A Security Framework for Cloud-Enabled IoT and Digital Twin Systems

Available online April 1, 2026
PDF

Abstract

Cloud powered IoT and digital-twin systems are linking physical operations with a centralized computing facility, but their security measures are often installed at single points be they a device, the network, the cloud or an application. This fragmentation allows compromised telemetry, stolen device identities, manipulated twin models, or virtual-machine attacks to propagate across the physical-virtual feedback loop. This paper proposes a layered framework that combines secure IoT onboarding, gateway policy enforcement, hybrid encryption, protected virtualization, digital-twin anomaly detection, continuous monitoring, and adaptive service-level agreements (SLAs). A normalized device-risk function Ri(t) and a covariance-weighted twin-deviation score At drive a composite SLA state S(t) and a graduated response ranging from reauthentication to command blocking. The control loop was implemented as a reproducible simulator of a water-process twin under replay, impersonation, false-data injection, flooding, model tampering, and key-release attacks. In that experiment, attested key release reduced virtualization attack success from 84.0% to 4.0%, dynamic SLA response at 900 concurrent users was 105~ms compared with 221~ms for a static SLA, and the proposed loop obtained higher normalized protection scores than traditional single-layer controls on the VM, encryption, IoT, twin, and SLA layers. The results demonstrate coordinated protection across physical, edge, cloud, and virtual-model layers and provide paper-ready Figures generated from the same executable notebook.

Keywords

Cloud security Internet of Things Digital twin Hybrid encryption Zero trust

Introduction

Cloud computing provides on-demand access to shared storage, processing, and networking resources. Its scalability has made it a central platform for the Internet of Things (IoT), in which sensors, actuators, vehicles, medical devices, and industrial equipment generate continuous data streams.Digital twins builds on this relationship by creating an ongoing virtual mirror of the physical asset or process. These virtual models can be used for the monitoring of the physical asset or process and the diagnosis, simulation, or decision-making required for operation. The practical importance of this problem has been growing steadily. The ENISA Threat Landscape 2025 analyses 4,875 cybersecurity incidents recorded between 1 July 2024 and 30 June 2025, highlighting the continuing evolution and convergence of cyber threats across the EU [9]. When considering a cloud-connected cyber-physical system, the issue might be: a production process is interrupted by a tampered sensor input, health of a patient is impacted by an unsafe command transmitted to a medical-device, or public infrastructure impacted by a compromised traffic-control state. The incorporation of cloud computing, IoT, and digital twins (DTs) further increase the attack surface. Many resource-constrained IoT devices employ weaker authentication, old firmware or use sparse cryptographic control mechanisms. Corrupted telemetry data can create erroneous twin status; an unauthorized command issued by the twin could impact physical system. Across the cloud the attack vectors of VM escapes, hypervisor compromises and cross-tenant attacks are ever-present threats [1]-[3].Static service-level agreements (SLAs) further restrict response because fixed security requirements do not reflect changing device trust, twin confidence, or threat conditions. Existing research commonly treats device security, virtualization, data protection, digital-twin trust, and service management as separate problems. The 2024-2026 literature has begun to close part of that gap by using digital twins as active security instruments for residual-based detection, orchestration, adversary simulation, and privacy-preserving learning [18]-[30], [32]. Even so, those systems still leave cloud-workload isolation, hybrid encryption of twin state, and adaptive SLAs outside the same control loop. The objective of this paper is to define an integrated framework that protects both cloud information assets and the physical-virtual feedback loop. The paper makes four contributions:

  • A cross-layer architecture that connects IoT onboarding, gateway risk scoring, hybrid encryption, attested virtualization, twin-residual analysis, and adaptive SLAs in one feedback process.

  • Bounded scoring models for device risk R_i(t), twin deviation A_t, and composite SLA state S(t), together with a graduated response algorithm that defaults to fail-safe operation when confidence is low.

  • A working code implementation of the control loop on a physics-based water-process twin, covering impersonation, replay, false-data injection, flooding, model tampering, and VM key-release attacks.

  • Experimental Figures and tables produced by that notebook, showing that attested key release and adaptive SLA profiles improve protection relative to traditional isolated controls.

The paper is organized as follow: Section 2 is about related work. Section 3 develops the integrated framework. Section 4 and Section 5 discuss the tests and applications of the framework within an executable simulation, respectively, and finally Section 6 gives a conclusion and future work.

Complete Article

The complete article, including all figures, tables, equations and algorithms, is available in the official publication PDF.

Conclusion

A layered security framework for IoT with DT embedded is then presented and simulated. The device risk Ri(t), twin remainder At, attested virtualization, hybrid-encryption wrap and SLA adaptability status S(t) works as an entire security control loop. It is shown in the simulation that by using attested key release, the rate of successful virtualization attack reduces from 84.0% to 4.0%. In the dynamic SLA policy, it took 105 ms at 900 simultaneous users for recovery time to respond whereas static SLA approach took 221 ms at 900 simultaneous users. The protection score also increases linearly from device to cloud and so do the advantages over traditional methods.Four direct practical implications can be drawn from the results of this paper. (1) Device’s telemetry must not be solely validated based on knowing the credentials. (2) Release of sensitive key should rely on the workload integrity, as attested; (3) Critical operations required by a certain workload should have a stricter authority level compare with read-only telemetry; (4) SLAs must define concrete security indications and corresponding performance indicators such that dynamic security mechanism can respond accordingly.

Further implementation could involve testing this architecture with actual industrial and network security datasets, like SWaT traces, WADI traces and CIC-DDoS traces. Additional testing should run multiple times with different seeds, report the confidence intervals, and justify the statistical relevance of results presented here. We also suggest investigating policy transfer between two different Cloud providers for this architecture with SLA definitions and attestation controls. Test across multiple-cloud and real-world operational environment will further validate this work.

References

  1. D. Zissis and D. Lekkas, “Addressing cloud computing security issues, ” Future Generation Computer Systems, vol. 28, no. 3, pp. 583-592, 2012, doi: 10.1016/j.future.2010.12.006
  2. S. Subashini and V. Kavitha, “A survey on security issues in service delivery models of cloud computing, ” Journal of Network and Computer Applications, vol. 34, no. 1, pp. 1-11, 2011, doi: 10.1016/j.jnca.2010.07.006
  3. W. Jansen and T. Grance, Guidelines on Security and Privacy in Public Cloud Computing, NIST Special Publication 800-144, National Institute of Standards and Technology, 2011, doi: 10.6028/NIST.SP.800-144
  4. M. Fagan, K. Megas, K. Scarfone, and M. Smith, IoT Device Cybersecurity Capability Core Baseline, NISTIR 8259A, National Institute of Standards and Technology, 2020, doi: 10.6028/NIST.IR.8259A
  5. G. Shao and M. Helu, “Framework for a digital twin in manufacturing: Scope and requirements, ” Manufacturing Letters, vol. 24, pp. 105-107, 2020, doi: 10.1016/j.mfglet.2020.04.004
  6. J. Voas, P. Mell, P. Laplante, and V. Piroumian, Security and Trust Considerations for Digital Twin Technology, NIST IR 8356, National Institute of Standards and Technology, 2025, doi: 10.6028/NIST.IR.8356
  7. E. C. Balta, M. Pease, J. Moyne, K. Barton, and D. M. Tilbury, “Digital twin-based cyber-attack detection framework for cyber-physical manufacturing systems, ” IEEE Transactions on Automation Science and Engineering, vol. 21, no. 2, pp. 1695-1712, 2024, doi: 10.1109/TASE.2023.3243147
  8. R. Barnes, K. Bhargavan, B. Lipp, and C. Wood, “Hybrid Public Key Encryption, ” RFC 9180, Internet Research Task Force, February 2022, doi: 10.17487/RFC9180
  9. European Union Agency for Cybersecurity, ENISA Threat Landscape 2025, October 2025, doi: 10.2824/1946374
  10. S. Rose, O. Borchert, A. Kerman, M. Souppaya, et al., Implementing a Zero Trust Architecture: High-Level Document, NIST Special Publication 1800-35, National Institute of Standards and Technology, 2025, doi: 10.6028/NIST.SP.1800-35
  11. National Institute of Standards and Technology, Considerations for Achieving Crypto Agility: Strategies and Practices, NIST Cybersecurity White Paper 39, December 2025, doi: 10.6028/NIST.CSWP.39
  12. V. C. Hu, Security Property Verification by Transition Model, NIST IR 8539, National Institute of Standards and Technology, January 2025, doi: 10.6028/NIST.IR.8539
  13. National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, February 2024, doi: 10.6028/NIST.CSWP.29
  14. European Parliament and Council of the European Union, “Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, ” Official Journal of the European Union, 2016.
  15. U. S. Department of Health and Human Services, “The HIPAA Security Rule, ” HHS.gov. [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/security/index.html.
  16. International Electrotechnical Commission, IEC 62443-3-3:2013, Industrial Communication Networks - Network and System Security - Part 3-3: System Security Requirements and Security Levels, IEC, Geneva, Switzerland, 2013.
  17. European Parliament and Council of the European Union, “Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), ” Official Journal of the European Union, November 20, 2024.
  18. C. Alcaraz and J. Lopez, “Digital twin: A comprehensive survey of security threats, ” IEEE Communications Surveys & Tutorials, vol. 24, no. 3, pp. 1475-1503, 2022, doi: 10.1109/COMST.2022.3171465
  19. H. Mun, K. Han, E. Damiani, H. K. Yeun, T.-Y. Kim, L. Martino, and C. Y. Yeun, “A comprehensive survey on digital twin: Focusing on security threats and requirements, ” IEEE Access, vol. 13, pp. 73362-73390, 2025, doi: 10.1109/ACCESS.2025.3563621
  20. A. R. Qureshi, A. Asensio, M. Imran, J. Garcia, and X. Masip-Bruin, “A survey on security enhancing Digital Twins: Models, applications and tools, ” Computer Communications, vol. 238, art. 108158, 2025, doi: 10.1016/j.comcom.2025.108158
  21. C. Alcaraz and J. Lopez, “Digital twin security: A perspective on efforts from standardization bodies, ” IEEE Security & Privacy, vol. 23, no. 1, pp. 83-90, 2025, doi: 10.1109/MSEC.2024.3504193
  22. K. E. Kampourakis, V. Gkioulos, and S. Katsikas, “Cybersecurity digital twins for industrial systems: From literature synthesis to framework design, ” Information, vol. 17, no. 3, art. 286, 2026, doi: 10.3390/info17030286
  23. P. J. Sinijoy, M. Bhasi, and V. R. Renjith, “Digital twin-based multilevel attack detection and automotive preventing scheme using machine learning and deep learning approaches, ” Expert Systems with Applications, vol. 302, art. 130647, 2026, doi: 10.1016/j.eswa.2025.130647
  24. P. Nguyen, A. Rauniyar, J. Bartel, J. Laufer, C. Dalamagkas, and K. Pohl, “AI-driven digital twin-based security orchestration, automation and response for critical infrastructures, ” Automated Software Engineering, vol. 33, art. 61, 2026, doi: 10.1007/s10515-026-00612-1
  25. F. Baiardi, S. Ruggieri, and V. Sammartino, “A Security Twin to Defeat Intrusions in Cyber Physical Systems, ” in Proceedings of the 35th European Safety and Reliability Conference (ESREL 2025) and the 33rd Society for Risk Analysis Europe Conference (SRA-E 2025), Stavanger, Norway, 2025, pp. 643-650, doi: 10.3850/978-981-94-3281-3_ESREL-SRA-E2025-P7829-cd
  26. M. Repetto, “Cybersecurity Digital Twins: Concept, blueprint, and challenges for multi-ownership digital service chains, ” Journal of Information Security and Applications, vol. 96, art. 104299, 2026, doi: 10.1016/j.jisa.2025.104299
  27. S. D. Okegbile and I. P. Gambo, “Artificial intelligence-driven security framework for internet of things-enhanced digital twin networks, ” Internet of Things, vol. 31, art. 101564, 2025, doi: 10.1016/j.iot.2025.101564
  28. W. Issa, N. Moustafa, B. Turnbull, and K.-K. R. Choo, “DT-BFL: Digital Twins for Blockchain-enabled Federated Learning in Internet of Things networks, ” Ad Hoc Networks, vol. 178, art. 103934, 2025, doi: 10.1016/j.adhoc.2025.103934
  29. A. Sayghe, “Digital Twin-Driven Intrusion Detection for Industrial SCADA: A Cyber-Physical Case Study, ” Sensors, vol. 25, no. 16, art. 4963, 2025, doi: 10.3390/s25164963
  30. M. M. Salim, D. Camacho, and J. H. Park, “Digital Twin and federated learning enabled cyberthreat detection system for IoT networks, ” Future Generation Computer Systems, vol. 161, pp. 701-713, 2024, doi: 10.1016/j.future.2024.07.017
  31. International Organization for Standardization, ISO 23247-1:2021, Automation Systems and Integration - Digital Twin Framework for Manufacturing - Part 1: Overview and General Principles, ISO, Geneva, Switzerland, 2021.
  32. M. Whaiduzzaman, N. T. Monalisa, S. T. Himi, S. Sultana, T. Jan, and A. Barros, “Enhancing IIoT security using digital twins in Industry 5.0: A systematic literature review, ” Information, vol. 17, no. 2, art. 209, 2026, doi: 10.3390/info17020209
35 17

Similar Articles

You may also start an advanced similarity search for this article.