← Back to VOLUME 15, ISSUE 8, AUGUST 2026
This work is licensed under a Creative Commons Attribution 4.0 International License.
SECURE API COMMUNICATION IN CLOUD APPLICATIONS
Mr. Naveen J, Manjunatha H, Sojo T Johnson
π 8 viewsπ₯ 4 downloads
Abstract: The rapid expansion of cloud-native applications has made API security a critical discipline in modern software engineering. APIs serve as the communication backbone of microservices, connecting mobile clients, third-party platforms, and enterprise back-ends across distributed cloud environments. This research investigates secure API communication mechanisms for cloud applications, comparing REST, GraphQL, and gRPC paradigms through a security lens. The OWASP API Security Top 10 is analysed with targeted mitigations, and four authentication mechanisms β OAuth 2.0 with PKCE, JWT, Mutual TLS, and Zero Trust β are evaluated both theoretically and experimentally. An empirical testbed built on Kubernetes, Istio, and Kong measured latency, throughput, and security scores across five protocol configurations. Results show that gRPC with mTLS achieves the best security-performance balance (9.2/10 security, 28 ms latency, 3,500 req/s).
The Unified Secure API Framework (USAF) β A Practical Reference Architecture for Real-World Cloud Implementations
Keywords: API Security, Cloud Computing, OAuth 2.0, JSON Web Token (JWT), Mutual TLS (mTLS), Zero Trust Architecture, OWASP API Security, REST, GraphQL, gRPC, Microservices, API Gateway, Secrets Management, PKCE, Rate Limiting, CloudNative Security
The Unified Secure API Framework (USAF) β A Practical Reference Architecture for Real-World Cloud Implementations
Keywords: API Security, Cloud Computing, OAuth 2.0, JSON Web Token (JWT), Mutual TLS (mTLS), Zero Trust Architecture, OWASP API Security, REST, GraphQL, gRPC, Microservices, API Gateway, Secrets Management, PKCE, Rate Limiting, CloudNative Security
How to Cite:
[1] Mr. Naveen J, Manjunatha H, Sojo T Johnson, βSECURE API COMMUNICATION IN CLOUD APPLICATIONS,β International Journal of Advanced Research in Computer and Communication Engineering (IJARCCE), DOI: 10.17148/IJARCCE.2026.15823
