With the exponential growth of payment card transactions, the global shift from cash to digital payments has intensified, and the Payment Card Industry (PCI) has embraced cloud computing for its scalability and efficiency. Traditional cloud storage systems, however, rely on trusted third-party providers, which can result in centralized storage, high costs, and trust concerns. This review examines a wide range of literature on cloud computing, cloud security and trust, e-commerce risk, and cryptographic techniques relevant to the protection of payment card data stored and shared in the cloud. It surveys the rise of cloud computing and its service and deployment models, the security issues and attack vectors that affect cloud-based systems, the role of phishing in payment card fraud, and the influence of perceived risk on consumers’ online purchase intention and trust. It further reviews cryptographic techniques used to secure cloud data, including symmetric and public-key encryption, searchable encryption, homomorphic encryption, and attribute-based cryptography (encryption, signatures, and signcryption), before examining blockchain technology as a decentralizing mechanism for cloud trust. A comparative analysis of existing cloud data security protocols is presented, showing that Attribute-Based Signcryption (ABSC) offers the most comprehensive coverage of confidentiality, integrity, availability, authenticity, and access control relative to Attribute-Based Encryption (ABE) and Attribute-Based Signatures (ABS) used independently. The review concludes that blockchain-integrated attribute-based signcryption is a promising direction for decentralizing trust in cloud-stored payment card data, but that such constructions require rigorous, formally verified security analysis before deployment, since at least one prominent scheme has been shown to be insecure.
Keywords: Blockchain, Cloud Computing, Cryptography, attribute-based signcryption, payment card security, perceived risk; phishing