<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">News of the Kabardino-Balkarian Scientific Center of the Russian Academy of Sciences</journal-id><journal-title-group><journal-title xml:lang="en">News of the Kabardino-Balkarian Scientific Center of the Russian Academy of Sciences</journal-title><trans-title-group xml:lang="ru"><trans-title>Известия Кабардино-Балкарского научного центра РАН</trans-title></trans-title-group></journal-title-group><issn publication-format="print">1991-6639</issn><issn publication-format="electronic">2949-1940</issn></journal-meta><article-meta><article-id pub-id-type="publisher-id">254327</article-id><article-id pub-id-type="doi">10.35330/1991-6639-2024-26-1-39-47</article-id><article-id pub-id-type="edn">GEVSAQ</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Информатика и информационные процессы</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Informatics and information processes</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">Development of an approach to ensuring information security in web-based information systems when transferring data using the Web Cryptography API interface</article-title><trans-title-group xml:lang="ru"><trans-title>Разработка подхода к обеспечению информационной безопасности в веб-ориентированных информационных системах при передаче данных с использованием интерфейса Web Cryptography API</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-6394-6966</contrib-id><name-alternatives><name xml:lang="en"><surname>Stupina</surname><given-names>Maria V.</given-names></name><name xml:lang="ru"><surname>Ступина</surname><given-names>Мария Валерьевна</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Candidate of Pedagogical Sciences, Associate Professor, Department of Information Technology</p></bio><bio xml:lang="ru"><p>канд. пед. наук, доцент кафедры информационных технологий</p></bio><email>masamvs@bk.ru</email><xref ref-type="aff" rid="aff1"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="ru">Донской государственный технический университет</institution></aff><aff><institution xml:lang="en">Don State Technical University</institution></aff></aff-alternatives><content-language>ru</content-language><pub-date date-type="pub" iso-8601-date="2024-02-15" publication-format="electronic"><day>15</day><month>02</month><year>2024</year></pub-date><pub-date date-type="collection"><year>2024</year></pub-date><volume>26</volume><issue>1</issue><issue-title xml:lang="ru"/><issue-title xml:lang="en"/><fpage>39</fpage><lpage>47</lpage><history><date date-type="received" iso-8601-date="2024-04-17"><day>17</day><month>04</month><year>2024</year></date><date date-type="accepted" iso-8601-date="2024-04-17"><day>17</day><month>04</month><year>2024</year></date></history><permissions><copyright-statement xml:lang="ru">Copyright ©; 2024, Ступина М.В.</copyright-statement><copyright-statement xml:lang="en">Copyright ©; 2024, Stupina M.V.</copyright-statement><copyright-year>2024</copyright-year><copyright-holder xml:lang="ru">Ступина М.В.</copyright-holder><copyright-holder xml:lang="en">Stupina M.V.</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://creativecommons.org/licenses/by/4.0</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.rcsi.science/1991-6639/article/view/254327">https://journals.rcsi.science/1991-6639/article/view/254327</self-uri><abstract xml:lang="en"><p>The aim of the research is to formulate general principles for ensuring information security in web-oriented information systems. The paper describes the main concepts of the Web Cryptography API interface, as well as presents practical aspects of using cryptographic methods to ensure data security in web-oriented information systems. The proposed approach, based on the introduction of a secure system for generating and storing users private keys through the use of the asynchronous ECDSA encryption algorithm via the Web Cryptography API interface, combined with encrypting private keys with passphrases and additional user authentication, allows a high level of protection of private keys from unauthorized access.</p></abstract><trans-abstract xml:lang="ru"><p>Целью исследования является формулирование общих принципов обеспечения информационной безопасности в веб-ориентированных информационных системах. В работе описаны основные концепции интерфейса Web Cryptography API, а также представлены практические аспекты использования криптографических методов для обеспечения безопасности данных веб-ориентированных информационных систем. Предложенный подход, основанный на введении безопасной системы генерации и хранения приватных ключей пользователей через использование асинхронного алгоритма шифрования ECDSA средствами интерфейса Web Cryptography API, в сочетании с шифрованием приватных ключей кодовыми словами и дополнительной аутентификацией пользователей позволяет обеспечить высокий уровень защиты приватных ключей от несанкционированного доступа.</p></trans-abstract><kwd-group xml:lang="en"><kwd>Web Cryptography API</kwd><kwd>cryptography</kwd><kwd>electronic signature</kwd><kwd>electronic document management</kwd><kwd>ECDSA</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>Web Cryptography API</kwd><kwd>криптография</kwd><kwd>электронная подпись</kwd><kwd>электронный документооборот</kwd><kwd>ECDSA</kwd></kwd-group><funding-group/></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><citation-alternatives><mixed-citation xml:lang="en">Mekhdiev E.T., Plekhanova E.A. Development of electronic document management systems in the digital economy. Diskussiya [Discussion]. 2023. No. 1(116). Pp. 58–70. DOI: 10.46320/ 2077-7639-2022-6-115-52-70. (In Russian)</mixed-citation><mixed-citation xml:lang="ru">Мехдиев Э. Т., Плеханова Е. А. Развитие систем электронного документооборота в цифровой экономике // Дискуссия. 2023. № 1(116). С. 58–70. DOI: 10.46320/2077-7639-2022-6-115-52-70</mixed-citation></citation-alternatives></ref><ref id="B2"><label>2.</label><citation-alternatives><mixed-citation xml:lang="en">Goncharov E.I., Shatkovskaya T.V. Problems of using digital signatures in electronic document management in Russia. Severo-Kavkazskiy yuridicheskiy vestnik [North Caucasian Legal Bulletin]. 2020. No. 2. Pp. 97–103. DOI: 10.22394/2074-7306-2020-1-2-97-103. (In Russian)</mixed-citation><mixed-citation xml:lang="ru">Гончаров Е. И., Шатковская Т. В. Проблемы применения цифровой подписи в электронном документообороте России // Северо-Кавказский юридический вестник. 2020. № 2. С. 97–103. DOI: 10.22394/2074-7306-2020-1-2-97-103</mixed-citation></citation-alternatives></ref><ref id="B3"><label>3.</label><citation-alternatives><mixed-citation xml:lang="en">Baranov A.S. Use of cryptographic information protection tools in organizations. Mezhdunarodnyy nauchno-issledovatel'skiy zhurnal [International Scientific Research Journal]. 2020. No. 6-1 (96). Pp. 131–133. DOI: 10.23670/IRJ.2020.96.6.023. (In Russian)</mixed-citation><mixed-citation xml:lang="ru">Баранов А. С. Использование средств криптографической защиты информации в организациях // Международный научно-исследовательский журнал. 2020. № 6-1 (96). С. 131–133. DOI: 10.23670/IRJ.2020.96.6.023</mixed-citation></citation-alternatives></ref><ref id="B4"><label>4.</label><citation-alternatives><mixed-citation xml:lang="en">Bylinskiy M.D. Protecting JavaScript applications using the Web Cryptographs Api. Vestnik Baltiyskogo federal'nogo universiteta im. I. Kanta. Seriya: Fiziko-matematicheskie i tekhnicheskie nauki [Bulletin of the Baltic Federal University. I. Kant. Series: Physics, mathematics and technical sciences]. 2022. No. 1. Pp. 53–60. (In Russian)</mixed-citation><mixed-citation xml:lang="ru">Былинский М. Д. Защита приложений javascript с помощью Web Cryptography Api // Вестник Балтийского федерального университета им. И. Канта. Серия: Физико-математические и технические науки. 2022. № 1. С. 53–60.</mixed-citation></citation-alternatives></ref><ref id="B5"><label>5.</label><citation-alternatives><mixed-citation xml:lang="en">Cairns K., Halpin H., Steel G. Security Analysis of the W3C Web Cryptography API. Proceedings of Security Standardisation Research (SSR). Gaithersberg. 2017. Pp. 112–140. DOI: 10.1007/978-3-319-49100-4_5</mixed-citation><mixed-citation xml:lang="ru">Cairns K., Halpin H., Steel G. Security Analysis of the W3C Web Cryptography API // Proceedings of Security Standardisation Research (SSR). Gaithersberg. 2017. Pp. 112–140. DOI: 10.1007/978-3-319-49100-4_5</mixed-citation></citation-alternatives></ref><ref id="B6"><label>6.</label><citation-alternatives><mixed-citation xml:lang="en">Wichmann P., Blochberger M., Federrath H. Web Cryptography API. Prevalence and Possible Developer Mistakes. In Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES '22). Association for Computing Machinery. New York. 2022. Pp. 1–10. DOI: 10.1145/3538969.3538977</mixed-citation><mixed-citation xml:lang="ru">Wichmann P., Blochberger M., Federrath H. Web Cryptography API // Prevalence and Possible Developer Mistakes. In Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES '22). Association for Computing Machinery. New York. 2022. Pp. 1–10. DOI: 10.1145/3538969.3538977</mixed-citation></citation-alternatives></ref><ref id="B7"><label>7.</label><citation-alternatives><mixed-citation xml:lang="en">Samir A., Abo-Taleb M., Shalaby et al. A Side-Channel Attack Resistive ECDSA. International Conference on Advanced Information Systems and Engineering. Journal of Physics: Conference Series. Cairo, Egypt. 2019. Pp. 112–140. DOI: 10.1088/1742-6596/1454/1/012003</mixed-citation><mixed-citation xml:lang="ru">Samir A., Abo-Taleb M., Shalaby, Nabil M., Elramly S. A Side-Channel Attack Resistive ECDSA // International Conference on Advanced Information Systems and Engineering. Journal of Physics: Conference Series. Cairo, Egypt. 2019. Pp. 112–140. DOI: 10.1088/1742-6596/1454/1/012003</mixed-citation></citation-alternatives></ref></ref-list></back></article>
