МОДЕЛЬ КОГНІТИВНОЇ БАГАТОСТОРОННЬОЇ АВТОРИЗАЦІЇ КРИТИЧНИХ КРИПТОГРАФІЧНИХ ОПЕРАЦІЙ У КОРПОРАТИВНИХ ХМАРНИХ ІНФОРМАЦІЙНИХ СИСТЕМАХ
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1335Ключові слова:
когнітивна модель, багатостороння авторизація, корпоративні хмарні інформаційні системи, критичні криптографічні операції, розподілені інтелектуальні системи, підтримка прийняття рішень, криптографічні ключі, Zero TrustАнотація
Статтю присвячено розробленню моделі когнітивної багатосторонньої авторизації критичних криптографічних операцій у корпоративних хмарних інформаційних системах, спрямованої на підвищення рівня захищеності криптографічних сервісів, достовірності прийняття рішень щодо виконання критичних операцій та зменшення ризику компрометації криптографічних ключів. Досліджено сучасні підходи до багатосторонньої авторизації, порогової криптографії, контекстно-орієнтованого контролю доступу, концепції Zero Trust і методів підтримки прийняття рішень у розподілених інтелектуальних системах. Встановлено, що існуючі механізми багатосторонньої авторизації переважно використовують статичні правила підтвердження криптографічних операцій і недостатньо враховують зміну контексту функціонування, рівень довіри до суб'єктів, критичність операції, поточний кіберризик та взаємозалежність факторів, які впливають на безпеку корпоративного хмарного середовища. Запропоновано модель когнітивної багатосторонньої авторизації, що ґрунтується на інтеграції когнітивного моделювання, контекстного оцінювання, розподіленого інтелектуального аналізу та адаптивного визначення необхідного рівня колективного підтвердження критичних криптографічних операцій. Розроблено модель прийняття рішень, яка формує вимоги до багатосторонньої авторизації на основі комплексного оцінювання критичності операції, рівня довіри, кіберризику, характеристик інформаційного ресурсу та поточного стану корпоративного хмарного середовища. Проведено структурно-функціональне оцінювання запропонованої моделі, результати якого показали її здатність адаптивно змінювати склад авторизаторів, поріг підтвердження та тип керуючого рішення відповідно до зміни контексту, довіри, критичності операції й прогнозованого кіберризику. Практичне значення отриманих результатів полягає у можливості використання запропонованої моделі під час побудови захищених корпоративних хмарних інформаційних систем, сервісів керування криптографічними ключами та інфраструктур підтримки критичних криптографічних операцій.
Завантаження
Посилання
Tong, Y., Li, S., Wang, Z., et al. (2025). Adaptively secure, splittable, and robust threshold unsigncryption. Cybersecurity, 8, Article 57. https://doi.org/10.1186/s42400-024-00344-3
Renisha, P. S., & Rudra, B. (2025). Quantum-safe threshold cryptography for decentralized group key management via dealerless DKG (CRYSTALS-Kyber). Mathematics, 13(21), Article 3429. https://doi.org/10.3390/math13213429
Wang, R., Li, C., Zhang, K., et al. (2025). Zero-trust based dynamic access control for cloud computing. Cybersecurity, 8, Article 12. https://doi.org/10.1186/s42400-024-00320-x
Jeong, E., & Yang, D. (2025). A trust score-based access control model for Zero Trust architecture: Design, sensitivity analysis, and real-world performance evaluation. Applied Sciences, 15(17), Article 9551. https://doi.org/10.3390/app15179551
Mao, Y., Fu, W., Zhao, Y., Yuan, Z., Sun, Z., & Zhao, Y. (2025). A Zero-Trust access control model based on attribute and dynamic trust evaluation for cloud environments. Symmetry, 17(12), Article 2059. https://doi.org/10.3390/sym17122059
Nie, S., Ren, J., Wu, R., Han, P., Han, Z., & Wan, W. (2025). Zero-Trust access control mechanism based on blockchain and inner-product encryption in the Internet of Things in a 6G environment. Sensors, 25(2), Article 550. https://doi.org/10.3390/s25020550
Alnaim, A. K. (2025). Adaptive Zero Trust policy management framework in 5G networks. Mathematics, 13(9), Article 1501. https://doi.org/10.3390/math13091501
Lee, S., Huh, J.-H., & Woo, H. (2025). Security system design and verification for Zero Trust architecture. Electronics, 14(4), Article 643. https://doi.org/10.3390/electronics14040643
Santucci, F., Oliva, G., Gonnella, M. T., Briga, M. E., Leanza, M., Massenzi, M., Faramondi, L., & Setola, R. (2025). Implementing Zero Trust: Expert insights on key security pillars and prioritization in digital transformation. Information, 16(8), Article 667. https://doi.org/10.3390/info16080667
Kostiuk, Y., Skladannyi, P., Samoilenko, Y., Khorolska, K., Bebeshko, B., & Sokolov, V. (2024). A system for assessing the interdependencies of information system agents in information security risk management using cognitive maps. In Proceedings of the Third International Conference on Cyber Hygiene & Conflict Management in Global Information Networks (CH&CMiGIN 2024) (CEUR Workshop Proceedings, Vol. 3925, pp. 249-264). CEUR-WS.org.
Ma, Y.-W., & Chiu, P.-H. (2025). A novel risk-based access control engine in Zero Trust architecture for IoT network. International Journal of Information Security, 24. https://doi.org/10.1007/s10207-025-01030-2
Kostiuk, Y., Skladannyi, P., Sokolov, V., & Vorokhob, M. (2025). Models and technologies of cognitive agents for decision-making with integration of artificial intelligence. In Proceedings of the Modern Data Science Technologies Doctoral Consortium (MoDaST 2025) (CEUR Workshop Proceedings, Vol. 4005, pp. 82-96). CEUR-WS.org.
Escaleira, P., Cunha, V. A., Barraca, J. P., et al. (2025). A systematic review on security mechanisms for serverless computing. Cluster Computing, 28, Article 465. https://doi.org/10.1007/s10586-025-05371-4
Kostiuk, Y. (2025). Multi-agent system for detecting and counteracting attacks on the enterprise information system. In Insider threats and security in corporations (pp. 205-232). https://doi.org/10.36690/ITSC-205-232
Shevchenko, S., Zhdanova, Y., Skladannyi, P., & Petrenko, T. (2024). Fuzzy cognitive maps as a visualization tool for incident response scenarios in security systems. Cybersecurity: Education, Science, Technique, 2(26), 417-429. https://doi.org/10.28925/2663-4023.2024.26.707
Musa, N. S., Murugan, T., N., N. A., et al. (2025). Research study on securing the cloud: Utilizing conventional and blockchain-based access control mechanisms. Journal of Cloud Computing, 14, Article 88. https://doi.org/10.1186/s13677-025-00803-3
Kostiuk, Y., Skladannyi, P., Mazur, N., Rzaieva, S., Hnatchenko, D., & Honcharenko, I. (2026). Formal model of adaptive selection of cryptographic parameters for protecting communication channels in corporate computer networks based on dynamic trust assessment. Cybersecurity: Education, Science, Technique, 4(32), 20-44. https://doi.org/10.28925/2663-4023.2026.32.1111
Wang, Y., Li, B., Wu, J., et al. (2025). An efficient multi-party signature for securing blockchain wallet. Peer-to-Peer Networking and Applications, 18, Article 137. https://doi.org/10.1007/s12083-025-01958-1
Skladannyi, P., Kostiuk, Y., & Rzaieva, S. (2026). Continuous access evaluation in Zero Trust access management based on security event signals and dynamic session management. Mathematical Machines and Systems, 1, 29-46. https://doi.org/10.34121/1028-9763-2026-1-29-46
Lilhore, U. K., Simaiya, S., Alroobaea, R., et al. (2025). SmartTrust: A hybrid deep learning framework for real-time threat detection in cloud environments using Zero-Trust architecture. Journal of Cloud Computing, 14, Article 35. https://doi.org/10.1186/s13677-025-00764-7
Kostiuk, Y. V., Skladannyi, P. M., & Hnatchenko, D. D. (2026). Risk-adaptive authorization in Zero Trust with dynamic trust and security tokens. Problems in Programming, 1, 66-81. https://doi.org/10.15407/pp2026.01.066
Alatawi, M. N. (2025). Blockchain-driven smart contracts for advanced authorization and authentication in cloud security. Electronics, 14(15), Article 3104. https://doi.org/10.3390/electronics14153104
Shevchenko, S., Zhdanova, Y., Kryvytska, O., Shevchenko, H., & Spasiteleva, S. (2024). Fuzzy cognitive mapping as a scenario approach for information security risk analysis. In Cybersecurity Providing in Information and Telecommunication Systems II 2024 (CEUR Workshop Proceedings, Vol. 3826, pp. 356-362). CEUR-WS.org.
Kostiuk, Y. V., & Skladannyi, P. M. (2026). Cryptographic trust model for security events in SIEM systems for intelligent generation of network incidents. Modern Information Protection, 1(65), 103-118. https://doi.org/10.31673/2409-7292.2026.011393
Li, Z., Du, X., Wu, X., et al. (2025). Gatac: Research on microservice access control techniques based on trust assessment and game analysis. Cybersecurity, 8, Article 122. https://doi.org/10.1186/s42400-025-00520-z
Paya, A., Vicente-García, J., & Gómez, A. (2025). Enhancing software-defined perimeters with integrated identity solutions and threat detection for robust Zero Trust security. International Journal of Information Security, 24, Article 178. https://doi.org/10.1007/s10207-025-01099-9
Calzarossa, M. C., Giudici, P., & Zieni, R. (2025). An assessment framework for explainable AI with applications to cybersecurity. Artificial Intelligence Review, 58, Article 150. https://doi.org/10.1007/s10462-025-11141-w
Опубліковано
Як цитувати
Номер
Розділ
Ліцензія
Авторське право (c) 2026 Юлія Костюк, Світлана Рзаєва, Наталія Мазур, Карина Хорольська, Богдан Бебешко, Дмитро Гнатченко

Ця робота ліцензується відповідно до Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.