<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>High-Performance Reliable Block Encryption Algorithms Secured against Linear and Differential Cryptanalytic Attacks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergiy Gnatyuk</string-name>
          <email>s.gnatyuk@nau.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vasyl Kinzeryavyy</string-name>
          <email>v.kinzeryavyy@nau.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maksim Iavich</string-name>
          <email>m.iavich@scsa.ge</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro Prysiazhnyi</string-name>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Khalicha Yubuzova</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Satbayev University</institution>
          ,
          <addr-line>Almaty</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Scientific Cyber Security Association</institution>
          ,
          <addr-line>Tbilisi</addr-line>
          ,
          <country country="GE">Georgia</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Vinnytsia National Technical University</institution>
          ,
          <addr-line>Vinnytsia</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2009</year>
      </pub-date>
      <abstract>
        <p>To be secure, modern information and communication technology (ICT) needs reliable encryption. Symmetric cryptography combines encryption algorithms that use the same cryptographic keys for both encryption of plaintext and decryption of ciphertext. These algorithms are used for confidentiality ensuring in different spheres but most of them are worn out and outdated. Modern encryption algorithms development is very actual task for ICT (up to date and next generation). In this paper to improve the security effectiveness of electronic information resources, two encryption algorithms have been developed based on fixed lookup tables with extended-bit depth and dynamic key-dependent lookup tables. The developed algorithms are at least two times faster than the previous national encryption standard and virtually secure to linear and differential cryptanalysis. Properties of random sequences formed using the proposed algorithms' encryption (in counter mode) were explored in the environment of NIST STS statistical tests, according to which they passed integrated control by mentioned tests with better results than other generators.</p>
      </abstract>
      <kwd-group>
        <kwd>IT security</kwd>
        <kwd>confidentiality</kwd>
        <kwd>cryptography</kwd>
        <kwd>cipher</kwd>
        <kwd>block encryption algorithm</kwd>
        <kwd>cryptographic security</kwd>
        <kwd>reliable encryption</kwd>
        <kwd>algebraic coding theory</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        As a result of modern global challenges in information security on the state level, the
requirements for state information resources security and other critical information
(transferred and stored in information and communication systems) are constantly
growing [
        <xref ref-type="bibr" rid="ref1 ref2">1-2</xref>
        ]. The cryptographic security of these resources is one of the most
significant security measures (especially in critical information infrastructure
protection [
        <xref ref-type="bibr" rid="ref2 ref3">2-3</xref>
        ]). Cryptographic security is one of the most reliable and effective
methods of information security; its principal and undeniable advantage is the data
protection without access to it. The principal criterion for choosing cryptosystems is
security, but for some applications (e.g., Big Data encryption, online banking
payment systems etc.) the key role played by cryptographic data processing is speed.
Despite the wide variety of modern encryption methods and algorithms, not all have
the necessary level of effectiveness (speed and security). In addition, the rapid
development of computational tools and their simultaneous cost reduction have led to
new requirements for both the security and the performance of cryptosystems–old
cryptographic algorithms disappear, and new ones must pass specific competitive
selection and prove their ability to provide security for a specific period of time in the
future [
        <xref ref-type="bibr" rid="ref10 ref4 ref5 ref6 ref7 ref8 ref9">4-10</xref>
        ]. Algorithm 28147:2009 was Ukrainian National Encryption Standard
until 2014. DSTU 7624:2014, the new Encryption Standard since 2015, has not been
well investigated [
        <xref ref-type="bibr" rid="ref6 ref9">6, 9</xref>
        ]. However, considering the significant progress in the field of
cryptanalysis methods and tools, Ukrainian National Encryption Standard 28147:2009
has become obsolete [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Thus, in accordance with the requirements of the New
European Schemes for Signatures, Integrity, and Encryption (NESSIE) project [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], the
algorithm of Ukrainian Encryption Standard 28147-2009 applies only to the third
(lowest) class of security [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. In addition, previous Ukrainian National Encryption
Standard 28147-2009 does not satisfy the modern requirements for data encryption
speed [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] that is important for mentioned tasks.
      </p>
      <p>
        Additional disadvantages include complexity of hardware implementation and use of
secret long-term key data, which are supplied in a prescribed manner [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Therefore,
the development of new algorithms to improve the efficiency of information security
is an important scientific task. The purpose of this work is to contribute to
improvement in the efficiency of electronic information resources security through
the development of modern secure high-performance reliable block ciphers.
2.
      </p>
      <p>Method for Speed of Block Ciphers Increasing
Consider a class of block ciphers with a set of open (encrypted) messages Vn  {0,1}n ,
n  128 p , p  N , a set of round keys K  Vn , and a family of cryptographic
transformations Fk  fr ,kr ... f1,k1 , k  k1,..., kr   K r , where r is the number of
encryption rounds.</p>
      <p>
        The round transformation fi, k  x for any x Vn , k  K , and i 1, r is described as
addition modulo 2 or 232l , l  N , l  n 32 . Substitutions   x and si  x are
defined by the formulas   x  Ls i  x , x Vn , si  x  si  xc1 , ... , si  x0  ,
where x   xc1,..., x0  , x j Vt , t  4 , c  n / t , j  0, c 1 , si involves m lookup
tables on the set Vt , used in the i-th round ( m 1, c ), аnd L x is a linear
transformation used in a block cipher. si – one of m ( m N ) substitution tables on
set Vt , that is using in i -th round, L x – linear transformation using in block cipher.
For the above class of block ciphers there are fairly well known analytical upper
estimates of the parameters [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ], characterizing practical security against linear
[
        <xref ref-type="bibr" rid="ref13 ref15">13, 15</xref>
        ] and differential [
        <xref ref-type="bibr" rid="ref13 ref14">13, 14</xref>
        ] cryptanalysis attacks:
      </p>
      <p>  x  k  , i  r
fi,k  
sr  x  k  , i  r
, where  is defined separately for each round operation of</p>
      <p>
        EDP   r1BL /21
ELP   r1BL /21
(1)
(2)
(3)
where   maxds  ,  : , Vt \ 0 is the maximum probability difference of
the substitution table s [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ],   maxls  ,  : , Vt \0 is the maximum
probability of linear approximation of the substitution table s [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], BL is the
number of the revitalization branches of the following linear transformation L x
( BL  min wt  x  wt  xL1  ) [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], EDP  is the average differential
characteristics probability of 
characteristic probability of  [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>
        [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], аnd ELP is the average linear
Variables ds ( , ) and ls ( , ) are defined by the following formulas (if the
operation “+” is addition modulo 2) [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ]:
ds ( , )  2t  (s(k  )  s(k), ) ,
kVt
      </p>
      <p>
        2
ls ( , )  2t   2t  (1) x s(xk)  (4)
kVt  xVt 
0, u   v
where  is the Kronecker delta symbol,  (u, v)   .
1, u   v
According to the standard methodology of constructing block ciphers [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], using
linear transformations with a large parameter BL and substitution tables with smaller
A)s a linear transformation of the considered maximum distance separable (MDS)
codes, covering w bytes ( w  4, 8, 16 ) allows the number of activation branches
BL  w 1 . We investigated the substitution table on the set Vq , where q  8, 16, 32 ,
for which the theoretically achievable levels of  and  are equal to 2q2 .
According to Table 1, the performance of block ciphers (considered as a class) can be
improved by taking the following steps:
1) Expand the variety of permutations to use the substitution table on the set V16
(most modern cryptographic algorithms use lookup tables on multiples of V8 ). Using
such a table requires only 128 KB of memory, which is now acceptable. A
substitution table on the set V32 requires much more memory, resulting in it being
impractical for current use.
2) Replace some MDS codes to cover a larger number of bytes (this will increase the
number of operations per round, but not significantly).
3) Reduce the number of block cipher rounds to improve performance.
For example, this method can be applied to block cipher Kalyna encryption
algorithms ( ,   25 , BL  9 , r  11 ) [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] and the Advanced Encryption Standard
(AES) (     26 , BL  5 , r  11 ) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], but in this case (with decreasing r ),
investigating their security in regard to other methods of cryptanalysis is a very
difficult task. However, the opportunity to enhance their performances deserves
attention.
3.
      </p>
      <p>New Block Encryption Algorithms Development
On the basis of the described method for increasing the speed of block ciphers, two
algorithms have been developed for encrypting the information using a fixed table lookup
with an extended bit depth (Luna) and with dynamic key-dependent lookup tables
(Neptune). The pseudocode for the algorithms is shown in Fig. 1a and 1b, respectively.
Luna Neptune
Input: 128-bit input data block state , Input: 128-bit input data block state ,
128-bit extended keys subkey i , i  0, r  2 .
128-bit extended keys subkey i , i  0, 2  r .</p>
    </sec>
    <sec id="sec-2">
      <title>Output: 128-bit output data block. 1. 2.</title>
      <sec id="sec-2-1">
        <title>AddKeyMod 2state, subkey1 ;</title>
        <p>For j  0, j  r 1, j   do
2.1. SubBytesLuna state ;</p>
        <sec id="sec-2-1-1">
          <title>2.2. ShiftRows state ;</title>
          <p>2.3. MixColumns state ;</p>
        </sec>
      </sec>
      <sec id="sec-2-2">
        <title>2.4. AddKeyMod2state, subkey j  2 ;</title>
        <sec id="sec-2-2-1">
          <title>3. SubBytesLuna state ;</title>
        </sec>
        <sec id="sec-2-2-2">
          <title>4. ShiftRows state ;</title>
        </sec>
      </sec>
      <sec id="sec-2-3">
        <title>AddKeyMod 2state, subkeyr 1 ;</title>
        <p>6. return state ;
a</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Output: 128-bit output data block. 1. 2.</title>
      <sec id="sec-3-1">
        <title>AddKeyMod 2  state, subkey 0 ;</title>
        <p>For j  0, j  r 1, j   do
2.1. SubBytesNeptun state, subkey2 j 1 ;</p>
        <sec id="sec-3-1-1">
          <title>2.2. ShiftRows state ;</title>
          <p>2.3. MixColumns state ;
2.4. AddKeyMod2state, subkey2 j  2 ;</p>
        </sec>
      </sec>
      <sec id="sec-3-2">
        <title>3. SubBytesNeptun state, subkey2 r 1 ;</title>
        <sec id="sec-3-2-1">
          <title>4. ShiftRows state ;</title>
          <p>5.</p>
        </sec>
      </sec>
      <sec id="sec-3-3">
        <title>AddKeyMod2state, subkey2 r ;</title>
        <p>6. return state ;
b
These algorithms use 128-bit data blocks (represented as 4  4 byte matrices) with
secret-key lengths of 128, 256, and 512 bits, formed from the required number of
128bit extended keys represented as matrices of size 4  4 bytes. The number r of
encryption rounds depends on the length of the secret key. With secret-key lengths of
128, 256, and 512 bits, r  7, 9, 13 in Luna and r  9, 13, 21 in Neptune,
respectively.</p>
        <p>The operation AddKeyMod 2state, subkeyi is bitwise addition modulo 2 of the
corresponding bits of the extended subkey i key and a state data block.
The MixColumns state operation is a linear state sequence transformation. In this
operation, the state data block is split into two parts of eight bytes (the first two
fourbyte columns form one eight-byte part, and the other eight – the second part), each of
which is considered as a polynomial over the field GF 28  with eight terms, which
are multiplied by x8 1 modulo a fixed polynomial c  x (see Fig. 2), thereby
ensuring that the number of activation branches is nine. The polynomial c  x is
given by c  x  3x7  7x6  x5  3x4  7x3  4x2 1Dx 1, where the coefficients are
represented in base-16 forms. A not given polynomial chosen polynomial is
m x  x8  x7  x5  x4  x 1 .</p>
        <p>X1,1
X1,2
X1,3
X1,4</p>
        <p>X2,1
X2,2
X2,3
X2,4</p>
        <p>X3,1
X3,2
X3,3
X3,4</p>
        <p>X4,1
X4,2
X4,3
X4,4
c(x)</p>
        <p>X</p>
        <p>=
y1
...
y8
y1
...
y8
replaced according to each of the 16- and 8-bit data blocks with a specific table of
substitutions (see Figs. 3a and 3b, respectively). Luna uses one 1616 substitution
table, while Neptune uses 16 tables, with the choice of a particular table in each round
depending on the expanded key (a dynamically changeable substitutions table
complicates the cryptanalysis and will dynamically manage the information
dispersion). The substitution table was constructed in such way that there were no
fixed points, as well as to satisfy the respective equalities for the parameters,
    214 for the Luna substitution table and     26 for each Neptune
substitution table.</p>
        <p>Sbox X   Y</p>
        <p>X1,1
X1,2
X1,3
X1,4</p>
        <p>X2,1
X2,2
X2,3
X2,4</p>
        <p>X3,1
X3,2
X3,3
X3,4
A</p>
        <p>X4,1
X4,2
X4,3
X4,4</p>
        <p>X1,1
X1,2
X1,3
X1,4</p>
        <p>X2,1
X2,2
X2,3
X2,4</p>
        <p>X3,1
X3,2
X3,3
X3,4
b</p>
        <p>X4,1
X4,2
X4,3
X4,4
C X 1  GF (2q ) and then performing affine transformations over the field GF (2) :
S(X )  M  C X 1 V , where X , C,V  GF (2q ) , and M is not a singular square
matrix over the GF (2) field of q  q size. For Luna, q  16 , and for Neptune, q  8 .
The C , V , and M settings for the Neptune and Luna table lookup algorithms are
shown in base-16 forms in Tables 2 and 3, respectively (each matrix row is shown in
the form of one base-16 number).
i ( i  2, 3 ) last string sequence state cyclically shifted right by 2 elements.
The procedures of Neptune and Luna decoding are similar to the encryption
procedure (see Figs. 1a and 1b), except that the extended keys are provided in reverse
order, with the reverse substitution tables and a reversed MixColumns state
operation
being
used
(multiplication
by
a
polynomial
d  x  7Ax7  A1x6  F8x5  EEx4  20x3  89x2  EBx  51).</p>
        <p>In the key expansion procedure, a128n -bit secret key K ( n  1, 2, 4 ) is divided into
n parts of 128 bits ( al , l  1, n ) to formulate extended keys. Each of these is divided
into four k li ( i  1, 4 ) parts that, together with the 32-bit variables A , B , C , D ,
E , F , and yi ( i  1, 4 ), are moved to the key expansion routine input, the
pseudocode of which is shown in Fig. 4.</p>
        <p>The Sbox  X  operation for Neptune and Luna performs tabular substitution in
accordance with each 16 and 8 bits, respectively (Luna uses a substitution table based
on the parameters from Table 2, while Neptune uses bases of the parameters from the
first row of Table 3). Mix  y1, y2 , y3, y4  is the operation of linear dispersion. In this
operation, variables yi are broken into two parts of eight bytes, each of which is
considered as a polynomial over the field GF 28  with eight terms that are
multiplied by x8 1 modulo a fixed c  x polynomial of order seven, where
cx  3x7  7x6  x5 3x4  7x3  4x2 1Dx 1. As a polynomial that is not chosen,
consider mx  x8  x7  x5  x4  x 1 .
2.1.1.5. y1  SboxSbox y1  kl2   kl1 E y4  ;
2.1.1.6. C  SboxC  F y1 D ;
2.1.1.7. y2  Sbox y2  C  kl2   kl1  ;
2.1.1.8.
2.1.1.9.</p>
        <p>Mix y1, y2, y3, y4  ;</p>
        <p>D  D  kl4    A kl3   y1 ;
2.1.1.10. kl3  SboxD  kl3   E ;
2.1.1.11. E  SboxE kl3   F kl1 ;
2.1.1.12. kl4  SboxE  kl4   kl2  D ;
2.1.1.13. y3  SboxSbox y3  kl4   kl3  B y2  ;
2.1.1.14. F  SboxF C y3  A;
2.1.1.15. y4  Sbox y4  F   kl4   kl3  ;
2.1.1.16. Mix y1, y2, y3, y4  ;
2.1.2 templk  y1 | y2 | y3 | y4 ;</p>
        <sec id="sec-3-3-1">
          <title>2.1.3 subkeyk  subkeyktemplk.</title>
          <p>Fig. 4. Pseudocode procedure for key expansion
Initial values of the variables A , B , C , D , E , F , yi are listed in base-16 in
Both Neptune and Luna utilize widely used algebraic operations in finite fields.
Immediate execution of these operations would lead to extremely inefficient
implementations. However, the byte-algorithm structure opens up opportunities for
optimization. Thus, two-byte substitution can be implemented during Luna
implementation, shifting and multiplying the result by the corresponding columns of
the matrix M as one of substitution 16 bits on 64 bits, and Neptune implementation
can be implemented as a bit-substitution shift, with a multiplication matrix state
element on the column of the matrix M being implemented as 8-bit on 64-bit
substitution. In that case, a complete round of Luna will consist of eight permutations
of 16 on 64 bits and eight-bit addition modulo 2. Similarly, performing a full round of
the Neptune algorithm requires only 16 substitutions of 8-bit on 64 bits and 16
additions modulo 2. Thus, by allocating a larger amount of RAM and performing
preliminary calculations, it is possible to reduce the number of operations in the round
and achieve a cryptographic processing speed boost.</p>
          <p>
            Statistical Security Estimation using NIST STS
Properties of pseudorandom sequences formed with the help of Neptune and Luna (in
counter mode) have been studied in the environment of NIST STS statistical tests
(testing technique described in [
            <xref ref-type="bibr" rid="ref17">17</xref>
            ]). Statistical portraits of Neptune and Luna
software implementations are shown in Figs. 5-6, respectively.
For comparison, Table 5 presents the results of testing sequences generated on the
basis of the Luna, Neptune, Ukrainian Encryption Standard 28147-2009, Blum Blum
Shub (BBS), and Kalyna algorithms. As can be seen from the results (Table 5), the
Luna- and Neptune-based generators passed comprehensive testing using the NIST
STS method and show better results than other algorithm-based generators.
          </p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Generator</title>
      <p>BBS
Kalyna
Luna
Neptune</p>
      <p>Number of tests in which the test was conducted
99% sequence
133 (70,3%)
132 (69,8%)
136 (72,0%)
141 (74,6%)
140 (74,0%)
96% sequence
189 (100%)
188 (99,4%)
189 (100%)
189 (100%)
189 (100%)</p>
      <p>Encryption Rate Estimation
Based on the described optimization software, the Luna, Neptune, AES, and Kalyna
encryption algorithms and Ukrainian Encryption Standard 28147-2009 were
implemented in the C++ programming language. During the Luna implementation,
two-byte substitution, shifting, and multiplying the result by the corresponding
columns of the matrix as a 16-bit to 64-bit substitution were presented. Similarly,
during the Neptune and Kalyna implementations, byte operation substitution, shift,
and multiplication of elements of the matrix by a column matrix as one eight-bit to
64-bit substitution were presented. During the DSTU 28147-2009 implementation,
every two four-by-four-bit substitution tables were combined as a table of eight by
eight bits, allowing reduction of the number of lookup operations from eight to four.
During AES implementation, the operations of byte substitution, shift, and
Luna -128
Neptune -128</p>
      <p>Security Estimation against Linear and Differential Cryptanalysis
During calculation of the analytical upper bounds of the parameters characterizing
practical security to linear and differential cryptanalysis using formulas (1) and (2), 
and  must be calculated depending on the parameters’ lookup table. For this
purpose, special software was developed and special tables were built using equations
(3) and (4). Then, we determined the maximum value in these tables (except for the
items in the zero-th row or column). As a result, it was determined that for Luna,
    214 , and for each Neptune table,     26 .</p>
      <p>Table 7 contains the analytical upper bounds of the parameters (using equations (1)
(2)), characterizing the practical security of the Neptune and Luna encryption
algorithms to differential and linear cryptanalysis.</p>
      <p>EDP()  2512
EDP()  2770</p>
      <p>ELP()  2512
ELP()  2770</p>
      <p>EDP()  2330
EDP()  2546</p>
      <p>ELP()  2330
ELP()  2546</p>
      <p>Conclusions
In this paper, two encryption algorithms were proposed to improve the efficiency of
electronic information resources security from viewpoint of reliability, speed and
security. As can be seen from the results of the experimental study, the proposed
algorithms, Luna and Neptune, are at least two times faster than the previous
Ukrainian National Encryption Standard 28147-2009 (in fact, this is the standard for
all post-Soviet states). In addition, designed algorithms passed comprehensive control
using the NIST STS technique and showed better results than other encryption
algorithm-based generators. It was also shown that the proposed algorithms are
practically secured against linear and differential cryptanalysis.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Gnatyuk</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhmurko</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Falat</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Efficiency increasing method for quantum secure direct communication protocols</article-title>
          .
          <source>In: Proceedings of the 2015 IEEE 8th International Conference on “Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications”</source>
          (IDAACS'
          <year>2015</year>
          ), Warsaw, Poland,
          <fpage>468</fpage>
          -
          <lpage>472</lpage>
          (
          <issue>September 24-26</issue>
          ,
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Korchenko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vasiliu</surname>
          </string-name>
          , Ye.,
          <string-name>
            <surname>Gnatyuk</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Modern quantum technologies of information security against cyber-terrorist attacks</article-title>
          .
          <source>Aviation</source>
          <volume>14</volume>
          (
          <issue>2</issue>
          ),
          <fpage>58</fpage>
          -
          <lpage>69</lpage>
          (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Kovtun</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovtun</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Okrimenko</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gnatyuk</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Search method development of birationally equivalent binary Edwards curves for binary Weierstrass curves from DSTU 4145- 2002</article-title>
          .
          <source>In: Proceedings of 2nd International Scientific-Practical Conf. on the Problems of Infocommunications. Science and Technology, Kharkiv, Ukraine</source>
          ,
          <fpage>135</fpage>
          -
          <lpage>139</lpage>
          (
          <issue>October 13-15</issue>
          ,
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>Advanced</given-names>
            <surname>Encryption</surname>
          </string-name>
          <article-title>Standard (AES): FIPS 197</article-title>
          .
          <string-name>
            <surname>Gaithersburg</surname>
          </string-name>
          , Maryland, USA: NIST,
          <year>2001</year>
          . http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>5. NESSIE contest (The New European Signature Algorithms</article-title>
          , Integrity and Encryption) Panasenko, S. http://old.cio-world.ru/bsolutions/e-safety/340556.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <article-title>Position about carrying out of open competition of cryptographic algorithms, Institute of Cybernetics named after V. Glushkov of NASU</article-title>
          . http://www.dstszi.gov.ua/dstszi/control/ru/ publish/article;jsessionid=EE63A37FEF8F5B34030F1E38D7247DBC?art_id=48387&amp;cat_id=
          <fpage>92733</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Gorbenko</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lisitskaya</surname>
            <given-names>I.</given-names>
          </string-name>
          :
          <article-title>Encryption algorithms standardization</article-title>
          .
          <article-title>Project requirements of national standard for block symmetric encryption on the modern stage of cryptography development</article-title>
          .
          <source>Radio Engineering</source>
          ,
          <fpage>5</fpage>
          -
          <lpage>10</lpage>
          (
          <year>2011</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Gorbenko</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dolgov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oliynykov</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          et al:
          <article-title>Principles of construction and properties of IDEA-like block symmetric ciphers</article-title>
          .
          <source>Applied Radio Electronics</source>
          <volume>6</volume>
          (
          <issue>2</issue>
          ),
          <fpage>158</fpage>
          -
          <lpage>173</lpage>
          (
          <year>2007</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. DSTU 7624:
          <year>2014</year>
          . Ukrainian National Encryption Standard “Kalyna”,
          <volume>86</volume>
          p. (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Panasenko</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>The encryption algorithms</article-title>
          . Special guide, St. Petersburg, BHVPetersburg.
          <volume>576</volume>
          (
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Alekseichuk</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovalchuk</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Skrynnik</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          et al:
          <article-title>Rating of practical resistance of Kalyna block cipher relative to the difference methods, linear cryptanalysis and algebraic attacks based on homomorphisms</article-title>
          .
          <source>Applied Radio Electronics</source>
          <volume>7</volume>
          (
          <issue>3</issue>
          ),
          <fpage>203</fpage>
          -
          <lpage>209</lpage>
          (
          <year>2008</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Alekseichuk</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovalchuk</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Skrynnik</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          et al:
          <article-title>Rating of practical resistance of “Kalyna” block cipher relative to the difference methods, linear cryptanalysis and algebraic attacks based on cryptanalysis</article-title>
          .
          <source>In: Proceedings of the 4th intern. conf. on security and countering terrorism</source>
          . MSU,
          <string-name>
            <given-names>M. V.</given-names>
            <surname>Lomonosov</surname>
          </string-name>
          .
          <volume>30</volume>
          -31 Oct.
          <year>2008</year>
          , 2th ed, M.:
          <string-name>
            <surname>MCCME</surname>
          </string-name>
          ,
          <fpage>15</fpage>
          -
          <lpage>20</lpage>
          (
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Alsalami</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yeun</surname>
            <given-names>C. Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martin</surname>
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Linear and differential cryptanalysis of small-sized random (n, m)-S-boxes</article-title>
          .
          <source>In: Proceedings of 2016 11th International Conference for Internet Technology and Secured Transactions</source>
          , Barcelona, Spain. DOI:
          <volume>10</volume>
          .1109/ICITST.
          <year>2016</year>
          .7856751
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Lai</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Massey</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Murphy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Markov ciphers and differential cryptanalysis</article-title>
          .
          <source>Advances in Cryptology, EUROCRYPT'91, Proceedings</source>
          , Springer Verlag,
          <fpage>17</fpage>
          -
          <lpage>38</lpage>
          (
          <year>1991</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Matsui</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Linear cryptanalysis methods for DES cipher</article-title>
          .
          <source>EUROCRYPT</source>
          , Springer Verlag (
          <year>1998</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Daemen</surname>
          </string-name>
          , J.:
          <article-title>Cipher and hash function design strategies based on linear and differential cryptanalysis:</article-title>
          <source>Ph. D. Thesis</source>
          , Katholieke Univ.
          <source>Leuven</source>
          (
          <year>1995</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Narges</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Khayyambashi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Performance Evaluation of Authentication Encryption and Confidentiality Block Cipher Modes of Operation on Digital Image</article-title>
          .
          <source>International Journal of Computer Network and Information Security (IJCNIS)</source>
          , Vol.
          <volume>9</volume>
          , No.
          <issue>9</issue>
          , pp.
          <fpage>30</fpage>
          -
          <lpage>37</lpage>
          ,
          <year>2017</year>
          . DOI:
          <volume>10</volume>
          .5815/ijcnis.
          <year>2017</year>
          .
          <volume>09</volume>
          .04.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>