Preview

Herald of Dagestan State Technical University. Technical Sciences

Advanced search

Hierarchical cryptographic key management system for biometric personal data protection in airport information systems

https://doi.org/10.21822/2073-6185-2026-53-2-153-161

Abstract

Objective. The article is devoted to the urgent problem of ensuring the security of biometric personal data processed in airport information systems. The purpose of the research is to develop a hierarchical cryptographic key management system capable of providing cryptographic flexibility, effective key rotation, and irreversible encryption of biometric data in accordance with the requirements of Federal Law No. 152-FZ "On Personal Data" and the regulations of the FSTEC of Russia.
Method. The methodological basis of the study was the current standards in the field of information security (GOST R ISO/IEC 27001-2021) and the FSTEC methodology for identifying current threats. Architecture development is based on a three-level hierarchy of keys (Root Key, KEK, DEK) with keys divided into data categories. The software implementation of the encryption module is made in Python using the PyCryptodome cryptographic library, which implements the AES-256-GCM algorithm, which ensures confidentiality, integrity and authenticity of data.
Result. During the study, a three-level key management system was developed and tested, which minimizes the scale of damage caused by compromise by using unique DEK keys for each passenger. Performance testing showed high data processing speed: encryption of 1 MB of biometric information is performed in 6.88 ms, which allows the system to process up to 100 registrations per second on a single server. The proposed architecture provides the ability to rotate keys without reencrypting the entire data array.
Conclusion. The hierarchical cryptographic key management system complies with Russian legislation on personal data and demonstrates high performance for use in highload airport environments. Further research includes integration with certified Russian-made hardware security modules (HSMs), the implementation of post-quantum cryptographic algorithms, and the use of distributed ledger technology to ensure the immutability of audit logs.

About the Authors

P. S. Shevchuk
Don State Technical University; Rostov State Transport University
Russian Federation

Petr S. Shevchuk, Dr. Sci. (Eng.), Prof., Department of Information Security in Computing Systems and Networks

Gagarina Square, Rostov-on-Don, 344002

22 Rostovskogo Strelkovogo Polka Narodnogo Opolcheniya Sq., Rostov-on-Don 344038



A. R. Aydinyan
Don State Technical University
Russian Federation

Andrey R. Aidinyan, Cand. Sci. (Eng.), Assoc. Prof., Assoc. Prof., Department of Computing Systems and Information Security

Gagarina Square, Rostov-on-Don, 344002



References

1. Roskomnadzor. Annual Report on the Activities of the Federal Service for Supervision of Communications, Information Technology, and Mass Media for 2024. Moscow, 2024; 156 p. (In Russ)

2. Kramarov S.O., Mityasova O.Yu., Sokolov S.V., Tishchenko E.N., Shevchuk P.S. Cryptographic Protection of Information: A Tutorial. Moscow, 2025. (In Russ)

3. Shevchuk P.S., Zverev A.P., Pazin M.S. Ensuring Information and Cybersecurity of Military Personnel in the Digital Age During a Special Military Operation. Engineering Bulletin of the Don. 2025;11(131):. 934-945. (In Russ)

4. Dobot Yu.N., Shevchuk P.S. Botnet Attacks and Protection of Telecommunication Systems Using Cryptographic Methods. Innovative Potential for Science Development in the Modern World: Achievements and Innovations: Collection of Scientific Articles Based on the Proceedings of the XV Int. Res. and Pract. Conf. – Ufa, 2024:11–18. (In Russ)

5. Dobot Yu.N., Shevchuk P.S. Detection and Mitigation of DDoS Attacks Based on SIEM // Innovative Ideas of Young Researchers: Collection of Scientific Articles Based on the Materials of the XV International Scientific and Practical Conf. – Ufa, 2024; 29–34. (In Russ)

6. Federal Law of the Russian Federation No. 152-FZ of 27.07.2006 (as amended on 06.02.2023) “On Personal Data”. http://www.consultant.ru/document/cons_doc_LAW_61801/ (accessed: 10.01.2026) (In Russ).

7. Plotkin A.S., Kesel S.A., Repin M.M., Fedorov N.V. Analysis of Vulnerabilities in Key Management Systems in Distributed Ledgers: The IBM Blockchain Case Study. Cybersecurity Issues. 2021; 2(42):61–70. (In Russ)

8. Petrov I.V., Sidorov A.A. Analysis of Vulnerabilities in Cryptographic Key Management Systems. Cybersecurity Issues. 2023; 4 (56):45–52. DOI: 10.21681/2311-3456-2023-4-45-52. (In Russ)

9. Ivanova M.S., Kozlov D.N. Challenges in Protecting Biometric Personal Data in Transport Infrastructure . Information Security of Regions. 2024;2 (47):18–25. (In Russ)

10. Livshits I.I. Risk Assessment of Personal Data Leakage from Supply-Chain Attacks. Herald of Dagestan State Technical University. Technical Sciences. 2025; 52(1):97–104. (In Russ)

11. Gruntovich M.M., Semkin A.N. Cryptographic Protection in the Support and Control System for Ground Vehicles. Information Technology Security. 2012; 19(1):65–69. (In Russ)

12. Gruntovskiy D.R., Sutorev I.S. Security Analysis of Containerized Applications in Environments with Special Data Security Requirements. Modern Scientific and Technical Achievements: New Technologies, Innovative Solutions: Collection of Scientific Papers. Ulyanovsk, 2025: 13–15. (In Russ)

13. Bokova O.I., Kanavin S.V., Khokhlov N.S., Gilev I.V., Lekar L.A. On Ensuring Secure Access to Information Systems Using Biometric Authentication Based on a Fuzzy User Identity Pattern and Neural Network Transformations. Herald of Dagestan State Technical University. Technical Sciences. 2023;50(4):. 75–84. (In Russ)

14. Cherkesova L.V., Savelyev V.A., Revyakina E.A., Polulyakh A.R., Sementsov M.A. Data Recovery Mechanism in the Event of Data Corruption, Infection, and/or Unauthorized Modification. Herald of Dagestan State Technical University. Technical Sciences. 2025;52(1):134–146. (In Russ)

15. Vasiliev A.E., Gazizov A.R., Shevchuk P.S. Cryptographic methods in access control systems: modern approaches and prospects. Actual problems of science and technology: materials of the All-Russian (national) scientific and practical conf., dedicated to the 95th anniversary of the Don State Technical University. - Rostov-on-Don, 2025; 383-384. (In Russ)

16. Smith J., Anderson K. Hierarchical Key Management Systems for Cloud Infrastructure. Journal of Cryptographic Engineering. 2023;13(3):245–258. – DOI: 10.1007/s13389-023-00312-5.

17. Chen L., Wang Y., Zhang H. Hardware Security Modules for Cryptographic Key Protection in Critical Infrastructure. IEEE Transactions on Information Forensics and Security. 2024;19:1234–1247. – DOI: 10.1109/TIFS.2024.1234567.

18. Johnson M., Brown R. Performance Analysis of AES-GCM for Biometric Data Protection. Computers & Security. 2023;134: Article 103421. – DOI: 10.1016/j.cose.2023.103421.

19. Smirnov V.I. Legal Aspects of Personal Data Protection in Information Systems: Monograph. – Moscow: Yurait, 2024; 284 p. (In Russ)

20. Davis P., Miller S. Cryptographic Agility in the Post-Quantum Era: Architectural Approaches. ACM Computing Surveys. 2024;56(2):Article 45. – DOI: 10.1145/3625567.

21. GOST R ISO/IEC 27001-2021. Information Technology. Security Techniques. Information Security Management Systems. Requirements. – Moscow: Standartinform, 2021. (In Russ)


Review

For citations:


Shevchuk P.S., Aydinyan A.R. Hierarchical cryptographic key management system for biometric personal data protection in airport information systems. Herald of Dagestan State Technical University. Technical Sciences. 2026;53(2):153-161. (In Russ.) https://doi.org/10.21822/2073-6185-2026-53-2-153-161

Views: 26

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2073-6185 (Print)
ISSN 2542-095X (Online)