Overview
This document contains all available topics for the Cloud Computing (CSS 451) and Computer Security (CSS 454) term project. Choose one topic from the groups below and reserve it in the course spreadsheet.
Group A: Searchable Encryption and Privacy-Preserving Data Access
1. Privacy-Preserving Range Query and Aggregation over Encrypted IIoT Data Using ABSE
- [x] TAKEN
- Focus: Range queries and data aggregation in Industrial IoT
- Key Technology: Attribute-Based Searchable Encryption (ABSE)
- Domain: IIoT (Industrial Internet of Things)
Analogy: Like being able to search through locked filing cabinets without opening them—you can query encrypted sensor data from factories without exposing the raw information.
2. Post-Quantum Attribute-Based Searchable Encryption with Dynamic Policy Update and Revocation for Multi-Group Data Sharing
- [ ] TAKEN
- Focus: Quantum-resistant searchable encryption
- Key Features: Dynamic policy updates, user revocation
- Use Case: Multi-group collaborative environments
Analogy: Think of a digital vault that's immune to quantum computer attacks, where you can change access rules on-the-fly and revoke permissions instantly—like a smart, future-proof digital safe.
3. Boolean and Multi-Keyword Searchable Encryption for Secure Data Sharing Across Multi-Cloud Environments
- [x] TAKEN
- Focus: Advanced search capabilities over encrypted data
- Key Features: Boolean operators (AND, OR, NOT), multiple keywords
- Infrastructure: Multi-cloud systems
Analogy: Like Google search but for encrypted data across different cloud providers—you can use complex queries ("diabetes AND treatment NOT surgery") without decrypting anything.
4. Post-Quantum ABSE Supporting Wildcard and Exclusion Queries for Encrypted Cloud Data
- [ ] TAKEN
- Focus: Flexible search patterns with quantum resistance
- Key Features: Wildcard searches (
*), exclusion queries - Security: Post-quantum cryptography
Analogy: Searching encrypted cloud files with patterns like "report_2024_*.pdf" while excluding certain categories—all while being safe from quantum computers.
5. Fine-Grained Access Control with Multi-Keyword Searchable Encryption for Multi-Group IoT Data Sharing
- [ ] TAKEN
- Focus: Precise permission management for IoT data
- Key Features: Granular access control, multi-keyword search
- Domain: IoT networks with multiple user groups
Analogy: Like having different keys for different rooms in a smart building—some people can search all sensor data, others only temperature data, all without decrypting what they can't access.
6. Secure and Efficient Query Processing over Encrypted Graph Databases in the Cloud
- [x] TAKEN
- Focus: Graph database queries on encrypted data
- Applications: Social networks, knowledge graphs, relationships
- Challenge: Maintaining efficiency while encrypted
Analogy: Analyzing a social network (who knows who) while the data stays encrypted—like finding connections in a web of relationships without seeing the actual names or details.
7. SQLias: SQL Injection Detection as a Service
- [x] TAKEN
- Focus: Detecting SQL injection attacks
- Deployment: Service-based model
- Protection: Database security
Analogy: Like having a security guard that specifically watches for people trying to sneak malicious commands into your database—provided as a cloud service you can subscribe to.
8. Cloud-Based NoSQL Injection Detection and Automated Corrective Response System
- [x] TAKEN
- Focus: NoSQL injection attack detection and mitigation
- Key Feature: Automated response and correction
- Database Type: NoSQL (MongoDB, Cassandra, etc.)
Analogy: A smart security system for modern databases that not only detects break-in attempts but also automatically fixes vulnerabilities and blocks attackers in real-time.
9. Scalable Privacy-Preserving Big Data Processing Framework for Sensitive IoT and EHR Datasets
- [ ] TAKEN
- Focus: Large-scale privacy-preserving computation
- Domains: IoT sensor data, Electronic Health Records (EHR)
- Challenge: Scalability with privacy guarantees
Analogy: Processing millions of medical records and IoT sensor readings to find patterns without ever exposing individual patient data—like analyzing a crowd without identifying anyone.
Group B: Post-Quantum Security, Functional Encryption, and Advanced Cryptography
10. Lightweight Functional Encryption for Fine-Grained Data Access Control in Cloud–Edge Environments
- [ ] TAKEN
- Focus: Efficient encryption for resource-constrained devices
- Key Feature: Functional encryption (decrypt only specific functions)
- Infrastructure: Cloud-edge computing
Analogy: Like giving someone a key that only unlocks the average temperature from your smart home, not the individual readings—efficient enough to run on tiny edge devices.
11. Post-Quantum Secure and Dynamic Load-Balanced Encryption for IIoT Data in Fog Computing
- [x] TAKEN
- Focus: Quantum-resistant encryption with load balancing
- Architecture: Fog computing (between edge and cloud)
- Domain: Industrial IoT
Analogy: Distributing encrypted factory data across fog nodes like spreading traffic across multiple roads—keeps everything secure from quantum attacks while preventing bottlenecks.
12. Post-Quantum Signcryption for Secure IoT Data Stream Processing in Cloud-Based Hadoop Systems
- [x] TAKEN
- Focus: Combined signing and encryption (signcryption)
- Platform: Hadoop for big data processing
- Security: Post-quantum resistance
Analogy: Signing and sealing a letter in one step (more efficient than doing separately) for IoT data streams—like a FedEx package that's both authenticated and secured, quantum-proof.
13. Post-Quantum ABSE for Secure Data Sharing and Revocation in Mobile Cloud Systems
- [x] TAKEN
- Focus: Quantum-resistant attribute-based searchable encryption
- Platform: Mobile cloud environments
- Key Feature: User revocation mechanisms
Analogy: Secure mobile data sharing that survives quantum computing—like a WhatsApp group where you can search messages while encrypted and kick people out instantly.
Group C: Identity, Authentication, ZKP, and Decentralized Access Control
14. Decentralized Single Sign-On with Anonymous Authentication for Multi-Cloud Systems Using Zero-Knowledge Proofs
- [x] TAKEN
- Focus: Privacy-preserving SSO across clouds
- Technology: Zero-Knowledge Proofs (ZKP)
- Feature: Anonymous authentication
Analogy: Logging into multiple cloud services with one credential while proving you're authorized without revealing who you are—like showing you're over 21 without showing your ID.
15. Scalable and Privacy-Preserving Blockchain-Based Decentralized Identity for Cross-Domain IoMT
- [x] TAKEN
- Focus: Self-sovereign identity for medical IoT
- Technology: Blockchain
- Domain: Internet of Medical Things (IoMT)
Analogy: Your medical devices and records having a digital passport that works across hospitals without a central authority—like having a universal medical ID that you control.
16. Decentralized Privacy-Preserving SSO with Aggregate Authentication and Flexible Authorization for Collaborative EHR Sharing Using SSI and Blockchain
- [x] TAKEN
- Focus: Advanced SSO for healthcare data sharing
- Technologies: Self-Sovereign Identity (SSI), blockchain
- Features: Aggregate authentication, flexible permissions
Analogy: Healthcare professionals collaborating on your records where you control who sees what, without a central gatekeeper—like a shared Google Doc but with blockchain-level security and privacy.
17. Real-Time and Dynamic PUF-Based Group Authentication for IoT in Edge–Cloud Computing
- [ ] TAKEN
- Focus: Hardware-based authentication using Physical Unclonable Functions
- Feature: Group authentication for IoT devices
- Performance: Real-time processing
Analogy: Each IoT device has a unique "fingerprint" from its hardware (like how no two snowflakes are alike) used for instant group authentication—authenticating a swarm of drones as one unit.
18. Cross-Domain Bilateral Access Control with Real-Time Verification for IoT in 6G Wireless Networks
- [ ] TAKEN
- Focus: Mutual access control across different domains
- Network: 6G wireless
- Performance: Real-time verification
Analogy: Two-way security handshake across different organizations' IoT networks at 6G speeds—like two embassies verifying each other's diplomats in milliseconds.
Group D: Auditing, Integrity, and Trust Management
19. Privacy-Preserving Deduplication and Data Integrity Auditing for Mobile Cloud Storage
- [x] TAKEN
- Focus: Detecting duplicate files while maintaining privacy
- Feature: Integrity verification
- Platform: Mobile cloud storage
Analogy: Finding duplicate photos in your cloud storage without the cloud provider seeing your actual photos, plus verifying no one has tampered with them—like a blind librarian organizing books without reading them.
20. Multi-Party Collaborative Auditing for Secure Outsourced Cloud Data
- [x] TAKEN
- Focus: Multiple parties jointly auditing cloud data
- Use Case: Outsourced storage verification
- Feature: Collaborative verification
Analogy: Multiple companies jointly checking that their shared cloud storage is intact without trusting a single auditor—like multiple accountants cross-checking the same books.
21. Real-Time and Batch Auditing of Encrypted Streaming Data Using Blockchain-Assisted Verification
- [ ] TAKEN
- Focus: Auditing data streams and batches
- Technology: Blockchain for tamper-proof logs
- Data Type: Encrypted streaming data
Analogy: Verifying live video streams and recordings haven't been tampered with using blockchain—like a digital notary that timestamps and verifies everything in real-time.
Group E: Cloud, Edge, Kubernetes, and Resource Management Security
22. Federated Access Control Policy Management for Secure Multi-Cluster Kubernetes Environments
- [x] TAKEN
- Focus: Managing access policies across multiple K8s clusters
- Architecture: Federated multi-cluster setup
- Challenge: Consistent policy enforcement
Analogy: Centrally managing security rules for multiple Kubernetes clusters across different regions—like a franchise owner setting uniform security policies for all branches.
23. Fault-Tolerant and Load-Balanced IIoT Edge–Fog Architecture over Multiple Kubernetes Clusters
- [x] TAKEN
- Focus: Resilient architecture for industrial IoT
- Features: Fault tolerance, load balancing
- Infrastructure: Edge-fog-cloud with K8s
Analogy: Building an industrial IoT system that never goes down—if one cluster fails, others take over automatically, like a power grid that reroutes electricity when a line goes down.
24. Fine-Grained Access Control with Load-Aware Scheduling in Cloud–Edge Kubernetes Environments
- [x] TAKEN
- Focus: Combining security with performance optimization
- Features: Granular permissions, intelligent task scheduling
- Infrastructure: Cloud-edge K8s
Analogy: A smart factory system that not only controls who accesses what data, but also intelligently routes tasks to less-busy machines—security meets efficiency.
25. Multi-Level Access Control for Multi-VM Cloud Systems with Optimized Performance Monitoring
- [x] TAKEN
- Focus: Hierarchical security for virtual machines
- Feature: Performance optimization
- Platform: Multi-VM cloud environments
Analogy: Different security clearance levels for different VMs (like military clearances) while monitoring and optimizing how resources are used—security without sacrificing speed.
26. Group-Based Proxy Load Balancing Using Task-Priority-Aware Dynamic Quorum Selection
- [ ] TAKEN
- Focus: Intelligent load balancing with priorities
- Method: Dynamic quorum selection
- Feature: Task prioritization
Analogy: A smart traffic controller that groups similar vehicles and prioritizes ambulances over regular cars, dynamically adjusting lanes—but for cloud tasks.
27. Adaptive Load-Aware Scheduling for Spark Workflows in Distributed Cloud Hadoop Environments
- [ ] TAKEN
- Focus: Optimizing Apache Spark job scheduling
- Platform: Distributed Hadoop clusters
- Feature: Adaptive to current load
Analogy: A factory manager who constantly monitors which assembly lines are busy and redirects work to idle stations—but for big data processing jobs.
28. Lightweight Edge–Fog–Cloud Architecture with Post-Quantum Support for Real-Time Internet of Vehicles (IoV)
- [ ] TAKEN
- Focus: Three-tier architecture for connected vehicles
- Security: Post-quantum cryptography
- Performance: Real-time processing for V2X communication
Analogy: A layered security system for self-driving cars where quick decisions happen at the edge (car), coordination at fog (roadside), and heavy analysis in the cloud—all quantum-proof.
29. Privacy-Preserving V2X Authentication Using Zero-Knowledge Proofs
- [ ] TAKEN
- Focus: Vehicle-to-everything (V2X) communication security
- Technology: Zero-Knowledge Proofs
- Privacy: Anonymous authentication
Analogy: Cars proving they're authorized to communicate with traffic lights and other vehicles without revealing their identity or location history—like a secret handshake that proves membership without showing ID.
30. Privacy-Preserving Cloud Intrusion Detection Using Encrypted Traffic Analytics
- [x] TAKEN
- Focus: Detecting attacks without decrypting traffic
- Method: Analytics on encrypted data
- Application: Cloud security monitoring
Analogy: A security guard who can spot suspicious behavior by watching movement patterns without seeing people's faces or reading their conversations—detecting threats while respecting privacy.
Group G: "As-a-Service" Model
31. Intrusion Detection As a Service (IDaaS)
- [x] TAKEN
- Focus: Cloud-based intrusion detection
- Deployment: Service model
- Benefit: Scalable security monitoring
Analogy: Netflix for security—subscribe to enterprise-grade intrusion detection without buying expensive hardware or hiring a security team. Just pay monthly and get protected.
32. Post-Quantum Signcryption-as-a-Service (PQEaaS)
- [x] TAKEN
- Focus: Quantum-resistant signing and encryption service
- Deployment: API-based service
- Security: Post-quantum cryptography
Analogy: Like using AWS Lambda for cryptography—call an API to sign and encrypt data with quantum-safe algorithms without implementing complex crypto yourself.
33. Zero-Knowledge Authentication-as-a-Service (ZK-AuthaaS)
- [ ] TAKEN
- Focus: Privacy-preserving authentication service
- Technology: Zero-Knowledge Proofs
- Deployment: Cloud service
Analogy: Authentication service where users prove who they are without passwords or revealing identity—like Stripe for payments, but for privacy-preserving login.
34. Secure Data Deduplication-as-a-Service (SDDaaS)
- [x] TAKEN
- Focus: Privacy-preserving duplicate detection
- Deployment: Cloud service
- Benefit: Storage optimization with security
Analogy: A cloud service that removes duplicate files across your organization without seeing the actual files—like a blind organizing service that saves you storage space securely.
Topic Selection Guide
Choosing Your Topic
Consider these factors:
- Interest: Choose something that excites you
- Complexity: Match your team's skill level
- Resources: Ensure you can access necessary tools/libraries
- Innovation: Look for opportunities to add novel contributions
- Publication potential: Some topics are more "hot" in research
Keywords to Understand
- ABSE: Attribute-Based Searchable Encryption
- Post-Quantum: Cryptography resistant to quantum computer attacks
- ZKP: Zero-Knowledge Proofs
- IIoT: Industrial Internet of Things
- IoMT: Internet of Medical Things
- V2X: Vehicle-to-Everything communication
- EHR: Electronic Health Records
- SSI: Self-Sovereign Identity
- PUF: Physical Unclonable Function
Difficulty Levels (Estimated)
Beginner-Friendly (Good starting points):
- Topics 7, 8, 31 (Service-based models are more implementation-focused)
Intermediate (Balanced theory and implementation):
- Topics 1, 3, 6, 19, 22, 23, 24, 25, 26, 27, 30
Advanced (Heavy cryptography/theory):
- Topics 2, 4, 10, 11, 12, 13, 14, 15, 16, 32, 33, 34
Very Advanced (Cutting-edge research):
- Topics 5, 9, 17, 18, 21, 28, 29
Next Steps
- Review all topics in detail
- Research 2-3 topics that interest you
- Discuss with your team members
- Reserve your chosen topic early
- Read related papers to understand the state-of-the-art
Pro Tip: Choose a topic where you can find at least 5-10 recent papers (2020-2024). This indicates active research interest and will help with your literature review!
Related Files
- Cloud_Computing_Network_Security_Term_Project - Project requirements and timeline