<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Voprosy
kiberbezopasnosti [Cybersecurity issues].</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.21681/2311-3456-2015-1-26-43</article-id>
      <title-group>
        <article-title>About Some Perspective Training Cryptography Disciplines</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexander A. Varfolomeev</string-name>
          <email>a.varfolomeev@mail.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2015</year>
      </pub-date>
      <volume>1</volume>
      <issue>9</issue>
      <fpage>135</fpage>
      <lpage>138</lpage>
      <abstract>
        <p>- The work contains proposals for new training disciplines on cryptography that go beyond the traditional disciplines such as "Cryptographic methods of information protection", specifying and supplementing them. Particular attention is paid to the content of disciplines "Financial Cryptography", "Post-Quantum Cryptography", etc. These disciplines could be included in the disciplines section of choice for training specialists and bachelors.</p>
      </abstract>
      <kwd-group>
        <kwd>financial cryptography</kwd>
        <kwd>post-quantum cryptography</kwd>
        <kwd>lightweight cryptography</kwd>
        <kwd>lattice-based cryptography</kwd>
        <kwd>code-based cryptography</kwd>
        <kwd>multivariate cryptography</kwd>
        <kwd>supersingular elliptic curve isogeny cryptography</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>The quality of training and the demand for information
security professionals largely depends on the disciplines
studied by them in the university, including those from
cryptographic disciplines. The purpose of the work was to
select relatively new, relevant fields and areas of research in
cryptography and to determine the possibility on their basis of
developing new disciplines for training specialists and
bachelors [1]. It is important not only to determine the name of
the discipline, but also to its sections.</p>
      <p>II.</p>
      <p>METHODOLOGY AND JUSTIFICATION OF THE CHOICE OF</p>
      <p>DISCIPLINES AND THEIR CONTENT</p>
      <p>We offer as the first sources for the selection of actual areas
of cryptography the pages of website of the International
Association of Cryptographic Research (IACR): Events and
Open position.</p>
      <p>The Events page contains a list of conferences, seminars
and schools on cryptography and information security. The
first step will be the consideration of the names of events,
which in some cases can help with the choice of the name of
the discipline. The second step is to review the sections and
works presented at these events.</p>
      <p>Activities related to concepts such as "Elliptic Curve
cryptography", "Hash functions", can be only sections of
disciplines, because of their narrow focus and connection with
several areas. For example, without getting acquainted with
these concepts it is impossible to set standards for digital
signature, etc. On the contrary, many activities cover too large
areas of cryptography (“Public
“Symmetric Key Cryptography”).</p>
      <p>Key</p>
    </sec>
    <sec id="sec-2">
      <title>Cryptography”,</title>
      <p>Similarly, in the list of cryptographic disciplines of the
department there are names that say little about their content.
For example, "Introduction to cryptography", "Cryptographic
methods of information protection". The latter discipline can
cover all cryptography.</p>
      <p>The author has allocated the following activities for the
formation of new disciplines:</p>
      <p>Financial Cryptography and Data Security (FC);</p>
    </sec>
    <sec id="sec-3">
      <title>Crypto Finance Conference (CFC);</title>
    </sec>
    <sec id="sec-4">
      <title>Cryptocurrency and</title>
    </sec>
    <sec id="sec-5">
      <title>Blockchain</title>
    </sec>
    <sec id="sec-6">
      <title>School on Technologies;</title>
    </sec>
    <sec id="sec-7">
      <title>International Conference Cryptography (PQCrypto); International Workshop on Lightweight Cryptography for Security &amp; Privacy (LightSec);</title>
      <p>Workshop on Fault Diagnosis and Tolerance in
Cryptography (FDTC);
Annual Workshop on the Economics of Information
Security (WEIS).</p>
    </sec>
    <sec id="sec-8">
      <title>Post-Quantum</title>
      <p>The second source of choice of subjects of disciplines
Open position - provides a list of areas of cryptography and
information security that are of interest to employers from
various organizations. A number of these areas are classical,
and a number are quite new and promising. Here are some of
them:
- homomorphic and split key encryption,
- function and format preserving encryption,
- lattice and pairing-based functional encryption,
- trusted computing,
- distributed ledger technologies,
- secure multiparty computation,
- financial cryptography,
- blockchain security,
- payments (micropayments),
- cryptocurrencies,
- smart contracts,
- secure cloud computing,
- IoT security protocols,
- bio-computation,
- quantum cryptography,
- quantum computation,
- post-quantum cryptography,
- elliptic curve cryptography,
- lattice-based cryptography,
- code-based cryptography,
- lightweight cryptography.</p>
      <p>
        The third source for substantiating the choice and formation
of disciplines are publications of domestic and foreign
periodicals on cryptography. (For example, [
        <xref ref-type="bibr" rid="ref5 ref6 ref7">2-12</xref>
        ]). On the
basis of the proposed approach, it is expedient to allocate the
following cryptographic disciplines for study:




"Financial cryptography";
"Post-quantum cryptography";
"Lightweight (low-resource, balanced) cryptography";
"Quantum cryptography".
      </p>
      <p>It is more difficult to justify the choice of sections and
training modules for each of the disciplines.</p>
      <p>“Financial cryptography”.</p>
      <p>The notion of "financial cryptography" can be defined as
ensuring the information security of financial transactions in
electronic (digital) form by cryptographic methods.</p>
      <p>In connection with this definition, in the discipline
"Financial Cryptography", in the author's opinion, the
following sections should be included:</p>
      <p>- cryptographic schemes and protocols of electronic
payments (including in remote banking systems (RBS);
- micropayments;
- electronic money;
- crypto-currencies;
- the use of smart cards;
- technology of digital watermarks;
- protocols of electronic auctions;
- special schemes for digital (electronic) signature, taking
into account domestic and international standards and
recommendations.</p>
      <p>In work [4] it was noted that the scope of "financial
cryptography" has changed significantly since the inception of
this concept. If earlier cryptography ensured the security of
operations with financial means presented in electronic form,
now, in addition, cryptography itself provides financial
resources in the form of crypto-currencies that do not have a
physical basis in the real world.</p>
      <p>As can be seen from the listed sections, it is difficult to
determine the necessary time for the presentation of this
material. In the case of a time limit of one semester, a complex
selection of material for each section is required.</p>
      <p>A feature of this area is its government regulation,
imposing its limitations on the application of security
measures. Apparently, for this it is necessary to select the
separate training module. In support of this, it is sufficient to
mention as examples Federal Law No. 161-FZ "On the
National Payment System" dated June 27, 2011, Regulation
No. 382-P of the Bank of Russia of June 9, 2012, RF
Government Decree of April 16, 2012. No. 313.</p>
      <p>In addition, in Russia and abroad systems of standards and
best practices are developing. In view of their specifics, it is
difficult to justify their inclusion in other cryptographic
disciplines. The Bank of Russia created a number of industry
standards (SRT BR IBBS -1.0., Etc.). The obligatory standard
on plastic cards Payment Card Industry Data Security Standard
(PCI DSS 3.2) still applies. We can say that financial
cryptography in our country is represented mainly by the
banking sphere of activity. Recently, the standard GOST R
57580.1-2017 "Safety of financial (banking) operations. Basic
composition of organizational and technical measures".
“Post-quantum cryptography”.</p>
      <p>Of course, it should be recalled that post-quantum
cryptography deals with the development and analysis of
cryptographic primitives that are resistant to methods of
analysis using a quantum computer. Thanks to the timely raised
security issue, the existing and widely used primitives from the
advent of quantum computers have done a lot. A number of
stable schemes based on various principles are proposed. Work
continues to increase the effectiveness of their implementation,
which is still inferior to those used in security systems.</p>
      <p>Since 2006, the conference "PQCrypto" (in 2017 - the
eighth). In fact, the names of its sections determine the
different directions and principles of building persistent
primitives. They can form training modules:




</p>
    </sec>
    <sec id="sec-9">
      <title>Cryptosystems based on hash functions;</title>
    </sec>
    <sec id="sec-10">
      <title>Cryptosystems based on algebraic codes;</title>
    </sec>
    <sec id="sec-11">
      <title>Cryptosystems based on algebraic lattices;</title>
    </sec>
    <sec id="sec-12">
      <title>Cryptosystems based on multivariate systems;</title>
      <p>Cryptosystems based on isogenies of supersingular
elliptic curves.</p>
      <p>As can be seen from the names of these modules, the
exposition of all of them requires a serious study of various
complex mathematical constructions. Therefore, it is difficult
to present these modules within one semester. Apparently, it is
necessary to prepare separate curricula of disciplines for each
of the listed directions.</p>
      <p>Currently, the National Institute of Standards and
Technology (NIST) has initiated a process to solicit, evaluate,
and standardize one or more quantum-resistant public-key
cryptographic algorithms. The deadline for submission of
applications (November 30, 2017) has already passed.
Sixtynine applications were submitted, three of which were rejected.
All applications are publicly available and can be downloaded
from the NIST website. On the site you can find comments on
the applications, you can participate in the discussion yourself.</p>
      <p>Materials of the process can be used in the study of
discipline in various ways. The lecture material should include
the study of cryptosystems that have existed for quite a long
time and have been subjected to a long analysis by many
researchers. New cryptosystems can be used to select themes
for course and diploma papers, topics for lectures in seminars.</p>
      <p>Below we give a list of the algorithms announced for the
NIST competition, selected according to the directions and
principles of construction, mentioned above.</p>
      <p>All algorithms and systems participating in the NIST
competition are related to asymmetric cryptography (for
symmetric cryptography, the threat of the appearance of a
quantum computer is not so terrible). Therefore, it is natural to
study this discipline after studying the issues of classical
asymmetric cryptography. It is possible to assign the module
"Cryptosystems based on algebraic codes" to a discipline such
as "The Mathematical Theory of Coding". But, even in this
case, it is not possible to expound this discipline in one
semester.</p>
      <p>“Lightweight (balanced, low-resource) cryptography”
This area of cryptography has reached a sufficient level of
development and has great practical application [2, 3].
Evidence of this can serve as the developed international
cryptographic standards:</p>
      <p>ISO / IEC 29192-1: 2012 Information technology
Security techniques - Lightweight cryptography - Part 1:
General.</p>
      <p>ISO / IEC 29192-2: 2012 - Lightweight cryptography
Part 2: Block ciphers.</p>
      <p>ISO / IEC 29192-3: 2012 - Lightweight cryptography
Part 3: Stream ciphers.</p>
      <p>ISO / IEC 29192-4: 2013 - Lightweight cryptography
Part 4: Mechanisms using asymmetric techniques.</p>
      <p>ISO / IEC 29192-5: 2016 - Lightweight cryptography
Part 5: Hash-functions.</p>
      <p>The preparation of these standards in recent years was
preceded by an active study of this field, the results of which
were included in several useful surveys [6-8].</p>
      <p>
        The presentation of them within the framework of this
discipline will relieve the discipline "Cryptographic standards".
It should also be noted that this discipline should be included in
a block of disciplines for choice for the preparation of
bachelors and specialists. Her teaching should naturally follow
after studying the basic concepts of cryptography such as block
and stream ciphers, hash functions and asymmetric
cryptosystems, which are mentioned in the name of the above
standards [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref14 ref15 ref16 ref8 ref9">13-21</xref>
        ].
      </p>
      <p>III. HARMONIZATION OF EDUCATIONAL MATERIAL OF
VARIOUS DISCIPLINES IN CONDITIONS OF TIME LIMITATIONS OF</p>
      <p>THE EDUCATIONAL PROCESS..</p>
      <p>In some universities, there was a separation of
cryptographic disciplines depending on the mathematical
apparatus used in the presentation and study. For example,
cryptographic disciplines related to asymmetric cryptography
require students to learn a lot from the theory of numbers that
are set out in early student training courses.</p>
      <p>
        At one time, the development and adoption of digital
signature standards on the basis of a group of elliptic curve
points led to a change and increase in the studied material in
basic mathematical disciplines, which eliminated the need to
present these issues in cryptographic disciplines. Similarly,
these disciplines should be influenced by new proposed
cryptographic disciplines. For example, one of the modules of
Post-Quantum Cryptography requires a greater study of
algebraic lattices. In addition, the discipline "Financial
Cryptography" obviously affects the basic cryptographic
disciplines themselves. Therefore, there is a lot of work to
select the material and its methodological coordination among
the mathematical and cryptographic disciplines, to ensure the
possibility of presenting all the necessary material in a
sufficiently tight framework of the educational process (e.g.
[
        <xref ref-type="bibr" rid="ref17 ref18">22, 23</xref>
        ]).
      </p>
      <p>CONCLUSIONS</p>
      <p>In this paper, a method for determining promising
educational cryptographic disciplines is proposed, with the use
of which a short list is compiled. The training modules that
compose them and their sections are presented. The
development and introduction of these cryptographic
disciplines in the educational process requires a lot of
methodological work to harmonize the material presented in
both cryptographic and mathematical disciplines.</p>
      <p>Varfolomeev А.А. Analysis of the change of the concept «Financial
cryptography» on the basis of 20 years subjects of the international
conference «Financial cryptography and data security». Statistics
and Economics. 2016; (4):12-15. (In Russ.)
DOI:10.21686/25003925-2016-4-12-15. (In Russ)</p>
      <p>Biryukov A., Perrin L., State of the Art in Lightweight Symmetric
Cryptography, IACR Cryptology ePrint Archive, 2017, pp. 1-40.
URL: https://eprint.iacr.org/2017/511.pdf.</p>
      <p>Cazorla M., Marquet K., Minier M., Survey and Benchmark of
Lightweight Block Ciphers for Wireless Sensor Networks. IACR
Cryptology ePrint Archive, 2013, pp. 1-13. URL:
https://eprint.iacr.org/2013/295.pdf.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Sheremet</surname>
            <given-names>I.A.</given-names>
          </string-name>
          <article-title>Directions of a New Level Education to Counter Cyberthreats in Financial Sphere</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2016. No</source>
          <volume>5</volume>
          (
          <issue>18</issue>
          ), pp.
          <fpage>3</fpage>
          -
          <lpage>7</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2016-5
          <issue>-3</issue>
          -7.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>Zhukov A.</given-names>
            <surname>Lightweight</surname>
          </string-name>
          <article-title>Cryptography: Modern Development Paradigms</article-title>
          .
          <source>In Proceedings of the 8th International Conference on Security of Information and Networks (Sochi, Russian Federation, September 08-10</source>
          ,
          <year>2015</year>
          ).
          <source>SIN '15</source>
          . ACM New York, NY, USA,
          <year>2015</year>
          , pp.
          <fpage>7</fpage>
          -
          <lpage>7</lpage>
          . DOI:
          <volume>10</volume>
          .1145/2799979.2799981.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>Delvaux J.</given-names>
            ,
            <surname>Peeters</surname>
          </string-name>
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Gu</surname>
          </string-name>
          <string-name>
            <given-names>D.</given-names>
            ,
            <surname>Verbauwhede</surname>
          </string-name>
          <string-name>
            <surname>I.</surname>
          </string-name>
          ,
          <article-title>A Survey on Lightweight Entity Authentication with Strong PUFs</article-title>
          ,
          <source>IACR Cryptology ePrint Archive</source>
          ,
          <year>2014</year>
          . URL: https://eprint.iacr.org/
          <year>2014</year>
          /977.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>Atzei N.</given-names>
            ,
            <surname>Bartoletti</surname>
          </string-name>
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Cimoli</surname>
          </string-name>
          <string-name>
            <surname>T.</surname>
          </string-name>
          ,
          <article-title>A survey of attacks on Ethereum smart contracts</article-title>
          ,
          <source>IACR Cryptology ePrint Archive</source>
          ,
          <year>2016</year>
          . URL: https://eprint.iacr.org/
          <year>2016</year>
          /1007.pdf
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Halak</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Waizi</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Islam</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <article-title>A Survey of Hardware Implementations of Elliptic Curve Cryptographic Systems</article-title>
          , IACR Cryptology ePrint Archive, https://eprint.iacr.org/
          <year>2016</year>
          /712.pdf
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Tschorsch</surname>
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scheuermann</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <source>Bitcoin and Beyond: A Technical Survey on Decentralized Digital Currencies, IACR Cryptology ePrint Archive</source>
          ,
          <year>2015</year>
          . URL: https://eprint.iacr.org/
          <year>2015</year>
          /464.pdf
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Bernstein</surname>
            <given-names>D.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Hopwood</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hülsing</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lange</surname>
            <given-names>T</given-names>
          </string-name>
          ., eds.
          <article-title>"SPHINCS: practical stateless hash-based signatures"</article-title>
          .
          <source>Lecture Notes in Computer Science</source>
          .
          <volume>9056</volume>
          (Advances in Cryptology --
          <source>EUROCRYPT</source>
          <year>2015</year>
          ):
          <fpage>368</fpage>
          -
          <lpage>397</lpage>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -46800-5_
          <fpage>15</fpage>
          . ISBN 9783662467992.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Augot</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Batina</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bernstein</surname>
            <given-names>D.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bos</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Buchmann</surname>
            <given-names>J.,</given-names>
          </string-name>
          <article-title>and etc. Initial recommendations of long-term secure post-quantum systems</article-title>
          ,
          <source>Technical report 2015</source>
          . URL: http://pqcrypto.eu.org/docs/initialrecommendations.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Overbeck</surname>
            <given-names>R.</given-names>
          </string-name>
          , Bernstein D., ed.
          <source>Code-based cryptography. PostQuantum Cryptography</source>
          . Springer Berlin Heidelberg,
          <year>2014</year>
          .
          <fpage>95</fpage>
          -
          <lpage>145</lpage>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>540</fpage>
          -88702-
          <issue>7</issue>
          _
          <fpage>4</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Misoczki</surname>
            <given-names>R..</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tillich</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sendrier</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barreto</surname>
            ,
            <given-names>P. S. L. M.</given-names>
          </string-name>
          <article-title>MDPCMcEliece: New McEliece variants from Moderate Density ParityCheck codes</article-title>
          .
          <source>2013 IEEE International Symposium on Information Theory:</source>
          <fpage>2069</fpage>
          -
          <lpage>2073</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ISIT.
          <year>2013</year>
          .
          <volume>6620590</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Hirschhorn</surname>
            <given-names>P.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hoffstein</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Howgrave-Graham</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Whyte</surname>
            <given-names>W.</given-names>
          </string-name>
          (
          <year>2009</year>
          )
          <article-title>Choosing NTRUEncrypt Parameters in Light of Combined Lattice Reduction and MITM Approaches</article-title>
          . In:
          <string-name>
            <surname>Abdalla</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pointcheval</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fouque</surname>
            <given-names>PA.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vergnaud</surname>
            <given-names>D</given-names>
          </string-name>
          . (eds) Applied Cryptography and
          <string-name>
            <given-names>Network</given-names>
            <surname>Security</surname>
          </string-name>
          .
          <source>ACNS 2009. Lecture Notes in Computer Science</source>
          , vol
          <volume>5536</volume>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -01957-
          <volume>9</volume>
          _
          <fpage>27</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>Peikert</given-names>
            <surname>Chris</surname>
          </string-name>
          .
          <article-title>Lattice Cryptography for the Internet</article-title>
          .
          <source>IACR. Archived from the original</source>
          ,
          <year>2014</year>
          . URl: https://eprint.iacr.org/
          <year>2014</year>
          /070.pdf ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Lin</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ding</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Xiaodong</surname>
            <given-names>A Simple</given-names>
          </string-name>
          <string-name>
            <surname>Provably</surname>
          </string-name>
          <article-title>Secure Key Exchange Scheme Based on the Learning with Errors Problem</article-title>
          .
          <source>IACR Cryptology ePrint Archive</source>
          ,
          <year>2012</year>
          . URL: https://eprint.iacr.org/
          <year>2012</year>
          /688.pdf
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Güneysu</surname>
          </string-name>
          , Tim; Lyubashevsky, Vadim; Pöppelmann, Thomas (
          <year>2012</year>
          ).
          <article-title>Practical Lattice-Based Cryptography: A Signature Scheme for Embedded Systems</article-title>
          .
          <source>In Proceeding CHES'12 Proceedings of the 14th international conference on Cryptographic Hardware and Embedded Systems</source>
          , pp.
          <fpage>530</fpage>
          -
          <lpage>547</lpage>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -33027- 8_
          <fpage>31</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Alkim</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ducas</surname>
          </string-name>
          .,
          <string-name>
            <surname>Pöppelmann</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schwabe</surname>
            <given-names>P</given-names>
          </string-name>
          .
          <article-title>"Post-quantum key exchange - a new hope"</article-title>
          .
          <source>In 25th Security Symposium</source>
          .
          <year>2016</year>
          . URL: https://www.usenix.org/conference/usenixsecurity16/technicalsessions/presentation/alkim.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Sun</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tian</surname>
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            <given-names>Y</given-names>
          </string-name>
          .
          <article-title>Toward Quantum-Resistant Strong Designated Verifier Signature from Isogenies</article-title>
          .
          <source>In: Intelligent Networking and Collaborative Systems (INCoS)</source>
          ,
          <year>2012</year>
          4th International Conference on. IEEE:
          <fpage>292</fpage>
          -
          <lpage>296</lpage>
          . DOI:
          <volume>10</volume>
          .1109/iNCoS.
          <year>2012</year>
          .
          <volume>70</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Zhukov</surname>
            <given-names>A.E.</given-names>
          </string-name>
          <string-name>
            <surname>Cellular</surname>
          </string-name>
          <article-title>Automata in Cryptography. Part 1</article-title>
          . Voprosy kiberbezopasnosti [Cybersecurity issues],
          <year>2017</year>
          , No
          <volume>3</volume>
          (
          <issue>21</issue>
          ), pp.
          <fpage>70</fpage>
          -
          <lpage>76</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-3-
          <fpage>70</fpage>
          -76.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Zhukov</surname>
            <given-names>A.E.</given-names>
          </string-name>
          <string-name>
            <surname>Cellular</surname>
          </string-name>
          <article-title>Automata in Cryptography. Part 2</article-title>
          . Voprosy kiberbezopasnosti [Cybersecurity issues],
          <year>2017</year>
          , No
          <volume>4</volume>
          (
          <issue>22</issue>
          ), pp.
          <fpage>47</fpage>
          -
          <lpage>66</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-4-
          <fpage>47</fpage>
          -66.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>