MODEL FOR PREVENTING CYBER FRAUD IN THE USE OF QUALIFIED ELECTRONIC SIGNATURES
Keywords:
квалифициран електронен подпис, киберизмами, цифрова идентичностAbstract
This paper analyses the main types of cyber fraud associated with the use of qualified electronic signatures and systematises methods for their prevention. The study examines technical, organisational and behavioural safeguards, including certificate lifecycle management, multi-factor authentication, private key protection, anomaly monitoring, user awareness and incident response procedures. A multi-layered prevention model is proposed for reducing the risk of misuse of qualified electronic signatures in public administration, the financial sector and organisations using trust services.
Downloads
References
1. Ангелов, А. (1986). Криминалистическо изследване на почерка и признаците на писмената реч. София: НИКК.
2. Беленски, Р. (1999). Съдебно-почеркова експертиза. София: Софи-Р.
3. Бенчев, С., & Несторов, Д. (2009). Ръководство за определяне строежа на писмените знаци и арабските цифри за нуждите на почерковите изследвания. София: НИКК – МВР.
4. Закон за електронния документ и електронните удостоверителни услуги. Държавен вестник.
5. Лозев, С. (1972). Определяне строежа на ръкописните букви и арабските цифри. София: НИКК.
6. Anderson, R. (2020). Security Engineering (3rd ed.). Wiley.
7. Bishop, M. (2018). Computer Security: Art and Science. Addison-Wesley.
8. Casey, E. (2020). Digital Evidence and Computer Crime (4th ed.). Academic Press.
9. ETSI. (2021). ETSI EN 319 411-1 – Policy and security requirements for trust service providers issuing certificates.
10. ETSI. (2021). ETSI EN 319 411-2 – Requirements for qualified trust service providers.
11. ETSI. (2024). ETSI EN 319 401 – General Policy Requirements for Trust Service Providers.
12. European Parliament and Council. (2014). Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS). Official Journal of the European Union.
13. European Parliament and Council. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR). Official Journal of the European Union.
14. European Parliament and Council. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2). Official Journal of the European Union.
15. European Parliament and Council. (2024). Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. Official Journal of the European Union.
16. European Union Agency for Cybersecurity (ENISA). (2024). ENISA Threat Landscape 2024. Athens: ENISA.
17. European Union Agency for Cybersecurity (ENISA). (2024). Guidelines on Electronic Identification and Trust Services. Athens: ENISA.
18. Ferguson, N., Schneier, B., & Kohno, T. (2010). Cryptography Engineering. Wiley.
19. International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements.
20. International Organization for Standardization. (2022). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls.
21. International Organization for Standardization. (2022). ISO/IEC 27005:2022 Information security risk management.
22. International Organization for Standardization. (2012). ISO/IEC 27037:2012 Guidelines for identification, collection, acquisition and preservation of digital evidence.
23. International Organization for Standardization. (2015). ISO/IEC 27042:2015 Guidelines for the analysis and interpretation of digital evidence.
24. Menezes, A. J., Van Oorschot, P. C., & Vanstone, S. A. (1996). Handbook of Applied Cryptography. CRC Press.
25. National Institute of Standards and Technology (NIST). (2020). Special Publication 800-63: Digital Identity Guidelines.
26. National Institute of Standards and Technology (NIST). (2024). Cybersecurity Framework (CSF 2.0). Gaithersburg, MD: NIST.
27. Nelson, B., Phillips, A., & Steuart, C. (2019). Guide to Computer Forensics and Investigations. Cengage.
28. Schneier, B. (2015). Applied Cryptography (20th Anniversary ed.). Wiley.
29. Stallings, W. (2017). Cryptography and Network Security: Principles and Practice (7th ed.). Pearson.
30. Whitman, M. E., & Mattord, H. J. (2022). Principles of Information Security. Cengage Learning.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Петя Петрова

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Articles published in "Computer Science and Communications" Magazine are licensed under Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.