251–255. doi: 10.1109/ISCIPT61983.2024.10673271.
R. Khedkar, A. Pawar, K. Dharmale, N. Gaikwad, and A. Kangane, “A Comprehensive Survey of Graphical Passwords Authentication Systems that Provides Security,” in 2024 International Conference on Expert Clouds and Applications (ICOECA), IEEE, Apr. 2024, pp. 130–136. doi: 10.1109/ICOECA62351.2024.00036.
N. Li, X. Li, Y. Yan, Q. Sun, Y. Han, and K. Cheng, “Joint Communication and Computing Resource Optimization for Collaborative AI Inference in Mobile Networks,” in 2023 IEEE 98th Vehicular Technology Conference (VTC2023-Fall), IEEE, Oct. 2023, pp. 1–5. doi: 10.1109/VTC2023-Fall60731.2023.10333702.

Similar Articles

31-40 of 50

You may also start an advanced similarity search for this article.