ISSN 2519-4216 e-ISSN 2519-4313 UDC 34

Mariia Turchina, Igor Rudenko, Olha Khorolska · Ûridičnij časopis Nacìonalʹnoï akademìï vnutrìšnìh sprav · 2025

The relevance of the study was determined by the need for legal and technical rethinking of state regulation of cryptographic information protection under the conditions of Ukraine’s digital transformation. The aim of the article was to identify the effectiveness of the existing regulatory, institutional, and technical model for data cryptographic protection, taking into account the provisions of international standards. The study applied methods of structural-functional analysis, systematic comparison of legal provisions, and content analysis of technical requirements. As a result of the study, it was established that the regulatory field covered two levels of influence – general technical and specialised – yet only approximately sixty percent of the provisions on electronic signature, cryptographic key management, and timestamps corresponded to international technical requirements. Fragmentation in the definition of mandatory certification procedures and the absence of unified regulations in the field of digital identification and electronic seals were recorded. Within the framework of interinstitutional interaction, it was found that only three out of eight functional areas were governed by formalised mechanisms, which complicated the response to cryptographic incidents. Technical analysis confirmed that the average key length in cryptographic algorithms resistant to quantum computing systems exceeded three thousand bits – two to three times higher than the parameters of traditional algorithms – yet the implementation of such solutions into the state certification system was limited. It was also established that only a portion of cryptographic protection hardware complied with international technical security level requirements. The practical significance of the study results lay in the potential application for updating the regulatory architecture, forming technical regulations, developing state control procedures, and supporting public authorities, technical expert units, and developers in the implementation of the national cybersecurity strategy

Read the paper · More papers on PaperTik