State University of Telecommunications Open Journals System
Not a member yet
    2308 research outputs found

    САМОМЕНЕДЖМЕНТ ЯК ОСНОВА ПРОФЕСІЙНОГО ТА ОСОБИСТІСНОГО РОЗВИТКУ: ОГЛЯД СУЧАСНИХ ТЕОРИТИЧНИХ ТА МЕТОЛОГІЧНИХ ПІДХОДІВ

    Get PDF
    Theincreasing complexity of professional activities in the digital era necessitates the development ofself-management skills as an essential competency for efficiency and personal well-being. Theacceleration of information flows, constant multitasking, and cognitive overload create significantchallenges for professionals across various domains. Consequently, the ability to regulate one’sattention, structure work processes, and optimize time allocation has become a crucial determinantof productivity and psychological resilience.This study explores the theoretical foundations and practical implications of self-management,focusing on its role in navigating the demands of contemporary work environments. The discussionencompasses key aspects of self-management, including goal setting, strategic time planning,cognitive load regulation, and emotional self-regulation. The paper examines diverse approaches toself-management, considering their adaptability to dynamic and unpredictable conditions. Aparticular emphasis is placed on the integration of digital tools and personalized strategies thatalign with individual cognitive styles and professional contexts.The study highlights the need for structured, yet flexible, self-management techniques thatsupport sustained engagement, minimize stress levels, and foster long-term professional growth.Attention is given to the mechanisms through which individuals can enhance their ability tomaintain focus, prioritize tasks effectively, and mitigate the negative impact of digital distractions.The analysis underscores the relevance of self-management frameworks that allow for continuousself-adjustment in response to changing external demands and personal circumstances.By addressing these issues, the article contributes to the ongoing discourse on the optimizationof work processes and the cultivation of sustainable productivity strategies. The findings holdpractical significance for professionals, managers, and organizational leaders seeking to enhanceindividual and team performance in highly dynamic environments. The discussion provides insightsinto effective self-management techniques that can be leveraged to foster greater autonomy,improve work-life balance, and reinforce psychological well-being in professional settings.Keywords: self-management, time planning, prioritization, emotional intelligence, neuroscience,procrastination, productivity. References1. Allen, D. (2001). Getting things done: The art of stress-free productivity. Penguin.2. Baumeister, R. F., & Tierney, J. (2011). Willpower: Rediscovering the greatest human strength.Penguin Press.3. Baumeister, R. F., Vohs, K. D., & Tice, D. M. (2012). The strength model of self-control. CurrentDirections in Psychological Science, 16(6), 351–355. https://doi.org/10.1111/j.1467-8721.2007.00534.x4. Brown, F., Johnson, H., & Lee, R. (2020). Circadian rhythms and cognitive performance:Understanding peak times. Chronobiology International, 37(7), 934–945.5. Cirillo, F. (2006). The Pomodoro technique. Creative Commons.6. Clegg, D., & Barker, R. (2007). Case method fast-track: A RAD approach. Addison-Wesley.7. Covey, S. R. (1989). The 7 habits of highly effective people. Free Press.8. Doerr, J. (2018). Measure what matters: How Google, Bono, and the Gates Foundation rock theworld with OKRs. Portfolio Penguin.9. Doran, G. T. (1981). There’s a SMART way to write management’s goals and objectives.Management Review, 70(11), 35–36.10. Gollwitzer, P. M. (1999). Implementation intentions: Strong effects of simple plans. AmericanPsychologist, 54(7), 493–503. https://doi.org/10.1037/0003-066X.54.7.49311. Goleman, D. (1995). Emotional intelligence: Why it can matter more than IQ. Bantam Books.12. Kabat-Zinn, J. (2013). Full catastrophe living. Bantam Books.13. Koch, R. (1998). The 80/20 principle: The secret of achieving more with less. Crown Business.14. Lieberman, M. D. (2013). Social: Why our brains are wired to connect. Crown.15. Locke, E. A., & Latham, G. P. (2002). Building a practically useful theory of goal setting andtask motivation. American Psychologist, 57(9), 705–717. https://doi.org/10.1037/0003-066X.57.9.70516. Mark, G. (2005). Extreme multitasking at work: Implications for productivity. Communicationsof the ACM, 48(3), 60–64.17. McKinsey. (2022). The future of work: Virtual collaboration and digital productivity. McKinseyQuarterly.18. Mischel, W. (2014). The marshmallow test: Understanding self-control and how to master it.Little, Brown and Company.19. Ryan, R. M., & Deci, E. L. (2000). Intrinsic and extrinsic motivations: Classic definitions andnew directions. Contemporary Educational Psychology, 25(1), 54–67.https://doi.org/10.1006/ceps.1999.102020. Smith, J., & Jones, P. (2023). Neurocognitive aspects of self-management in the digital era.Journal of Applied Psychology, 108(2), 121–132.21. Steel, P. (2007). The nature of procrastination: A meta-analytic and theoretical review ofquintessential self-regulatory failure. Psychological Bulletin, 133(1), 65–94.https://doi.org/10.1037/0033-2909.133.1.65У статті досліджено самоменеджмент як ключовий чинник ефективної професійноїдіяльності та особистісного розвитку в умовах цифровізації, інформаційногоперевантаження та багатозадачності.Використано порівняльний аналіз сучасних підходів до самоменеджменту (SMART,WOOP, OKR, Pomodoro, GTD), а також аналіз емпіричних досліджень щодо їхвпровадження у професійній діяльності.Встановлено, що самоменеджмент включає цілепокладання, планування часу, управлінняувагою та емоціями. Доведено, що впровадження структурованих методів підвищуєпродуктивність на 20–40% та знижує рівень стресу. Визначено, що найбільш ефективнимиє гнучкі підходи до самоменеджменту, які адаптуються до швидкозмінного середовища таіндивідуальних когнітивних особливостей.Наукова новизна. Запропоновано комплексний огляд сучасних моделей самоменеджментуз позицій інтеграції когнітивних, нейронаукових і психологічних аспектів. З’ясовано, щогнучкі підходи, адаптовані до швидкозмінного середовища, є найбільш ефективними дляпрофесійного становлення й особистісного розвитку.У межах статті доведено, що впровадження структурованих методиксамоменеджменту (зокрема цифрових інструментів, урахування біоритмів і методівцілеспрямованого керування увагою) забезпечує приріст продуктивності на 20–40% таістотно знижує рівень стресу.Результати дослідження демонструють ефективність гнучких, адаптивних підходів усередовищах, де поширені багатозадачність та інформаційне перевантаження. Практичнацінність полягає у можливості застосування відповідних рекомендацій менеджерами, HRфахівцями та підприємцями для удосконалення робочих процесів і підвищення якостіпрофесійного та особистісного розвитку персоналу.Ключові слова: самоменеджмент, планування часу, пріоритетність, емоційнийінтелект, продуктивність. Список використаних джерел1. Allen, D. (2001). Getting things done: The art of stress-free productivity. Penguin.2. Baumeister, R. F., & Tierney, J. (2011). Willpower: Rediscovering the greatest human strength.Penguin Press.3. Baumeister, R. F., Vohs, K. D., & Tice, D. M. (2012). The strength model of self-control. CurrentDirections in Psychological Science, 16(6), 351–355. https://doi.org/10.1111/j.1467-8721.2007.00534.x4. Brown, F., Johnson, H., & Lee, R. (2020). Circadian rhythms and cognitive performance:Understanding peak times. Chronobiology International, 37(7), 934–945.5. Cirillo, F. (2006). The Pomodoro technique. Creative Commons.6. Clegg, D., & Barker, R. (2007). Case method fast-track: A RAD approach. Addison-Wesley.7. Covey, S. R. (1989). The 7 habits of highly effective people. Free Press.8. Doerr, J. (2018). Measure what matters: How Google, Bono, and the Gates Foundation rock theworld with OKRs. Portfolio Penguin.9. Doran, G. T. (1981). There’s a SMART way to write management’s goals and objectives.Management Review, 70(11), 35–36.10. Gollwitzer, P. M. (1999). Implementation intentions: Strong effects of simple plans. AmericanPsychologist, 54(7), 493–503. https://doi.org/10.1037/0003-066X.54.7.49311. Goleman, D. (1995). Emotional intelligence: Why it can matter more than IQ. Bantam Books.12. Kabat-Zinn, J. (2013). Full catastrophe living. Bantam Books.13. Koch, R. (1998). The 80/20 principle: The secret of achieving more with less. Crown Business.14. Lieberman, M. D. (2013). Social: Why our brains are wired to connect. Crown.15. Locke, E. A., & Latham, G. P. (2002). Building a practically useful theory of goal setting andtask motivation. American Psychologist, 57(9), 705–717. https://doi.org/10.1037/0003-066X.57.9.70516. Mark, G. (2005). Extreme multitasking at work: Implications for productivity. Communicationsof the ACM, 48(3), 60–64.17. McKinsey. (2022). The future of work: Virtual collaboration and digital productivity. McKinseyQuarterly.18. Mischel, W. (2014). The marshmallow test: Understanding self-control and how to master it.Little, Brown and Company.19. Ryan, R. M., & Deci, E. L. (2000). Intrinsic and extrinsic motivations: Classic definitions andnew directions. Contemporary Educational Psychology, 25(1), 54–67.https://doi.org/10.1006/ceps.1999.102020. Smith, J., & Jones, P. (2023). Neurocognitive aspects of self-management in the digital era.Journal of Applied Psychology, 108(2), 121–132.21. Steel, P. (2007). The nature of procrastination: A meta-analytic and theoretical review ofquintessential self-regulatory failure. Psychological Bulletin, 133(1), 65–94.https://doi.org/10.1037/0033-2909.133.1.6

    Титул

    No full text
    TitleТиту

    ЦИФРОВІЗАЦІЯ БІЗНЕС-ПРОЦЕСІВ: ВИКЛИКИ ТА МОЖЛИВОСТІ ДЛЯ ПІДПРИЄМСТВ ІКТ-ГАЛУЗІ

    Get PDF
    The article explores the impact of digitalization on the transformation of businessprocesses in enterprises operating in the information and communication technology (ICT) sector. Itidentifies key challenges faced by ICT companies in the context of the digital economy, includingrapid technological change, heightened customer expectations, and the need for operational agility.At the same time, the study highlights opportunities provided by the integration of digitaltechnologies, such as cloud computing, big data analytics, artificial intelligence, and processautomation. The research emphasizes the importance of strategic rethinking of business processmanagement in order to increase flexibility, innovation potential, and customer orientation. Thepaper substantiates that digital transformation is not merely a technological shift, but acomprehensive organizational change that affects corporate culture, decision-making, and valuecreation. Directions for optimizing business processes through the implementation of digital tools areproposed, which are crucial for enhancing the competitiveness and resilience of ICT enterprises in avolatile market environment.Keywords: digitalization, business processes, ICT enterprises, digital transformation, innovations,management. References1.Westerman, G., Bonnet, D., & McAfee, A. (2014). Leading Digital: Turning Technology intoBusiness Transformation. Boston, MA: Harvard Business Press.2.Bharadwaj, A., El Sawy, O. A., Pavlou, P. A., & Venkatraman, N. (2013). Digital BusinessStrategy: Toward a Next Generation of Insights. MIS Quarterly, 37(2), 471–482.https://doi.org/10.25300/MISQ/2013/37:2.33.Kane, G. C., Palmer, D., Phillips, A. N., Kiron, D., & Buckley, N. (2015). Strategy, NotTechnology, Drives Digital Transformation. MIT Sloan Management Review and Deloitte UniversityPress.4.Zgurska, O. M., Martynenko, M. O., & Illyushchenko, N. V. (2023). Modern trends in ecommerce development in the context of digitalization of society. Ekonomika. Menedzhment. Biznes,(1–2)41, 32–38. https://doi.org/10.31673/2415-8089.2023.1206605.Brynjolfsson, E., & McAfee, A. (2014). The Second Machine Age: Work, Progress, andProsperity in a Time of Brilliant Technologies. New York: W. W. Norton & Company.6.Semenova, I. M. (2021). Digitalization of the Economy: Challenges for Enterprises. Economicsand Organization of Management, (2), 85–91.7.Oksana Zghurska, Andrii Zakrevskyi, Bohdan Nechytailo, Olena Korchynska, OksanaHavrysh, Andriy Tarasiuk (2024). ASSESSMENT OF FINANCIAL LOSSES DUE TO THE WARIMPACT ON THE AGRICULTURE DEVELOPMENT OF UKRAINE. FINANCIAL AND CREDITACTIVITY: Problems of Theory and Practice. Volume 4 (57), 2024. 578–590. URL: DOI:https://doi.org/10.55643/fcaptp.6.59.2024.45328.Hrynko, O. I., & Kovalenko, S. Y. (2020). Barriers to Business Digital Transformation inUkraine. Scientific Notes of the National University of Ostroh Academy, (3), 30–35.9.Shevchenko, M. L. (2022). Risks and Barriers of Digitalization in the ICT Sector. EconomicStrategy and Prospects for the Development of Trade and Services, 1(33), 105–112.У статті досліджено вплив цифровізації на трансформацію бізнес-процесів підприємств,що функціонують у сфері інформаційно-комунікаційних технологій. Визначено ключовівиклики, з якими стикаються ІКТ-компанії в умовах цифрової економіки, та проаналізованоможливості, що відкриваються завдяки впровадженню цифрових технологій. Обґрунтовано необхідність стратегічного переосмислення підходів до управління бізнес-процесами зурахуванням змін у зовнішньому середовищі та підвищення вимог до гнучкості, інноваційностіта клієнтоорієнтованості. Запропоновано напрями оптимізації бізнес-процесів шляхомінтеграції цифрових інструментів, таких як хмарні обчислення, аналітика великих даних,штучний інтелект та автоматизація. Акцентовано увагу на важливості цифровоїтрансформації як чинника підвищення конкурентоспроможності підприємств ІКТ-галузі.Ключові слова: цифровізація, бізнес-процеси, ІКТ-підприємства, цифрова трансформація,інновації, управління. Список використаних джерел1.Westerman, G., Bonnet, D., & McAfee, A. (2014). Leading Digital: Turning Technology intoBusiness Transformation. Boston, MA: Harvard Business Press.2.Bharadwaj, A., El Sawy, O. A., Pavlou, P. A., & Venkatraman, N. (2013). Digital BusinessStrategy: Toward a Next Generation of Insights. MIS Quarterly, 37(2), 471–482.https://doi.org/10.25300/MISQ/2013/37:2.33.Kane, G. C., Palmer, D., Phillips, A. N., Kiron, D., & Buckley, N. (2015). Strategy, NotTechnology, Drives Digital Transformation. MIT Sloan Management Review and Deloitte UniversityPress.4.Zgurska, O. M., Martynenko, M. O., & Illyushchenko, N. V. (2023). Modern trends in ecommerce development in the context of digitalization of society. Ekonomika. Menedzhment. Biznes,(1–2)41, 32–38. https://doi.org/10.31673/2415-8089.2023.1206605.Brynjolfsson, E., & McAfee, A. (2014). The Second Machine Age: Work, Progress, andProsperity in a Time of Brilliant Technologies. New York: W. W. Norton & Company.6.Semenova, I. M. (2021). Digitalization of the Economy: Challenges for Enterprises. Economicsand Organization of Management, (2), 85–91.7.Oksana Zghurska, Andrii Zakrevskyi, Bohdan Nechytailo, Olena Korchynska, OksanaHavrysh, Andriy Tarasiuk (2024). ASSESSMENT OF FINANCIAL LOSSES DUE TO THE WARIMPACT ON THE AGRICULTURE DEVELOPMENT OF UKRAINE. FINANCIAL AND CREDITACTIVITY: Problems of Theory and Practice. Volume 4 (57), 2024. 578–590. URL: DOI:https://doi.org/10.55643/fcaptp.6.59.2024.45328.Hrynko, O. I., & Kovalenko, S. Y. (2020). Barriers to Business Digital Transformation inUkraine. Scientific Notes of the National University of Ostroh Academy, (3), 30–35.9.Shevchenko, M. L. (2022). Risks and Barriers of Digitalization in the ICT Sector. EconomicStrategy and Prospects for the Development of Trade and Services, 1(33), 105–112

    ПОКАЗНИКИ FRR І FAR ЯК КРИТЕРІЇ ОЦІНЮВАННЯ НАДІЙНОСТІ БІОМЕТРИЧНИХ МЕТОДІВ

    No full text
    In the context of growing threats to information security, in particular unauthorized access to critical objects, modernorganizations are faced with the challenge of choosing and implementing reliable solutions for personal identification. Biometrictechnologies provide a number of important advantages, including high accuracy and speed, at the same time, choosing the mostsuitable biometric solution for a specific organization or performing a certain function is not an easy task and requires a thoroughevaluation of various biometric methods.It has been established that the main criteria for evaluating biometric methods are universality, uniqueness, constancy,measurability, availability, convenience and ease of use, the probability of falsification, the cost of installing and operating thetechnology, etc. In the context of information security, an important factor in choosing a biometric solution is its reliability, themain criteria for evaluating which are the false rejection rate (FRR) and false admission rate (FAR).The study showed that the lower the value of both indicators, the higher the reliability of the biometric method: a lowFRR level indicates a more reliable and convenient biometric system, and a low FAR indicator indicates a higher level of itssecurity. At the same time, the implementation of a reliable biometric system with low FAR and FRR indicators is moreexpensive. It was found that biometric methods have significant differences in both indicators.As a result of comparing the most popular biometric methods (based on fingerprints, face and hand geometry, voice;iris) by such factors as FRR and FAR, probability of falsification, stability, sensitivity to the environment, speed of operation,simplicity and cost, it was found that the best indicators are achieved by iris identification methods, 3D face recognition andfingerprints.Keywords: biometric identification methods, biometric method evaluation criteria, false rejection rate FRR, false accessrate FAR. References1. Preferred ways to sign-in to online accounts, apps, and smart devices in selected countries in 2024. Statista.URL: https://www.statista.com/statistics/1448883/preferred-security-authentication-methods-in-selected-countries/2. Milan Adámek, Miroslav Matýsek, Petr Neumann. Security of Biometric Systems 2015. URL:https://www.sciencedirect.com/science/article/pii/S18777058150038233. Wencheng Yang, Song Wang, Jiankun Hu, Zheng Guanglou. Security and Accuracy of Fingerprint-BasedBiometrics: A Review 2019. URL: https://www.researchgate.net/publication/330711092_Security_and_Accuracy_of_Fingerprint-Based_Biometrics_A_Review4. Manal Abdullah, Majda Wazzan, Sahar Busaeed. Optimizing Face Recognition Using PCA. 2012. URL:https://www.researchgate.net/publication/225279599_Optimizing_Face_Recognition_Using_PCA5. Ziaul Haque Choudhury. Biometrics security based on face recognition. 2013. URL:https://bsaulibrary.files.wordpress.com/2017/02/2013-biometrics-security-based-on-face-recognition.pdf6. Anil K. Jain, Arun Ross, S. Pankanti. Biometrics: a tool for information security. 2006. URL:https://www.researchgate.net/publication/3455239_Biometrics_a_tool_for_information_security_IEEE_Tran_Inform_Forensics_Secur7. Reetu Awasthi, R.A.Ingolikar. A Study Of Biometrics Security System. 2013. URL:https://www.internationaljournalcorner.com/index.php/ijird_ojs/article/view/133344/925518. Mohamad El-Abed Christophe Charrier Christophe Rosenberger. Evaluation of Biometric Systems. 2012.URL: https://www.researchgate.net/publication/257365353_Evaluation_of_Biometric_Systems9. Babita Gupta. Biometrics: Enhancing Security in Organizations. IBM Center for The Business of Government.2008. URL: https://www.businessofgovernment.org/sites/default/files/GuptaReport.pdf10. Олешко І. В. Порівняльний аналіз методів автентифікації з відбитку пальця. Харків: ХНУРЕ, 2011.URL: https://openarchive.nure.ua/server/api/core/bitstreams/9f8b266f-7783-43f0-9b46-dfacc92f7ee1/content11. Олешко І. В. Моделі та методи оцінки захищеності механізмів багатофакторної автентифікації віднесанкціонованого доступу: Автореферат дисертації на здобуття наукового ступеня кандидата технічних наук.Харків : ХНУРЕ, 2014. 126 с.12. Бугаєнко Х. А., Горбенко І. Д. Аналіз трьох біометричних методів автентифікації особи: наук.-техн.журнал. Харків : ХНУРЕ, 2012. 266 с.13. Безрук В.М., Кобцева В.М. Порівняння методів біометричної автентифікації за сукупнимипоказниками якості. Харків: ХНУРЕ. URL: https://openarchive.nure.ua/server/api/core/bitstreams/af6afb36-6ddd425f-be72-c0dfdcde5efd/content14. Скорик Ю., Безрук В. Вибір переважного методу біометричної автентифікації. International ScienceJournal of Engineering & Agriculture. 2023. № 2(4). С. 28-34.15. Луцків А. М., Крутиголова О. І. Критерії вибору систем біометричної автентифікації. Тернопіль: ТНТУім. І. Пулюя, 2016. URL: https://elartu.tntu.edu.ua/bitstream/123456789/20215/2/ConfATMT_2016vII_Lutskiv_A_MSelection_criteria_of_biometric_71-72.pdf16. FAR and FRR: security level versus ease of use Recogtech. Recogtech. URL:https://recogtech.com/en/insights-en/far-and-frr-security-level-versus-ease-of-use/17. False Acceptance Rate (FAR) and False Recognition Rate (FRR) in Biometrics. Bayometric. URL:https://www.bayometric.com/false-acceptance-rate-far-false-recognition-rate-frr/18. What you need to know about FRR and FAR. Cursor Insight. URL: https://www.linkedin.com/pulse/whatyou-need-know-frr-far-cursor-insight/19. ДСТУ 2860-94 Надійність техніки. Терміни та визначення. URL:https://dbn.co.ua/load/normativy/dstu/dstu_2860_94_nadijnist_tekhniki_termini_ta_viznachennja/5-1-0-120920. Eduardo Garcia. Has COVID-19 monitoring changed how UK consumers feel about sharing biometric data?Capterra. URL: https://www.capterra.co.uk/blog/2715/covid-monitoring-and-biometric-data-uk-consumersВ умовах зростаючих загроз інформаційній безпеці, зокрема несанкціонованого доступу до критичнихоб’єктів, сучасні організації стоять перед викликом вибору і впровадження надійних рішень ідентифікаціїособистості. Біометричні технології створюють низку важливих переваг, серед яких висока точність і швидкість,водночас, вибір найбільш прийнятного біометричного рішення для конкретної організації чи виконання певноїфункції є нелегким завданням і потребує ретельного оцінювання різних методів біометрії.Встановлено, що основними критеріями оцінювання біометричних методів є універсальність,унікальність, постійність, вимірюваність, доступність, зручність і простота використання, ймовірністьфальсифікації, вартість встановлення та експлуатації технології тощо. У контексті інформаційної безпекиважливим чинником вибору біометричного рішення є його надійність, основними критеріями оцінювання якої єпоказники хибних відмов FRR і хибних допусків FAR.Дослідження показало, що чим менше значення обох показників, тим вища надійність біометричногометоду: низький рівень FRR вказує на більш надійну та зручну біометричну систему, а низький показник FAR –на вищий рівень її безпеки. Водночас, провадження надійної біометричної системи з низькими показниками FARі FRR є більш дороговартісним. З’ясовано, що біометричні методи мають суттєві відмінності за обомапоказниками.У результаті порівняння найпопулярніших біометричних методів (на основі відбитків пальців, геометріїобличчя та руки, голосу; райдужної оболонки ока) за такими факторами як FRR і FAR, ймовірність фальсифікації,стабільність, чутливість до середовища, швидкість роботи, простота і вартість встановлено, що найкращіпоказники мають методи ідентифікації за райдужною оболонкою ока, 3D розпізнавання обличчя і відбиткамипальців.Ключові слова: методи біометричної ідентифікації, критерії оцінювання біометричних методів, показникхибних відмов FRR, показник хибних доступів FAR. Перелік посилань1. Preferred ways to sign-in to online accounts, apps, and smart devices in selected countries in 2024. Statista.URL: https://www.statista.com/statistics/1448883/preferred-security-authentication-methods-in-selected-countries/2. Milan Adámek, Miroslav Matýsek, Petr Neumann. Security of Biometric Systems 2015. URL:https://www.sciencedirect.com/science/article/pii/S18777058150038233. Wencheng Yang, Song Wang, Jiankun Hu, Zheng Guanglou. Security and Accuracy of Fingerprint-BasedBiometrics: A Review 2019. URL: https://www.researchgate.net/publication/330711092_Security_and_Accuracy_of_Fingerprint-Based_Biometrics_A_Review4. Manal Abdullah, Majda Wazzan, Sahar Busaeed. Optimizing Face Recognition Using PCA. 2012. URL:https://www.researchgate.net/publication/225279599_Optimizing_Face_Recognition_Using_PCA5. Ziaul Haque Choudhury. Biometrics security based on face recognition. 2013. URL:https://bsaulibrary.files.wordpress.com/2017/02/2013-biometrics-security-based-on-face-recognition.pdf6. Anil K. Jain, Arun Ross, S. Pankanti. Biometrics: a tool for information security. 2006. URL:https://www.researchgate.net/publication/3455239_Biometrics_a_tool_for_information_security_IEEE_Tran_Inform_Forensics_Secur7. Reetu Awasthi, R.A.Ingolikar. A Study Of Biometrics Security System. 2013. URL:https://www.internationaljournalcorner.com/index.php/ijird_ojs/article/view/133344/925518. Mohamad El-Abed Christophe Charrier Christophe Rosenberger. Evaluation of Biometric Systems. 2012.URL: https://www.researchgate.net/publication/257365353_Evaluation_of_Biometric_Systems9. Babita Gupta. Biometrics: Enhancing Security in Organizations. IBM Center for The Business of Government.2008. URL: https://www.businessofgovernment.org/sites/default/files/GuptaReport.pdf10. Олешко І. В. Порівняльний аналіз методів автентифікації з відбитку пальця. Харків: ХНУРЕ, 2011.URL: https://openarchive.nure.ua/server/api/core/bitstreams/9f8b266f-7783-43f0-9b46-dfacc92f7ee1/content11. Олешко І. В. Моделі та методи оцінки захищеності механізмів багатофакторної автентифікації віднесанкціонованого доступу: Автореферат дисертації на здобуття наукового ступеня кандидата технічних наук.Харків : ХНУРЕ, 2014. 126 с.12. Бугаєнко Х. А., Горбенко І. Д. Аналіз трьох біометричних методів автентифікації особи: наук.-техн.журнал. Харків : ХНУРЕ, 2012. 266 с.13. Безрук В.М., Кобцева В.М. Порівняння методів біометричної автентифікації за сукупнимипоказниками якості. Харків: ХНУРЕ. URL: https://openarchive.nure.ua/server/api/core/bitstreams/af6afb36-6ddd425f-be72-c0dfdcde5efd/content14. Скорик Ю., Безрук В. Вибір переважного методу біометричної автентифікації. International ScienceJournal of Engineering & Agriculture. 2023. № 2(4). С. 28-34.15. Луцків А. М., Крутиголова О. І. Критерії вибору систем біометричної автентифікації. Тернопіль: ТНТУім. І. Пулюя, 2016. URL: https://elartu.tntu.edu.ua/bitstream/123456789/20215/2/ConfATMT_2016vII_Lutskiv_A_MSelection_criteria_of_biometric_71-72.pdf16. FAR and FRR: security level versus ease of use Recogtech. Recogtech. URL:https://recogtech.com/en/insights-en/far-and-frr-security-level-versus-ease-of-use/17. False Acceptance Rate (FAR) and False Recognition Rate (FRR) in Biometrics. Bayometric. URL:https://www.bayometric.com/false-acceptance-rate-far-false-recognition-rate-frr/18. What you need to know about FRR and FAR. Cursor Insight. URL: https://www.linkedin.com/pulse/whatyou-need-know-frr-far-cursor-insight/19. ДСТУ 2860-94 Надійність техніки. Терміни та визначення. URL:https://dbn.co.ua/load/normativy/dstu/dstu_2860_94_nadijnist_tekhniki_termini_ta_viznachennja/5-1-0-120920. Eduardo Garcia. Has COVID-19 monitoring changed how UK consumers feel about sharing biometric data?Capterra. URL: https://www.capterra.co.uk/blog/2715/covid-monitoring-and-biometric-data-uk-consumer

    АНАЛІЗ ТЕХНІЧНИХ ОСОБЛИВОСТЕЙ РЕАЛІЗАЦІЇ ШИФРУВАННЯ ДАНИХ НА SD-КАРТАХ В ANDROID

    No full text
    The article investigates the mechanisms of data encryption on removable media in the Android operating system. Adetailed analysis of two main approaches to information protection is carried out: file-based encryption when using an SD cardas a removable media (Portable Storage) and full-disk encryption when using a memory card as an extension of the device'sinternal memory (Adoptable Storage). The technical features of the implementation of these methods are investigated, includingthe encryption algorithms used, the structure of encrypted data, and key storage mechanisms. As a result of the study, it wasfound that for full-disk encryption, the dm-crypt kernel module is used in plain mode with the AES-256-CBC-ESSIV: SHA256cipher, and for file-based encryption, the eCryptFS kernel module is used. The locations of encryption keys are determined andthe structure of encrypted data for both methods is analyzed. It was found that when using the Adoptable Storage mode, morecomprehensive data protection is provided due to full-disk encryption, while the Portable Storage mode with per-file encryptionprovides greater flexibility in use, but may be less secure due to the ability to analyze the file system structure and file metadata.Special attention was paid in the study to the analysis of the data encryption and decryption processes in each of themodes. It was found that the Portable Storage mode uses a per-file encryption system that creates a unique encryption key (FileEncryption Key, FEK) for the file, which in turn is encrypted by the user's master key. In this case, the encrypted data is storedtogether with metadata containing information about the encryption algorithms used and other parameters. The AdoptableStorage mode uses full-disk encryption, which creates a single encryption key for the entire partition stored in the protected areaof the device's internal memory.The study also found that the implementation of encryption mechanisms may differ depending on the devicemanufacturer and the version of the Android operating system, which creates additional difficulties when analyzing data securityon removable media. In particular, differences were found in the implementation of encryption key storage mechanisms and theorganization of the structure of encrypted data in different device manufacturers.The issue of security of encryption key storage and the possibility of their compromise was considered separately. It wasfound that when using the Adoptable Storage mode, encryption keys are stored in a protected area of the device's memory,access to which is possible only with root rights. This provides an additional level of protection, but at the same time createsrisks when an attacker obtains elevated access privileges to the system.The results of the study are of practical importance for understanding the level of data security when using differentmodes of operation with removable media in the Android system and can be used to improve existing information protectionmechanisms. The data obtained can also be useful in developing recommendations for the safe use of removable media and inconducting a security audit of mobile devices.Keywords: Android, data encryption, removable media, SD card, Portable Storage, Adoptable Storage, dm-crypt,eCryptFS, information security, cryptographic protection. References1. Android Open Source Project. Traditional storage | Android Open Source Project. Android Open SourceProject. URL: https://source.android.com/docs/core/storage/traditional (date of access: 27.12.2024).2. Android Open Source Project. Adoptable storage | Android Open Source Project. Android Open SourceProject. URL: https://source.android.com/docs/core/storage/adoptable (date of access: 27.12.2024).3. What happened to Android's adopted storage option що ви можете зробити SD card як internal storage space?My S10 Plus мав upgrade до Android 12 і я не можу це зробити. Quora. URL: https://www.quora.com/What-happenedto-Android-s-adopted-storage-option-that-allowed-you-to-mount-the-SD-card-as-internal-storage-space-My-S10-Plushad-an-upgrade-to-Android-2-wh 12.2024).4. Linux Kernel Organization, Inc. WHAT IS Flash-Friendly File System (F2FS)? - The Linux Kerneldocumentation. Linux Kernel Documentation – Linux Kernel Documentation. URL: https://docs.kernel.org/filesystems/f2fs.html (date of access: 29.12.2024).5. Linux Kernel Organization, Inc. ext4 Data Structures and Algorithms – Linux Kernel documentation. LinuxKernel Documentation – Linux Kernel Documentation. URL: https://docs.kernel.org/filesystems/ext4/index.html (date ofaccess: 29.12.2024).6. Kirkland D. eCryptfs. eCryptfs. URL: https://www.ecryptfs.org/ (date of access: 29.12.2024).7. Euresys sa eCryptfs Header. Euresys Documentation. URL: https://documentation.euresys.com/Products/PICOLO_NET_HD1/PICOLO_NET_HD1/en-us/Content/encrypted-media-storage/ecryptfs-header.htm?TocPath=Resources|Encrypted%20Media%20Storage|_____2.8. Linux Kernel Organization, Inc. Натиснуті клавіші для файлу eCryptfs - The Linux Kernel documentation.Linux Kernel Archives. URL: https://www.kernel.org/doc/html/v4.17/security/keys/ecryptfs.html (date of access:29.12.2024).9. Cryptsetup/cryptsetup GitLab. GitLab. URL: https://gitlab.com/cryptsetup/cryptsetup (date of access: 29.12.2024).10. Kerrisk M. dmsetup(8) - Linux manual page. Michael Kerrisk – man7.org. URL: https://man7.org/linux/manpages/man8/dmsetup.8.html (date of access: 29.12.2024).11. POQDavid. How to decrypt and split adopted storage?. XDA Developers URL: https://xdaforums.com/t/howto-decrypt-and-split-adopted-storage.3383666/ (date of access: 29.12.2024).У статті досліджуються механізми шифрування даних на знімних носіях у операційній системі Android.Проведено детальний аналіз двох основних підходів до захисту інформації: пофайлове шифрування привикористанні SD-картки як знімного носія (Portable Storage) та повнодискове шифрування при використаннікартки пам'яті як розширення внутрішньої пам'яті пристрою (Adoptable Storage). Досліджено технічніособливості реалізації шкірних методів, включаючи використовувані алгоритми шифрування, структурузашифрованих даних та механізми зберігання ключів.В результаті дослідження встановлено, що для повнодискового шифрування використовується модульядра dm-crypt у режимі plain із шифром AES-256-CBC-ESSIV:SHA256, а для пофайлового шифруваннязастосовується модуль ядра eCryptFS. Визначено місця зберігання ключів шифрування та проаналізованоструктуру зашифрованих даних для обох методів. Виявлено, що при використанні режиму Adoptable Storageзабезпечується більш комплексний захист даних завдяки повнодисковому шифруванню, тоді як режим PortableStorage з пофайловим шифруванням надає більшу гнучкість у використанні, але може бути менш захищенимчерез можливість аналізу структури файлової системи та метаданих файлів.Особливу увагу в дослідженні приділено аналізу процесів шифрування та розшифрування даних укожному з режимів. Встановлено, що в режимі Portable Storage використовується система пофайловогошифрування, яка створює для шкірного файлу унікальний ключ шифрування (File Encryption Key, FEK), який усвою чергу шифрується головним ключем користувача. При цьому зашифровані дані зберігаються разом зметаданими, що містять інформацію про використані алгоритми шифрування та інші параметри. В режиміAdoptable Storage застосовується повнодискове шифрування, при якому створюється єдиний ключ шифруваннядля всього розділу, що зберігається у захищеній області внутрішньої пам'яті пристрою.Проведене дослідження також виявило, що реалізація механізмів шифрування може відрізнятись залежновід виробника пристрою та версії операційної системи Android, що створює додаткові складнощі при аналізібезпеки даних на знімних носіях. Зокрема, виявлено відмінності у реалізації механізмів зберігання ключівшифрування та організації структури зашифрованих даних у різних виробників пристроїв.Окремо розглянуто питання безпеки зберігання ключів шифрування та можливості їх компрометації.Встановлено, що при використанні режиму Adoptable Storage ключі шифрування зберігаються в захищенійобласті пам'яті пристрою, доступ до якої можливий лише з root-правами. Це забезпечує додатковий рівеньзахисту, але водночас створює ризики при отриманні зловмисником підвищених привілеїв доступу до системи.Результати дослідження мають практичне значення для розуміння рівня захищеності даних привикористанні різних режимів роботи зі знімними носіями в системі Android та можуть бути використані дляудосконалення існуючих механізмів захисту інформації. Отримані дані також можуть бути корисними прирозробці рекомендацій щодо безпечного використання знімних носіїв та при проведенні аудиту безпекимобільних пристроїв.Ключові слова: Android, шифрування даних, знімні носії, SD-карта, Portable Storage, Adoptable Storage,dm-crypt, eCryptFS, інформаційна безпека, криптографічний захист. Список використаних джерел1. Android Open Source Project. Traditional storage | Android Open Source Project. Android Open SourceProject. URL: https://source.android.com/docs/core/storage/traditional (date of access: 27.12.2024).2. Android Open Source Project. Adoptable storage | Android Open Source Project. Android Open SourceProject. URL: https://source.android.com/docs/core/storage/adoptable (date of access: 27.12.2024).3. What happened to Android's adopted storage option що ви можете зробити SD card як internal storage space?My S10 Plus мав upgrade до Android 12 і я не можу це зробити. Quora. URL: https://www.quora.com/What-happenedto-Android-s-adopted-storage-option-that-allowed-you-to-mount-the-SD-card-as-internal-storage-space-My-S10-Plushad-an-upgrade-to-Android-2-wh 12.2024).4. Linux Kernel Organization, Inc. WHAT IS Flash-Friendly File System (F2FS)? - The Linux Kerneldocumentation. Linux Kernel Documentation – Linux Kernel Documentation. URL: https://docs.kernel.org/filesystems/f2fs.html (date of access: 29.12.2024).5. Linux Kernel Organization, Inc. ext4 Data Structures and Algorithms – Linux Kernel documentation. LinuxKernel Documentation – Linux Kernel Documentation. URL: https://docs.kernel.org/filesystems/ext4/index.html (date ofaccess: 29.12.2024).6. Kirkland D. eCryptfs. eCryptfs. URL: https://www.ecryptfs.org/ (date of access: 29.12.2024).7. Euresys sa eCryptfs Header. Euresys Documentation. URL: https://documentation.euresys.com/Products/PICOLO_NET_HD1/PICOLO_NET_HD1/en-us/Content/encrypted-media-storage/ecryptfs-header.htm?TocPath=Resources|Encrypted%20Media%20Storage|_____2.8. Linux Kernel Organization, Inc. Натиснуті клавіші для файлу eCryptfs - The Linux Kernel documentation.Linux Kernel Archives. URL: https://www.kernel.org/doc/html/v4.17/security/keys/ecryptfs.html (date of access:29.12.2024).9. Cryptsetup/cryptsetup GitLab. GitLab. URL: https://gitlab.com/cryptsetup/cryptsetup (date of access: 29.12.2024).10. Kerrisk M. dmsetup(8) - Linux manual page. Michael Kerrisk – man7.org. URL: https://man7.org/linux/manpages/man8/dmsetup.8.html (date of access: 29.12.2024).11. POQDavid. How to decrypt and split adopted storage?. XDA Developers URL: https://xdaforums.com/t/howto-decrypt-and-split-adopted-storage.3383666/ (date of access: 29.12.2024)

    АНАЛІЗ БЕЗПЕКИ МЕРЕЖЕВИХ ПЛАГІНІВ KUBERNETES

    No full text
    This paper examines Kubernetes, which uses the Container Network Interface (CNI) standard to provide communicationbetween containers deployed on different nodes, providing a flexible and scalable approach to network configuration. The paperexamines how such flexibility, while beneficial for efficient resource utilization and simplified management, also poses certainsecurity risks. Four popular network plugins—Flannel, Calico, Weave Net, and Cilium—are analyzed, examining theirarchitecture, methods for providing communication between pods, and highlighting various risks associated with their use, suchas the ability for an attacker to move within the network if a pod is compromised. The main focus is on how different plugins implement security features. Some of them provide the ability to configure advanced network policies and encrypt traffic, whileothers rely on minimalism and ease of setup. The article emphasizes that effective traffic isolation cannot be based on defaultsettings alone, especially given the “flat” Kubernetes network model. That is why platform administrators are advised tocombine strategies of network segmentation, strict adherence to the principle of least privilege, regular plugin updates andenvironment monitoring. The article presents a number of recommendations that cover technical measures, configurationguidelines and organizational processes. These include applying network policies, enabling encryption, restricting the privilegesof CNI components and updating them in a timely manner. As the Kubernetes platform grows, the need for careful managementof network plugins increases so that their flexibility and scalability do not come at the expense of security.Keywords: Kubernetes, CNI, BGP, eBPF, pods, network policies, traffic encryption. References1. With Kubernetes, the U.S. Department of Defense is enabling DevSecOps on F-16s and battleships (2020).CNCF. https://www.cncf.io/case-studies/dod/2. CNCF SURVEY 2019 (2019). CNCF. https://www.cncf.io/wp-content/uploads/2020/08/CNCF_Survey_Report.pdf3. Minna F. et al. (2021). Understanding the Security Implications of Kubernetes Networking. IEEE Security &Privacy, 19(5), 46–54. https://balakrishnanc.github.io/papers/minna-ieeesp2021.pdf4. Budigiri G. et al. (2021). Network Policies in Kubernetes: Performance Evaluation and Security Analysis. JointEuCNC & 6G Summit. https://doi.org/10.1109/EuCNC/6GSummit51104.2021.94825265. Yevle D. (2024). Exploring eBPF and its Integration with Kubernetes. OpenSourceForU. https://www.opensourceforu.com/2024/12/exploring-ebpf-and-its-integration-with-kubernetes/6. Calico Official Documentation. https://docs.tigera.io/calico/latest/about/7. Hoffman K. (2023). Comparing Networking Solutions for Kubernetes: Cilium vs. Calico vs. Flannel. CivoBlog. https://www.civo.com/blog/calico-vs-flannel-vs-cilium8. Cilium Official Documentation. https://docs.cilium.io/en/stable/9. Flannel Official Documentation. https://github.com/flannel-io/flannel10. Weave Net Official Documentation. https://github.com/weaveworks/weave/tree/master11. Nam J. et al. (2020). BASTION: A Security Enforcement Network Stack for Container Networks. У 2020USENIX Annual Technical Conference. http://www.usenix.org/system/files/atc20-nam.pdf12. Weaveworks (2020). Weave Net 2.8.0 Release Notes (Removal of hostPID and other hardening). OpenCVE.https://app.opencve.io/cve/?vendor=weaveРобота присвячена розгляду Kubernetes, що застосовує стандарт Container Network Interface (CNI) длязабезпечення зв’язку між контейнерами, розгорнутими на різних нодах, надаючи гнучкий та масштабованийпідхід до конфігурації мережі. У статті розглядається, як така гнучкість, будучи корисною для ефективноговикористання ресурсів та спрощення керування, водночас створює також і певні ризики з точки зору безпеки.Предметом аналізу стають чотири популярні мережеві плагіни — Flannel, Calico, Weave Net та Cilium,розглядається їх архітектура, способи забезпечення зв’язку між подами та підкреслюються різноманітні ризикипід час їх використання, як от переміщення зловмисника всередині мережі у разі компроментації поди. Основнийакцент зроблено на тому, як різні плагіни реалізують засоби безпеки. Деякі з них надають можливістьконфігурування розширених мережевих політик та шифрування трафіку, в той час як інші покладаються намінімалізм та простоту налаштування. У статті наголошується, що ефективна ізоляція трафіку не можеґрунтуватися лише на налаштуваннях за замовчуванням, особливо з огляду на «плоску» мережеву модельKubernetes. Саме тому адміністраторам платформи рекомендується поєднувати стратегії сегментації мережі,суворого дотримання принципу найменших привілеїв, регулярного оновлення плагінів та моніторингусередовища. У статті представлено низку рекомендацій що охоплюють технічні заходи, настанови з конфігураціїта організаційні процеси. До них належать застосування мережевих політик, увімкнення шифрування, обмеженняпривілеїв компонентів CNI та їх своєчасне оновлення. У міру розростання платформи Kubernetes, зростає іпотреба у ретельному керуванні мережевими плагінами, щоб їх гнучкість та масштабованість не відбувалися зарахунок безпекиКлючові слова: Kubernetes, CNI, BGP, eBPF, поди, мережеві політики, шифрування трафіку Список використаних джерел1. With Kubernetes, the U.S. Department of Defense is enabling DevSecOps on F-16s and battleships (2020).CNCF. https://www.cncf.io/case-studies/dod/2. CNCF SURVEY 2019 (2019). CNCF. https://www.cncf.io/wp-content/uploads/2020/08/CNCF_Survey_Report.pdf3. Minna F. et al. (2021). Understanding the Security Implications of Kubernetes Networking. IEEE Security &Privacy, 19(5), 46–54. https://balakrishnanc.github.io/papers/minna-ieeesp2021.pdf4. Budigiri G. et al. (2021). Network Policies in Kubernetes: Performance Evaluation and Security Analysis. JointEuCNC & 6G Summit. https://doi.org/10.1109/EuCNC/6GSummit51104.2021.94825265. Yevle D. (2024). Exploring eBPF and its Integration with Kubernetes. OpenSourceForU. https://www.opensourceforu.com/2024/12/exploring-ebpf-and-its-integration-with-kubernetes/6. Calico Official Documentation. https://docs.tigera.io/calico/latest/about/7. Hoffman K. (2023). Comparing Networking Solutions for Kubernetes: Cilium vs. Calico vs. Flannel. CivoBlog. https://www.civo.com/blog/calico-vs-flannel-vs-cilium8. Cilium Official Documentation. https://docs.cilium.io/en/stable/9. Flannel Official Documentation. https://github.com/flannel-io/flannel10. Weave Net Official Documentation. https://github.com/weaveworks/weave/tree/master11. Nam J. et al. (2020). BASTION: A Security Enforcement Network Stack for Container Networks. У 2020USENIX Annual Technical Conference. http://www.usenix.org/system/files/atc20-nam.pdf12. Weaveworks (2020). Weave Net 2.8.0 Release Notes (Removal of hostPID and other hardening). OpenCVE.https://app.opencve.io/cve/?vendor=weav

    Титул

    No full text
    TitleТиту

    АНАЛІЗ МОЖЛИВОСТЕЙ ПОКРАЩЕННЯ СТАНУ БЕЗПЕКИ ХМАРНОЇ ІНФРАСТРУКТУРИ ЗА ДОПОМОГОЮ NLP ТА ML

    No full text
    As data volumes and the complexity of multi-cloud environments grow, ensuring cybersecurity of cloud infrastructureis becoming an increasingly difficult task. Traditional approaches based on static rules, signature analysis and centralized SIEMsystems show limited effectiveness when working with dynamic resources and adaptive attacks, such as ART campaigns, insiderthreats or zero-day exploits. This necessitates the implementation of intelligent analysis and response mechanisms that canquickly correlate heterogeneous events and reduce the number of false positives. The integration of natural language processing(NLP) and machine learning (ML) technologies opens up new opportunities for automating incident analytics, semantic parsingof event logs (hereinafter referred to as logs) and classifying threats by risk level. NLP modules allow processing large arraysof unstructured text data — event logs, user messages and configuration files — and identifying sociotechnical attack patterns.ML algorithms, in turn, provide anomaly detection using classification, clustering, and behavioral analytics (UEBA), whichallows you to predict potential attacks before they are implemented. Modern cybersecurity concepts, in particular the Zero Trustmodel and the Principle of Least Privilege (PoLP), combined with the Security as Code approach, create the basis for dynamicaccess control and automated rights management. Architectural solutions combining Cloud IAM, PAM, and CIEM arecomplemented by AI-driven mechanisms for real-time query context assessment and automated verification of excessiveprivileges. This helps reduce response time and increase the adaptability of security policies. This study systematically reviewedmore than ten modern scientific publications covering practical implementations of intelligent DLP systems, automated threatdetection mechanisms in AWS, Azure, and GCP, as well as approaches to integrating NLP/ML into CI/CD processes and SOARplatforms. Requirements for building adaptive, context-sensitive solutions are formulated, taking into account scalability,interpretable artificial intelligence (Explainable AI) and compliance with ethical and legal norms (GDPR, ISO/IEC 27001). Theresults of the study prove that a combined approach based on NLP and ML allows to significantly reduce the number of falsepositives, reduce the average response time to incidents and increase the accuracy of detecting complex threats. The obtainedconclusions will be useful for IT departments, security engineers and DevOps teams seeking to optimize cyber protectionprocesses in dynamic multi-cloud environments.Keywords: cybersecurity, cloud technologies, NLP, ML, Zero Trust, Security as Code, UEBA, DLP. References1. K.C. Sunkara, K. Narukulla, AI Enhanced Ontology Driven NLP for Intelligent Cloud Resource QueryProcessing Using Knowledge Graphs, Independent Research Report, IEEE Senior Members, Raleigh/San Jose, USA(2023). doi: 10.48550/arXiv.2502.18484.2. Rajendra Muppalaneni, Anil Chowdary Inaganti and Nischal Ravichandran, AI-Enhanced Data LossPrevention (DLP) Strategies for Multi-Cloud Environments, Journal of Computing Innovations and Applications, 2(2),pp. 1–13. (2024). Available at: https://ciajournal.com/index.php/jcia/article/view/9 (Accessed: 10 May 2025).3. Jaya J. Application of Deep Learning in Cloud Security. Deep Learning Approaches to Cloud Security.(2022). doi: 10.1002/9781119760542.ch124. J.S. Nimbhorkar, AI Enabled Cloud RAN Test Automation: Automatic Test Case Prediction Using NaturalLanguage Processing and Machine Learning Techniques, M.Sc. Thesis, KTH Royal Institute of Technology, EricssonAB, Stockholm (2023). URN: urn:nbn:se:kth:diva-3400905. T.K. Vashishth, V. Sharma, B. Kumar, S. Chaudhary, R. Panwar, Enhancing Cloud Security: The Role ofArtificial Intelligence and Machine Learning, In: IGI Global, Chapter 4 (2024). doi: 10.4018/979-8-3693-1431-9.ch004.6. R.K. Jha, Strengthening Smart Grid Cybersecurity: An In-Depth Investigation into the Fusion of MachineLearning and Natural Language Processing, J. Trends Comput. Sci. Smart Technol. 5(3) (2023) 284–301. doi:10.36548/jtcsst.2023.3.005.7. Y.I. Alzoubi, A. Mishra, A.E. Topcu, Research trends in deep learning and machine learning for cloudcomputing security, Artif. Intell. Rev. 57 (2024) 132. doi: 10.1007/s10462-024-10776-5.8. Martseniuk, Y., Partyka, A., Harasymchuk, O., Nyemkova, E., Karpinski, M. Shadow IT risk analysis inpublic cloud infrastructure (2024) CEUR Workshop Proceedings, 3800, pp. 22-31. URN: urn:nbn:de:0074-3800-2.9. Martseniuk, Y., Partyka, A., Harasymchuk, O., Shevchenko, S. Universal centralized secret data managementfor automated public cloud provisioning (2024) CEUR Workshop Proceedings, 3826, pp. 72-81. URN: urn:nbn:de:0074-3826-1.10. Volodymyr Khoma, Aziz Abibulaiev, Andrian Piskozub, and Taras Kret. Comprehensive Approach forDeveloping an Enterprise Cloud Infrastructure (2024) CEUR Workshop Proceedings, 3654, pp. 201-215. URN:urn:nbn:de:0074-3654-7.11. S.R. Mamidi, The Role of AI and Machine Learning in Enhancing Cloud Security, J. Artif. Intell. Gen. Sci.3(1) (2024). doi: 10.5281/zenodo.10987665.12. J. Wang, AI/ML-Powered Cybersecurity and Cloud Computing Strategies for Optimized BusinessIntelligence in ERP Cloud, ResearchGate (2023). doi: 10.13140/RG.2.2.27926.66882.13. K. Rangappa, A.K.B. Ramaswamy, M. Prasad, S.A. Kumar, A Secure Cloud Service for Managing User’sCrucial Data Using NLP, Blockchain, and Smart Contracts, Preprints.org (2024). doi: 10.20944/preprints202409.1738.v1.14. Buttar AM, Shahzad F, Jamil U. Conversational AI: Security Features, Applications, and Future Scope atCloud Platform. Conversational Artificial Intelligence, (2024). doi: 10.1002/9781394200801.ch3.15. T.-M. Georgescu, Natural Language Processing Model for Automatic Analysis of Cybersecurity-RelatedDocuments, Symmetry 12(3) (2020) 354. doi: 10.3390/sym12030354.16. Belal MM, Sundaram DM. Comprehensive review on intelligent security defences in cloud: Taxonomy,security issues, ML/DL techniques, challenges and future trends. Journal of King Saud University-Computer andInformation Sciences. (2022). doi: 10.1016/j.jksuci.2022.08.035.17. J. Wang, AI/ML-Powered Cybersecurity and Cloud Computing Strategies for Optimized BusinessIntelligence in ERP Cloud, ResearchGate (2023). doi: 10.13140/RG.2.2.27926.66882.18. Nina P, Ethan K. AI-driven threat detection: Enhancing cloud security with cutting-edge technologies.International Journal of Trend in Scientific Research and Development, Volume-4, pp.1362-1374. (2019). Available at:https://www.ijtsrd.com/papers/ijtsrd29520.pdf (Accessed 12 May 2025).19. Z. Kilhoffer and M. Bashir, Cloud Privacy Beyond Legal Compliance: An NLP Analysis of CertifiablePrivacy and Security Standards, IEEE Cloud Summit, Washington, DC, USA, pp. 79-86, (2024). doi: 10.1109/CloudSummit61220.2024.00020.20. Sunkara KC, Narukulla K. AI Enhanced Ontology Driven NLP for Intelligent Cloud Resource QueryProcessing Using Knowledge Graphs, (2025). doi: 10.48550/arXiv.2502.18484.21. Mamidi SR. The Role of AI and Machine Learning in Enhancing Cloud Security. Journal of ArtificialIntelligence General science (JAIGS), (2024). doi: 10.60087/jaigs.v3i1.161.22. D. M. Rakgoale, H. I. Kobo, Z. Z. Mapundu and T. N. Khosa, A Review of AI/ML Algorithms for SecurityEnhancement in Cloud Computing with Emphasis on Artificial Neural Networks, 4th International MultidisciplinaryInformation Technology and Engineering Conference (IMITEC), Vanderbijlpark, South Africa, pp. 329-336, (2024). doi:10.1109/IMITEC60221.2024.10851076.23. Talati, N. D. V., Scalable AI and data processing strategies for hybrid cloud environments, World Journal ofAdvanced Research and Reviews, 10(3), pp. 482–492, (2021), doi: 10.30574/wjarr.2021.10.3.0289.24. Al Saidat MR, Yerima SY, Shaalan K. Advancements of SMS Spam Detection: A Comprehensive Surveyof NLP and ML Techniques. Procedia Computer Science, (2024). doi: 10.1016/j.procs.2024.10.198.25. H. Aldawsari, S.A. Kouchay, Integrating AI and Machine Learning Algorithms in Cloud SecurityFrameworks for Enhanced Proactive Threat Detection and Mitigation, J. Eng. Technol. Manag. 74 (2024). Available at:https://ciajournal.com/index.php/jcia/article/view/9 (Accessed: 11 May 2025).26. Mohamed, N., Current trends in AI and ML for cybersecurity: A state-of-the-art survey. CogentEngineering, 10(2), (2023). doi: 10.1080/23311916.2023.2272358.Разом із зростанням обсягів даних та складності мультихмарних середовищ забезпечення кібербезпекихмарної інфраструктури стає дедалі важчим завданням. Традиційні підходи на основі статичних правил,сигнатурного аналізу та централізованих SIEM-систем виявляють обмежену ефективність при роботі здинамічними ресурсами й адаптивними атаками, такими як АРТ-кампанії, insider threat чи zero-day експлойти. Цезумовлює необхідність впровадження інтелектуальних механізмів аналізу та реагування, здатних оперативнокорелювати різнорідні події та знижувати кількість хибнопозитивних спрацювань. Інтеграція технологій обробкиприродної мови (NLP) і машинного навчання (ML) відкриває нові можливості для автоматизації аналітикиінцидентів, семантичного розбору журналів подій (далі – логів) і класифікації загроз за рівнем ризику. NLPмодулі дозволяють обробляти великі масиви неструктурованих текстових даних — журнали подій, повідомленнякористувачів та конфігураційні файли — й ідентифікувати соціотехнічні шаблони атак. ML-алгоритми, у своючергу, забезпечують виявлення аномалій із використанням класифікації, кластеризації та поведінкової аналітики(UEBA), що дозволяє прогнозувати потенційні атаки ще до їхньої реалізації. Сучасні концепції кіберзахисту,зокрема модель Zero Trust і принцип найменших привілеїв (PoLP), у поєднанні з підходом Security as Codeстворюють основу для динамічного контролю доступу та автоматизованого управління правами. Архітектурнірішення, що поєднують Cloud IAM, PAM і CIEM, доповнюються механізмами, керованими штучним інтелектом,для оцінки контексту запитів у реальному часі та автоматизованої перевірки надлишкових привілеїв. Це сприяєзменшенню часу реагування та підвищенню адаптивності політик безпеки. В рамках цього дослідженняпроведено систематичний огляд більше десяти сучасних наукових публікацій, що охоплюють практичніреалізації інтелектуальних DLP-систем, механізми автоматизованого виявлення загроз у AWS, Azure та GCP, атакож підходи до інтеграції NLP/ML у CI/CD процеси та SOAR-платформи. Сформульовано вимоги до побудовиадаптивних, контекстно-чутливих рішень із урахуванням масштабованості, інтерпретованого штучногоінтелекту (Explainable AI) та дотримання етичних і правових норм (GDPR, ISO/IEC 27001). Результатидослідження доводять, що комбінований підхід на основі NLP і ML дозволяє значно знизити кількістьхибнопозитивних спрацювань, скоротити середній час реагування на інциденти та підвищити точність виявленняскладних загроз. Отримані висновки будуть корисними для IT-відділів, інженерів із безпеки та DevOps-команд,які прагнуть оптимізувати процеси кіберзахисту в динамічних мультихмарних середовищах.Ключові слова: кібербезпека, хмарні технології, NLP, ML, Zero Trust, Security as Code, UEBA, DLP. Перелік посилань1. K.C. Sunkara, K. Narukulla, AI Enhanced Ontology Driven NLP for Intelligent Cloud Resource QueryProcessing Using Knowledge Graphs, Independent Research Report, IEEE Senior Members, Raleigh/San Jose, USA(2023). doi: 10.48550/arXiv.2502.18484.2. Rajendra Muppalaneni, Anil Chowdary Inaganti and Nischal Ravichandran, AI-Enhanced Data LossPrevention (DLP) Strategies for Multi-Cloud Environments, Journal of Computing Innovations and Applications, 2(2),pp. 1–13. (2024). Available at: https://ciajournal.com/index.php/jcia/article/view/9 (Accessed: 10 May 2025).3. Jaya J. Application of Deep Learning in Cloud Security. Deep Learning Approaches to Cloud Security.(2022). doi: 10.1002/9781119760542.ch124. J.S. Nimbhorkar, AI Enabled Cloud RAN Test Automation: Automatic Test Case Prediction Using NaturalLanguage Processing and Machine Learning Techniques, M.Sc. Thesis, KTH Royal Institute of Technology, EricssonAB, Stockholm (2023). URN: urn:nbn:se:kth:diva-3400905. T.K. Vashishth, V. Sharma, B. Kumar, S. Chaudhary, R. Panwar, Enhancing Cloud Security: The Role ofArtificial Intelligence and Machine Learning, In: IGI Global, Chapter 4 (2024). doi: 10.4018/979-8-3693-1431-9.ch004.6. R.K. Jha, Strengthening Smart Grid Cybersecurity: An In-Depth Investigation into the Fusion of MachineLearning and Natural Language Processing, J. Trends Comput. Sci. Smart Technol. 5(3) (2023) 284–301. doi:10.36548/jtcsst.2023.3.005.7. Y.I. Alzoubi, A. Mishra, A.E. Topcu, Research trends in deep learning and machine learning for cloudcomputing security, Artif. Intell. Rev. 57 (2024) 132. doi: 10.1007/s10462-024-10776-5.8. Martseniuk, Y., Partyka, A., Harasymchuk, O., Nyemkova, E., Karpinski, M. Shadow IT risk analysis inpublic cloud infrastructure (2024) CEUR Workshop Proceedings, 3800, pp. 22-31. URN: urn:nbn:de:0074-3800-2.9. Martseniuk, Y., Partyka, A., Harasymchuk, O., Shevchenko, S. Universal centralized secret data managementfor automated public cloud provisioning (2024) CEUR Workshop Proceedings, 3826, pp. 72-81. URN: urn:nbn:de:0074-3826-1.10. Volodymyr Khoma, Aziz Abibulaiev, Andrian Piskozub, and Taras Kret. Comprehensive Approach forDeveloping an Enterprise Cloud Infrastructure (2024) CEUR Workshop Proceedings, 3654, pp. 201-215. URN:urn:nbn:de:0074-3654-7.11. S.R. Mamidi, The Role of AI and Machine Learning in Enhancing Cloud Security, J. Artif. Intell. Gen. Sci.3(1) (2024). doi: 10.5281/zenodo.10987665.12. J. Wang, AI/ML-Powered Cybersecurity and Cloud Computing Strategies for Optimized BusinessIntelligence in ERP Cloud, ResearchGate (2023). doi: 10.13140/RG.2.2.27926.66882.13. K. Rangappa, A.K.B. Ramaswamy, M. Prasad, S.A. Kumar, A Secure Cloud Service for Managing User’sCrucial Data Using NLP, Blockchain, and Smart Contracts, Preprints.org (2024). doi: 10.20944/preprints202409.1738.v1.14. Buttar AM, Shahzad F, Jamil U. Conversational AI: Security Features, Applications, and Future Scope atCloud Platform. Conversational Artificial Intelligence, (2024). doi: 10.1002/9781394200801.ch3.15. T.-M. Georgescu, Natural Language Processing Model for Automatic Analysis of Cybersecurity-RelatedDocuments, Symmetry 12(3) (2020) 354. doi: 10.3390/sym12030354.16. Belal MM, Sundaram DM. Comprehensive review on intelligent security defences in cloud: Taxonomy,security issues, ML/DL techniques, challenges and future trends. Journal of King Saud University-Computer andInformation Sciences. (2022). doi: 10.1016/j.jksuci.2022.08.035.17. J. Wang, AI/ML-Powered Cybersecurity and Cloud Computing Strategies for Optimized BusinessIntelligence in ERP Cloud, ResearchGate (2023). doi: 10.13140/RG.2.2.27926.66882.18. Nina P, Ethan K. AI-driven threat detection: Enhancing cloud security with cutting-edge technologies.International Journal of Trend in Scientific Research and Development, Volume-4, pp.1362-1374. (2019). Available at:https://www.ijtsrd.com/papers/ijtsrd29520.pdf (Accessed 12 May 2025).19. Z. Kilhoffer and M. Bashir, Cloud Privacy Beyond Legal Compliance: An NLP Analysis of CertifiablePrivacy and Security Standards, IEEE Cloud Summit, Washington, DC, USA, pp. 79-86, (2024). doi: 10.1109/CloudSummit61220.2024.00020.20. Sunkara KC, Narukulla K. AI Enhanced Ontology Driven NLP for Intelligent Cloud Resource QueryProcessing Using Knowledge Graphs, (2025). doi: 10.48550/arXiv.2502.18484.21. Mamidi SR. The Role of AI and Machine Learning in Enhancing Cloud Security. Journal of ArtificialIntelligence General science (JAIGS), (2024). doi: 10.60087/jaigs.v3i1.161.22. D. M. Rakgoale, H. I. Kobo, Z. Z. Mapundu and T. N. Khosa, A Review of AI/ML Algorithms for SecurityEnhancement in Cloud Computing with Emphasis on Artificial Neural Networks, 4th International MultidisciplinaryInformation Technology and Engineering Conference (IMITEC), Vanderbijlpark, South Africa, pp. 329-336, (2024). doi:10.1109/IMITEC60221.2024.10851076.23. Talati, N. D. V., Scalable AI and data processing strategies for hybrid cloud environments, World Journal ofAdvanced Research and Reviews, 10(3), pp. 482–492, (2021), doi: 10.30574/wjarr.2021.10.3.0289.24. Al Saidat MR, Yerima SY, Shaalan K. Advancements of SMS Spam Detection: A Comprehensive Surveyof NLP and ML Techniques. Procedia Computer Science, (2024). doi: 10.1016/j.procs.2024.10.198.25. H. Aldawsari, S.A. Kouchay, Integrating AI and Machine Learning Algorithms in Cloud SecurityFrameworks for Enhanced Proactive Threat Detection and Mitigation, J. Eng. Technol. Manag. 74 (2024). Available at:https://ciajournal.com/index.php/jcia/article/view/9 (Accessed: 11 May 2025).26. Mohamed, N., Current trends in AI and ML for cybersecurity: A state-of-the-art survey. CogentEngineering, 10(2), (2023). doi: 10.1080/23311916.2023.2272358

    АВТЕНТИФІКАЦІЯ КОРИСТУВАЧА В ІНФОРМАЦІЙНИХ СИСТЕМАХ НА ОСНОВІ БІОМЕТРИЧНИХ СИГНАЛІВ МОБІЛЬНИХ ПРИСТРОЇВ

    No full text
    The use of physiological biometric signals obtained using mobile devices to improve the efficiency and reliability ofauthentication in information systems has been investigated. It has been established that dynamic parameters – heart rate (HR),heart rate variability (HRV), blood oxygen saturation (SpO₂), skin temperature and respiratory rate – are capable of forming anindividual biometric user profile that can be used for continuous authentication. The results of biometric authentication usingmobile devices have been compared with classical methods based on fingerprints and face recognition, and their advantageshave been identified: dynamism, adaptability and increased resistance to spoofing attacks. A method for constructing a biometricuser matrix with periodic updates every 5 minutes has been proposed, which demonstrates stable authentication results andconfirms the feasibility of using such an approach even without the use of complex machine learning models. The impact ofchanges in the user's physiological state (stress, physical activity, recovery period) on the stability of the authentication processis analyzed, and the effectiveness of approaches that combine several types of biometric data to increase the reliability ofrecognition is also investigated. Promising directions for integrating mobile devices with machine learning, blockchain, andquantum-resistant encryption technologies are identified in order to create secure, adaptive, and energy-efficient identificationsystems. It is shown that physiological signals of mobile devices are a key element of future continuous authentication systemsin information security.Keywords: physiological biometric signals, mobile devices, authentication, blockchain, continuous authentication,information security, information protection, user identification. References1. Manta, C., Jain, S. S., Coravos, A., Mendelsohn, D., & Izmailova, E. S. (2020). An Evaluation of BiometricMonitoring Technologies for Vital Signs in the Era of COVID-19 // Clinical and Translational Science, 13(6), 1034–1044. https://doi.org/10.1111/cts.12874.2. Sun, W., Guo, Z., Yang, Z., Wu, Y., Lan, W., Liao, Y., Wu, X., & Liu, Y. (2022). A Review of RecentAdvances in Vital Signals Monitoring of Sports and Health via Flexible Wearable Sensors // Sensors, 22(20), 7784.https://doi.org/10.3390/s22207784.3. Chhibbar, L. D., Patni, S., Todi, S., Bhatia, A., & Tiwari, K. (2024). Enhancing security through continuousbiometric authentication using wearable sensors // Internet of Things, 28, 101374. https://doi.org/10.1016/j.iot.2024.101374.4. Shao, W., Liang, Z., Zhang, R., Fang, R., Miao, N., Kourkchi, E., Rafatirad, S., Homayoun, H., & Fang, C.(2025). Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPG// arXiv preprint arXiv:2508.13690. https://doi.org/10.48550/arXiv.2508.13690.5. Журавель Ю.І., Лісовський Б.В. (2025). Аналіз моделей та алгоритмів автентифікації на основібіометричних даних. Сучасний захист інформації, №2(62), 51–58. https://doi.org/10.31673/2409-7292.2025.0227016. O’Grady, B., Lambe, R., Baldwin, M., Acheson, T., & Doherty, C. (2024). The Validity of Apple WatchSeries 9 and Ultra 2 for Serial Measurements of Heart Rate Variability and Resting Heart Rate // Sensors, 24(19), 6220.https://doi.org/10.3390/s24196220.7. Bonneval, L., Wing, D., Sharp, S., Parra, M. T., Moran, R., LaCroix, A., & Godino, J. (2025). Validity ofHeart Rate Variability Measured with Apple Watch Series 6 Compared to Laboratory Measures // Sensors, 25(8), 2380.https://doi.org/10.3390/s25082380.8. Windisch, P., Schröder, C., Förster, R., Cihoric, N., & Zwahlen, D. R. (2023). Accuracy of the Apple WatchOxygen Saturation Measurement in Adults: A Systematic Review // Cureus, 15(2), e35355. https://doi.org/10.7759/cureus.35355.9. Browne, S. H., Bernstein, M., & Bickler, P. E. (2025). Evaluation of Pulse Oximetry Accuracy in aCommercial Smartphone and Smartwatch Device During Human Hypoxia Laboratory Testing // Sensors, 25(5), 1286.https://doi.org/10.3390/s25051286.10. Alzueta, E., Gombert-Labedens, M., Javitz, H., Yuksel, D., Perez-Amparan, E., Camacho, L., Kiss, O.,Zambotti, M., Sattari, N., Alejandro-Pena, A., Zhang, J., Shuster, A., Morehouse, A., Simon, K., Mednick, S., & Baker,F. C. (2024). Menstrual Cycle Variations in Wearable-detected Finger Temperature and Heart Rate, but not in SleepMetrics, in Young and Midlife Individuals // Journal of Biological Rhythms, 39(5), 395–412. https://doi.org/10.1177/07487304241265018.11. Muratyan, A., Cheung, W., Dibbo, S. V., & Vhaduri, S. (2021). Opportunistic Multi-Modal UserAuthentication for Health-Tracking IoT Wearables // arXiv preprint arXiv:2109.13705. https://doi.org/10.48550/arXiv.2109.13705.12. Sancho, J., Alesanco, Á., & García, J. (2018). Biometric Authentication Using the PPG: A Long-TermFeasibility Study // Sensors, 18(5), 1525. https://doi.org/10.3390/s18051525.13. Davoodi, M., Soker, A., Behar, J., & Yaniv, Y. (2023). Using Beat-to-Beat Heart Signals for AgeIndependent Biometric Verification // Scientific Reports, 13(1). https://doi.org/10.1038/s41598-023-42841-4.14. Ashtiyani, M., Iavasani, S. N., Alvar, A. A., & Deevband, M. R. (2018). Heart Rate Variability ClassificationUsing Support Vector Machine and Genetic Algorithm // Journal of Biomedical Physics and Engineering, 8(4).https://doi.org/10.31661/jbpe.v0i0.614.15. Wittenberg, T., Koch, R., Pfeiffer, N., & Eskofier, B. (2020). Evaluation of HRV Estimation Algorithmsfrom PPG Data Using Neural Networks // Current Directions in Biomedical Engineering, 6(3), 505–509. https://doi.org/10.1515/cdbme-2020-3130.16. Ding, J., Liu, Q., Ling, B. W.-K., & Li, W. (2026). Heart Rate Estimation Based on Joint ConvolutionalNeural Network and Conditional Generative Adversarial Network via Heart Rate Variabilities and Other FeaturesExtracted from Photoplethysmograms // Biomedical Signal Processing and Control, 112(C), 108831. https://doi.org/10.1016/j.bspc.2025.108831.17. Ólafsdóttir G. B., Larsson J. Deep Learning Approach for Extracting Heart Rate Variability from aPhotoplethysmographic Signal // Bachelor Thesis, Kristianstad University, Sweden. 2020. Режим доступу: https://researchportal.hkr.se/ws/portalfiles/portal/35216086/FULLTEXT01.pdf.Досліджено використання фізіологічних біометричних сигналів, отриманих за допомогою мобільнихпристроїв, для підвищення ефективності та надійності автентифікації в інформаційних системах. Встановлено,що динамічні параметри – частота серцевих скорочень (HR), варіабельність серцевого ритму (HRV), насиченістькрові киснем (SpO₂), температура шкіри та частота дихання – здатні формувати індивідуальний біометричнийпрофіль користувача, який можна застосовувати для безперервної автентифікації. Проведено порівняннярезультатів біометричної автентифікації за допомогою мобільних пристроїв з класичними методами, щобазуються на відбитках пальців та розпізнаванні обличчя, визначено їх переваги: динамічність, адаптивність іпідвищена стійкість до атак типу спуфінг. Запропоновано методику побудови біометричної матриці користувачаз періодичним оновленням кожні 5 хвилин, яка демонструє стабільні результати автентифікації та підтверджуєдоцільність застосування такого підходу навіть без використання складних моделей машинного навчання.Проаналізовано вплив змін фізіологічного стану користувача (стрес, фізичне навантаження, період відновлення)на стабільність процесу автентифікації, а також досліджено ефективність підходів, що поєднують кілька типівбіометричних даних для підвищення надійності розпізнавання. Визначено перспективні напрями інтеграціїмобільних пристроїв з технологіями машинного навчання, блокчейну та квантово-стійкого шифрування з метоюстворення безпечних, адаптивних і енергоефективних систем ідентифікації. Показано, що фізіологічні сигналимобільних пристроїв є ключовим елементом майбутніх систем безперервної автентифікації в інформаційнійбезпеці.Ключові слова: фізіологічні біометричні сигнали, мобільні пристрої, автентифікація, блокчейн,безперервна автентифікація, інформаційна безпека, захист інформації, ідентифікація користувача. Перелік посилань1. Manta, C., Jain, S. S., Coravos, A., Mendelsohn, D., & Izmailova, E. S. (2020). An Evaluation of BiometricMonitoring Technologies for Vital Signs in the Era of COVID-19 // Clinical and Translational Science, 13(6), 1034–1044. https://doi.org/10.1111/cts.12874.2. Sun, W., Guo, Z., Yang, Z., Wu, Y., Lan, W., Liao, Y., Wu, X., & Liu, Y. (2022). A Review of RecentAdvances in Vital Signals Monitoring of Sports and Health via Flexible Wearable Sensors // Sensors, 22(20), 7784.https://doi.org/10.3390/s22207784.3. Chhibbar, L. D., Patni, S., Todi, S., Bhatia, A., & Tiwari, K. (2024). Enhancing security through continuousbiometric authentication using wearable sensors // Internet of Things, 28, 101374. https://doi.org/10.1016/j.iot.2024.101374.4. Shao, W., Liang, Z., Zhang, R., Fang, R., Miao, N., Kourkchi, E., Rafatirad, S., Homayoun, H., & Fang, C.(2025). Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPG// arXiv preprint arXiv:2508.13690. https://doi.org/10.48550/arXiv.2508.13690.5. Журавель Ю.І., Лісовський Б.В. (2025). Аналіз моделей та алгоритмів автентифікації на основібіометричних даних. Сучасний захист інформації, №2(62), 51–58. https://doi.org/10.31673/2409-7292.2025.0227016. O’Grady, B., Lambe, R., Baldwin, M., Acheson, T., & Doherty, C. (2024). The Validity of Apple WatchSeries 9 and Ultra 2 for Serial Measurements of Heart Rate Variability and Resting Heart Rate // Sensors, 24(19), 6220.https://doi.org/10.3390/s24196220.7. Bonneval, L., Wing, D., Sharp, S., Parra, M. T., Moran, R., LaCroix, A., & Godino, J. (2025). Validity ofHeart Rate Variability Measured with Apple Watch Series 6 Compared to Laboratory Measures // Sensors, 25(8), 2380.https://doi.org/10.3390/s25082380.8. Windisch, P., Schröder, C., Förster, R., Cihoric, N., & Zwahlen, D. R. (2023). Accuracy of the Apple WatchOxygen Saturation Measurement in Adults: A Systematic Review // Cureus, 15(2), e35355. https://doi.org/10.7759/cureus.35355.9. Browne, S. H., Bernstein, M., & Bickler, P. E. (2025). Evaluation of Pulse Oximetry Accuracy in aCommercial Smartphone and Smartwatch Device During Human Hypoxia Laboratory Testing // Sensors, 25(5), 1286.https://doi.org/10.3390/s25051286.10. Alzueta, E., Gombert-Labedens, M., Javitz, H., Yuksel, D., Perez-Amparan, E., Camacho, L., Kiss, O.,Zambotti, M., Sattari, N., Alejandro-Pena, A., Zhang, J., Shuster, A., Morehouse, A., Simon, K., Mednick, S., & Baker,F. C. (2024). Menstrual Cycle Variations in Wearable-detected Finger Temperature and Heart Rate, but not in SleepMetrics, in Young and Midlife Individuals // Journal of Biological Rhythms, 39(5), 395–412. https://doi.org/10.1177/07487304241265018.11. Muratyan, A., Cheung, W., Dibbo, S. V., & Vhaduri, S. (2021). Opportunistic Multi-Modal UserAuthentication for Health-Tracking IoT Wearables // arXiv preprint arXiv:2109.13705. https://doi.org/10.48550/arXiv.2109.13705.12. Sancho, J., Alesanco, Á., & García, J. (2018). Biometric Authentication Using the PPG: A Long-TermFeasibility Study // Sensors, 18(5), 1525. https://doi.org/10.3390/s18051525.13. Davoodi, M., Soker, A., Behar, J., & Yaniv, Y. (2023). Using Beat-to-Beat Heart Signals for AgeIndependent Biometric Verification // Scientific Reports, 13(1). https://doi.org/10.1038/s41598-023-42841-4.14. Ashtiyani, M., Iavasani, S. N., Alvar, A. A., & Deevband, M. R. (2018). Heart Rate Variability ClassificationUsing Support Vector Machine and Genetic Algorithm // Journal of Biomedical Physics and Engineering, 8(4).https://doi.org/10.31661/jbpe.v0i0.614.15. Wittenberg, T., Koch, R., Pfeiffer, N., & Eskofier, B. (2020). Evaluation of HRV Estimation Algorithmsfrom PPG Data Using Neural Networks // Current Directions in Biomedical Engineering, 6(3), 505–509. https://doi.org/10.1515/cdbme-2020-3130.16. Ding, J., Liu, Q., Ling, B. W.-K., & Li, W. (2026). Heart Rate Estimation Based on Joint ConvolutionalNeural Network and Conditional Generative Adversarial Network via Heart Rate Variabilities and Other FeaturesExtracted from Photoplethysmograms // Biomedical Signal Processing and Control, 112(C), 108831. https://doi.org/10.1016/j.bspc.2025.108831.17. Ólafsdóttir G. B., Larsson J. Deep Learning Approach for Extracting Heart Rate Variability from aPhotoplethysmographic Signal // Bachelor Thesis, Kristianstad University, Sweden. 2020. Режим доступу: https://researchportal.hkr.se/ws/portalfiles/portal/35216086/FULLTEXT01.pdf

    РОЗРОБКА МЕТОДІВ АВТЕНТИФІКАЦІЇ НА ОСНОВІ МОДИФІКОВАНИХ ТЕОРЕТИКО-КОДОВИХ СХЕМ

    No full text
    Development of authentication methods is a key element of modern cryptographic systems used to ensure datatransmission security, digital signatures and protection of confidential information. One of the most common approaches is theuse of traditional RSA and ECC algorithms standardized in NIST recommendations[1,2]. These algorithms are characterizedby high cryptographic stability in classical computing environments and flexibility due to support for various mathematicalstructures, which makes them in demand in government and commercial information protection systems. The analysis showedthat, despite a number of advantages, RSA and ECC have significant disadvantages. Among them are vulnerability to quantumattacks, in particular Shor`s algorithm, increased computational costs for large key data and critical dependence on the qualityof random data. The most significant problem is the lack of resistance to quantum computing, which complicates the assessmentof their characteristics and reduces the predictability of work in critical cryptographic applications. To eliminate the identifiedlimitations, two variants of authentication methods based on modified McEliece and Niederreiter code-theoretic schemes areproposed. Algebrogeometric codes are included in their structure, which allows us to formally determine the minimum cyclelength of the sequence and ensure its guaranteed period. Additional algorithmic procedures complicate the analysis of theinternal states of the methods, increasing their cryptoresistance. The article presents structural diagrams of the proposedmethods, describes the stages of their functioning and key analytical dependencies that determine the process of formingauthentication data. The developed approaches preserve the cryptographic stability of traditional schemes, while ensuring postquantum security and improved capabilities for managing authentication parameters. The results obtained can be used in thecreation of software and hardware means of information protection and cryptographic protocols that require high reliability andpredictability of authentication systems.Keywords: authentication methods, McAlice code-theoretic schemes, Niederreitercode-theoretic schemes, informationprotection, cybersecurity, threats References1. National Institute of Standards and Technology. NIST Special Publication. https://doi.org/10.6028/NIST.SP.800-56Ar3.2. National Institute of Standards and Technology. NIST Special Publication. .https://doi.org/10.6028/NIST.SP.800-56Br2 .3. Dustin Moody Post-Quantum Cryptography: NIST’s Plan for the PQCrypto 2016 conference. Post-QuantumCryptography 7th International Workshop, PQCrypto 2016 Fukuoka, Japan, February 24–26, 2016: https://csrc.nist.gov/csrc/media/projects/post-quantum-cryptography/documents/pqcrypto-2016-presentation.pdf.4. Shor, Peter W. “Algorithms for quantum computation: discrete logarithms and factoring.” In Proceedings 35thannual symposium on foundations of computer science, pp. 124-134. Ieee, 1994.5. McEliece R. J. A public-key cryptosystem based on algebraic coding theory. DSN Progress Report 42-44, JetPro-pulsion Lab., Pasadena, CA, January-February, 1978. P. 114-116.6. Niederreiter, H. Knapsack-type cryp-tosystems and algebraic coding theory // Problem Control and InformTheory, 1986, v. 15. P. 19-34.7. S. Yevseiev, O. Korol, and other, “Development of mceliece modified asymmetric crypto-code system onelliptic truncated codes”, Eastern-European Journal of Enterprise Technologies, 4, 9(82), р. 18 – 26, 20168. National Institute of Standards and Technology. NIST IR 8413 https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413.pdf.9. Alexander Meyer Post-Quantum Cryptography: An Analysis of Code-Based and Lattice-Based Cryptosystemshttps://doi.org/10.48550/arXiv.2505.0879.10. National Institute of Standards and Technology.NIST IR 8545: Status Report on the Fourth Round of the NISTPost-Quantum Cryptography Standardization https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf.11. Dariusz Rzońca, Andrzej Stec, Bartosz Trybus Secure web access to mini distributed control system:Niewielkie rozproszone systemy sterowania ze zdalnym dostępem przez sieć January 2012, Automatyka/Automatics,16(2) p. 155-164].12. Lukova-Chuiko, N., Herasymenko, O., Toliupa, S., ...Laptievа, T., Laptiev, O. The method detection of radiosignals by estimating the parameters signals of eversible Gaussian propagation 2021 IEEE 3rd International Conferenceon Advanced Trends in Information Theory, ATIT 2021 – Proceedings. 2021. Р. 67–70.13. Serhii Yevseiev & Yuliia Khokhlachova & Serhii Ostapov & Oleksandr Laptiev et al, 2023. "Models of sociocyber-physical systems security," Monographs, PC TECHNOLOGY CENTER, number 978-617-7319-72-5.redif,December. DOI: https://doi.org/10.15587/978-617-7319-72-5.14. Oleksandr Laptiev, Volodymyr Tkachev, Oleksii Maystrov, Oleksandr Krasikov, Pavlo Open’ko, VolodimirKhoroshko, Lubomir Parkhuts. The method of spectral analysis of the determination of random digital signals.International Journal of Communication Networks and Information Security (IJCNIS). 2021.Vol 13, No 2, August Р.271-277. . DOI : https://doi.org/10.54039/ijcnis.v13i2.5008.15. Roman Kyrychok, Oleksandr Laptiev, Rostyslav Lisnevsky, Valeri Kozlovsky, Vitaliy Klobukov.Development of a method for checking vulnerabilities of a corporate network using bernstein transformations. EasternEuropean journal of enterprise technologies. Vol.1№9 (115), 2022 Р. 93–101. DOI: https://doi.org/10.15587/1729-4061.2022.253530.16. Oleksandr Laptiev, Andrii Musienko, Volodymyr Nakonechnyi, Andrii Sobchuk, Sergii Gakhov, SerhiiKopytko. Algorithm for Recognition of Network Traffic Anomalies Based on Artificial Intelligence.5th InternationalCongress on Human-Computer Interaction, Optimization and Robotic Applications (HORA) 08-10 June 202317. DOI: https://doi.org/10.1109/HORA58378.2023.10156702.Розробка методів автентифікації є ключовим елементом сучасних криптографічних систем, щозастосовуються для забезпечення безпеки передачі даних, цифрових підписів та захисту конфіденційноїінформації. Одним з найбільш поширених підходів є використання традиційних алгоритмів RSA та ECC,стандартизованих у рекомендаціях NIST [1, 2]. Дані алгоритми відрізняються високою криптографічноюстійкістю у класичних обчислювальних середовищах та гнучкістю завдяки підтримці різних математичнихструктур, що робить їх затребуваними в державних та комерційних системах захисту інформації. Проведенийаналіз показав, що, незважаючи на низку переваг, RSA та ECC мають суттєві недоліки. Серед них – уразливістьдо квантових атак, зокрема алгоритму Шора, підвищені обчислювальні витрати для великих ключових даних такритична залежність від якості випадкових даних. Найбільш значима проблема полягає в відсутності стійкостідо квантових обчислень, що ускладнює оцінку їх характеристик та знижує передбачуваність роботи в критичнихкриптографічних додатках. Для усунення виявлених обмежень запропоновано два варіанти методівавтентифікації на основі модифікованих теоретко-кодових схем McEliece та Niederreiter. У їх структуру включеноалгеброгеометричні коди, що дозволяє формально визначити мінімальну довжину циклу послідовності тазабезпечити її гарантований період. Додаткові алгоритмічні процедури ускладнюють аналіз внутрішніх станівметодів, підвищуючи їх криптостійкість. У статті представлено структурні схеми запропонованих методів,описано етапи їх функціонування та ключові аналітичні залежності, що визначають процес формуванняавтентифікаційних даних. Розроблені підходи зберігають криптографічну стійкість традиційних схем,забезпечуючи при цьому постквантову безпеку та покращені можливості управління параметрамиавтентифікації. Отримані результати можуть бути використані при створенні програмно-апаратних засобівзахисту інформації та криптографічних протоколів, що вимагають високої надійності та передбачуваності роботисистем автентифікації.Ключові слова: методи автентифікації, теоретико-кодові схеми Мак-Еліса, теоретико-кодові схемиНідерайтера, захист інформації, кібербезпека, загрози. Перелік посилань1. National Institute of Standards and Technology. NIST Special Publication. https://doi.org/10.6028/NIST.SP.800-56Ar3.2. National Institute of Standards and Technology. NIST Special Publication. .https://doi.org/10.6028/NIST.SP.800-56Br2 .3. Dustin Moody Post-Quantum Cryptography: NIST’s Plan for the PQCrypto 2016 conference. Post-QuantumCryptography 7th International Workshop, PQCrypto 2016 Fukuoka, Japan, February 24–26, 2016: https://csrc.nist.gov/csrc/media/projects/post-quantum-cryptography/documents/pqcrypto-2016-presentation.pdf.4. Shor, Peter W. “Algorithms for quantum computation: discrete logarithms and factoring.” In Proceedings 35thannual symposium on foundations of computer science, pp. 124-134. Ieee, 1994.5. McEliece R. J. A public-key cryptosystem based on algebraic coding theory. DSN Progress Report 42-44, JetPro-pulsion Lab., Pasadena, CA, January-February, 1978. P. 114-116.6. Niederreiter, H. Knapsack-type cryp-tosystems and algebraic coding theory // Problem Control and InformTheory, 1986, v. 15. P. 19-34.7. S. Yevseiev, O. Korol, and other, “Development of mceliece modified asymmetric crypto-code system onelliptic truncated codes”, Eastern-European Journal of Enterprise Technologies, 4, 9(82), р. 18 – 26, 20168. National Institute of Standards and Technology. NIST IR 8413 https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413.pdf.9. Alexander Meyer Post-Quantum Cryptography: An Analysis of Code-Based and Lattice-Based Cryptosystemshttps://doi.org/10.48550/arXiv.2505.0879.10. National Institute of Standards and Technology.NIST IR 8545: Status Report on the Fourth Round of the NISTPost-Quantum Cryptography Standardization https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf.11. Dariusz Rzońca, Andrzej Stec, Bartosz Trybus Secure web access to mini distributed control system:Niewielkie rozproszone systemy sterowania ze zdalnym dostępem przez sieć January 2012, Automatyka/Automatics,16(2) p. 155-164].12. Lukova-Chuiko, N., Herasymenko, O., Toliupa, S., ...Laptievа, T., Laptiev, O. The method detection of radiosignals by estimating the parameters signals of eversible Gaussian propagation 2021 IEEE 3rd International Conferenceon Advanced Trends in Information Theory, ATIT 2021 – Proceedings. 2021. Р. 67–70.13. Serhii Yevseiev & Yuliia Khokhlachova & Serhii Ostapov & Oleksandr Laptiev et al, 2023. "Models of sociocyber-physical systems security," Monographs, PC TECHNOLOGY CENTER, number 978-617-7319-72-5.redif,December. DOI: https://doi.org/10.15587/978-617-7319-72-5.14. Oleksandr Laptiev, Volodymyr Tkachev, Oleksii Maystrov, Oleksandr Krasikov, Pavlo Open’ko, VolodimirKhoroshko, Lubomir Parkhuts. The method of spectral analysis of the determination of random digital signals.International Journal of Communication Networks and Information Security (IJCNIS). 2021.Vol 13, No 2, August Р.271-277. . DOI : https://doi.org/10.54039/ijcnis.v13i2.5008.15. Roman Kyrychok, Oleksandr Laptiev, Rostyslav Lisnevsky, Valeri Kozlovsky, Vitaliy Klobukov.Development of a method for checking vulnerabilities of a corporate network using bernstein transformations. EasternEuropean journal of enterprise technologies. Vol.1№9 (115), 2022 Р. 93–101. DOI: https://doi.org/10.15587/1729-4061.2022.253530.16. Oleksandr Laptiev, Andrii Musienko, Volodymyr Nakonechnyi, Andrii Sobchuk, Sergii Gakhov, SerhiiKopytko. Algorithm for Recognition of Network Traffic Anomalies Based on Artificial Intelligence.5th InternationalCongress on Human-Computer Interaction, Optimization and Robotic Applications (HORA) 08-10 June 202317. DOI: https://doi.org/10.1109/HORA58378.2023.10156702

    1,003

    full texts

    2,308

    metadata records
    Updated in last 30 days.
    State University of Telecommunications Open Journals System
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇