<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article
PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20190208//EN"
       "JATS-journalpublishing1.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.4" xml:lang="en">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">National Security and Strategic Planning</journal-id>
   <journal-title-group>
    <journal-title xml:lang="en">National Security and Strategic Planning</journal-title>
    <trans-title-group xml:lang="ru">
     <trans-title>Национальная безопасность и стратегическое планирование</trans-title>
    </trans-title-group>
   </journal-title-group>
   <issn publication-format="print">2307-1400</issn>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="publisher-id">6a84bbac94fbba14f785fe4a</article-id>
   <article-id pub-id-type="doi">10.37468/2307-1400-2020-3-59-68</article-id>
   <article-categories>
    <subj-group subj-group-type="toc-heading" xml:lang="ru">
     <subject>Информационная безопасность</subject>
    </subj-group>
    <subj-group subj-group-type="toc-heading" xml:lang="en">
     <subject>Information Security</subject>
    </subj-group>
    <subj-group>
     <subject>Информационная безопасность</subject>
    </subj-group>
   </article-categories>
   <title-group>
    <article-title xml:lang="en">On the problem of authentication using passwords in information interaction</article-title>
    <trans-title-group xml:lang="ru">
     <trans-title>О проблеме аутентификации с использованием паролей при информационном взаимодействии</trans-title>
    </trans-title-group>
   </title-group>
   <contrib-group content-type="authors">
    <contrib contrib-type="author">
     <name-alternatives>
      <name xml:lang="ru">
       <surname>Метельков</surname>
       <given-names>А. Н.</given-names>
      </name>
      <name xml:lang="en">
       <surname>Metelkov</surname>
       <given-names>A. N.</given-names>
      </name>
     </name-alternatives>
     <email>metelkov5178@mail.ru</email>
     <bio xml:lang="ru">
      <p>кандидат юридических наук;</p>
     </bio>
     <bio xml:lang="en">
      <p>candidate of jurisprudence sciences;</p>
     </bio>
     <xref ref-type="aff" rid="aff-1"/>
    </contrib>
   </contrib-group>
   <aff-alternatives id="aff-1">
    <aff>
     <institution xml:lang="ru">Санкт-Петербургский университет ГПС МЧС России</institution>
    </aff>
    <aff>
     <institution xml:lang="en">Saint Petersburg university of State fire service of EMERCOM of Russia</institution>
    </aff>
   </aff-alternatives>
   <fpage>59</fpage>
   <lpage>68</lpage>
   <permissions>
    <copyright-statement xml:lang="ru">© Метельков А.Н.</copyright-statement>
    <copyright-statement xml:lang="en">© Metelkov A.N.</copyright-statement>
    <copyright-holder xml:lang="ru">Метельков А. Н.</copyright-holder>
    <copyright-holder xml:lang="en">Metelkov A. N.</copyright-holder>
   </permissions>
   <self-uri xlink:href="https://futurepubl.ru/en/nauka/publications/6a84bbac94fbba14f785fe4a/view">https://futurepubl.ru/en/nauka/publications/6a84bbac94fbba14f785fe4a/view</self-uri>
   <abstract xml:lang="ru">
    <p>Среди пользователей и специалистов не утихают споры по поводу эффективности паролей, используемых для аутентификации субъектов доступа к информационным система. Актуальность выбора темы статьи объясняется применением паролей практически в любой информационной системе, а во многих системах парольная защита используется как единственное средство. При этом стойкость пароля к вскрытию нередко определяет и безопасность всей информационной системы. Проанализированы и обобщены отечественные и зарубежные современные подходы к формированию политики паролей. На этой основе выработаны предложения по совершенствованию защиты информации с использованием паролей.</p>
   </abstract>
   <trans-abstract xml:lang="en">
    <p>There is an ongoing debate among users and specialists about the effectiveness of passwords used to authenticate subjects of access to information systems. The relevance of choosing the topic of the article is explained by the use of passwords in almost any information system, and in many systems password protection is used as the only means. At the same time, the password's resistance to opening often determines the security of the entire information system. Domestic and foreign modern approaches to password policy formation are analyzed and generalized. On this basis, proposals have been developed to improve the protection of information using passwords.</p>
   </trans-abstract>
   <kwd-group xml:lang="ru">
    <kwd>аутентификация</kwd>
    <kwd>пароли</kwd>
    <kwd>длина пароля</kwd>
    <kwd>парольная политика</kwd>
    <kwd>пользователи информационной системы</kwd>
    <kwd>многофакторная аутентификация</kwd>
    <kwd>криптографические методы аутентификации</kwd>
    <kwd>алфавит пароля</kwd>
    <kwd>строгая аутентификация</kwd>
    <kwd>управление паролями</kwd>
   </kwd-group>
   <kwd-group xml:lang="en">
    <kwd>authentication</kwd>
    <kwd>passwords</kwd>
    <kwd>password length</kwd>
    <kwd>password policy</kwd>
    <kwd>information system users</kwd>
    <kwd>multi-factor authentication</kwd>
    <kwd>cryptographic authentication methods</kwd>
    <kwd>password alphabet</kwd>
    <kwd>strong authentication</kwd>
    <kwd>password management</kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <p></p>
 </body>
 <back>
  <ref-list>
   <ref id="B1">
    <label>1.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Гатчин Ю.А., Теплоухова О.А. Алгоритм аутентификации участников информационного взаимодействия при удаленной загрузке операционной системы на тонкий клиент // Научно-технический вестник информационных технологий, механики и оптики. - 2016. - Том 16. - № 3. - С.497-505.</mixed-citation>
     <mixed-citation xml:lang="en">Gatchin Yu.A., Teplouhova O.A. Algoritm autentifikacii uchastnikov informacionnogo vzaimodeystviya pri udalennoy zagruzke operacionnoy sistemy na tonkiy klient // Nauchno-tehnicheskiy vestnik informacionnyh tehnologiy, mehaniki i optiki. - 2016. - Tom 16. - № 3. - S.497-505.</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B2">
    <label>2.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Герман Греф: я - игрок в долгую. 29 июня 2020 г. [Электронный ресурс]. - Режим доступа: https://tass.ru/business-officials/8827375 (дата обращения 03.07.2020)</mixed-citation>
     <mixed-citation xml:lang="en">German Gref: ya - igrok v dolguyu. 29 iyunya 2020 g. [Elektronnyy resurs]. - Rezhim dostupa: https://tass.ru/business-officials/8827375 (data obrascheniya 03.07.2020)</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B3">
    <label>3.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Комарова А.В. Методы повышения безопасности комбинированных схем аутентификации. Дисс. …. кан. технич. наук. Специальность: 05.13.19. - СПб, 2019. - С.16.</mixed-citation>
     <mixed-citation xml:lang="en">Komarova A.V. Metody povysheniya bezopasnosti kombinirovannyh shem autentifikacii. Diss. …. kan. tehnich. nauk. Special'nost': 05.13.19. - SPb, 2019. - S.16.</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B4">
    <label>4.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Введение в информационную безопасность: Учебное пособие для вузов / А. А. Малюк, В. С. Горбатов, В. И. Королев и др.; Под ред. В. С. Горбатова. − М.: Горячая линия - Телеком, 2018 - 288 с.</mixed-citation>
     <mixed-citation xml:lang="en">Vvedenie v informacionnuyu bezopasnost': Uchebnoe posobie dlya vuzov / A. A. Malyuk, V. S. Gorbatov, V. I. Korolev i dr.; Pod red. V. S. Gorbatova. − M.: Goryachaya liniya - Telekom, 2018 - 288 s.</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B5">
    <label>5.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Пользователи хотят отказаться от паролей [Электронный ресурс]. - Режим доступа: https://www.azone-it.ru/polzovateli-hotyat-otkazatsya-ot-paroley (дата обращения  9.06.2020)</mixed-citation>
     <mixed-citation xml:lang="en">Pol'zovateli hotyat otkazat'sya ot paroley [Elektronnyy resurs]. - Rezhim dostupa: https://www.azone-it.ru/polzovateli-hotyat-otkazatsya-ot-paroley (data obrascheniya  9.06.2020)</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B6">
    <label>6.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Сулавко А. Е., Жумажанова С. С., Фофанов  Г. А. Перспективные нейросетевые алгоритмы распознавания динамических биометрических образов в пространстве взаимосвязанных признаков // Динамика систем, механизмов и машин. - 2018. - Том 6. - № 4. - С.130.</mixed-citation>
     <mixed-citation xml:lang="en">Sulavko A. E., Zhumazhanova S. S., Fofanov  G. A. Perspektivnye neyrosetevye algoritmy raspoznavaniya dinamicheskih biometricheskih obrazov v prostranstve vzaimosvyazannyh priznakov // Dinamika sistem, mehanizmov i mashin. - 2018. - Tom 6. - № 4. - S.130.</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B7">
    <label>7.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Шелупанов А.А., Евсютин О.О., Конев А.А. и др. Актуальные направления развития методов и средств защиты информации // Доклады ТУСУР. - 2017. - Т. 20. - № 3. - С.15</mixed-citation>
     <mixed-citation xml:lang="en">Shelupanov A.A., Evsyutin O.O., Konev A.A. i dr. Aktual'nye napravleniya razvitiya metodov i sredstv zaschity informacii // Doklady TUSUR. - 2017. - T. 20. - № 3. - S.15</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B8">
    <label>8.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Яровицын Р. Полковника подвел пароль: Андрея Солдаткина осудили за неправомерный доступ к информации МВД // Коммерсантъ (Н.Новгород) №101 от 09.06.2020. с.8. [Электронный ресурс]. - Режим доступа: https://www.kommersant.ru/doc/4373270 (дата обращения 10.06.2020).</mixed-citation>
     <mixed-citation xml:lang="en">Yarovicyn R. Polkovnika podvel parol': Andreya Soldatkina osudili za nepravomernyy dostup k informacii MVD // Kommersant' (N.Novgorod) №101 ot 09.06.2020. s.8. [Elektronnyy resurs]. - Rezhim dostupa: https://www.kommersant.ru/doc/4373270 (data obrascheniya 10.06.2020).</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B9">
    <label>9.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Greene, Mike. 4 Automated Password Policy Enforcers for NIST Password Guidelines. Automate Screening of Exposed Passwords and Password Policy Enforcement, November 15, 2019. [Электронный ресурс]. - Режим доступа: https://www.bankinfosecurity.com/blogs/enzoic-blog-3-6-x2-p-2803 (дата обращения: 13.08.2020).</mixed-citation>
     <mixed-citation xml:lang="en">Greene, Mike. 4 Automated Password Policy Enforcers for NIST Password Guidelines. Automate Screening of Exposed Passwords and Password Policy Enforcement, November 15, 2019. [Elektronnyy resurs]. - Rezhim dostupa: https://www.bankinfosecurity.com/blogs/enzoic-blog-3-6-x2-p-2803 (data obrascheniya: 13.08.2020).</mixed-citation>
    </citation-alternatives>
   </ref>
   <ref id="B10">
    <label>10.</label>
    <citation-alternatives>
     <mixed-citation xml:lang="ru">Pandey, Dr.Anand. Password Management Using OTP Authentication // International Journal Of Advanced Research In  Engineering Technology &amp; Sciences. - 2015. - Vol. 2. - Is.3. - р.101-105. [Электронный ресурс]. - Режим доступа: https://www.researchgate.net/publication/292148986_Password_Management_Using_OTP_Authentication.</mixed-citation>
     <mixed-citation xml:lang="en">Pandey, Dr.Anand. Password Management Using OTP Authentication // International Journal Of Advanced Research In  Engineering Technology &amp; Sciences. - 2015. - Vol. 2. - Is.3. - r.101-105. [Elektronnyy resurs]. - Rezhim dostupa: https://www.researchgate.net/publication/292148986_Password_Management_Using_OTP_Authentication.</mixed-citation>
    </citation-alternatives>
   </ref>
  </ref-list>
 </back>
</article>
