Today information is seen as a strategic resource. Modification of the information or it’s illegal dissemination can lead to serious consequences. The process of ensuring information protection get’s complicated with the development of computing machines. The integrity of important operating system files, programs or data controled of hash function. Hashing is used to construct associative arrays and duplicate in a series of datasets, build unique identifiers for a set of data, with a view to determining the Checksumming accidental or deliberate errors in you save or transfer, to save passwords on systems of protection, in the formulation of an electronic signature. More recently, industry related cryptographic hash faced a significant challenge-sustainability to multikolizijam that use attack Zhuks. In his work Zhuks has shown that sustainability, calculates the hash value by cascading these functions, not much more than the stability of one of them. In addition, the known hash algorithms do not allow to fully address the issues of ensuring the durability and performance of cryptographic algorithms. Therefore, developing new and improving existing hash functions with a view to enhancing the effectiveness of cryptographic protection will not lose its relevance. With this in mind, in the work of the proposed hash function newMD4, which was developed on the basis of the original hash function MD4. Designed hash function newMD4 has several innovations compared to MD4: if you are compressing instead of four 32-bit variables proposed using five 64-bit variable increased the length of the hash value to 256-bits; replaced by additional functions added additional operations at each stage. In the work of the experimental research on the evaluation of Expressway and the statistical characteristics of the proposed hash function. Under the same conditions, conducted pilot studies to assess mental speed characteristics, which showed that the hash function newMD4 faster than the original MD4 in 1,43 times. For research of statistical characteristics of NIST tests were used in the STS, at the same hash function used to generate sequences, statistical characteristics of teristiki which tested the specified tests. According to the research results, consistency, using the hash function sgenerirovanye newMD4 showed better statistical characteristics compared to the original.
In the last few years, development of quantum cryptography has attracted the scientist’s attention. Researches passed from the theoretical level to introduction of ready commercial decisions. The main difference between the methods of quantum cryptography and traditional (symmetric and asymmetric) cryptography consists in use of absolutely different principles in the basis. The quantum cryptography does not depend on computing or other intruder opportunities, uses specific unique quantum particles properties and based on inviolability of quantum physics laws. Among the most developed technologies of quantum cryptography is worth noting quantum secure direct communication, which can transmit information by open channel without encryption - removing key distribution problem, but in these protocols each bit of information is confidential and intruder shouldn’t get it, that's why requirements for protocols stability is much higher and require security amplification methods. Such method was previously developed by authors, but its implementation requires the use of reliable trit pseudorandom sequences. In this context, this study presents an experimental research of trit pseudorandom sequence generating method for cryptographic applications. For evaluating the effectiveness of this method was developed experimental methodology, which confirms the possibility of using trit sequences generated by the method for ensuring the stability of quantum cryptography qutrit protocols to non-coherent attacks and for other crypto-graphic applications in modern information and communication technologies.
The application of web technologies and forms of electronic document circulation in the process of information exchange between users though simplifies this process, however, generates a number of new threats to the confidentiality, integrity and availability of information and the appearance of previously unknown vulnerabilities. One of the most common methods of protection is the use of digital certificates that ensure the confidential exchange of data between a client and a server by encrypting and authenticating a digital certificate. A digital certificate is a public key, certified by the EDS of the certification center. However, a digital certificate is not just a public key with information, but a so-called signature of a server or web resource that is implemented using the hex functions. However, with the development of information technology and the emergence of new types of attacks, leads to an increase in the number of disadvantages of existing gash functions. Thus, in the paper a new heaching function was proposed, which was developed on the basis of the SHA-2 hex function. Improvements involved the introduction of a number of changes: increased the size of words and an increase in the message digest; At the pre-processing stage, the incoming message is supplemented by a pseudo-random sequence; the number of nonlinear functions is increased. The proposed changes allow to reduce the number of rounds in the compression function, which will guarantee at least similar stability indicators with simultaneous increase in data processing speed.
Providing of confidentiality of data is the important stage in the process of providing of cyber security of the critical aviation informative systems and aviation industry on the whole. Known methods do not allow to fully provide cyberattacks resistance to linear and differential cryptanalysis and the required speed of cryptographic data processing. Taking into account it, the cryptographic method of defence of the critical aviation information systems is in-process worked out. On the basis of this method, a block symmetric cipher Luna-2k17 was developed and its specification is given in the work. Also, the values of the upper estimates of parameters that characterize its practical stability to cyber attacks of linear and differential cryptanalysis are calculated. At equal terms, experimental studies are undertaken from the estimation of speed characteristics of ciphers, that showed that cipher Luna-2k17 more faster than a cipher GOST 28147-89 approximately in 3,11 times, than ciphers Kalina and AES in 1,271 times.
Providing of confidentiality of data is the important stage in the process of providing of cyber security of the critical aviation informative systems and aviation industry on the whole. Known methods do not allow to fully provide cyberattacks resistance to linear and differential cryptanalysis and the required speed of cryptographic data processing. Taking into account it, the cryptographic method of defence of the critical aviation information systems is in-process worked out. On the basis of this method, a block symmetric cipher Luna-2k17 was developed and its specification is given in the work. Also, the values of the upper estimates of parameters that characterize its practical stability to cyber attacks of linear and differential cryptanalysis are calculated. At equal terms, experimental studies are undertaken from the estimation of speed characteristics of ciphers, that showed that cipher Luna-2k17 more faster than a cipher GOST 28147-89 approximately in 3,11 times, than ciphers Kalina and AES in 1,271 times.
In this paper was done analysis of existing classifications for obfuscation software security methods. Based on the above analysis of these classification it was found that software protection has certain drawbacks such as are not taken into account some obfuscation methods that can strongly increase stability of the code. In this work presented modern obfuscation software security methods and developed generalized classification of these methods. Subsequently, based on developed classification, it is planned to create software based on presented algorithm, that will allow to embrangle code, made the process of software analysis more complicated and will provide software security from unauthorized disclosure. The obtained results expand the knowledge on how to use obfuscation security methods and will provide the development of modern and effective software security systems.
Today acutely raises the issue of providing information confidentiality in conditions of growth quantity and quality of violations in cyberspace that are constantly improving and developing. Reliability of traditional methods for ensuring confidentiality is questionable taking into account contemporary threats. So look for alternative methods and means of security is urgent issue. Significant interest causes quantum cryptography, which do not depend on computing or other capabilities of offender, uses specific unique properties of quantum particles, and based on the inviolability of the laws of quantum physics. One of the most advanced technology of quantum cryptog-raphy is quantum secure direct communication, which can transmit information directly by open channel (without encryption – in this case there is no key distribution problem), but they have only asymptotic resistance to noncoherent attacks and, certainly requires some methods for amplification security. In this regard, developed a method of ensuring the stability of quantum cryptography protocols. To evaluate the effectiveness of this method was developed a methodology for conducting experimental research, according to which it is made comparing of its performance with known method. According to the obtained results, the proposed method has a speed in 1.52 times faster against analogs at the same level of resistance to noncoherent attacks.
In this paper was done analysis of existing classifications for obfuscation software security methods. Based on the above analysis of these classification it was found that software protection has certain drawbacks such as are not taken into account some obfuscation methods that can strongly increase stability of the code. In this work presented modern obfuscation software security methods and developed generalized classification of these methods. Subsequently, based on developed classification, it is planned to create software based on presented algorithm, that will allow to embrangle code, made the process of software analysis more complicated and will provide software security from unauthorized disclosure. The obtained results expand the knowledge on how to use obfuscation security methods and will provide the development of modern and effective software security systems.
Modern powerful computing technology development threatens the confidentiality of information that usually provided by traditional cryptographic means and forces researchers to look for alternative security methods. Given the current trends, these alternatives may be quantum cryptography and communication methods. These methods unlike traditional (classical) analogues use specific unique properties of quantum particles and are based on the inviolability of the quantum physics laws. Existing classifications in quantum cryptography and communications do not include the large number of modern methods. It complicates its study and use in the quantum information security systems development. In the paper modern methods of quantum cryptography and communication were analyzed, their advantages and disadvantages, security assessment to various kinds of cyberattacks were defined, and also the existing classifications of these methods were studied. On the basis of partial generalizations of theoretical positions and practical advances in quantum cryptography, the generalized classification of quantum cryptography and communication methods was constructed. This classification reveals a problem in this area and can extend the possibilities for choosing the appropriate methods for modern quantum information security systems development.
Modern powerful computing technology development threatens the confidentiality of information that usually provided by traditional cryptographic means and forces researchers to look for alternative security methods. Given the current trends, these alternatives may be quantum cryptography and communication methods. These methods unlike traditional (classical) analogues use specific unique properties of quantum particles and are based on the inviolability of the quantum physics laws. Existing classifications in quantum cryptography and communications do not include the large number of modern methods. It complicates its study and use in the quantum information security systems development. In the paper modern methods of quantum cryptography and communication were analyzed, their advantages and disadvantages, security assessment to various kinds of cyberattacks were defined, and also the existing classifications of these methods were studied. On the basis of partial generalizations of theoretical positions and practical advances in quantum cryptography, the generalized classification of quantum cryptography and communication methods was constructed. This classification reveals a problem in this area and can extend the possibilities for choosing the appropriate methods for modern quantum information security systems development.
The rapid development of modern computing technology threatens the confidentiality of information that is provided, usually, by traditional cryptographic means and forces researchers to look for alternative methods of security. Considering the development tendencies one of these alternatives may be quantum cryptography that unlike traditional (which is mostly based on the impossibility of solving a certain class of mathematical problems by certain period of time) uses specific unique properties of quantum particles, based on the inviolability of the quantum physics laws. It is known that some quantum cryptography protocols allowing to achieve information-theoretic stability – a key distribution protocols mostly. Another class of quantum cryptography protocols - secure direct communication protocols, most of which have asymptotic stability. Therefore, it was suggested a number of methods to increase the stability of such protocols. One of these methods will increase the asymptotic stability of quantum secure direct connection protocols with entangled pairs (correlated) of qutrit, but this method requires the generation of ternary (trit) pseudorandom sequences. In the work proposed generating pseudorandom trit sequences method based on the number of irreversible functions and transformation over the field GF (3). Also at the basis of a method developed appropriate algorithm that reflected as pseudo code. Further research will focus on the development of a quality evaluation of trit generated pseudorandom sequences method, as virtually all existing methods focused on binary sequence.
The main stages of information security incidents management are responding and investigation. These functions are assigned to specialized teams and centers (such as CERT – Computer Emergency Response Team). The information security level of organization and whole state depends on CERT`s performance. The analysis showed that CERT`s performance assessment is not carried out properly. That’s why in this paper basic performance parameters for cyberincidents response teams – it gives a possibility to assess CERT`s performance during necessary period. The report on these parameters should be performed regularly such as once a week (month, year etc.) to obtain a complete picture of their changes and identify key trends. Using the obtained parameters will enable: to make quick management decisions, evaluate the level of CERT`s specialists, to improve the CERT efficiency, to reduce losses associated with incidents, to improve user productivity, to use staff effectively and others. As well by influencing on the CERT`s specialists actions and their correction can improve information security level of organization and whole state. Further on the basis of these parameters it is planned to develop mathematical models to ensure continuous improvement of the cyberincidents management.
The theory analysis and basis of block ciphers resistance with fixed replacement nodes regard to the linear and differential cryptanalysis is quite developed.There are also block ciphers in which the nodes are defined by replacing the round key. It is clear that the using of randomized replacement nodes in ciphers makes difficult cryptanalysis for them, but it is difficult to assess quantitatively. Given this, the urgent task is to take the analytical expressions that allow to prove the practical resistance of block ciphers with randomized replacement nodes regard to the linear and differential cryptanalysis and will make a quantitative assessment of their effectiveness. In this paper obtain analytical upper bounds for the parameters characterizing the practical resistance of block ciphers with randomized replacement nodes regard to the linear and differential cryptanalysis. These estimates generalize previously known to block ciphers with randomized replacement nodes can explain increase resistance regard to these methods of cryptanalysis.
Two encryption algorithms were developed to improve security of electronic information resources. These algorithms based on fixed table of substitution with extended capacity and dynamic key-dependent tables of substitutions. Developed algorithms are at least two times faster than domestic encryption standard GOST 28147-2009 and practically resistant to linear and differential cryptanalysis. Properties of pseudorandom sequences generated by the proposed encryption algorithms (in counter mode) were investigated by statistical tests NIST STS and they were complex controlled by NIST STS methodic and have better results than other generators.
In this paper the basic principles of abstract model of intruder development in state information and communication systems are given. The main principles of different cryptosystems for state information resources protection are showed. Besides the main problems of keys data management in the process of state information resources protection are analyzed.
Запропоновано новий метод підсилення секретності пінг-понг протоколу з парами переплутаних кутритів, який дозволяє підвищити ефективність його роботи. Розроблено генератор тритових послідовностей, за допомогою якого формується тритова ключова послідовність, що використовується в методі підсилення секретності.
У даній статті проведено дослідження існуючих методів квантової стеганографії. Запропоновано класифікацію сучасних квантово-стеганографічних методів з точки зору застосовуваних стегоконтейнерів, а також проведено якісний аналіз їх переваг та недоліків з позицій ефективності та можливості практичної реалізації.
У даній статті запропоновано новий перспективний блоковий симетричний криптоалгоритм «LUNA». Наведено основні поняття та терміни, що використовуються для опису даного алгоритму, формалізовано основні параметри, операції та процедури. Крім того, визначено коло подальших досліджень даного криптографічного алгоритму, що полягає у перевірці його стійкості до відомих методів криптоаналізу, оцінці швидкісних параметрів та проведенні статистичного тестування.