<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">vdgtu</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Дагестанского государственного технического университета. Технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of Dagestan State Technical University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2073-6185</issn><issn pub-type="epub">2542-095X</issn><publisher><publisher-name>Daghestan State Technical University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21822/2073-6185-2026-53-2-153-161</article-id><article-id custom-type="elpub" pub-id-type="custom">vdgtu-2102</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ И ТЕЛЕКОММУНИКАЦИИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION TECHNOLOGY AND TELECOMMUNICATIONS</subject></subj-group></article-categories><title-group><article-title>Иерархическая система управления криптографическими ключами для защиты биометрических персональных данных в информационных системах аэропортов</article-title><trans-title-group xml:lang="en"><trans-title>Hierarchical cryptographic key management system for biometric personal data protection in airport information systems</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Шевчук</surname><given-names>П. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Shevchuk</surname><given-names>P. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Петр Сергеевич Шевчук, доктор технических наук, профессор кафедры информационной безопасно-сти в вычислительных системах и сетях</p><p>344002, г. Ростов-на-Дону, пл. Гагарина, 1</p><p>344038, г. Ростов-на-Дону, площадь Ростовского Стрелкового Полка Народного Ополчения, зд. 2</p></bio><bio xml:lang="en"><p>Petr S. Shevchuk, Dr. Sci. (Eng.), Prof., Department of Information Security in Computing Systems and Networks</p><p>Gagarina Square, Rostov-on-Don, 344002</p><p>22 Rostovskogo Strelkovogo Polka Narodnogo Opolcheniya Sq., Rostov-on-Don 344038</p></bio><email xlink:type="simple">andstyle@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-9455-4079</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Айдинян</surname><given-names>А. Р.</given-names></name><name name-style="western" xml:lang="en"><surname>Aydinyan</surname><given-names>A. R.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Айдинян Андрей Размикович, кандидат технических наук, доцент, доцент, кафедра информационной безопасности в вычислительных системах и сетях</p><p>344002, г. Ростов-на-Дону, пл. Гагарина, 1</p></bio><bio xml:lang="en"><p>Andrey R. Aidinyan, Cand. Sci. (Eng.), Assoc. Prof., Assoc. Prof., Department of Computing Systems and Information Security</p><p>Gagarina Square, Rostov-on-Don, 344002</p></bio><email xlink:type="simple">79081891239@yandex.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Донской государственный технический университет; Ростовский государственный университет путей сообщения</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Don State Technical University; Rostov State Transport University</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Донской государственный технический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Don State Technical University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>10</day><month>08</month><year>2026</year></pub-date><volume>53</volume><issue>2</issue><fpage>153</fpage><lpage>161</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Шевчук П.С., Айдинян А.Р., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Шевчук П.С., Айдинян А.Р.</copyright-holder><copyright-holder xml:lang="en">Shevchuk P.S., Aydinyan A.R.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.dgtu.ru/jour/article/view/2102">https://vestnik.dgtu.ru/jour/article/view/2102</self-uri><abstract><p>Цель. Статья посвящена актуальной проблеме обеспечения безопасности биометрических персональных данных, обрабатываемых в информационных системах аэропортов. Цель исследования заключается в разработке иерархической системы управления криптографическими ключами, способной обеспечить криптографическую гибкость (crypto agility), эффективную ротацию ключей и необратимое шифрование биометрических данных в соответствии с требованиями Федерального закона № 152-ФЗ «О персональных данных» и нормативными актами ФСТЭК России.Метод. Методологической основой исследования послужили действующие стандарты в области защиты информации (ГОСТ Р ИСО/МЭК 27001-2021) и методика ФСТЭК России по определению актуальных угроз. Разработка архитектуры базируется на трёхуровневой иерархии ключей (Root Key, KEK, DEK) с разделением ключей по категориям данных. Программная реализация модуля шифрования выполнена на языке Python с использованием криптографической библиотеки PyCryptodome, реализующей алгоритм AES-256-GCM, обеспечивающий конфиденциальность, целостность и аутентичность данных.Результат. Разработана и протестирована трёхуровневая система управления ключами, минимизирующая масштаб ущерба при компрометации за счёт использования уникальных ключей DEK для каждого пассажира. Тестирование производительности показало высокую скорость обработки данных: шифрование 1 МБ биометрической информации выполняется за 6,88 мс, что позволяет системе обрабатывать до 100 регистраций в секунду на одном сервере. Предложенная архитектура обеспечивает возможность ротации ключей без перешифрования всего массива данных.Вывод. Разработанная иерархическая система управления криптографическими ключами полностью соответствует требованиям российского законодательства в области персональных данных и демонстрирует высокую производительность, пригодную для эксплуатации в условиях высоконагруженных систем аэропортов. Направлениями дальнейших исследований являются интеграция с сертифицированными аппаратными модулями безопасности (HSM) российского производства, внедрение постквантовых криптографических алгоритмов и применение технологии распределённых реестров для обеспечения неизменяемости журналов аудита.</p></abstract><trans-abstract xml:lang="en"><p>Objective. The article is devoted to the urgent problem of ensuring the security of biometric personal data processed in airport information systems. The purpose of the research is to develop a hierarchical cryptographic key management system capable of providing cryptographic flexibility, effective key rotation, and irreversible encryption of biometric data in accordance with the requirements of Federal Law No. 152-FZ "On Personal Data" and the regulations of the FSTEC of Russia.Method. The methodological basis of the study was the current standards in the field of information security (GOST R ISO/IEC 27001-2021) and the FSTEC methodology for identifying current threats. Architecture development is based on a three-level hierarchy of keys (Root Key, KEK, DEK) with keys divided into data categories. The software implementation of the encryption module is made in Python using the PyCryptodome cryptographic library, which implements the AES-256-GCM algorithm, which ensures confidentiality, integrity and authenticity of data.Result. During the study, a three-level key management system was developed and tested, which minimizes the scale of damage caused by compromise by using unique DEK keys for each passenger. Performance testing showed high data processing speed: encryption of 1 MB of biometric information is performed in 6.88 ms, which allows the system to process up to 100 registrations per second on a single server. The proposed architecture provides the ability to rotate keys without reencrypting the entire data array.Conclusion. The hierarchical cryptographic key management system complies with Russian legislation on personal data and demonstrates high performance for use in highload airport environments. Further research includes integration with certified Russian-made hardware security modules (HSMs), the implementation of post-quantum cryptographic algorithms, and the use of distributed ledger technology to ensure the immutability of audit logs.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>персональные данные</kwd><kwd>биометрия</kwd><kwd>криптографическая защита</kwd><kwd>иерархия ключей</kwd><kwd>AES-256-GCM</kwd><kwd>управление ключами</kwd><kwd>аэропорт</kwd><kwd>информационная безопасность</kwd></kwd-group><kwd-group xml:lang="en"><kwd>personal data</kwd><kwd>biometrics</kwd><kwd>cryptographic protection</kwd><kwd>key hierarchy</kwd><kwd>AES-256-GCM</kwd><kwd>key management</kwd><kwd>airport</kwd><kwd>information security</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Роскомнадзор. Отчёт о деятельности Федеральной службы по надзору в сфере связи, информационных технологий и массовых коммуникаций за 2024 год. – М., 2024. – 156 с.</mixed-citation><mixed-citation xml:lang="en">Roskomnadzor. Annual Report on the Activities of the Federal Service for Supervision of Communications, Information Technology, and Mass Media for 2024. Moscow, 2024; 156 p. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Крамаров С.О., Митясова О.Ю., Соколов С.В., Тищенко Е.Н., Шевчук П.С. Криптографическая защита информации: учебное пособие. – М., 2025.</mixed-citation><mixed-citation xml:lang="en">Kramarov S.O., Mityasova O.Yu., Sokolov S.V., Tishchenko E.N., Shevchuk P.S. Cryptographic Protection of Information: A Tutorial. Moscow, 2025. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Шевчук П.С., Зверев А.П., Пазин М.С. Обеспечение информационной и кибербезопасности военнослужащих в цифровую эпоху при проведении специальной военной операции // Инженерный вестник Дона. – 2025. – № 11 (131). – С. 934–945.</mixed-citation><mixed-citation xml:lang="en">Shevchuk P.S., Zverev A.P., Pazin M.S. Ensuring Information and Cybersecurity of Military Personnel in the Digital Age During a Special Military Operation. Engineering Bulletin of the Don. 2025;11(131):. 934-945. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Добот Ю.Н., Шевчук П.С. Ботнет-атаки и защита телекоммуникационных систем с использованием криптографических методов // Инновационный потенциал развития науки в современном мире: достижения и инновации: сб. науч. ст. по материалам XV Междунар. науч.-практ. конф. – Уфа, 2024. – С. 11–18.</mixed-citation><mixed-citation xml:lang="en">Dobot Yu.N., Shevchuk P.S. Botnet Attacks and Protection of Telecommunication Systems Using Cryptographic Methods. Innovative Potential for Science Development in the Modern World: Achievements and Innovations: Collection of Scientific Articles Based on the Proceedings of the XV Int. Res. and Pract. Conf. – Ufa, 2024:11–18. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Добот Ю.Н., Шевчук П.С. Обнаружение и устранение DDoS-атаки на основе SIEM // Инновационные идеи молодых исследователей: сб. науч. ст. по материалам XV Междунар. науч.-практ. конф. – Уфа, 2024. – С. 29–34.</mixed-citation><mixed-citation xml:lang="en">Dobot Yu.N., Shevchuk P.S. Detection and Mitigation of DDoS Attacks Based on SIEM // Innovative Ideas of Young Researchers: Collection of Scientific Articles Based on the Materials of the XV International Scientific and Practical Conf. – Ufa, 2024; 29–34. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Федеральный закон от 27.07.2006 №152-ФЗ (ред. от 06.02.2023) «О персональных данных». – URL: http://www.consultant.ru/document/cons_doc_LAW_61801/ (дата обращения: 10.01.2026).</mixed-citation><mixed-citation xml:lang="en">Federal Law of the Russian Federation No. 152-FZ of 27.07.2006 (as amended on 06.02.2023) “On Personal Data”. http://www.consultant.ru/document/cons_doc_LAW_61801/ (accessed: 10.01.2026) (In Russ).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Плоткин А.С., Кесель С.А., Репин М.М., Федоров Н.В. Анализ уязвимостей систем управления ключами в распределенных реестрах на примере блокчейн IBM // Вопросы кибербезопасности. – 2021. – № 2 (42). – С. 61–70.</mixed-citation><mixed-citation xml:lang="en">Plotkin A.S., Kesel S.A., Repin M.M., Fedorov N.V. Analysis of Vulnerabilities in Key Management Systems in Distributed Ledgers: The IBM Blockchain Case Study. Cybersecurity Issues. 2021; 2(42):61–70. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Петров И.В., Сидоров А.А. Анализ уязвимостей систем управления криптографическими ключами // Вопросы кибербезопасности. – 2023. – № 4 (56). – С. 45–52. DOI: 10.21681/2311-3456-2023-4-45-52.</mixed-citation><mixed-citation xml:lang="en">Petrov I.V., Sidorov A.A. Analysis of Vulnerabilities in Cryptographic Key Management Systems. Cybersecurity Issues. 2023; 4 (56):45–52. DOI: 10.21681/2311-3456-2023-4-45-52. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Иванова М.С., Козлов Д.Н. Проблемы защиты биометрических персональных данных в транспортной инфраструктуре // Информационная безопасность регионов. – 2024. – № 2 (47). – С. 18–25.</mixed-citation><mixed-citation xml:lang="en">Ivanova M.S., Kozlov D.N. Challenges in Protecting Biometric Personal Data in Transport Infrastructure . Information Security of Regions. 2024;2 (47):18–25. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Лившиц И.И. Оценка рисков утечки персональных данных от атак по каналам поставщиков // Вестник Дагестанского государственного технического университета. Технические науки. – 2025. – Т. 52. – № 1. – С. 97–104.</mixed-citation><mixed-citation xml:lang="en">Livshits I.I. Risk Assessment of Personal Data Leakage from Supply-Chain Attacks. Herald of Dagestan State Technical University. Technical Sciences. 2025; 52(1):97–104. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Грунтович М.М., Семкин А.Н. Криптографическая защита в системе сопровождения и управления наземными транспортными средствами // Безопасность информационных технологий. – 2012. – Т. 19. – № 1. – С.65–69.</mixed-citation><mixed-citation xml:lang="en">Gruntovich M.M., Semkin A.N. Cryptographic Protection in the Support and Control System for Ground Vehicles. Information Technology Security. 2012; 19(1):65–69. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Грунтовский Д.Р., Суторев И.С. Анализ защищённости контейнерных приложений в средах с особыми требованиями к безопасности данных // Современные научно-технические достижения современности: новые технологии, инновационные решения: сб. науч. ст. – Ульяновск, 2025. – С. 13–15.</mixed-citation><mixed-citation xml:lang="en">Gruntovskiy D.R., Sutorev I.S. Security Analysis of Containerized Applications in Environments with Special Data Security Requirements. Modern Scientific and Technical Achievements: New Technologies, Innovative Solutions: Collection of Scientific Papers. Ulyanovsk, 2025: 13–15. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Бокова О.И., Канавин С.В., Хохлов Н.С., Гилев И.В., Лекарь Л.А. К вопросу обеспечения защищенного доступа к информационным системам с применением биометрической аутентификации на основе нечеткого образа личности пользователя и нейросетевых преобразований // Вестник Дагестанского государственного технического университета. Технические науки. – 2023. – Т. 50. – № 4. – С. 75–84.</mixed-citation><mixed-citation xml:lang="en">Bokova O.I., Kanavin S.V., Khokhlov N.S., Gilev I.V., Lekar L.A. On Ensuring Secure Access to Information Systems Using Biometric Authentication Based on a Fuzzy User Identity Pattern and Neural Network Transformations. Herald of Dagestan State Technical University. Technical Sciences. 2023;50(4):. 75–84. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Черкесова Л.В., Савельев В.А., Ревякина Е.А., Полулях А.Р., Семенцов М.А. Механизм восстановления данных в результате их повреждения, заражения и/или несанкционированного изменения // Вестник Дагестанского государственного технического университета. Технические науки. – 2025. – Т. 52. – № 1. – С. 134–146.</mixed-citation><mixed-citation xml:lang="en">Cherkesova L.V., Savelyev V.A., Revyakina E.A., Polulyakh A.R., Sementsov M.A. Data Recovery Mechanism in the Event of Data Corruption, Infection, and/or Unauthorized Modification. Herald of Dagestan State Technical University. Technical Sciences. 2025;52(1):134–146. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Васильев А.Э., Газизов А.Р., Шевчук П.С. Криптографические методы в системах контроля и управления доступом: современные подходы и перспективы // Актуальные проблемы науки и техники: материалы Всерос. (нац.) науч.-практ. конф., посвящённой 95-летию Донского гос. техн. ун-та. – Ростов-на-Дону, 2025. – С. 383–384.</mixed-citation><mixed-citation xml:lang="en">Vasiliev A.E., Gazizov A.R., Shevchuk P.S. Cryptographic methods in access control systems: modern approaches and prospects. Actual problems of science and technology: materials of the All-Russian (national) scientific and practical conf., dedicated to the 95th anniversary of the Don State Technical University. - Rostov-on-Don, 2025; 383-384. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Smith J., Anderson K. Hierarchical Key Management Systems for Cloud Infrastructure // Journal of Cryptographic Engineering. – 2023. – Vol. 13. – No. 3. – P. 245–258. – DOI: 10.1007/s13389-023-00312-5.</mixed-citation><mixed-citation xml:lang="en">Smith J., Anderson K. Hierarchical Key Management Systems for Cloud Infrastructure. Journal of Cryptographic Engineering. 2023;13(3):245–258. – DOI: 10.1007/s13389-023-00312-5.</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Chen L., Wang Y., Zhang H. Hardware Security Modules for Cryptographic Key Protection in Critical Infrastructure // IEEE Transactions on Information Forensics and Security. – 2024. – Vol. 19. – P. 1234–1247. – DOI: 10.1109/TIFS.2024.1234567.</mixed-citation><mixed-citation xml:lang="en">Chen L., Wang Y., Zhang H. Hardware Security Modules for Cryptographic Key Protection in Critical Infrastructure. IEEE Transactions on Information Forensics and Security. 2024;19:1234–1247. – DOI: 10.1109/TIFS.2024.1234567.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Johnson M., Brown R. Performance Analysis of AES-GCM for Biometric Data Protection // Computers &amp; Security. – 2023. – Vol. 134. – Article 103421. – DOI: 10.1016/j.cose.2023.103421.</mixed-citation><mixed-citation xml:lang="en">Johnson M., Brown R. Performance Analysis of AES-GCM for Biometric Data Protection. Computers &amp; Security. 2023;134: Article 103421. – DOI: 10.1016/j.cose.2023.103421.</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">Смирнов В.И. Правовые аспекты защиты персональных данных в информационных системах: монография. – М.: Юрайт, 2024. – 284 с.</mixed-citation><mixed-citation xml:lang="en">Smirnov V.I. Legal Aspects of Personal Data Protection in Information Systems: Monograph. – Moscow: Yurait, 2024; 284 p. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">Davis P., Miller S. Cryptographic Agility in Post-Quantum Era: Architectural Approaches // ACM Computing Surveys. – 2024. – Vol. 56. – No. 2. – Article 45. – DOI: 10.1145/3625567.</mixed-citation><mixed-citation xml:lang="en">Davis P., Miller S. Cryptographic Agility in the Post-Quantum Era: Architectural Approaches. ACM Computing Surveys. 2024;56(2):Article 45. – DOI: 10.1145/3625567.</mixed-citation></citation-alternatives></ref><ref id="cit21"><label>21</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО/МЭК 27001-2021. Информационная технология. Методы и средства обеспечения безопасности. Системы менеджмента информационной безопасности. Требования. – М.: Стандартинформ, 2021.</mixed-citation><mixed-citation xml:lang="en">GOST R ISO/IEC 27001-2021. Information Technology. Security Techniques. Information Security Management Systems. Requirements. – Moscow: Standartinform, 2021. (In Russ)</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
