The rapid growth of cloud and edge computing has increased the challenge of protecting Personally Identifiable Information (PII) during runtime, where conventional encryption leaves data exposed while in use. Existing approaches rely on static encryption, fixed access policies, or resource-intensive security mechanisms, limiting adaptability to dynamic threats and compliance requirements. This paper proposes an AI-driven, context-aware Just-In-Time (JIT) cryptographic framework that combines machine learning-based risk assessment with adaptive encryption selection. Four classifiers (Random Forest, XGBoost, SVM, and Neural Network), trained on CICIDS2017, CICIoT2023, and UNSW-NB15 datasets, generate real-time risk scores based on user behavior, data sensitivity, and execution context. Based on risk levels, the framework dynamically applies QKD-enhanced AES-256-GCM, AES-256-GCM with RSA-4096, ChaCha20-Poly1305, or tokenization/masking, while zero-trust access control ensures secure data governance. Evaluation on 1,000 synthetic PII records across nine deployment environments achieved up to 98.74% classification accuracy, 11.3 ms average JIT encryption latency (6.5 ms at the edge), 92.5/100 security score, and 100% regulatory compliance, outperforming static encryption frameworks with 30% higher security and lower latency. The results demonstrate an efficient, scalable, and regulation-compliant approach for adaptive PII protection in modern cloud-edge environments.
Introduction
This paper proposes an AI-Driven Just-in-Time (JIT) Dexterized Cryptographic Framework to improve the protection of Personally Identifiable Information (PII) in cloud and edge computing environments. Traditional encryption methods (e.g., AES and TLS) protect data when it is stored or transmitted, but they must decrypt data during processing, exposing sensitive information to threats such as insider attacks, malware, compromised edge devices, and memory-scraping attacks.
To overcome this limitation, the proposed framework uses artificial intelligence and machine learning to assess the real-time risk associated with each data access request. Instead of encrypting all data uniformly, the system selectively applies cryptographic protection only when the calculated risk exceeds a predefined threshold, enabling adaptive, context-aware security.
The framework evaluates four machine learning models—Random Forest (RF), XGBoost, Support Vector Machine (SVM), and Neural Network (NN)—using three benchmark intrusion detection datasets: CICIDS2017, CICIoT2023, and UNSW-NB15. These models generate risk scores that are processed by a Grant Analysis Engine (GAE) and a Privacy Assessment Engine (PAE) to determine whether and how data should be encrypted. The adaptive encryption controller supports multiple techniques, including AES, post-quantum cryptography (PQC), quantum key distribution (QKD), masking, tokenization, and redaction.
Principal Contributions
The proposed framework provides:
100% PII encryption coverage and full compliance with GDPR, HIPAA, and PCI-DSS in cloud deployments.
Low encryption latency (as low as 6.5 ms in optimized Edge-IoT environments and 11.3 ms on average).
A maximum security score of 92.5/100, demonstrating strong resilience against insider attacks, ransomware, zero-day exploits, and quantum threats.
Real-time, AI-driven adaptive encryption suitable for both cloud and edge computing.
Related Work and Research Gap
Existing studies mainly rely on static encryption, hybrid cryptography, blockchain auditing, or AI-based intrusion detection. Although these approaches improve security, they generally:
Apply the same encryption regardless of data sensitivity.
Do not connect intrusion detection with automatic encryption decisions.
Lack support for resource-constrained edge devices.
Ignore post-quantum security and compliance-aware encryption.
Use limited datasets for validation.
The proposed framework addresses these gaps by integrating:
AI-based risk scoring directly with encryption decisions.
Adaptive cryptographic algorithm selection based on contextual risk.
Support for cloud, edge, and IoT environments.
Multi-dataset validation.
Compliance enforcement and immutable audit logging.
Quantum-resistant cryptographic capabilities.
Proposed System Architecture
The framework consists of 11 integrated components:
User Layer
Edge Layer
Cloud Layer
Grant Analysis Engine
Privacy Assessment Engine
AI Risk Assessment Engine
Adaptive Encryption Controller
Key Management System
Compliance Engine
Secure Storage Layer
Audit and Governance Layer
The workflow follows: User Request → Grant Analysis → Privacy Assessment → AI Risk Assessment → Encryption Decision → Key Management → Secure Storage → Audit Logging → Compliance Validation.
The Grant Analysis Engine evaluates whether an access request is authorized before invoking AI-based risk assessment, reducing unnecessary computation and ensuring that only legitimate requests proceed to adaptive encryption. The architecture supports autonomous edge operation through locally cached security policies while maintaining centralized compliance and audit capabilities in the cloud.
Conclusion
This paper described an AI-Driven Just-In-Time (JIT) Cryptographic Framework for safeguarding of Personally Identifiable Information/Data in cloud and edge computing environments. The framework overcame the major drawback of conventional static encryption, namely its lack of responsiveness to the cryptographic protection of data in the face of real-time contextual threat dynamics, through the use of a formal Grant Analysis Engine, a Privacy Assessment Engine, four classifiers (Random Forest, XGBoost, SVM, and Neural Network) evaluated against three benchmark datasets (CICIDS2017, CICIoT2023 and UNSW-NB15), a multi-parameter composite risk scoring engine, selective encryption triggering logic, and a hierarchical collection of cryptographic algorithms. The work demonstrates that context-aware, selective cryptography can provide full privacy, security and protection for PII/ Data enabling a scalable, regulation-compliant solution for distributed computing systems.
References
[1] M. Armbrust et al., “A view of cloud computing,” Communications of the ACM, vol. 53, no. 4, pp. 50–58, 2010. DOI: https://doi.org/10.1145/1721654.1721672
[2] W. Shi, J. Cao, Q. Zhang, Y. Li and L. Xu, “Edge computing: Vision and challenges,” IEEE Internet Of Things Journal, vol. 3, no. 5, pp. 637–646, 2016. DOI: https://doi.org/10.1109/JIOT.2016.2579198
[3] European Parliament and Council, “Regulation (EU) 2016/679 (General Data Protection Regulation),” Official Journal of the European Union, 2016.
[4] U.S. Department of Health and Human Services, “HIPAA Security Rule,” 45 CFR Parts 160 and 164, 2003.
[5] PCI Security Standards Council, “Payment Card Industry Data Security Standard (PCI DSS) – Version 4.0” 2022.
[6] M. Ali, S. U. Khan and A. V. Vasilakos, “Security in cloud computing: Opportunities and challenges,” Information Sciences, vol. 305, pp. 357–383, 2015. DOI: https://doi.org/10.1016/j.ins.2015.01.025
[7] S. Rose et al., “Zero trust architecture,” NIST Special Publication 800-207, 2020. DOI: https://doi.org/10.6028/NIST.SP.800-207
[8] J. Park, \"Blockchain-Enabled Cloud Security Using Smart Contracts for Immutable Audit Trails,\" Journal of Cloud Computing, vol. 9, no. 1, 2020. DOI: https://doi.org/10.1186/s13677-020-00195-w
[9] Y. LeCun, Y. Bengio, and G. Hinton, \"Deep Learning,\" Nature, vol. 521, pp. 436–444, 2015. DOI: https://doi.org/10.1038/nature14539
[10] K. Hashizume, D. G. Rosado, E. Fernández-Medina, and E. B. Fernandez, \"An Analysis of Security Issues for Cloud Computing,\" Journal of Internet Services and Applications, vol. 4, no. 1, p. 5, 2013.
[11] K. Ntafloukas, L. McCausland, and P. Paspallis, \"A Vulnerability Assessment Approach for Cyber-Physical Systems and Industrial IoT,\" in Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES), 2022. DOI: https://doi.org/10.1145/3538969.3544469
[12] J. Bharti and S. Singh, \"A Hybrid Approach Using AES-RSA Encryption with Machine Learning-Based Intrusion Detection for Cloud Data Security,\" Applied Sciences, vol. 14, no. 3, p. 1082, 2024. DOI: https://doi.org/10.3390/app14031082
[13] S. Prabhakaran and A. Kulandasamy, \"Deep Learning-Based Intrusion Detection with AES Encryption for Cloud Data Protection,\" IEEE Access, vol. 10, pp. 30604–30619, 2022. DOI: https://doi.org/10.1109/ACCESS.2022.3158968
[14] R. Agrawal and P. Bhatt, \"Elliptic Curve Cryptography for Constrained IoT and Edge Devices: A Comparative Survey,\" IEEE Internet of Things Journal, vol. 9, no. 15, pp. 13543–13557, 2022.
[15] V. Goyal, O. Pandey, A. Sahai, and B. Waters, \"Attribute Based Encryption for Fine-Grained Access Control of Encrypted Data,\" Proceedings of ACM CCS, 2006.
[16] Y. Chen, \"Secure Big Data Processing Using Proxy Re-Encryption in Distributed Cloud Systems,\" Future Generation Computer Systems, vol. 115, pp. 341–352, 2021.
[17] J. Park, \"Blockchain-Based Data Provenance For Cloud Analytics Environments,\" Symmetry, vol. 13, no. 8, p. 1510, 2021.
[18] A. Abouelmehdi, A. Beni-Hessane, and H. Khaloufi, \"Big Healthcare Data: Preserving Security and Privacy,\" Journal of Big Data, vol. 5, no. 1, 2018.
[19] P. Krishnamurthy, S. Bhatt, and T. Cucinotta, \"Context-Aware Security for Financial Data Protection in Cloud Environments,\" IEEE Transactions on Services Computing, vol. 14, no. 5, pp. 1498–1512, 2021.
[20] T. Chen and C. Guestrin, \"XGBoost: A Scalable Tree Boosting System,\" Proceedings of ACM SIGKDD, 2016.
[21] A. Aldallal and F. Alisa, \"Effective Intrusion Detection System to Secure Data in Cloud Using Machine Learning,\" Symmetry, vol. 13, no. 12, p. 2306, 2021.
[22] S. Chockalingam et al., \"Privacy-Aware Cloud Architecture: A Systematic Review,\" IEEE/Elsevier Survey, 2023.
[23] J. Agunuru, \"AI-Based Cybersecurity Transformation: A Review of Adaptive Authentication and Federated Learning Approaches,\" IEEE Access, 2023.
[24] V. Satyam et al., \"AI-Driven Identity Threat Detection for Cloud Security Operations Centres,\" IEEE Access, vol. 12, 2024.
[25] L. Breiman, \"Random Forests,\" Machine Learning, vol. 45, no. 1, pp. 5-32, 2001.
[26] F. Xu, M. Ma, Q. Zhang, H.-K. Lo, and J. Pan, \"Secure Quantum Key Distribution with Realistic Devices,\" Reviews of Modern Physics, vol. 92, no. 2, p. 025002, 2020.
[27] J. Li et al., \"Federated Learning for Privacy-Preserving Anomaly Detection in Edge Networks,\" IEEE Transactions on Information Forensics and Security, vol. 18, pp. 1234-1248, 2023.
[28] National Institute of Standards and Technology (NIST), \"Post-Quantum Cryptography Standardization Project: CRYSTALS-Kyber and CRYSTALS-Dilithium Standards,\" NIST IR 8413, 2022-2024. Link: https://www.nist.gov/pqcrypto
[29] X. Zhang et al., \"Zero-Trust Adaptive Access Control for Cloud-Native Microservices,\" Future Generation Computer Systems, vol. 158, pp. 221-234, 2024.
[30] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, \"Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization (CICIDS2017),\" Proceedings of ICISSP, 2018.
[31] E. C. P. Neto et al., \"CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment,\" Sensors, vol. 23, no. 13, p. 5941, 2023.
[32] N. Moustafa and J. Slay, \"UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems,\" Proceedings of IEEE MilCIS, 2015.