TНЕ CONCEPT OF INFORMATION SECURITY
Abstract
Any adverse impact on information subjects caused by accidental or intentional natural or artificial influences, we understand that information is protected from users and owners of information that would cause undue harm to information subjects, including supporting infrastructure.
Full text
THE VI INTERNATIONAL SCIENTIFIC CONFERENCE “SCIENTIFIC FOUNDATIONS FOR THE USE OF INFORMATION TECHNOLOGIES OF A NEW LEVEL AND MODERN PROBLEMS OF AUTOMATION”, NOVEMBER 20, 2025 55 TНЕ CONCEPT OF INFORMATION SECURITY 1Akhmedova Sanabarkhan Khafizovna, 2Kosheleva Aleksandra Dmitrievna 1Candidate of Economic Sciences, Associate Professor of the Department “Economics and Logistics”, Belarusian-Uzbek Joint Intersectoral Institute of Applied Technical Skills; 2Master's student in Quality Assurance, Belarusian-Uzbek Joint Intersectoral Institute of Applied Engineering https://doi.org/10.5281/zenodo.17712352 Abstract. Any adverse impact on information subjects caused by accidental or intentional natural or artificial influences, we understand that information is protected from users and owners of information that would cause undue harm to information subjects, including supporting infrastructure. Cryptography is a collection of ideas and techniques related to transforming information in order to protect it from unintended users. Information is presented in the form of text (message). Such information is called plain text. Such information is called plaintext. The process of converting it into a protected state is called encryption, and the process of converting it into a cipher state is called encryption. From cryptogram, i.e. from encrypted text to clear text, it is carried out by decryption. To perform encryption and decryption, additional information called a key is used. The key itself is the secret of encryption. It should not be significantly difficult or practically impossible to read the cryptogram within a limited time without knowing the key. Cryptography is one of the components of cryptology - the science of sending information protected from unauthorized access. Cryptography, as mentioned, deals with the encryption and decryption of data using a secret key. Another component of cryptology, cryptanalysis, deals with the theory of extracting information from a cryptogram without knowing the key. Key words: adverse effects, information, cryptography, encryption, decryption. Аннотация. При любом неблагоприятном воздействии на субъекты информации, вызванные случайным или преднамеренным естественным или искусственным воздействием, как мы понимаем, информация защищена от пользователей и владельцев информации, которые могли бы нанести неоправданный вред субъектам информации, включая поддерживающую инфраструктуру. Криптография — это совокупность идей и методов, связанных с преобразованием информации для её защиты от несанкционированного доступа. Информация представляется в виде текста (сообщения). Такая информация называется открытым текстом. Процесс перевода его в защищенное состояние называется шифрованием, процесс перевода его в зашифрованное состояние также называется шифрованием. Перевод криптограммы, то есть зашифрованного текста в открытый, осуществляется путём расшифровки. Для шифрования и расшифровки используется дополнительная информация, называемая ключом. Сам ключ — это секрет шифрования. Прочитать криптограмму за ограниченное время без знания ключа не должно быть существенно сложно или практически невозможно. Криптография является одним из компонентов криптологии — науки о передаче информации, защищённой от несанкционированного доступа. Криптография, как уже упоминалось, занимается шифрованием и дешифрованием данных с использованием секретного ключа. Другой раздел
THE VI INTERNATIONAL SCIENTIFIC CONFERENCE “SCIENTIFIC FOUNDATIONS FOR THE USE OF INFORMATION TECHNOLOGIES OF A NEW LEVEL AND MODERN PROBLEMS OF AUTOMATION”, NOVEMBER 20, 2025 56 криптологии, криптоанализ, занимается теорией извлечения информации из криптограммы без знания ключа. By information security, we mean the protection of information from accidental or intentional natural or artificial influences that could cause undue harm to information subjects, including information users and owners who support the infrastructure. Information protection is a complex set of measures aimed at ensuring the safety of information. The main organizers of information security consist of the following categories: ensuring confidentiality, integrity and availability of supporting infrastructure and information resources. Usability is the ability to obtain the necessary information service within a certain period of time. Integrity is the validity of information and its protection against destruction and unauthorized modification. Only those with the appropriate rights should have the ability to modify information. Confidentiality is the protection of information from unauthorized access. Only those with the appropriate rights should have access to information. Basic methods of information protection Permission control is a method of protection by regulating the use of all resources of information systems and information technologies. Such methods should be able to eliminate all possibilities of unauthorized access to information. Permissions management includes the following security features: • identification of users, employees and system resources (giving a personal identifier to each object); • identify objects or entities by their assigned identifier (authentication); • verify the owner of access rights; • register access to protected resources; • prevent unauthorized access detection of attempted actions (alarm warning, system shutdown, system shutdown, non-response to requests). Identification and authentication can be considered an important software and technical means of security, since the remaining services are intended only for the entities themselves. Identification and authentication are the initial line of defense for accessing the information space of the enterprise. The combined implementation of the identification and authentication procedures is considered an authorization procedure. Identification allows entities (users, processes, and those acting on behalf of a particular user) to identify themselves. Authentication lets you know who the other party really is. Sometimes the term "authentication" is used as a synonym for "authentication". Authentication is of two types, one-way (usually the client authenticates to the server) and two-way (both parties authenticate each other). One-way authentication An example of a procedure is the state of users logging into a system. In an open network environment, there is no trusted route for identification/authentication between parties. It is necessary to provide protection against passive and active eavesdropping, i.e. interception, modification and processing of data in networks. Modern identification/authentication tools should support the concept of centralized
THE VI INTERNATIONAL SCIENTIFIC CONFERENCE “SCIENTIFIC FOUNDATIONS FOR THE USE OF INFORMATION TECHNOLOGIES OF A NEW LEVEL AND MODERN PROBLEMS OF AUTOMATION”, NOVEMBER 20, 2025 57 network access. Centralized network access is primarily a requirement for user convenience. If many information services in a corporate network make requests independently of each other, then identification/authentication becomes very difficult. One of the authentication methods in computer systems is to enter a user identifier, commonly known as a login (in English - the name under which the user is registered) and a password - some kind of confidential information. The trusted password and login pair is stored in a special database. Simple authentication consists of the following general algorithms: 1. The subject requests permission to enter the system and enters a personal identifier and password. 2. The entered non-returnable data is compared with the standard on the authentication server. 3. If the data matches the authentication standard, it is considered successful; if it does not match, the subject proceeds to step 1. The password entered by the subject is transmitted to the network in two ways: • based on the Password Authentication Protocol (PAP), in the clear, unencrypted state • using SSL or TLS encryption. The irretrievable data entered by the subject is transmitted over the network in a protected state. • Cryptography (Greek for writing with secret symbols) is a set of ideas and techniques related to the transformation of information in order to protect it from unintended users. Information is presented in the form of text (message). Such information is called plaintext. The process of converting it into a protected state is called cipher, the process of converting it into a cipher state is called encryption, and the changed text obtained as a result of encryption is called a cryptogram. The transformation from a cryptogram, that is, from encrypted text to plain text, is carried out by decryption. To perform encryption and decryption, additional information called a key is used. It is the key that is the secret of encryption. It should not be significantly difficult or practically impossible to read the cryptogram within a limited time without knowing the key. Cryptography is one of the components of cryptology - the science of sending information protected from unauthorized access. Cryptography, as mentioned, deals with the encryption and decryption of data using a secret key. Another component of cryptology, cryptanalysis, deals with the theory of extracting information from a cryptogram without knowing the key. Modern cryptography consists of four major branches: • Symmetric cryptosystems; • Public-key cryptosystems; • Electronic digital signature systems; • Key management. Symmetric cryptosystems include algorithms that perform encryption and decryption using a single key. These algorithms are sometimes called secret-key algorithms. In such systems, the key that the sender and receiver of the message intend to use must have been previously exchanged over a secret channel. Among cryptographic data protection systems, the most effective are publickey cryptosystems, in other words, asymmetric cryptosystems. In such systems, one key is used for data encryption and another key is used for decryption (hence the word asymmetric). The first key is known to all users in the system and is used to encrypt data. The public key cannot be used to decrypt data. The user uses a second key, the private key, to decrypt the encrypted data. It should be
THE VI INTERNATIONAL SCIENTIFIC CONFERENCE “SCIENTIFIC FOUNDATIONS FOR THE USE OF INFORMATION TECHNOLOGIES OF A NEW LEVEL AND MODERN PROBLEMS OF AUTOMATION”, NOVEMBER 20, 2025 58 noted that the decryption key cannot be found using the key used for encryption. Electronic digital signature (EDI) is a requisite of an electronic document, which is used to protect the electronic document from forgery and confirm the source of information. An electronic digital signature consists of a sequence of symbols created as a result of cryptographic modification of an electronic document. The ERI is added to the data block and allows the data receiver to protect the data source, data integrity and falsification. An electronic digital signature is generated through cryptographic self-regulation using special software and a secret key of an electronic digital signature. ERI improves electronic document exchange and guarantees document reliability. If the initial text is optionally changed, the ERI will not be valid. A unique public and secret cryptographic key is generated for each user participating in electronic document exchange and using an electronic digital signature. An important element is the secret key: with its help, electronic documents are encrypted and an electronic digital signature is created. An important element is the secret key: with its help, electronic documents are encrypted and an electronic digital signature is created. The private key also remains with the user and is transmitted via a separate medium: this can be a floppy disk, smart card, or touch memory. It must be kept secret from other users on the network. The public key is used to verify the validity of the ERI. A copy of the public keys is stored in the authentication center, i.e. public key certificate library. The certification authority ensures that the registration and public key are protected from incorrect entry or forgery. provides protection against attempts. When a user wants to put his digital signature on an electronic document, the secret key of the digital signature LITERATURE 1. Akhmedova S.Kh. Lecture materials. 2. Internet resources