Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I B.Tech - Computer Science / Information Science / Information Technology - Semester V Cloud Security A Comprehensive Undergraduate Textbook CHAPTER 1 Fundamentals of Cloud Security, Design and Architecture for Cloud Unit I: Fundamentals of Cloud Security, Design and Architecture for Cloud Sections Covered 1.1 Overview of Cloud Security 1.10 Inter-tenant Segmentation 1.2 Security Services in Cloud Computing 1.11 Data Protection Strategies 1.3 Security Design Principles 1.12 Retention, Deletion and Archiving 1.4 Comprehensive Data Protection 1.13 Encryption Techniques 1.5 End-to-End Access Control 1.14 Data Redaction 1.6 Common Attack Vectors and Threats 1.15 Tokenization 1.7 Network and Storage Security 1.16 Obfuscation 1.8 Secure Isolation Strategies 1.17 PKI and Key Management 1.9 Virtualization Strategies Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Table of Contents Chapter Introduction / Overview Learning Outcomes Key Concepts 1.1 Overview of Cloud Security 1.2 Security Services in Cloud Computing 1.3 Security Design Principles for Cloud Computing 1.4 Comprehensive Data Protection 1.5 End-to-End Access Control 1.6 Common Attack Vectors and Threats 1.7 Network and Storage Security 1.8 Secure Isolation Strategies 1.9 Virtualization Strategies 1.10 Inter-tenant Network Segmentation Strategies 1.11 Data Protection Strategies 1.12 Data Retention, Deletion and Archiving Procedures for Tenant Data 1.13 Encryption Techniques 1.14 Data Redaction 1.15 Tokenization 1.16 Obfuscation 1.17 Public Key Infrastructure (PKI) and Key Management Laboratory Exercise Further Reading / Viewing Assessment Questions Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Chapter Introduction / Overview Cloud computing allows organizations to use computing resources such as servers, storage, databases, networking, analytics and applications over the internet. It improves flexibility and scalability, but it also changes the security boundary. Data, applications and users may be distributed across many locations, devices and cloud services. Cloud security is the set of policies, technologies, processes and controls used to protect cloud-based systems, data and services. It includes identity and access management, encryption, network security, data protection, monitoring, secure configuration, compliance, incident response and tenant isolation. A strong cloud security architecture does not depend on a single product. It uses layered security, shared responsibility, least privilege, secure design, continuous monitoring and careful data lifecycle management. Security must be planned from the beginning of cloud design instead of being added after deployment. This chapter introduces the fundamentals of cloud security design and architecture. It explains security services, cloud design principles, comprehensive data protection, access control, attack vectors, network and storage security, virtualization, tenant segmentation, data retention, encryption, redaction, tokenization, obfuscation, PKI and key management. By the end of this chapter, students will be able to understand the major security areas of cloud computing and design a basic secure cloud architecture for academic and real-world applications. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.1: Layered cloud security architecture Learning Outcomes Upon successful completion of this chapter, students will be able to: 1. Define cloud security and explain why security architecture is important in cloud computing. 2. Describe common cloud security services such as IAM, encryption, firewalling, monitoring, backup and compliance services. 3. Apply security design principles such as shared responsibility, least privilege, defense in depth, zero trust and secure defaults. 4. Explain data protection across the data lifecycle: creation, storage, use, sharing, archiving and deletion. 5. Design end-to-end access control using identity, authentication, authorization, MFA, roles, policies and continuous monitoring. 6. Identify common cloud attack vectors such as misconfiguration, credential theft, insecure APIs, malware, ransomware and DDoS. 7. Explain network and storage security controls including VPC/VNet segmentation, firewalls, private endpoints, encryption and backups. 8. Discuss secure isolation, virtualization and multi-tenant segmentation strategies. 9. Differentiate encryption, redaction, tokenization and obfuscation with examples. 10. Explain Public Key Infrastructure, certificates, key management lifecycle and cloud key management services. Key Concepts Glossary of Key Terms in This Chapter Cloud Security: A collection of technologies, policies and processes used to protect cloud applications, data, platforms and infrastructure. Shared Responsibility Model: A cloud security model that divides responsibilities between the cloud provider and the customer or tenant. IAM: Identity and Access Management; a system for managing users, roles, permissions and access policies. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Least Privilege: A principle where users and services receive only the permissions needed to perform their tasks. Zero Trust: A security approach based on continuous verification and never automatically trusting a user, device or network location. Multi-tenancy: A cloud architecture where multiple customers share provider infrastructure while remaining logically isolated. Encryption: A method of converting readable data into unreadable ciphertext using cryptographic keys. Tokenization: A technique that replaces sensitive data with non-sensitive tokens while the original data is stored securely elsewhere. Data Redaction: The removal or masking of sensitive information from data before display, sharing or storage. PKI: Public Key Infrastructure; a system of certificates, keys and trusted authorities used to support secure communication and identity verification. KMS: Key Management Service; a service for creating, storing, rotating and controlling access to cryptographic keys. Tenant Isolation: Techniques used to ensure that one customer cannot access another customer’s data, workloads or network traffic. 1.1 Overview of Cloud Security Cloud security protects cloud-based resources against unauthorized access, data leakage, service disruption and misuse. It covers infrastructure security, platform security, application security, data security, identity security and operational security. The cloud changes security because systems are no longer limited to an organization’s internal data center. Users may access services from many devices and locations, applications may run in multiple regions, and data may move between services through APIs. Because of this, cloud security must be identity-centered, automated, continuously monitored and designed for distributed environments. Cloud security is influenced by the service model. In Infrastructure as a Service, the customer manages operating systems, applications, identities and data while the provider manages physical infrastructure. In Platform as a Service, the provider manages more of the platform. In Software as a Service, the provider manages most of the application environment, but the customer still manages users, data classification, access policies and safe usage. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.2: Shared responsibility model in cloud security Security Area Purpose Example Controls Identity security Ensures that only valid users and services can access resources. IAM, MFA, SSO, RBAC, conditional access Data security Protects data from leakage, tampering and loss. Encryption, backup, DLP, tokenization, classification Network security Controls how workloads communicate. Virtual networks, firewalls, security groups, private endpoints Workload security Protects compute, containers, serverless and applications. Patch management, image scanning, endpoint protection, secure SDLC Monitoring security Detects attacks and abnormal behavior. Cloud logs, SIEM, alerts, threat detection, incident response Governance and compliance Ensures controls follow rules and standards. Policies, audit, evidence, risk management, control frameworks Important Point Cloud security is not only the cloud provider’s responsibility. Customers must configure services securely, manage identities carefully, protect data and monitor usage. 1.2 Security Services in Cloud Computing Cloud providers offer many built-in security services. These services help customers implement identity management, encryption, network filtering, monitoring, backup, vulnerability detection and compliance. However, the availability of a service does not automatically make a workload secure. The customer must configure the service correctly and align it with security requirements. Security services can be grouped into categories such as identity and access, network protection, data protection, threat detection, compliance, backup and disaster recovery. A secure architecture normally combines several categories instead of using only one tool. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I For example, a database should not rely only on a password. It should be protected by IAM roles, private network access, encryption at rest, audit logging, backups, vulnerability management and least-privilege access policies. Service Category Typical Cloud Service Security Function Identity and access IAM, directory service, SSO, MFA Manages users, groups, roles, permissions and authentication. Network security Firewall, security groups, network ACLs, WAF Filters traffic and protects public-facing endpoints. Data protection KMS, secret manager, backup service, DLP Protects data, keys, secrets and recovery copies. Threat detection Cloud threat detection, vulnerability scanning Finds suspicious activity, exposed resources and risky configurations. Logging and monitoring Cloud logs, metrics, SIEM integration Collects events for investigation and alerting. Compliance and posture Security posture management, policy enforcement Checks whether resources follow organizational or regulatory requirements. Resilience Backup, replication, disaster recovery service Supports availability during failure, deletion or ransomware attack. Best Practice Enable logging, MFA, encryption and backup early. These controls are easier to configure during initial cloud design than after many resources are already deployed. 1.3 Security Design Principles for Cloud Computing Security design principles guide architects in building secure cloud systems. They are not limited to a single vendor or product. They help students and engineers make good design decisions before selecting specific services. Important principles include shared responsibility, defense in depth, least privilege, secure defaults, zero trust, segmentation, automation, logging, encryption by design, resilience and continuous improvement. These principles reduce the chance of human error and limit the impact of attacks. A good cloud design assumes that failures and attacks can happen. Therefore, the architecture should limit blast radius, monitor activity, protect data, enforce access boundaries and support fast recovery. Design Principle Meaning Cloud Example Shared responsibility Understand what the provider secures and what the customer secures. Customer configures IAM and data access even when provider secures hardware. Defense in depth Use multiple layers of protection. IAM + private network + encryption + WAF + logging. Least privilege Grant only needed permissions. A backup service can read storage but cannot delete production databases. Secure by default Start with restricted access and open only what is required. Storage buckets are private by default. Zero trust Verify identity, device and context for each access request. Require MFA and policy checks even from internal networks. Segmentation Separate workloads, tenants and trust zones. Use separate virtual networks and subnets for web, app and database tiers. Automation Use templates and policies to reduce manual mistakes. Infrastructure as Code with security checks. Continuous monitoring Observe logs, metrics and behavior. Generate alerts for unusual login or public exposure. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.3: End-to-end access control with zero trust thinking 1.4 Comprehensive Data Protection Comprehensive data protection means protecting information throughout its complete lifecycle. Data must be protected when it is created, stored, processed, transmitted, shared, archived and deleted. A weakness at any stage can lead to data leakage or compliance failure. Data protection begins with classification. Organizations should identify whether data is public, internal, confidential, personally identifiable, financial, medical, academic or restricted. Classification decides which controls must be applied. Technical controls include encryption, access control, backup, data loss prevention, masking, tokenization, retention policies and secure deletion. Administrative controls include policies, user training, audit and accountability. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.4: Data protection across the cloud data lifecycle Data State Risk Protection Technique Data at rest Unauthorized access to stored files, disks or databases. Storage encryption, access policies, backup protection, key management. Data in transit Interception or modification during network transfer. TLS, VPN, private connectivity, certificate validation. Data in use Exposure while being processed in memory or applications. Least privilege, secure enclaves/confidential computing where required, application controls. Data shared externally Accidental sharing with wrong users or systems. DLP, expiration links, data classification, tokenization. Data archived Long-term exposure or forgotten sensitive records. Retention schedule, encrypted archive, access review. Data deleted Recoverable remnants or incomplete deletion. Secure deletion, crypto-shredding, documented disposal process. 1.5 End-to-End Access Control End-to-end access control ensures that every request to a cloud resource is authenticated, authorized, logged and continuously evaluated. Access control should cover human users, service accounts, workloads, APIs, databases, storage and administrative consoles. A strong access design includes identity federation, multi-factor authentication, role-based or attribute-based access control, least privilege, privileged access management, access reviews and policy monitoring. Access control is not complete if it protects only login. It must also control what a user or service can do after login. For example, a student portal administrator may be allowed to view user profiles but not modify exam results unless explicitly authorized. Access Control Component Description Example Authentication Verifies who the user or service is. Password + MFA, SSO, certificate-based service identity. Authorization Determines what actions are allowed. Read-only role for auditors; admin role for limited security team. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Policy enforcement Applies access rules at the resource or service level. Deny public storage access unless approved. Privileged access Controls powerful administrative accounts. Just-in-time admin access with approval and expiry. Access review Regularly checks whether access is still needed. Remove accounts of completed students or ex- employees. Audit logging Records access attempts and changes. Log successful and failed console/API actions. # Pseudo-policy idea for least privilege ALLOW user_group = "BackupOperators" ACTION = ["read_storage", "create_backup", "restore_backup"] RESOURCE = "production-storage" DENY ACTION = ["delete_storage", "change_encryption_key"] CONDITION = "MFA required and request logged" 1.6 Common Attack Vectors and Threats Cloud environments face many of the same threats as traditional systems, but cloud scale, remote access and automation can increase the impact of mistakes. Common attack vectors include stolen credentials, weak passwords, exposed keys, insecure APIs, public storage misconfiguration, vulnerable workloads, malware, ransomware and DDoS attacks. Misconfiguration is a major cloud risk because cloud services are often created quickly. A storage bucket, database or management port accidentally made public can expose sensitive data. Similarly, overly broad IAM permissions can allow attackers to move from one resource to another after an account is compromised. Threat management requires prevention, detection and response. Prevention includes secure configuration and least privilege. Detection includes logging, anomaly detection and alerts. Response includes containment, investigation, recovery and lessons learned. Figure 1.5: Common cloud attack vectors and threats Threat Example Main Control Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Credential theft Attacker uses leaked access key from code repository. MFA, secret scanning, key rotation, least privilege. Misconfiguration Public database or open storage bucket. Policy checks, secure defaults, configuration scanning. Insecure API API accepts unauthorized requests. API gateway, authentication, authorization, rate limiting. DDoS Flood of traffic against a web application. DDoS protection, CDN, WAF, scaling, rate limits. Malware / ransomware Compromised VM encrypts files. Endpoint protection, backups, segmentation, patching. Insider threat Authorized user downloads excessive sensitive data. DLP, monitoring, access review, separation of duties. Supply chain attack Compromised container image deployed to cloud. Image scanning, trusted registries, signed artifacts. 1.7 Network and Storage Security Network security controls how cloud resources communicate with users, the internet, internal workloads and other cloud services. A secure cloud network normally separates public resources from private resources. Web servers may be publicly reachable, but application and database layers should usually remain private. Storage security protects object storage, block storage, file storage, backups and snapshots. Controls include private access, encryption, versioning, immutability, access logging, backup protection and lifecycle rules. Network and storage security should work together. For example, a database should be accessible only from approved application subnets, encrypted at rest, protected by IAM policies and backed up with restricted delete permissions. Area Security Control Purpose Virtual network VPC/VNet segmentation Creates isolated cloud network boundaries. Subnet design Public, private and data subnets Separates internet-facing and internal resources. Firewall rules Security groups, network ACLs Allows only necessary ports and directions. Private connectivity VPN, private link, direct connection Reduces exposure to the public internet. Object storage Bucket policy, encryption, versioning Prevents public leakage and supports recovery. Database storage Encryption, backup, private endpoint Protects database confidentiality and availability. Backup storage Immutable backups, retention lock Defends against ransomware and accidental deletion. Practical Design Rule Expose only the minimum required endpoints to the internet. Keep databases, message queues, internal APIs and backup storage in private zones wherever possible. 1.8 Secure Isolation Strategies Secure isolation prevents one workload, user, tenant or security zone from affecting another. Isolation is essential in cloud computing because resources may run on shared infrastructure. Without effective isolation, a compromise in one component could spread to other workloads or tenants. Isolation can be implemented at several layers: account or subscription level, project level, network level, subnet level, workload level, identity level and data level. Strong designs often use multiple isolation boundaries. For example, production and development environments should be separated. Sensitive workloads can use separate accounts, separate networks, dedicated keys, private endpoints and stricter monitoring. Isolation Layer Technique Example Organizational Separate accounts, projects or subscriptions Separate production, development and testing cloud Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I accounts. Network Virtual networks, subnets, routing and firewalls Database subnet not reachable from internet. Identity Separate roles and service accounts Application role cannot access security audit logs. Compute VM isolation, container namespaces, sandboxing Untrusted jobs run in restricted containers. Data Separate storage containers, row-level rules, tenant IDs Each tenant can read only its own records. Key management Separate keys per tenant or environment Tenant A data encrypted with Tenant A key. 1.9 Virtualization Strategies Virtualization is a foundation of cloud computing. It allows multiple virtual machines, containers or workloads to share physical hardware while appearing separate to users. Security depends on strong isolation, controlled resource sharing and secure management of the virtualization layer. Virtual machines provide isolation through a hypervisor. Containers provide process-level isolation using the host operating system. Serverless platforms abstract infrastructure further, but still require secure code, identity and data access control. Virtualization security includes patching hypervisors and hosts, hardening images, scanning machine images and container images, limiting privileged containers, using trusted repositories and monitoring runtime behavior. Virtualization Model Main Feature Security Consideration Virtual Machine Each workload runs with its own guest OS. Patch OS, secure images, restrict management ports. Container Application shares host kernel but uses isolated namespaces. Scan images, avoid privileged mode, protect secrets. Serverless Provider manages infrastructure and scaling. Secure functions, IAM roles, triggers and environment variables. Bare metal / dedicated host Customer gets dedicated physical host or hardware isolation. Useful for strict compliance or licensing needs. Confidential computing Protects data in use using hardware-backed trusted execution. Useful for highly sensitive processing but requires careful design. Important Point Containers are not automatically more secure than virtual machines. Their security depends on image quality, host security, runtime settings, network policy and secrets handling. 1.10 Inter-tenant Network Segmentation Strategies Inter-tenant network segmentation ensures that different customers or departments using shared cloud infrastructure cannot directly access each other’s networks or data. It is central to multi-tenant cloud security. Segmentation strategies include separate virtual networks, separate subnets, route tables, security groups, firewall policies, private endpoints, tenant-aware application logic and service-level authorization checks. In SaaS applications, network isolation alone may not be enough because many tenants may use the same application and database platform. The application must also enforce tenant identity, tenant IDs, row-level access and audit logging. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.6: Inter-tenant network segmentation and secure isolation Strategy How It Works Use Case Separate virtual networks Each tenant or environment receives an isolated network boundary. Large enterprise tenants or regulated workloads. Subnet segmentation Web, application and data layers use separate subnets. Three-tier application security. Security groups / firewall rules Only approved traffic is allowed between zones. Allow app-to-database traffic only on required port. Private endpoints Access managed services through private network paths. Private database or storage access. Tenant-aware authorization Application checks tenant identity for each request. Multi-tenant SaaS with shared application layer. Microsegmentation Fine-grained control between workloads. High-security environments and zero trust architecture. 1.11 Data Protection Strategies Data protection strategies combine technical, administrative and operational controls to protect confidentiality, integrity and availability. A complete strategy starts with identifying sensitive data and then applying controls based on risk. Key strategies include classification, minimization, encryption, access control, backup, replication, versioning, DLP, monitoring, retention, deletion and incident response. Data minimization is important because data that is not collected or stored cannot be leaked later. Data protection should also include recovery planning. Backups should be tested, protected from deletion, encrypted and stored separately from production workloads. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Strategy Purpose Example Data classification Identify sensitivity and required controls. Mark student records as confidential. Data minimization Collect only necessary information. Do not store Aadhaar/passport details if not required. Access control Restrict who ca n view or change data. Only exam cell staff can modify marks. Encryption Protect data at rest and in transit. Encrypt databases and use TLS for APIs. Backup and recovery Recover from loss, deletion or ransomware. Daily encrypted backups with restore testing. DLP and monitoring Detect unauthorized sharing. Alert when bulk export of student data occurs. Retention and deletion Keep data only as long as required. Delete old logs after approved retention period. 1.12 Data Retention, Deletion, and Archiving Procedures for Tenant Data Data retention defines how long information must be kept. Deletion defines how data is removed when it is no longer required. Archiving moves less frequently used data to long-term storage while preserving required access, integrity and legal compliance. Tenant data procedures are important in multi-tenant cloud systems because customers may have different legal, academic, business or contractual requirements. A tenant may request export, deletion or retention of their data according to policy. Good procedures define data owners, retention periods, deletion triggers, approval workflows, backup handling, archive encryption, access controls and evidence of deletion. Procedure What It Defines Security Requirement Retention policy How long each data category is kept. Should match legal, academic or business requirements. Archiving How inactive data is moved to long-term storage. Archive must remain encrypted and access- controlled. Deletion request How a tenant requests removal of data. Verify tenant identity and authorization. Secure deletion How data is removed or made unrecoverable. Delete records, remove indexes, manage backups and keys. Crypto-shredding Destroy encryption key to make encrypted data unreadable. Useful when direct deletion from distributed storage is difficult. Audit evidence Proof that deletion or archiving was completed. Maintain logs without exposing deleted data. Best Practice Retention and deletion should be documented before collecting tenant data. Otherwise, organizations may keep sensitive information longer than necessary. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I 1.13 Encryption Techniques Encryption converts readable data called plaintext into unreadable ciphertext using cryptographic algorithms and keys. Encryption helps protect confidentiality if storage, network traffic or backup media are accessed by unauthorized parties. The most common cloud encryption categories are encryption at rest, encryption in transit and encryption in use. Encryption at rest protects stored data. Encryption in transit protects network communication. Encryption in use protects data during computation using specialized techniques such as confidential computing. Encryption is only as strong as the key management process. If keys are exposed, attackers may decrypt the data. Therefore, keys should be stored separately from data, access should be limited, usage should be logged and keys should be rotated as per policy. Technique Description Example Symmetric encryption Same key is used for encryption and decryption. AES-based storage encryption. Asymmetric encryption Public key encrypts or verifies; private key decrypts or signs. TLS certificates and digital signatures. Hashing One-way transformation for integrity or password verification. Password hash with salt; file integrity hash. TLS Protocol for secure network communication. HTTPS access to cloud web application. Envelope encryption Data key encrypts data; master key encrypts data key. Cloud KMS protecting storage encryption keys. Client-side encryption Data encrypted before it reaches the cloud provider. Sensitive file encrypted by application before upload. Important Point Encryption protects confidentiality, but it does not replace access control, logging, backup or secure application design. 1.14 Data Redaction Data redaction removes or masks sensitive information from a document, database field, log or report. It is useful when users need to see part of a record but should not see the sensitive part. For example, a support employee may see only the last four digits of a phone number or account number. A log file may replace an email address with a masked value before it is stored or shared. Redaction must be applied carefully. If the original sensitive data remains in hidden metadata, comments, temporary files or unprotected logs, the redaction is incomplete. Redaction Type Example Use Case Full redaction Name: [REDACTED] Remove sensitive fields from reports. Partial redaction Phone: ******7890 Show limited identifying information. Dynamic redaction Different users see different levels of detail. Admin sees full value; support staff sees masked value. Log redaction Password parameter removed from logs. Prevent secrets from being stored in monitoring systems. 1.15 Tokenization Tokenization replaces sensitive data with a token that has no useful meaning outside a protected token vault or mapping system. The original value is stored securely, and applications use the token for processing where the actual value is not required. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Tokenization is commonly used for payment card numbers, personal identifiers and sensitive account information. It reduces exposure because many systems can process tokens without storing the original sensitive value. Unlike encryption, tokenization usually requires a token vault or mapping system to recover the original value. Tokens should be generated securely and should not reveal patterns from the original data. Original Data Tokenized Form Why It Helps Card number 4111 1111 1111 1111 tok_pay_7H9K2 Applications can process payment reference without storing card number. Student ID with sensitive registration number tok_stu_20491 Reports can link records without exposing actual identifier. Bank account number tok_acc_83FA1 Customer service tools can use token for workflow. Patient number tok_med_01X9B Research data can be pseudonymized before analysis. Comparison Encryption is reversible using a key. Tokenization is reversible only through a controlled token mapping system. Both require strong access control. 1.16 Obfuscation Obfuscation makes data, code or configuration harder to understand. It does not provide the same strength as encryption, but it can reduce casual exposure and make reverse engineering more difficult. Data obfuscation may include masking names, shuffling test data, replacing values, generalizing locations or changing dates. Code obfuscation makes program logic harder to read, but it should not be treated as the main security control. Obfuscation is useful for training, testing and analytics where realistic-looking data is needed but real sensitive data should not be used. It must be combined with proper access control and secure data handling. Technique Description Example Masking Hide part of the value. Email: a***@example.com Substitution Replace real value with fake value. Amit -> User001 Shuffling Rearrange values between records. Shuffle dates of birth in test dataset. Generalization Reduce precision. Exact address -> city only. Code obfuscation Make source or bytecode harder to understand. Renaming variables and restructuring code. Synthetic data Generate artificial records with similar structure. Fake student dataset for lab practice. 1.17 Public Key Infrastructure (PKI) and Key Management Public Key Infrastructure is the framework used to create, manage, distribute, validate and revoke digital certificates. PKI supports secure communication, identity verification, digital signatures and trust between systems. In cloud systems, PKI is used for HTTPS websites, service-to-service authentication, VPNs, device identity, API security and secure management connections. Certificates connect a public key to an identity and are issued by a Certificate Authority. Key management is the process of managing cryptographic keys throughout their lifecycle: generation, storage, distribution, use, rotation, backup, revocation, expiration and destruction. Poor key management can defeat strong encryption. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I Figure 1.7: PKI and key management components PKI / Key Management Element Purpose Security Consideration Certificate Authority Issues and signs certificates. Must be trusted and protected. Certificate Binds identity to a public key. Should be renewed before expiry and revoked if compromised. Public key Shared key used for encryption or verification. Can be distributed openly. Private key Secret key used for decryption or signing. Must be protected, never exposed in code or logs. KMS Manages cryptographic keys in cloud. Use IAM policies, rotation and audit logs. HSM Hardware-backed secure key storage. Used for high-value keys and compliance needs. Rotation Replaces old keys with new keys. Limits damage if a key is exposed. Revocation Invalidates certificates or keys. Needed when keys or certificates are compromised. Best Practice Store secrets and private keys in a dedicated key management or secrets management service. Do not hard-code passwords, API keys or private keys in source code. Laboratory Exercise Design a Secure Cloud Architecture for an Online Examination Portal In this laboratory exercise, students design a secure cloud architecture for a simple online examination portal used by a college. The system contains student login, exam scheduling, question storage, answer submission, result processing and administrator reporting. Step Task Expected Output 1 Identify important data types such as student profiles, questions, answers, Data classification table. Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I marks and logs. 2 Create an access-control plan for students, teachers, exam cell admins and auditors. Roles and permissions matrix. 3 Design network zones for public web access, private application servers and private databases. Simple cloud network diagram. 4 Select data protection controls for storage, database, backups and logs. Encryption, backup and retention plan. 5 List common attack vectors and matching defenses. Threat-control mapping table. 6 Prepare key management and certificate usage plan. KMS, TLS and secret-management plan. 7 Define monitoring and incident response steps. Log sources, alert rules and response checklist. Suggested Submission Students may submit a two-page architecture diagram, one IAM matrix, one data protection table and one short explanation of how their design follows least privilege, segmentation and defense in depth. Further Reading / Viewing The following resources are recommended for students who want to strengthen their understanding of cloud security design, controls and architecture. Resource Type Resource Reason for Recommendation Official standard NIST Cloud Computing Security Reference Architecture Explains security components and responsibilities in a cloud ecosystem. Official standard NIST SP 800-207 Zero Trust Architecture Introduces zero trust concepts for modern distributed environments. Cloud framework CSA Cloud Controls Matrix Provides cloud-focused security control objectives and domains. Government guide CISA Cloud Security Technical Reference Architecture Gives recommended approaches for cloud migration and data protection. Provider guidance AWS Well-Architected Framework - Security Pillar Useful practical guidance for designing secure cloud workloads. Cryptography guide NIST SP 800-57 Part 1 Recommendation for Key Management Reference for cryptographic key lifecycle and key management practices. Practice activity Cloud provider free-tier security labs Hands-on practice for IAM, network rules, storage encryption and logging. Assessment Questions Part A - Multiple Choice Questions (1 Mark Each) Q1. Which principle gives users only the permissions required to perform their job? 1. Defense in depth 2. Least privilege 3. Public access 4. Obfuscation Answer: (b) Q2. Which control is mainly used to verify user identity before access? Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I 1. Authentication 2. Archiving 3. Compression 4. Caching Answer: (a) Q3. Which technique converts plaintext into ciphertext? 1. Tokenization 2. Encryption 3. Shuffling 4. Logging Answer: (b) Q4. Which model divides cloud security duties between provider and customer? 1. Shared responsibility model 2. OSI model 3. Waterfall model 4. Object model Answer: (a) Q5. Which cloud risk is caused by accidentally making a storage bucket public? 1. DDoS 2. Misconfiguration 3. Hash collision 4. Indexing error Answer: (b) Q6. Which protocol is commonly used to protect data in transit on websites? 1. HTTP only 2. FTP 3. TLS/HTTPS 4. Telnet Answer: (c) Q7. Which component is used to issue and manage digital certificates? 1. PKI 2. CSV 3. DNS cache 4. Load balancer only Answer: (a) Q8. Which technique replaces sensitive data with a non-sensitive substitute value? Chapter 1: Fundamentals of Cloud Security, Design and Architecture for Cloud Cloud Security - Unit I 1. Tokenization 2. Plaintext storage 3. Public sharing 4. Index scan Answer: (a) Part B - Short Answer Questions (5 Marks Each) Q9. Define cloud security and explain why it is important in cloud computing. Q10. Explain the shared responsibility model with one example for IaaS and one example for SaaS. Q11. List and explain any five security services commonly available in cloud platforms. Q12. Explain defense in depth and least privilege with suitable cloud examples. Q13. Differentiate between authentication and authorization. Q14. Explain common cloud attack vectors such as credential theft, misconfiguration and insecure APIs. Q15.