<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">9</article-id>
      <article-id pub-id-type="doi">10.66424/2071-8217-2026-1-9</article-id>
      <title-group>
        <article-title>Multi-level model of secure interoperability in e-commerce based on a security profile</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Многоуровневая модель безопасной интероперабельности в электронной коммерции на основе профиля</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0002-7760-6337</contrib-id>
          <name>
            <surname>Razinkin</surname>
            <given-names>Evgeny</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>erazinkin@mail.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Saint Petersburg State University of Aerospace Instrumentation</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-03-30">
        <day>30</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <issue>1</issue>
      <fpage>123</fpage>
      <lpage>133</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2026_1_5-6.pdf"/>
      <abstract xml:lang="en">
        <p>As e-commerce evolves, the number of integration points between online storefronts, payment services, logistics, accounting and analytics systems continues to grow. At the same time, information security measures are typically specified in a fragmented manner and are weakly aligned with interoperability models and risk management processes. This paper proposes a multi-layer model of secure interoperability for e-commerce systems, which embeds information security requirements into the interaction profile. The model is complemented by a classification of intersystem exchanges and a reference integration scenario via a gateway, forming a multi-layer interoperability structure within which security invariants are defined. An attacker model is developed that maps attack vectors to framework levels and classes of exchanges. Based on this model, a matrix is constructed that links threats to configuration parameters and control settings of the integration gateway and monitoring systems. Requirements are defined for a machine-readable security profile that includes invariants, indicators, countermeasures and their traceable identifiers, as well as integration with KPI/KRI-based monitoring and DevSecOps processes. The proposed structure enables risk-oriented design and assessment of protection for e-commerce integration points and can serve as a basis for further automation of security profile configuration and audit.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>E-commerce</kwd>
        <kwd>information security</kwd>
        <kwd>interoperability</kwd>
        <kwd>integration gateway</kwd>
        <kwd>attacker model</kwd>
        <kwd>risk assessment</kwd>
        <kwd>security profile</kwd>
        <kwd>KPI</kwd>
        <kwd>KRI</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
