Post-quantum multi-factor authentication in multi-domain identity federations with adaptive security policy management

User Rating:  / 0
PoorBest 

Authors:


Ye. Zhyvylo, orcid.org/0000-0003-4077-7853, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine

A. Yanko*, orcid.org/0000-0003-2876-9316, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine

e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

Yu. Kuchma, orcid.org/0009-0002-5498-4271, Limited Liability Company Private Higher Education Institution “University of Modern Technologies”, Kyiv, Ukraine

T. Fesenko, orcid.org/0009-0006-1698-3795, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine

Yu. Kalashnikova, orcid.org/0000-0001-9899-4784, National University “Yuri Kondratyuk Poltava Polytechnic”, Poltava, Ukraine

* Corresponding author e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.


повний текст / full article



Naukovyi Visnyk Natsionalnoho Hirnychoho Universytetu. 2026, (4): 146 - 155

https://doi.org/10.33271/nvngu/2026-4/146



Abstract:



Purpose.
The study aims to develop and provide a theoretical and technical substantiation for a post-quantum multi-factor authentication (PQ-MFA) architecture tailored for multi-domain identity federations. The goal is to enhance the resilience of access control systems against quantum threats while ensuring adaptive security policy management.


Methodology.
The research methodology integrates an analytical review of contemporary federated identity management models, the selection of post-quantum cryptographic primitives, and architectural modeling of the authentication system. The architecture is designed based on the principles of modularity, trust distribution, and adaptive security policy management. The proposed approach is evaluated through a qualitative analysis of its quantum resistance, compatibility with federated access models, and alignment with the requirements of modern identity management systems.


Findings.
An adaptive post-quantum authentication architecture for multi-domain federations has been developed, leveraging hybrid cryptographic algorithms (Kyber, Dilithium, and Falcon). The core component of the system is an intelligent Policy Manager module, which performs real-time dynamic adjustment of access factors based on risk-oriented analysis of context and behavioral patterns. Experimental validation confirmed a 30–40 % reduction in session compromise probability and a 15 % increase in risk prediction accuracy while maintaining acceptable latency thresholds. The proposed solution integrates seamlessly with OIDC, SAML, and FIDO2 protocols, establishing a scientifically grounded framework for the next generation of adaptive post-quantum authentication systems within the Zero Trust Identity Fabric paradigm.


Originality.
The architecture of adaptive post-quantum authentication has been improved through the implementation of a Policy Manager module based on the BR-MDP model, which provides context-aware adaptation of cryptographic primitives to the risk level. A multicriteria model for evaluating system effectiveness has been proposed, which, unlike existing approaches, allows for a coordinated analysis of cryptographic resilience, computational delay, and policy stability within a multi-domain federated environment.


Practical value.
The research findings can be applied to the secure integration of post-quantum cryptographic mechanisms into corporate identity management systems and Zero Trust Identity Fabric architectures. The established principles provide a methodological framework for developing and standardizing robust authentication mechanisms in the post-quantum era. The proposed approaches are suitable for practical implementation during the modernization of existing information systems without requiring a complete overhaul of their software infrastructure.



Keywords:
post-quantum cryptography, multi-factor authentication, security policies, machine learning, Zero Trust Architecture

References.


1. Lund, B. D., & Shahriar, S. (2025). Quantum Computing: A Concise Introduction. Encyclopedia, 5(4), 173. https://doi.org/10.3390/encyclopedia5040173

2. Abbasi, M., Cardoso, F., Váz, P., Silva, J., & Martins, P. (2025). A Practical Performance Benchmark of Post-Quantum Cryptography Across Heterogeneous Computing Environments. Cryptography, 9(2), 32. https://doi.org/10.3390/cryptography9020032

3. Yanko, A., Krasnobayev, V., Hlushko, A., & Myziura, M. (2025). Implementation of cryptographic transformations for digital security using the Residue Number System. 13 th International Scientific and Practical Conference “Information Control Systems & Technologies” (ICST-2025). CEUR Workshop Proceedings, 4048, (pp. 55-67). https://ceur-ws.org/Vol-4048/paper05.pdf

4. Shyshatskyi, A., Zvieriev, O., Salnikova, O., Demchenko, Y., Trotsko, O., & Neroznak, Y. (2020). Complex methods of processing different data in intellectual systems for decision support system. International Journal of Advanced Trends in Computer Science and Engineering, 9(4), 5583-5590. https://doi.org/10.30534/ijatcse/2020/206942020

5. Alsadeh, A., Yatim, N., & Hassouneh, Y. (2022). A Dynamic Federated Identity Management Using OpenID Connect. Future Internet, 14(11), 339. https://doi.org/10.3390/fi14110339

6. Almohri, H. M. J. (2025). Alohomora: Workflow-Aware Authentication and Authorization in Heterogeneous Systems. Network, 5(4), 51. https://doi.org/10.3390/network5040051

7. Han, A. H., & Lee, D. H. (2023). Detecting Risky Authentication Using the OpenID Connect Token Exchange Time. Sensors, 23(19), 8256. https://doi.org/10.3390/s23198256

8. NIST Computer Security Resource Center (2025). NIST Computer Security Resource Center. (n.d.). Post-Quantum Cryptography (PQC). https://csrc.nist.gov/projects/post-quantum-cryptography

9. Temoshok, D., Proud-Madruga, D., Choong, Y.-Y., Galluzzo, R., Gupta, S., LaSalle, C., Lefkovitz, N., & Regenscheid, A. (2024). NIST SP 800-63-4: Digital identity guidelines. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63-4

10.      International Organization for Standardization & International Electrotechnical Commission (2025). Information security, cybersecurity and privacy protection – A framework for identity management – Part 1: Core concepts and terminology (ISO/IEC Standard No. 24760-1:2025). https://www.iso.org/standard/24760-1

11.      International Organization for Standardization (2013). Information technology — Security techniques — Entity authentication assurance framework (ISO/IEC Standard No. 29115:2013, reconfirmed in 2020). https://www.iso.org/standard/45138.html

12.      Li, F., Wang, J., Shang, M., Zhang, D., & Li, T. (2023). Research on Quantum-Attack-Resistant Strong Forward-Secure Signature Schemes. Entropy, 25(8), 1159. https://doi.org/10.3390/e25081159

13.      National Institute of Standards and Technology (2024). Federal Information Processing Standards Publication: ModuleLatticeBased KeyEncapsulation Mechanism Standard (FIPS 203). U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.203

14.      National Institute of Standards and Technology (2024). Federal Information Processing Standards Publication: ModuleLatticeBased Digital Signature Standard (FIPS 204). U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.204

15.      National Institute of Standards and Technology (2024). FIPS 205: Stateless HashBased Digital Signature Standard. U.S. Department of Commerce. https://doi.org/10.6028/NIST.FIPS.205

16.      International Organization for Standardization & International Electrotechnical Commission (2025). Information security, cybersecurity and privacy protection ‒ A framework for identity management ‒ Part 3: Practice (ISO/IEC Standard No. 24760-3:2025). https://www.iso.org/standard/24760-3

17.      Aramide, O. O. (2022). Post-Quantum Cryptography (PQC) for Identity Management. Adhyayan: A Journal of Management Sciences, 12(02), 59-67. https://doi.org/10.21567/adhyayan.v12i2.11

18.      Wen, Y., Su, Y., & Li, W. (2025). Post-Quantum Secure Multi-Factor Authentication Protocol for Multi-Server Architecture. Entropy, 27(7), 765. https://doi.org/10.3390/e27070765

19.      Zdorenko, Y., Yanko, A., Myziura, M., & Fesokha, N. (2025). Development of a fuzzy risk assessment model for information security management. Technology Audit and Production Reserves, 4(2(84)), 71-79. https://doi.org/10.15587/2706-5448.2025.334954

20.      Onyshchenko, S., Haitan, O., Yanko, A., Zdorenko, Yu., & Rudenko, O. (2024). Method for detection of the modified DDoS cyber attacks on a web resource of an Information and Telecommunication Network based on the use of intelligent systems. Modern Data Science Technologies Workshop (MoDaST 2024). CEUR Workshop Proceedings, 3723, 219-235. https://ceur-ws.org/Vol-3723/paper12.pdf

21.      Chennuri, K. M. R. (2024). Adaptive Multi-Factor Authentication Systems: A Comprehensive Analysis of Modern Security Approaches. International Journal of Computer Engineering and Technology, 15(6), 787-795. https://doi.org/10.5281/zenodo.14235976

22.      Singh, J., Patel, C., & Chaudhary, N. K. (2024). Resilient risk-based adaptive authentication and authorization (RAD-AA) framework. In S. J. Patel, N. K. Chaudhary, B. N. Gohil, & S. S. Iyengar (Eds.). Information Security, Privacy and Digital Forensics, 1075, (pp. 317-328). Springer. https://doi.org/10.1007/978-981-99-5091-1_27

23.      Ruban, I., Horenskyi, H., Romanenkov, Y., & Revenko, D. (2022). Models of adaptive integration of weighted interval data in tasks of predictive expert assessment. Eastern-European Journal of Enterprise Technologies, 5(4(119)), 6-15. https://doi.org/10.15587/1729-4061.2022.265782

24.      Romanenkov, Y., Danova, M., Kashcheyeva, V., Bugaienko, O., Volk, M., Karminska-Bielobrova, M., & Lobach, O. (2018). Complexification methods of interval forecast estimates in the problems on short­term prediction. Eastern-European Journal of Enterprise Technologies, 3(3(93)), 50-58. https://doi.org/10.15587/1729-4061.2018.131939

25.      Laktionov, A. (2019). Application of index estimates for improving accuracy during selection of machine operators. Eastern-European Journal of Enterprise Technologies, 3(1(99)), 18-26. https://doi.org/10.15587/1729-4061.2019.165884

26.      Ghashghaei, F. R., Ahmed, Y., Elmrabit, N., & Yousefi, M. (2024). Enhancing the Security of Classical Communication with Post-Quantum Authenticated-Encryption Schemes for the Quantum Key Distribution. Computers, 13(7), 163. https://doi.org/10.3390/computers13070163

27.      Banerjee, T. (2025). Post-quantum cryptography: Reshaping the future of identity and access management. World Journal of Advanced Engineering Technology and Sciences, 15(2), 350-356. https://doi.org/10.30574/wjaets.2025.15.2.0567

28.      Kashkevich, S., Shyshatskyi, A., Dmytriieva, O., Zhyvylo, Y., Plekhova, G., & Neronov, S. (2024). The development of management methods based on bio-inspired algorithms. Information and control systems: Modelling and optimizations, (pp. 35-69). PC TECHNOLOGY CENTER. https://doi.org/10.15587/978-617-8360-04-7.CH2

29.      IETF PQUIP Working Group (2024). Post-quantum cryptography for engineers (Internet-Draft draft-ietf-pquip-pqc-engineers-00). IETF Datatracker. https://datatracker.ietf.org/doc/draft-ietf-pquip-pqc-engineers/00/

30.      Onyshchenko, S., Bilko, S., Yanko, A., & Sivitska, S. (2023). Business information security. V. Onyshchenko, G. Mammadova, S. Sivitska, & A. Gasimov (Eds.). Proceedings of the 4 th International Conference on Building Innovations. ICBI 2022, 299, (pp. 769-778). Springer, Cham. https://doi.org/10.1007/978-3-031-17385-1_65

 

Guest Book

If you have questions, comments or suggestions, you can write them in our "Guest Book"

Registration data

ISSN (print) 2071-2227,
ISSN (online) 2223-2362.
Journal was registered by Ministry of Justice of Ukraine.
Registration number КВ No.17742-6592PR dated April 27, 2011.

Contacts

D.Yavornytskyi ave.,19, pavilion 3, room 24-а, Dnipro, 49005
Tel.: +38 (066) 379 72 44.
e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
You are here: Home Home EngCat Archive 2026 Content №4 2026 Post-quantum multi-factor authentication in multi-domain identity federations with adaptive security policy management