In today's financial landscape, individuals face challenges when it comes to determining the most effective investment strategies. Cryptocurrencies have emerged as a recent and enticing option for investment. This paper focuses on forecasting the price of Ethereum using two distinct methods: artificial intelligence (AI)-based methods like Genetic Algorithms (GA), and econometric models such as regression analysis and time series models. The study incorporates economic indicators such as Crude Oil Prices and the Federal Funds Effective Rate, as well as global indices like the Dow Jones Industrial Average and Standard and Poor's 500, as input variables for prediction. To achieve accurate predictions for Ethereum's price one day ahead, we develop a hybrid algorithm combining Genetic Algorithms (GA) and Artificial Neural Networks (ANN). Furthermore, regression analysis serves as an additional prediction tool. Additionally, we employ the Autoregressive Moving Average (ARMA) model to assess the relationships between variables (dependent and independent variables). To evaluate the performance of our chosen methods, we utilize daily historical data encompassing economic and global indices from the beginning of 2019 until the end of 2021. The results demonstrate the superiority of AI-based approaches over econometric methods in terms of predictability, as evidenced by lower loss functions and increased accuracy. Moreover, our findings suggest that the AI approach enhances computational speed while maintaining accuracy and minimizing errors.
Current directions of development of information and communication technologies and control tools 114 ПРОБЛЕМНІ ПИТАННЯ ЗАСТОСУВАННЯ ГОМОМОРФНОГО ШИФРУВАННЯ Гущин Б.-Д.І.Харківський національний університет радіоелектроніки, Харків, Україна Гомоморфне шифрування (Homomorphic Encryption, HE) -технологія, що дозволяє виконувати обчислення над зашифрованими даними без їх розшифрування [1-3].Застосування гомоморфного шифрування відкриває великі можливості для обробки зашифрованих даних без їх розшифрування в багатьох сферах, де критично важливо зберігати конфіденційність інформації.. Однак, попри потенціал, існує низка проблемних питань, які стримують широке впровадження цієї технології в практичні системи безпеки та обробки даних.Метою доповіді є аналіз проблемних питань при практичному застосуванні гомоморфного шифрування.В роботі розглянуті ключові сучасні сфери застосування HE [1-3].1. Хмарні обчислення (Cloud Computing), обробка зашифрованих даних на стороні постачальника хмарних послуг без розкриття вмісту.2. В медицині та біоінформатиці захищене зберігання та аналіз медичних записів пацієнтів, генетичної інформації (DНК).Використання HE у дослідженнях із багатьма організаціями без обміну розшифрованими даними.3. В фінансових сервісах конфіденційна аналітика для банків, страхових компаній, бірж.Обчислення кредитного рейтингу, оцінка ризиків без доступу до відкритих даних клієнта. Електронне голосування (E-voting).Забезпечення анонімності та перевірності результатів голосування, так як дані не розкриваються, але можуть бути агреговані без розшифрування.5. В Інтернеті речей (IoT) для обробки конфіденційних даних, зібраних з розумних пристроїв, безпосередньо на сервері або у хмарі.Використання в промисловому IoT (IIoT), медичних пристроях, Smart City.6. Захист персональних даних у Big Data, аналітика зашифрованих великих масивів даних з соціальних мереж, телекомів, сервісів для обчислення трендів, поведінкових моделей, не розкриваючи особистості.7. Машинне навчання над зашифрованими даними (Privacy-Preserving ML).Навчання або інференс моделей на даних, які ніколи не розшифровуються.Використання в конфіденційній медичній діагностиці, рекомендаційних системах, фінансах.Працює разом з Federated Learning, Secure Multi-Party Computation (SMPC).8. В юридичних сервісах та державному управлінні для безпечної взаємодії між державними структурами при обробці реєстрів, митних даних, податкових баз, де важлива повна конфіденційність.9. В системах кібербезпеки та цифрової ідентичності.Застосовується в антифрод-системах, аналізі поведінки користувачів без втрати їхньої конфіденційності.Підтримка Zero Knowledge Proofs та протоколів автентифікації.
In this age of always-on connection, it is very important to keep data safe while also protecting user privacy. In today's networks, where data travels through many pathways, such as cloud services and IoT devices, cryptographic algorithms are very important for keeping private data safe. But it's still exceptionally difficult to create beyond any doubt that information is secure without putting people's protection at chance. This conversation goes into detail almost privacy-preserving security strategies, looking at their significance, issues, and other ways to solve them. The objective of privacy-preserving cryptographic strategies is to create beyond any doubt that private information is kept secure whereas still permitting secure contact and computation. To keep data secure from individuals who shouldn't have get to to it, these frameworks utilize diverse sorts of cryptography, like encryption, hashing, and secure multi-party computation (SMPC). Information spills and illicit observing are less likely to happen with these methods because they cover up information at diverse steps of exchange and handling. Indeed in spite of the fact that they may well be useful, privacy-preserving cryptographic strategies have a number of issues. Finding a great blend between client security and information security is one of the most issues. Extreme security measures may offer assistance keep information secure, but they frequently include collecting information in ways that are as well intrusive and abuse people's security. On the other hand, putting as well much accentuation on protection might make security weaker, taking off information open to being abused. Finding a cautious adjust between these competing objectives is key to making cryptographic frameworks that work well. A few potential methods that permit secure information taking care of whereas ensuring security are homomorphic encryption, differential protection, and zero-knowledge proofs. Improvements in hardware-accelerated cryptography and distributed computing tools also make it possible to speed up secure processes and make them more scalable.
V. S. Balatska, R. L. Tkachuk, A. I. Ivanusa, V. I. Yashchuk · 5 authors
Problem. The growing intensity of cyberattacks on state registers and the increasing complexity of insider threats expose the weaknesses of traditional comprehensive information security systems (CISS), particularly the reliance on centralized logging and change verification mechanisms. This reduces audit transparency, complicates the evidential value of incidents, and creates regulatory risks in personal data protection. Purpose. To develop and substantiate a scientific and methodological approach for integrating permissioned blockchain technology into CISS of state registers to enhance resistance to insider actions, ensure transparency of access control, and increase trust in electronic public services. Methods. The study applies a systems analysis of CISS architectures and regulatory requirements, mathematical modeling of data flows, and experimental modeling in a virtualized environment using Hyperledger Fabric as a decentralized logging and verification module. Zero-Knowledge Proofs were applied to preserve transaction confidentiality, and behavioral analytics based on machine learning algorithms were used to detect anomalous activity. Results. A hybrid architecture was proposed in which traditional mechanisms of authentication, access control, and cryptographic protection are reinforced by a distributed event log and consensus-based verification of operations. This integration ensures data immutability and reproducibility of access history, reduces the possibility of hidden record editing by administrators, accelerates the detection of atypical user behavior, and creates a reliable evidential base for auditing. The proposed architecture complies with ISO/IEC 27001 requirements and supports data minimization and accountability principles, facilitating GDPR compliance during personal data processing. Conclusions. Integrating permissioned blockchain into CISS of state registers establishes a new level of trust and controllability of security: it increases audit transparency, mitigates insider risks, and preserves transaction confidentiality. The proposed approach is scalable and suitable for national e-government platforms and interagency data exchange systems.
The article examines the evolution of the concept of Integrated Information Security Systems (IISS) in the context of the digital transformation of the public sector, modernization of the national cybersecurity framework, and harmonization of Ukrainian legislation with international information security standards. The study reveals the relationship between classical approaches to building IISS – based on mandatory certification of technical protection complexes – and the modern paradigm of risk-oriented security management introduced by the new Law of Ukraine No. 4336-IX “On Amendments to Certain Laws of Ukraine on the Protection of Information and Cybersecurity of State Information Resources and Critical Information Infrastructure Objects.” The research emphasizes the shift from a formal certification model to a process-oriented approach based on security profiles, risk management, continuous monitoring, and security auditing. Special attention is devoted to analyzing the potential of blockchain technologies in enhancing the resilience of state information systems against cyberattacks, insider threats, and unauthorized data modifications. The study substantiates the feasibility of using distributed ledgers to ensure the immutability, authenticity, transparency, and accountability of information processes. It is determined that blockchain can serve as an innovative component of the modern IISS architecture, complementing cryptographic protection mechanisms, access control, user activity auditing, and event monitoring. A conceptual model of blockchain integration into the traditional structure of IISS is proposed, forming a new trust ecosystem within state information resources. The combination of technological innovation with the legal requirements of Law No. 4336-IX creates a foundation for improving the effectiveness of the national cybersecurity system. The purpose of the study is to substantiate the scientific, methodological, and technological directions for the modernization of Ukraine’s Integrated Information Security Systems through the integration of blockchain technologies in protecting state information resources in accordance with current legislation and international standards ISO/IEC 27001, ISO/IEC 27701, and GDPR.
Андрій Олександрович Гашко, Андрій Петрович Бондарчук, Максим Петрович Трембовецький, Олександр Ілліч Чумак
The article examines an automated method for verifying the correctness of smart contracts in the Solana blockchain network. The relevance of the research is driven by the growing popularity of Web3 applications and the need to ensure their security, as even minor errors in smart contract code can lead to significant financial losses. The primary goal is to develop an automated verification methodology for smart contracts that can detect vulnerabilities such as the absence of founder rights verification, arithmetic operation errors, and missing transaction check signatures. Using static analysis techniques in the Rust programming language, the authors propose an approach that enables rapid analysis-taking less than three minutes per contract-and automatic generation of reports on identified vulnerabilities. The methodology is based on analyzing external data flows through smart contracts, allowing for the early detection of potential threats. To automate the process, Python and Bash scripts are employed, integrating with cloud services such as Amazon Web Services to scale the analysis. Testing results on real Web3 applications demonstrate the effectiveness of the methodology, particularly in reducing analysis time and improving the accuracy of error detection. An important aspect of the research is the continuous updating of knowledge bases and analysis tools, enabling the consideration of new types of attacks and vulnerabilities. The article also highlights the importance of interoperability between different blockchain networks, which remains a challenging task but is a key element for the future development of Web3. The research results show that the proposed methodology is promising for scaling and adapting to new challenges in blockchain ecosystems such as Solana. Thus, the developed approach to automated smart contract verification not only enhances the security of Web3 applications but also contributes to their further development, ensuring stability and reliability in the dynamic evolution of blockchain technologies.
The paper presents the main approaches to the construction of the PKI public key architecture divided into basic, two-level, and multi-level hierarchies. Modern methods of attacks on existing public key infrastructures, protocols for building secure connections of both wired and wireless systems are considered. The basics of the class of attacks on PKI infrastructures are defined, of which the main attention is paid to the most dangerous class of attacks – man-in-the-middle (MITM-attacks). The paper provides models of various classes of MITM attacks, their details and existing methods of reducing the risks of their implementation. Existing examples of successful attacks on enterprises and various organizations that implemented MITM attack models at the application, network, and physical levels of the network interaction model are also given. For the PKI infrastructure, one of the options is its segmentation, which allows to reduce the scope of attacks on the key certification center. The paper also provides an alternative way to protect against MITM attacks using distributed micro ledger technology (DLT) to create a decentralized cryptographic key distribution system (DKMS). The solution is based on the use of micro ledgers (distributed ledger technology – DMLT). Using DMLT to create a DKMS allows protection against additional classes of MITM attacks.
Relevance: Starting with the invention of the Internet, the world began to change rapidly, and the pace of change is increasing, so the problem of data storage and processing is becoming more and more relevant. The ZK-STARK protocol is a new cryptographic zero-knowledge proof protocol that is not yet widely used in practice and allows you to check a message or a transaction on the blockchain network for authenticity without reproducing it completely. At the moment, gaps and problems related to this protocol are identified: computational complexity, possible poor compatibility with other protocols, and resistance to attacks from quantum computers. Therefore, the paper aims to supplement the coverage of the problem associated with computational complexity and to propose solutions to this problem. Purpose: on the basis of the theoretical implementation of the first stage named Arithmetization of the ZK-STARK protocol, to test its software implementation in order to provide recommendations on its most computationally efficient version. Research methods: mathematical statements on interpolation theory, group theory, number theory; information on Fibonacci numbers; information on the Euler function; generating element of a group; cyclic groups; Lagrange interpolation polynomial and the sequence of calculations of Arithmetization; Visual Studio 2022 programming environment, C++ programming language, NTL library, Microsoft Excel. Results of work: The result of the work is the theoretical implementation of the first stage of the ZK-STARK protocol and the effectiveness testing of the first stage, and providing recommendations for its most effective version. Conclusion: Testing has shown that the practical implementation of the Arithmetization based on the inverse fast Fourier transform has a time complexity , that is in times less than the time complexity of the Arithmetization based on inverse matrices method and Gaussian method for interpolation, that speeds up the work of Arithmetization of the ZK-STARK protocol.
Open access
Cybersecurity and Information Systems
Advanced Computational Techniques in Science and Engineering
The emergence of blockchain technology has revolutionized various sectors by introducing decentralized and immutable ledgers. Ethereum, one of the leading blockchain platforms, has gained significant attention for its smart contract capabilities and ability to produce decentralized applications. Despite these innovative advancements, blockchain transaction networks, including Ethereum, have become a new space for the emergence of illegal activities from financial fraud to money laundering and terrorist financing. By combining theoretical knowledge with practical methodologies, this paper aims to contribute to the ongoing efforts to increase the security and transparency of blockchain networks, especially the Ethereum blockchain. The proposed methods leverage supervised machine learning, Financial Action Task Force (FATF) red flags and transaction graph visualization. Through the development and validation of innovative detection methods, the findings of this research are expected to enable stakeholders to proactively mitigate the risks associated with illicit transaction activities on the Ethereum blockchain.
ABSTRACT Nowadays, the image security is one of the most challenging issues to address the technological age. Security is the primary issue in data management and transmission because of the original data form that is read, abused and destroyed. The cloud companies struggle to secure the file. The cloud security is the major concern in cloud computing context. Numerous researches have been presented so far to protect the cloud environment. But, none of them provides the sufficient security. Therefore, this paper proposes a Blockchain‐based technique for Image Security that combines Hierarchical Auto‐Associative Polynomial Convolutional Neural Network Fostered Cryptography (BC‐SIE‐HAPCNN‐FODCE). The Flickr30k dataset is used to collect the input images. At that point, cryptographic pixel values of picture are kept on blockchain to defend security of picture information. It uses Delegated Proof of Stake Consensus (DT‐DPoS) approach appointed confirmation of stake agreement approach. The performance parameters, like processing time, reaction time, runtime, correlation coefficient analysis, entropy analysis, mean square error, and availability are used to determine the efficacy of the proposed BC‐SIE‐HAPCNN‐FODCE approach. The performance of the proposed technique attains 18.81%, 32.05%, and 22.28% higher correlation coefficient and 25.38%, 20.81%, and 26.04% higher entropy compared with existing methods, such as Multiple Rossler lightweight Logistic sine mapping dependent Federated convolutional method with cyber blockchain in medical image encryption (BC‐SIE‐FCAL‐MRLLSM), color image encryption under Hénon‐zigzag map with chaotic restricted Boltzmann machine over Blockchain (BC‐SIE‐CRBM‐HZM) and blockchain‐assisted safe picture transmission along detection method on Internet of Medical Things Environment (BC‐SIE‐ECC‐DBN), respectively.
Advanced Steganography and Watermarking Techniques
The article discusses the use of Ethereum blockchain technology in the Internet of Things (IoT) network for IT diagnostics of patients, which increases data security and user privacy. This integration is proving effective for storing and managing sensitive data of patients with neurological diseases. An integrated system architecture has been developed that combines the IoT network, the IPFS (InterPlanetary File System) file structure with the Ethereum blockchain to create a reliable data storage model. This system ensures efficient, secure and transparent data processing, optimizing the processes of data registration, authorization and verification. Using IPFS for decentralized file storage, along with the Ethereum blockchain to create tamper-proof medical records, provides increased efficiency, scalability and privacy. During the experiments, the process of creating and testing the system was implemented, including setting up the environment, connecting an IPFS node, programming Ethereum smart contracts, sampling voice data and storing their hashes.
The characteristics of blockchain technology, which is a decentralised database or "distributed ledger," include independence, lack of central authority, and a trustless setting. Because of these characteristics, blockchain technology is well-suited for use in many IoT applications. This article details a real-world use of the Proof of Authority (PoA) Ethereum blockchain on an web of Things (IoT) system. In order to study and highlight potential challenges that might impact the integration of blockchain with IoT, and to set the stage for future research and potential solutions to these concerns, this implementation was carried out in a practical sense.
Олег Гарасимчук, Юрій Наконечний, Тарас Луковський, Роман Андріїв · 5 authors
Постійне збільшення обсягів даних породжує проблеми, пов'язані з вибором ефективних методів та засобів зберігання, а також забезпеченням захисту цих даних від несанкціонованого доступу. У статті детально розглянуто критичну тему збереження та захисту важливої інформації в умовах зростання обсягів даних і численності кібератак. Необхідність надійного збереження і захисту даних наростає, особливо у контексті підвищеної загрози з боку зловмисників. Висвітлюється, як блокчейн-технології, особливо на базі платформи Ethereum, можуть вирішити проблеми надійного збереження і безпеки даних. Ethereum пропонує альтернативу традиційній клієнт-серверній моделі, децентралізуючи зберігання даних за допомогою розподіленої мережі вузлів. Ця технологія значно підвищує безпеку, ускладнюючи несанкціонований доступ до інформації, оскільки для злому приватного ключа потрібні значні обчислювальні ресурси. Смарт-контракти на Ethereum дозволяють створювати застосунки, які виконуються точно відповідно до заздалегідь визначених умов, без можливості втручання третіх осіб. Це особливо важливо для месенджерів, де конфіденційність і доступність даних мають принципове значення. Вартість транзакцій в блокчейні, хоча й висока, компенсується високою надійністю та безпекою зберігання даних. Застосована методологія підтверджує, що використання публічного (децентралізованого) сховища даних є безпечним, оскільки зламати приватний ключ Ethereum практично неможливо.
K P Premalatha, Kuldip Kumar Sahu, Murli Manohar Gour
This paper explores the performance of implemented cryptography algorithms used for various blockchain technologies, which include Bitcoin, Ethereum, and Hyperledger. Diverse techniques for assessing cryptographic algorithm implementations and their relative performances are mentioned, inclusive of efficiency (variety of bits processed in step with unit time), strength intake, and hardware overhead. Through studying the computational complexity, conversation complexity, and garage ability, the paper assesses commonplace operations together with key era, key alternate, virtual signature, and encryption/decryption for a ramification of algorithms. Further, the scalability of the algorithms on big networks is tested and analyzed. ultimately, an assessment of the security of the algorithms is executed by measuring security parameters, which include facet-channel assault resistance, nonce reuse resistance, and quantum resistance. This paper provides an overview of the overall performance of applied cryptography algorithms, which allows researchers and developers to pick out the algorithm that is most appropriate for their blockchain utility.
Cybersecurity and Information Systems
Economic and Technological Systems Analysis
Advanced Computational Techniques in Science and Engineering
The prevalence of financial fraud poses significant challenges to global financial stability, resulting in billions of dollars in losses annually and undermining consumer trust in financial institutions. With the increasing complexity and volume of financial transactions driven by the rapid growth of digital banking and e-commerce, traditional fraud detection methodologies have proven inadequate in addressing the scale and sophistication of modern fraudulent activities. This paper seeks to investigate and delineate the development of advanced data science and artificial intelligence (AI) methodologies aimed at detecting, mitigating, and preventing financial fraud in real-time systems. By exploring a range of state-of-the-art models, algorithms, and technologies, this research aims to provide comprehensive insights into how these systems can be deployed effectively to safeguard financial operations and maintain systemic integrity. Financial fraud detection is inherently challenging due to the dynamic and evolving nature of fraudulent tactics. The emergence of techniques such as machine learning (ML) and deep learning (DL) has significantly enhanced the ability to identify complex, non-linear patterns within large datasets that were previously undetectable by conventional rule-based systems. This paper focuses on the integration of supervised, unsupervised, and semi-supervised learning methods, as well as hybrid approaches that combine different algorithmic strategies for greater detection accuracy. In the context of financial fraud, algorithms such as decision trees, support vector machines (SVM), random forests, and neural network architectures have been adapted and fine-tuned to operate under stringent latency constraints inherent in real-time processing systems. Moreover, the adaptation of generative adversarial networks (GANs) for synthetic data generation and anomaly detection is examined to bolster the robustness and adaptability of fraud detection models. A critical aspect of this research lies in the exploration of feature engineering and data pre-processing techniques to optimize the input datasets for AI models. Given that the quality of data directly influences the efficacy of predictive algorithms, innovative feature extraction, dimensionality reduction, and data augmentation methods are discussed in detail. The use of time-series analysis and sequence modeling, especially through recurrent neural networks (RNNs) and long short-term memory (LSTM) networks, is emphasized for fraud detection in transactions that require contextual and sequential understanding. Such methodologies enable the capture of temporal dependencies that are essential for detecting anomalous behaviors indicative of fraudulent activities. Additionally, the paper addresses the significance of explainable AI (XAI) in the realm of financial fraud prevention. Trust in AI-driven fraud detection systems can be undermined by their "black-box" nature, where decision-making processes remain opaque to users and regulators. As such, incorporating interpretable models and explainability tools is essential for meeting regulatory requirements and fostering confidence in automated systems. This research evaluates various XAI techniques, such as SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations), and their integration with AI models to ensure that the decision-making process can be audited and understood by human analysts. The paper also explores the real-world applicability of AI and data science-based fraud detection through case studies of financial institutions and tech firms that have implemented such systems. These case studies illustrate the challenges faced, such as the need for real-time processing, false positive management, and system scalability. Furthermore, it provides an analysis of the trade-offs between model accuracy, computational resources, and real-time performance requirements. The dynamic nature of fraud tactics demands adaptive learning mechanisms that can update models in response to new data, which brings attention to the necessity of continuous learning and model retraining protocols. Techniques such as online learning and active learning are discussed as viable solutions to ensure that models remain effective against emerging fraud patterns. The challenges of data privacy and security are also examined, given the sensitive nature of financial data. AI and ML models, particularly those deployed in real-time environments, must comply with stringent data protection laws such as the General Data Protection Regulation (GDPR) and regional financial regulations. The implications of privacy-preserving machine learning, differential privacy, and federated learning as methods to process data without compromising individual user privacy are evaluated. This aspect is critical for building trust between financial institutions and customers, ensuring that fraud detection efforts do not come at the expense of user data confidentiality. Lastly, the research covers future directions and emerging trends that could shape the landscape of financial fraud detection and prevention. The integration of blockchain technology and distributed ledger systems is considered for enhancing transparency and reducing opportunities for fraudulent activities. Advanced threat intelligence platforms that leverage cross-industry data sharing and the collective insights of AI models trained on diverse datasets are also discussed as potential avenues for mitigating fraud in a proactive manner. The role of collaborative networks and the potential for AI-driven fraud detection to be part of a larger cybersecurity framework are posited as next-generation solutions to create a more secure financial ecosystem. The findings of this research underline the significance of continuous advancements in data science and AI to stay ahead of increasingly sophisticated financial fraud tactics. While AI models have shown promising capabilities in detecting fraudulent activities in real-time, challenges such as model interpretability, scalability, and adaptability remain prominent. This paper concludes with a strategic roadmap for financial institutions, policymakers, and technology developers to enhance the efficacy of fraud prevention strategies, which include fostering innovation in AI-driven solutions, promoting the development of robust real-time processing infrastructures, and encouraging collaborative research efforts that leverage cross-sector knowledge and resources.
Lyudmila Kovalchuk, Nataliia Kuchynska, Mikhail S. Kondratenko
The paper investigates the issues of the safe operation of a two-level blockchain with a complex mixed consensus protocol — Proof-of-Stake in the main blockchain (mainchain) and Proof-of-Work in the secondary (sidechain). This two-level blockchain is built on the principle of the Proof-of-Proof protocol, where the safety of the sidechain is ensured by the stability of the mainchain, by referring the mainchain blocks to the sidechain blocks using special transactions. Such a structure allows faster issuance of blocks in the sidechain and, accordingly, faster processing of transactions without loss of security and without increasing the volume of the block. In turn, such a two-level blockchain is of the greatest interest for the creation of a cascade system of state registers, which will be guaranteed to be protected against the substitution and forgery of documents. The main results of the work are explicit analytical expressions for estimates of probability of double spend attack on such two-level blockchain, under the condition of adversary in sidechain and in mainchain. Keywords: blockchain, mainchain, sidechain, cryptocurrencies, mining, Proof-of-Proof consensus protocol, double spend attack.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Research in Systems and Signal Processing
Privacy and security in the current modern, digital communication and data transfer-oriented world has become imperative. Most commonly used encryption methods often involve exposing sensitive information, which might be an open gate for potential vulnerabilities. This paper aims to explore the topic of applying ZKPs in cybersecurity in a comprehensive manner. For this purpose, Proposed work will provide an exhaustive description of the basic concepts of Zero-Knowledge Proofs , which refer to both the interactive and non-interactive forms of the product. Additionally, the study will focus on presenting various cryptographic protocols and algorithms utilizing Zero-Knowledge Proofs , such as zk-SNARKs and zk-STARKs . In addition to theoretical studies, Proposed work analyze the practical implementation details of Zero-Knowledge Proofs implementations , cryptographic libraries, programming languages, and frameworks commonly used to create ZKP-based applications . Zero-knowledge proofs enable groundbreaking approaches to address cybersecurity problems with an emphasis on user privacy and data confidentiality. On average, cryptographic operations experienced delays of approximately 10 milliseconds which was not intrusive for real-time systems. The system’s throughout remained at a steady average of 100 Mbps all times, so it performed well at processing data despite cryptographic overhead. The packet delivery ratio was constantly high at 98%, implying that most data packets were delivered consistently even over encrypted communication paths.
Abstract— The paper presents the results of an analysis of the decrease in cryptographic strength of the most common symmetric ciphers, taking into account the development of cryptanalytic methods. The vector of the threat to the reduction of information confidentiality stored and processed in information systems in the long term has been determined. An approach to constructing hybrid ciphers, based on the symbiosis of a composite cipher and the Vernam cipher, has been proposed to enhance the asymptotic cryptographic strength of symmetric cryptographic systems used for data encryption in information systems, the relevance of stored and processed information in which does not significantly decrease over time. For instance, this is applicable to information systems built on distributed ledger technology (blockchain networks).
The article examines the peculiarities of the emergence and development of virtual assets -cryptocurrencies. The history and reasons for the creation of the most famous cryptocurrency -bitcoin -are analysed. The advantages and disadvantages of using cryptocurrencies are presented. The principle of blockchain operation is described. The foreign experience of regulating the circulation of cryptocurrencies is analysed. The possibility of integrating best practices to legalise and minimise the risks of using cryptocurrencies in Ukraine is substantiated.
Ірина Стрелковська, Олексій Онацький, Лариса Григорівна Йона
Background. To ensure the protection of the biometric access control system used in unsecured communication channels, it is necessary to exclude the storage and transfer, transfer of biometric data as well as sequences generated on their basis. The paper proposes a cryptographic protocol of two-factor authentication with the zero-knowledge over the extended field GF(2m) on elliptic curves using biometric data and the private key of the user. Objective. The aim of the article is to develop a cryptographic protocol for zero-knowledge two-factor authentication based on elliptic curves using biometric data and the user’s private key, which allows increasing cryptographic strength and reducing the duration of the authentication process. Methods. The process of implementing zero-knowledge proof protocols is as follows: one user (proofer) can convince another user (verifier) that he has some secret without disclosing the secret itself. Results. A cryptographic protocol for two-factor authentication with zero-knowledge over the extended field GF(2m) of elliptic curves using user biometric data is proposed, which significantly reduces the size of the protocol parameters and increases cryptographic strength (computational complexity of the breaking). There is no leakage of private key information and biometric data of the user during the execution of the zero-knowledge proof protocol. Conclusions. The implementation of a cryptographic protocol with zero-knowledge proof two-factor authentication based on elliptic curves allows significantly reducing the size of protocol parameters and increasing the cryptographic strength (computational complexity of the breaking).
The problem of monitoring a computer network under conditions of limitations on the use of system resources and high requirements for the survivability of the monitoring system has been considered. An autonomous decentralized computer network monitoring system has been developed, consisting of a team of software agents. Each agent can operate in two modes: main mode and monitoring system management console mode. In the main mode, the agent collects information about the computer network. In management console mode, the agent provides the user with access to information collected by all agents and allows the user to execute commands to manage the monitoring system. The developed monitoring system allows you to obtain more reliable information about the operation of the network with greater efficiency under the conditions of limitations on the use of system resources specified by the user. The autonomous monitoring system is created on the basis of the concept of multi-agent systems, within which a software agent of the system has some initiative for planning and implementing monitoring scenarios. The operation of software agents implements methods for organizing adaptive processes for collecting information using the principles of self-organization and the concept of structural adaptation. A decentralized software architecture for an autonomous monitoring system without a control center has been proposed. This ensures high reliability and survivability of the monitoring system. The software architecture of the autonomous monitoring system implements the SMA application software interface and the corresponding software library, which allows you to collect statistical data on the operation of the computer network and its nodes. The implementation of a software agent and a management console for an autonomous computer network monitoring system has been considered. Key words: computer network monitoring, autonomous system, decentralized control, software agent
Open access
Cybersecurity and Information Systems
Advanced Data Processing Techniques
Advanced Research in Systems and Signal Processing