Hierarchical cryptographic key management system for biometric personal data protection in airport information systems
Rattachement africain : ru. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Objective . The article is devoted to the urgent problem of ensuring the security of biometric personal data processed in airport information systems. The purpose of the research is to develop a hierarchical cryptographic key management system capable of providing cryptographic flexibility, effective key rotation, and irreversible encryption of biometric data in accordance with the requirements of Federal Law No. 152-FZ "On Personal Data" and the regulations of the FSTEC of Russia. Method . The methodological basis of the study was the current standards in the field of information security (GOST R ISO/IEC 27001-2021) and the FSTEC methodology for identifying current threats. Architecture development is based on a three-level hierarchy of keys (Root Key, KEK, DEK) with keys divided into data categories. The software implementation of the encryption module is made in Python using the PyCryptodome cryptographic library, which implements the AES-256-GCM algorithm, which ensures confidentiality, integrity and authenticity of data. Result . During the study, a three-level key management system was developed and tested, which minimizes the scale of damage caused by compromise by using unique DEK keys for each passenger. Performance testing showed high data processing speed: encryption of 1 MB of biometric information is performed in 6.88 ms, which allows the system to process up to 100 registrations per second on a single server. The proposed architecture provides the ability to rotate keys without reencrypting the entire data array. Conclusion . The hierarchical cryptographic key management system complies with Russian legislation on personal data and demonstrates high performance for use in highload airport environments. Further research includes integration with certified Russian-made hardware security modules (HSMs), the implementation of post-quantum cryptographic algorithms, and the use of distributed ledger technology to ensure the immutability of audit logs.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Hierarchical cryptographic key management system for biometric personal data protection in airport information systems
- Date Crossref
- 10/08/2026
- Éditeur
- FSB Educational Establishment of Higher Education Daghestan State Technical University
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Les institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.