Post-quantum multi-factor authentication in multi-domain identity federations with adaptive security policy management
- Details
- Parent Category: 2026
- Category: Content №4 2026
- Created on 24 August 2026
- Last Updated on 24 August 2026
- Published on 30 November -0001
- Written by Ye. Zhyvylo, A. Yanko, Yu. Kuchma, T. Fesenko, Yu. Kalashnikova
- Hits: 1231
Authors:
Ye. Zhyvylo, orcid.org/0000-0003-4077-7853, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine
A. Yanko*, orcid.org/0000-0003-2876-9316, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine
e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
Yu. Kuchma, orcid.org/0009-0002-5498-4271, Limited Liability Company Private Higher Education Institution “University of Modern Technologies”, Kyiv, Ukraine
T. Fesenko, orcid.org/0009-0006-1698-3795, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine
Yu. Kalashnikova, orcid.org/0000-0001-9899-4784, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine
* Corresponding author e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
Naukovyi Visnyk Natsionalnoho Hirnychoho Universytetu. 2026, (4): 146 - 155
https://doi.org/10.33271/nvngu/2026-4/146
Abstract:
Purpose. The study aims to develop and provide a theoretical and technical substantiation for a post-quantum multi-factor authentication (PQ-MFA) architecture tailored for multi-domain identity federations. The goal is to enhance the resilience of access control systems against quantum threats while ensuring adaptive security policy management.
Methodology. The research methodology integrates an analytical review of contemporary federated identity management models, the selection of post-quantum cryptographic primitives, and architectural modeling of the authentication system. The architecture is designed based on the principles of modularity, trust distribution, and adaptive security policy management. The proposed approach is evaluated through a qualitative analysis of its quantum resistance, compatibility with federated access models, and alignment with the requirements of modern identity management systems.
Findings. An adaptive post-quantum authentication architecture for multi-domain federations has been developed, leveraging hybrid cryptographic algorithms (Kyber, Dilithium, and Falcon). The core component of the system is an intelligent Policy Manager module, which performs real-time dynamic adjustment of access factors based on risk-oriented analysis of context and behavioral patterns. Experimental validation confirmed a 30–40 % reduction in session compromise probability and a 15 % increase in risk prediction accuracy while maintaining acceptable latency thresholds. The proposed solution integrates seamlessly with OIDC, SAML, and FIDO2 protocols, establishing a scientifically grounded framework for the next generation of adaptive post-quantum authentication systems within the Zero Trust Identity Fabric paradigm.
Originality. The architecture of adaptive post-quantum authentication has been improved through the implementation of a Policy Manager module based on the BR-MDP model, which provides context-aware adaptation of cryptographic primitives to the risk level. A multicriteria model for evaluating system effectiveness has been proposed, which, unlike existing approaches, allows for a coordinated analysis of cryptographic resilience, computational delay, and policy stability within a multi-domain federated environment.
Practical value. The research findings can be applied to the secure integration of post-quantum cryptographic mechanisms into corporate identity management systems and Zero Trust Identity Fabric architectures. The established principles provide a methodological framework for developing and standardizing robust authentication mechanisms in the post-quantum era. The proposed approaches are suitable for practical implementation during the modernization of existing information systems without requiring a complete overhaul of their software infrastructure.
Keywords: post-quantum cryptography, multi-factor authentication, security policies, machine learning, Zero Trust Architecture
References.
1. Lund, B. D., & Shahriar, S. (2025). Quantum Computing: A Concise Introduction. Encyclopedia, 5(4), 173. https://doi.org/10.3390/encyclopedia5040173
2. Abbasi, M., Cardoso, F., Váz, P., Silva, J., & Martins, P. (2025). A Practical Performance Benchmark of Post-Quantum Cryptography Across Heterogeneous Computing Environments. Cryptography, 9(2), 32. https://doi.org/10.3390/cryptography9020032
3. Yanko, A., Krasnobayev, V., Hlushko, A., & Myziura, M. (2025). Implementation of cryptographic transformations for digital security using the Residue Number System. 13 th International Scientific and Practical Conference “Information Control Systems & Technologies” (ICST-2025). CEUR Workshop Proceedings, 4048, (pp. 55-67). https://ceur-ws.org/Vol-4048/paper05.pdf
4. Shyshatskyi, A., Zvieriev, O., Salnikova, O., Demchenko, Y., Trotsko, O., & Neroznak, Y. (2020). Complex methods of processing different data in intellectual systems for decision support system. International Journal of Advanced Trends in Computer Science and Engineering, 9(4), 5583-5590. https://doi.org/10.30534/ijatcse/2020/206942020
5. Alsadeh, A., Yatim, N., & Hassouneh, Y. (2022). A Dynamic Federated Identity Management Using OpenID Connect. Future Internet, 14(11), 339. https://doi.org/10.3390/fi14110339
6. Almohri, H. M. J. (2025). Alohomora: Workflow-Aware Authentication and Authorization in Heterogeneous Systems. Network, 5(4), 51. https://doi.org/10.3390/network5040051
7. Han, A. H., & Lee, D. H. (2023). Detecting Risky Authentication Using the OpenID Connect Token Exchange Time. Sensors, 23(19), 8256. https://doi.org/10.3390/s23198256
8. NIST Computer Security Resource Center (2025). NIST Computer Security Resource Center. (n.d.). Post-Quantum Cryptography (PQC). https://csrc.nist.gov/projects/post-quantum-cryptography
9. Temoshok, D., Proud-Madruga, D., Choong, Y.-Y., Galluzzo, R., Gupta, S., LaSalle, C., Lefkovitz, N., & Regenscheid, A. (2024). NIST SP 800-63-4: Digital identity guidelines. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63-4
10. International Organization for Standardization & International Electrotechnical Commission (2025). Information security, cybersecurity and privacy protection – A framework for identity management – Part 1: Core concepts and terminology (ISO/IEC Standard No. 24760-1:2025). https://www.iso.org/standard/24760-1
11. International Organization for Standardization (2013). Information technology — Security techniques — Entity authentication assurance framework (ISO/IEC Standard No. 29115:2013, reconfirmed in 2020). https://www.iso.org/standard/45138.html
12. Li, F., Wang, J., Shang, M., Zhang, D., & Li, T. (2023). Research on Quantum-Attack-Resistant Strong Forward-Secure Signature Schemes. Entropy, 25(8), 1159. https://doi.org/10.3390/e25081159
13. National Institute of Standards and Technology (2024). Federal Information Processing Standards Publication: ModuleLatticeBased KeyEncapsulation Mechanism Standard (FIPS 203). U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.203
14. National Institute of Standards and Technology (2024). Federal Information Processing Standards Publication: ModuleLatticeBased Digital Signature Standard (FIPS 204). U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.204
15. National Institute of Standards and Technology (2024). FIPS 205: Stateless HashBased Digital Signature Standard. U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.205
16. International Organization for Standardization & International Electrotechnical Commission (2025). Information security, cybersecurity and privacy protection ‒ A framework for identity management ‒ Part 3: Practice (ISO/IEC Standard No. 24760-3:2025). https://www.iso.org/standard/24760-3
17. Aramide, O. O. (2022). Post-Quantum Cryptography (PQC) for Identity Management. Adhyayan: A Journal of Management Sciences, 12(02), 59-67. https://doi.org/10.21567/adhyayan.v12i2.11
18. Wen, Y., Su, Y., & Li, W. (2025). Post-Quantum Secure Multi-Factor Authentication Protocol for Multi-Server Architecture. Entropy, 27(7), 765. https://doi.org/10.3390/e27070765
19. Zdorenko, Y., Yanko, A., Myziura, M., & Fesokha, N. (2025). Development of a fuzzy risk assessment model for information security management. Technology Audit and Production Reserves, 4(2(84)), 71-79. https://doi.org/10.15587/2706-5448.2025.334954
20. Onyshchenko, S., Haitan, O., Yanko, A., Zdorenko, Yu., & Rudenko, O. (2024). Method for detection of the modified DDoS cyber attacks on a web resource of an Information and Telecommunication Network based on the use of intelligent systems. Modern Data Science Technologies Workshop (MoDaST 2024). CEUR Workshop Proceedings, 3723, 219-235. https://ceur-ws.org/Vol-3723/paper12.pdf
21. Chennuri, K. M. R. (2024). Adaptive Multi-Factor Authentication Systems: A Comprehensive Analysis of Modern Security Approaches. International Journal of Computer Engineering and Technology, 15(6), 787-795. https://doi.org/10.5281/zenodo.14235976
22. Singh, J., Patel, C., & Chaudhary, N. K. (2024). Resilient risk-based adaptive authentication and authorization (RAD-AA) framework. In S. J. Patel, N. K. Chaudhary, B. N. Gohil, & S. S. Iyengar (Eds.). Information Security, Privacy and Digital Forensics, 1075, (pp. 317-328). Springer. https://doi.org/10.1007/978-981-99-5091-1_27
23. Ruban, I., Horenskyi, H., Romanenkov, Y., & Revenko, D. (2022). Models of adaptive integration of weighted interval data in tasks of predictive expert assessment. Eastern-European Journal of Enterprise Technologies, 5(4(119)), 6-15. https://doi.org/10.15587/1729-4061.2022.265782
24. Romanenkov, Y., Danova, M., Kashcheyeva, V., Bugaienko, O., Volk, M., Karminska-Bielobrova, M., & Lobach, O. (2018). Complexification methods of interval forecast estimates in the problems on shortterm prediction. Eastern-European Journal of Enterprise Technologies, 3(3(93)), 50-58. https://doi.org/10.15587/1729-4061.2018.131939
25. Laktionov, A. (2019). Application of index estimates for improving accuracy during selection of machine operators. Eastern-European Journal of Enterprise Technologies, 3(1(99)), 18-26. https://doi.org/10.15587/1729-4061.2019.165884
26. Ghashghaei, F. R., Ahmed, Y., Elmrabit, N., & Yousefi, M. (2024). Enhancing the Security of Classical Communication with Post-Quantum Authenticated-Encryption Schemes for the Quantum Key Distribution. Computers, 13(7), 163. https://doi.org/10.3390/computers13070163
27. Banerjee, T. (2025). Post-quantum cryptography: Reshaping the future of identity and access management. World Journal of Advanced Engineering Technology and Sciences, 15(2), 350-356. https://doi.org/10.30574/wjaets.2025.15.2.0567
28. Kashkevich, S., Shyshatskyi, A., Dmytriieva, O., Zhyvylo, Y., Plekhova, G., & Neronov, S. (2024). The development of management methods based on bio-inspired algorithms. Information and control systems: Modelling and optimizations, (pp. 35-69). PC TECHNOLOGY CENTER. https://doi.org/10.15587/978-617-8360-04-7.CH2
29. IETF PQUIP Working Group (2024). Post-quantum cryptography for engineers (Internet-Draft draft-ietf-pquip-pqc-engineers-00). IETF Datatracker. https://datatracker.ietf.org/doc/draft-ietf-pquip-pqc-engineers/00/
30. Onyshchenko, S., Bilko, S., Yanko, A., & Sivitska, S. (2023). Business information security. V. Onyshchenko, G. Mammadova, S. Sivitska, & A. Gasimov (Eds.). Proceedings of the 4 th International Conference on Building Innovations. ICBI 2022, 299, (pp. 769-778). Springer, Cham. https://doi.org/10.1007/978-3-031-17385-1_65
Newer news items:
- Legal support for the right to entrepreneurial activity in Ukraine on the path to European integration - 24/08/2026 21:43
- Property rights: legal guarantees of security in Ukraine under martial state - 24/08/2026 21:43
- Conceptual principles of developing a system of state control of defence procurement in Ukraine - 24/08/2026 21:43
- Does privacy paradox survive when context matters? - 24/08/2026 21:43
- Modelling impact of hybrid methodology on performance of IT-enterprises - 24/08/2026 21:43
- The role of U.S. universities in reintegration of veterans: case of USC - 24/08/2026 21:43
- The innovation ecosystem as a tool for supporting Ukraine’s strategic industries - 24/08/2026 21:43
- Forecasting the development of innovative entrepreneurship ecosystems in entropic conditions - 24/08/2026 21:43
- Low-jitter reference-based synchronization for dual RF transmitters - 24/08/2026 21:43
- Detection of anomalies in local traffic using secure gating networks - 24/08/2026 21:43
Older news items:
- Robotic complex for radiation reconnaissance and detection of ionizing radiation sources - 24/08/2026 21:43
- A hybrid ANN–FEM framework for high accuracy slope stability prediction - 24/08/2026 21:43
- Proportional response to criminal offences against the environment - 24/08/2026 21:43
- The potential of using hyperspectral airborne data in monitoring post-mining novel ecosystems - 24/08/2026 21:43
- Directions for the enhancement of methodological support of the psychosocial risk management process - 24/08/2026 21:43
- Comparison of impulse processes in spatially shifted ring-like cores made of ferrite and thin sheet steel - 24/08/2026 21:43
- Stability and bifurcations of eccentrically reinforced compound shell structures by means of computer algebra - 24/08/2026 21:43
- Intelligent control of in-wheel motors in a vehicle with analytical determination of torque distribution - 24/08/2026 21:43
- Phase composition of multicomponent aluminum bronzes criteria-based evaluation (Part 1. Supersaturated copper α-matrix and phase composition of Cu–Al–X system multicomponent bronzes stability criteria) - 24/08/2026 21:43
- Reduction of the visibility of a motor generator set in urban conditions using artificial intelligence technologies - 24/08/2026 21:43



