<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN"
  "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink"
         xmlns:mml="http://www.w3.org/1998/Math/MathML"
         article-type="research-article"
         dtd-version="1.2">

  <!-- ============================================================ FRONT -->
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">IJLTEMAS</journal-id>
      <journal-title-group>
        <journal-title>International Journal of Latest Technology in Engineering, Management &amp; Applied Science (IJLTEMAS)</journal-title>
        <abbrev-journal-title abbrev-type="publisher">IJLTEMAS</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="epub">2278-2540</issn>
      <publisher>
        <publisher-name>IJLTEMAS</publisher-name>
      </publisher>
    </journal-meta>

    <article-meta>
      <!-- IDs -->
      <article-id pub-id-type="publisher-id">108</article-id>
            <article-id pub-id-type="doi">10.51583/IJLTEMAS.2026.150700103</article-id>
      
      <!-- Categories -->
            <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Cloud Security</subject>
        </subj-group>
      </article-categories>
      
      <!-- Title -->
      <title-group>
        <article-title>Enhanced Secure Storage Architecture for IAAS Cloud Environments</article-title>
      </title-group>

      <!-- Authors -->
      <contrib-group>
                <contrib contrib-type="author">
                    <name>
            <surname>Coulibaly</surname>
            <given-names>Yahaya</given-names>
          </name>
                              <aff>
            Research and Innovation Centre, Agency for Information and Communication Technology (AGETIC), Bamako, Mali                        <country>Mali</country>
                      </aff>
                    
        </contrib>
                <contrib contrib-type="author">
                    <name>
            <surname>Paloute Karim Charlemagne</surname>
            <given-names>Ouedraogo</given-names>
          </name>
                              <aff>
            Higher School of Computer Science, University Nazi Boni, Bobo-Dioulasso, Burkina Faso                        <country>Mali</country>
                      </aff>
                    
        </contrib>
                <contrib contrib-type="author">
                    <name>
            <surname>Yann Christian Florian</surname>
            <given-names>Ouedraogo</given-names>
          </name>
                              <aff>
            Higher School of Computer Science, University Nazi Boni, Bobo-Dioulasso, Burkina Faso                        <country>Mali</country>
                      </aff>
                    
        </contrib>
                <contrib contrib-type="author">
                    <name>
            <surname>Abdoulahi</surname>
            <given-names>Alfadoulou</given-names>
          </name>
                              <aff>
            Research and Innovation Centre, Agency for Information and Communication Technology (AGETIC), Bamako, Mali                        <country>Mali</country>
                      </aff>
                    
        </contrib>
              </contrib-group>

      <!-- Volume / Issue / Pages -->
            <volume>15</volume>
                  <issue>7</issue>
                        <fpage>1321</fpage>
            <lpage>1331</lpage>
            
      <!-- Dates -->
      <history>
                <date date-type="received">
          <day>01</day>
          <month>08</month>
          <year>2026</year>
        </date>
                        <date date-type="accepted">
          <day>06</day>
          <month>08</month>
          <year>2026</year>
        </date>
              </history>

            <pub-date pub-type="epub">
        <day>18</day>
        <month>08</month>
        <year>2026</year>
      </pub-date>
      
      <!-- DOI Self-URI -->
            <self-uri xlink:href="https://doi.org/10.51583/IJLTEMAS.2026.150700103"/>
      
      <!-- Keywords -->
            <kwd-group kwd-group-type="author">
                <kwd>Cloud Computing</kwd>
                <kwd>Infrastructure as a Service (IaaS)</kwd>
                <kwd>Cloud Storage Security</kwd>
                <kwd>Data Encryption</kwd>
                <kwd>AES-256</kwd>
                <kwd>RSA</kwd>
                <kwd>Key Management System (KMS)</kwd>
                <kwd>Zero Trust Architecture.</kwd>
              </kwd-group>
      
    </article-meta>
  </front>

  <!-- ============================================================ BODY (Abstract) -->
  <body>
        <sec>
      <title>Abstract</title>
      <p>The growing adoption of Cloud Computing has profoundly transformed the management of IT infrastructures by providing flexible, scalable, and on-demand accessible resources. Among the various cloud computing service models, Infrastructure as a Service (IaaS) enables organizations to outsource their computing, networking, and storage resources to cloud providers. However, this outsourcing raises significant security concerns, particularly regarding the confidentiality, integrity, and availability of stored data. This paper presents an analytical study of storage security techniques in IaaS environments and examines the main threats that may affect data hosted in the cloud, including unauthorized access, misconfigurations, insider threats, and cyber attacks. Particular attention is given to cryptographic mechanisms used to protect data, including symmetric, asymmetric, and hybrid encryption techniques, as well as client-side and server-side encryption approaches. Based on this analysis, an enhanced secure storage architecture is proposed. This architecture relies on three main techniques: client-side data encryption using AES-256, encryption key protection through RSA, and the use of a Key Management System (KMS). It also incorporates secure communication protocols and enhanced authentication mechanisms. The objective is to ensure effective data protection while preserving the advantages provided by cloud infrastructures. The results of this study highlight the importance of combining robust encryption techniques, secure key management, and appropriate access control mechanisms to strengthen trust in cloud storage solutions. Finally, emerging approaches such as homomorphic encryption and Zero Trust architectures are presented as promising directions for future developments in cloud security.</p>
    </sec>
      </body>

  <!-- ============================================================ BACK (References) -->
    <back>
    <ref-list>
      <title>References</title>
            <ref id="ref1">
        <label>1</label>
        <mixed-citation>P. Mell et T. Grance, « The NIST Definition of Cloud Computing », National Institute of Standards and Technology, Gaithersburg, MD, Special Publication (NIST SP) 800‑145, sept. 2011. doi: 10.6028/NIST.SP.800-145.</mixed-citation>
      </ref>
            <ref id="ref2">
        <label>2</label>
        <mixed-citation>P. Yang, N. Xiong, et J. Ren, « Data Security and Privacy Protection for Cloud Storage: A Survey », IEEE Access, vol. 8, p. 131723‑131740, 2020, doi: 10.1109/ACCESS.2020.3009876.</mixed-citation>
      </ref>
            <ref id="ref3">
        <label>3</label>
        <mixed-citation>« Threat Landscape | ENISA ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape</mixed-citation>
      </ref>
            <ref id="ref4">
        <label>4</label>
        <mixed-citation>« Top Threats to Cloud Computing 2024 | CSA ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2024</mixed-citation>
      </ref>
            <ref id="ref5">
        <label>5</label>
        <mixed-citation>« Cloud Security Threats: Top Threats and 3 Mitigation Strategies », Exabeam. Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.exabeam.com/explainers/cloud-security/cloud-security-threats-top-threats-and-3-mitigation-strategies/</mixed-citation>
      </ref>
            <ref id="ref6">
        <label>6</label>
        <mixed-citation>N. I. of S. and Technology, « Advanced Encryption Standard (AES) », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 197, mai 2023. doi: 10.6028/NIST.FIPS.197-upd1.</mixed-citation>
      </ref>
            <ref id="ref7">
        <label>7</label>
        <mixed-citation>« RSA and Elliptic Curve Encryption System »:, Int. J. Inf. Secur. Priv., vol. 18, no 1, janv. 2024, doi: 10.4018/IJISP.340728.</mixed-citation>
      </ref>
            <ref id="ref8">
        <label>8</label>
        <mixed-citation>M. R. Khan et al., « Analysis of Elliptic Curve Cryptography &amp; RSA », J. ICT Stand., p. 355‑378, nov. 2023, doi: 10.13052/jicts2245-800X.1142.</mixed-citation>
      </ref>
            <ref id="ref9">
        <label>9</label>
        <mixed-citation>« Using server-side encryption with AWS KMS keys (SSE-KMS) - Amazon Simple Storage Service ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur:</mixed-citation>
      </ref>
            <ref id="ref10">
        <label>10</label>
        <mixed-citation>https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html</mixed-citation>
      </ref>
            <ref id="ref11">
        <label>11</label>
        <mixed-citation>K. Munjal et R. Bhatia, « A systematic review of homomorphic encryption and its contributions in healthcare industry », Complex Intell. Syst., p. 1‑28, mai 2022, doi: 10.1007/s40747-022-00756-z.</mixed-citation>
      </ref>
            <ref id="ref12">
        <label>12</label>
        <mixed-citation>J. S. Rauthan, « Homomorphic Encryption in Healthcare Industry Applications for Protecting Data Privacy », 7 janvier 2025, arXiv: arXiv:2501.04058. doi: 10.48550/arXiv.2501.04058.</mixed-citation>
      </ref>
            <ref id="ref13">
        <label>13</label>
        <mixed-citation>« Protecting data with server-side encryption - Amazon Simple Storage Service ». Consulté le: 14 juin 2026. [En ligne]. Disponible sur:</mixed-citation>
      </ref>
            <ref id="ref14">
        <label>14</label>
        <mixed-citation>https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html</mixed-citation>
      </ref>
            <ref id="ref15">
        <label>15</label>
        <mixed-citation>S. Rose, O. Borchert, S. Mitchell, et S. Connelly, « Zero Trust Architecture », National Institute of Standards and Technology, NIST Special Publication (SP) 800-207, août 2020. doi:</mixed-citation>
      </ref>
            <ref id="ref16">
        <label>16</label>
        <mixed-citation>10.6028/NIST.SP.800-207.</mixed-citation>
      </ref>
            <ref id="ref17">
        <label>17</label>
        <mixed-citation>« Cybersecurity Framework », NIST, nov. 2013, Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.nist.gov/cyberframework</mixed-citation>
      </ref>
            <ref id="ref18">
        <label>18</label>
        <mixed-citation>M. Dworkin, « Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC », National Institute of Standards and Technology, NIST Special Publication (SP) 800-38D, nov. 2007. doi: 10.6028/NIST.SP.800-38D.</mixed-citation>
      </ref>
            <ref id="ref19">
        <label>19</label>
        <mixed-citation>« (PDF) IDENTITY AND ACCESS MANAGEMENT (IAM) IN CLOUD SECURITY FRAMEWORKS », ResearchGate. Consulté le: 14 juin 2026. [En ligne]. Disponible sur: https://www.researchgate.net/publication/391270909_IDENTITY_AND_ACCESS_MANAGEMENT_IAM_IN_CLOUD_SECURITY_FRAMEWORKS</mixed-citation>
      </ref>
            <ref id="ref20">
        <label>20</label>
        <mixed-citation>I. T. L. Computer Security Division, « Key Management Guidelines - Key Management | CSRC | CSRC », CSRC | NIST. Consulté le: 15 juin 2026. [En ligne]. Disponible sur:</mixed-citation>
      </ref>
            <ref id="ref21">
        <label>21</label>
        <mixed-citation>https://csrc.nist.gov/projects/key-management/key-management-guidelines</mixed-citation>
      </ref>
            <ref id="ref22">
        <label>22</label>
        <mixed-citation>E. Barker, « Recommendation for Key Management: Part 1 – General », National Institute of Standards and Technology, NIST Special Publication (SP) 800-57 Part 1 Rev. 5, mai 2020. doi: 10.6028/NIST.SP.800-57pt1r5.</mixed-citation>
      </ref>
            <ref id="ref23">
        <label>23</label>
        <mixed-citation>garrodonnell, « How to generate &amp; transfer HSM-protected keys – BYOK – Azure Key Vault ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://learn.microsoft.com/en-us/azure/key-vault/keys/hsm-protected-keys-byok</mixed-citation>
      </ref>
            <ref id="ref24">
        <label>24</label>
        <mixed-citation>« Customer-managed encryption keys (CMEK) | Cloud Key Management Service », Google Cloud Documentation. Consulté le: 15 juin 2026. [En ligne]. Disponible sur:</mixed-citation>
      </ref>
            <ref id="ref25">
        <label>25</label>
        <mixed-citation>https://docs.cloud.google.com/kms/docs/cmek</mixed-citation>
      </ref>
            <ref id="ref26">
        <label>26</label>
        <mixed-citation>msmbaldwin, « Azure encryption overview ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://learn.microsoft.com/en-us/azure/security/fundamentals/encryption-overview</mixed-citation>
      </ref>
            <ref id="ref27">
        <label>27</label>
        <mixed-citation>« Customer-managed encryption keys | Cloud Storage », Google Cloud Documentation. Consulté le: 15 juin 2026. [En ligne]. Disponible sur:</mixed-citation>
      </ref>
            <ref id="ref28">
        <label>28</label>
        <mixed-citation>https://docs.cloud.google.com/storage/docs/encryption/customer-managed-keys</mixed-citation>
      </ref>
            <ref id="ref29">
        <label>29</label>
        <mixed-citation>« Cross-Border Data Sharing Under the CLOUD Act ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://www.congress.gov/crs-product/R45173</mixed-citation>
      </ref>
            <ref id="ref30">
        <label>30</label>
        <mixed-citation>« Demystifying AWS KMS key operations, bring your own key (BYOK), custom key store, and ciphertext portability | AWS Security Blog ». Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://aws.amazon.com/blogs/security/demystifying-kms-keys-operations-bring-your-own-key-byok-custom-key-store-and-ciphertext-portability/</mixed-citation>
      </ref>
            <ref id="ref31">
        <label>31</label>
        <mixed-citation>« Cloud HSM vs KMS: What’s Best for Enterprise Security? », Fortanix. Consulté le: 15 juin 2026. [En ligne]. Disponible sur: https://www.fortanix.com/blog/cloud-hsm-vs-kms-which-is-right-for-your-enterprise-data-security-strategy</mixed-citation>
      </ref>
            <ref id="ref32">
        <label>32</label>
        <mixed-citation>N. I. of S. and Technology, « Module-Lattice-Based Key-Encapsulation Mechanism Standard », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 203, août 2024. doi: 10.6028/NIST.FIPS.203.</mixed-citation>
      </ref>
            <ref id="ref33">
        <label>33</label>
        <mixed-citation>N. I. of S. and Technology, « Module-Lattice-Based Digital Signature Standard », U.S. Department of Commerce, Federal Information Processing Standard (FIPS) 204, août 2024. doi:  10.6028/NIST.FIPS.204.</mixed-citation>
      </ref>
          </ref-list>
  </back>
  
</article>
