<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>MST3 Cryptosystem Based on a Generalized Suzuki 2- Groups</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kharkiv National University of Radioelectronics</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kharkiv</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ukraine hennadii.khalimov@nure.ua</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Kharkiv National University of Radioelectronics</institution>
          ,
          <addr-line>Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Customs and Finance</institution>
          ,
          <addr-line>Dnipro</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2054</year>
      </pub-date>
      <fpage>0000</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>The article describes a new implementation of MST3 cryptosystems based on the generalized Suzuki 2 - groups. The main difference in the presented implementation is the presence of many-stage recovery of parts of the message from the encrypted text. The presented implementation of a cryptosystem has lower costs of key data. The complexity of the cryptanalysis and the size of the message for encryption depend of the power a generalized Suzuki 2 - groups.</p>
      </abstract>
      <kwd-group>
        <kwd>MST cryptosystem</kwd>
        <kwd>logarithmic signature</kwd>
        <kwd>random cover</kwd>
        <kwd>generalized Suzuki 2 - groups</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Current is the development of efficient cryptographic cryptosystems that can with stand
quantum attacks. It is believed that the advent of quantum computers and the presence
of quantum algorithms for factoring integers and discrete logarithms will lead to
hacking of known cryptosystems with a public key.</p>
      <p>The idea of constructing public-key cryptosystems on the basis of an intractable
word problem was proposed by Wagner and Magyarik in [1]. The basis is the use of
permutation groups. Since the 2000s, several dozen cryptosystems in group
constructions have been proposed [2÷5].</p>
      <p>The development of the idea of Wagner and Magyarik is the proposal of Magliveras
[6]. Magliveras proposed a symmetric cryptosystem based on a special type of
factorization of finite groups named logarithmic signatures for finite permutation groups. The
idea of using a logarithmic signature was investigated by Lempken et al. and developed
in the construction for random covers in [7].</p>
      <p>In this scheme, the public key consists of a tame logarithmic signature as well as
some random numbers, and the secret key is design of random cover and sandwich
transformation of the cover [8].</p>
      <p>The intractability assumptions of this scheme are group factorization problem on
nonabelian groups.</p>
      <p>Magliveras cryptosystem based on the Suzuki group is known as MST3. Further
improvements to this scheme were made by Svaba and van Trung in [9]. They
introduced a secret cover of a random cover. A digital signature scheme based on MST3
cryptosystems was proposed and explored in [Hong].</p>
      <p>Using two Suzuki parametric groups to build the MST3 cryptosystem leads to
security and complexity of the assessment, proportional to the square of the measurement
of the final field.</p>
      <p>A further increase in security is possible by expanding the group. The MST3
cryptosystem based on the three-parameter group of automorphisms of the functional field
of the Hermite curve [14] and the small Ri group has security and complexity estimates
proportional to the cube of the dimension of the finite field [15].</p>
      <p>In this paper will be presentation MST3 cryptosystems based on the
multi-parameter generalized Suzuki 2 - groups.
2</p>
    </sec>
    <sec id="sec-2">
      <title>The generalized Suzuki 2 - groups</title>
      <p>The construct a generalizations of Suzuki 2-groups was proposed by Hakai in [16] at
research conjugacy classes and characters for a family of groups satisfying Bannai
condition. Construction of groups.</p>
      <p>Let F , q = 2n is the finite field, and  is an automorphism of F . Define for a
q
positive integer l and a1, a2 ,..., al  F the following matrix
and
 1 
 a1 1 
S(a1, a2 ,..., al ) =  aa32 aa12 a11 2 1   Ml+1(F)
 ... ... ... ... ... 
 al al−1 al−2 2 ... a1 l−1 1</p>
      <p>Al (n, ) = S (a1, a2 ,..., al ) | ai  Fq  .</p>
      <p>The each element of Al (n, ) can be expressed uniquely and it follows that
Al (n, ) = 2nl and Al (n, ) define a group of order 2nl . If l = 2 , this group is
isomorphic to a Suzuki 2-group A(n, ) .</p>
      <p>Group operation is defined as a product of two matrices
S (a1, a2 ,..., al )S (b1, b2 ,...,bl ) = S (a1 + b1, a2 + (a1 )b1 + b2 , a3 + (a2 )b1 + (a1 2 )b2 + b3 ,
..., al + (al−1 )b1 + ... + (a1 l−1)bl−1 + bl ).</p>
      <p>Identity element is unit diagonal matrix S (01, 0,..., 0) .The inverse element is
determined by the inverse of the matrix. The direct calculations can to show that
S (a1 ,a2 ,a3 ,..., al )−1 = S (a1 ,a2 + a1 a1 ,a3 + a2 a1 + a1 2 (a2 + a1 a1),..., al + al−1 a1 + ...).</p>
      <p>Put G = Al (n, ) . The group G is nonabelian group and has nontrivial center</p>
      <p>Z (G ) = S (0,0,..., c) c  Fq  .</p>
      <p>Since the center Z (G ) is elementary abelian of order q, it can be identified with
the additive group of the field F . Assume that  is the Frobenius automorphism of
q
F , : x → x2 . All the involutions of G are in the center Z (G ) . Define</p>
      <p>Gi = S (0,..., 0, ai , ai+1,..., al ) .</p>
      <p>The elements g  Gi have order 2l−i .</p>
      <p>Let  /  ≙   −1( ,  ). Thus Gi is a normal subgroup of Al (n, ) . Simple show
that group Gi for i  (l +1) / 2 is abelian. This holds by direct calculations.</p>
      <p>Let   F  , λ is a generator of F  and is fixed and define mapping
 : Al (n, ) → Al (n, ) by
where</p>
      <p> ( S (a1, a2 ,..., al )) = S (1a1,2a2 ,...,l al )
1 =  , 2 =  2 , 3 =  ( 2 )2 , …, i =  2i−1 +1 .</p>
      <p>Then mapping   is an automorphism of Al (n, ) and if (n, i) = 1 , then   permutes
Gi / Gi+1 − Gi+1 transitively. For the fixed finite field, the group Al (n, ) order is greater
than classical Suzuki 2 - group. A larger group order gives an advantage to
cryptosystem secrecy, and definition over small fields gives an advantage for the implementation
in general.
3</p>
    </sec>
    <sec id="sec-3">
      <title>MST cryptosystems</title>
      <p>The basic idea of MST cryptosystems is to surjective mapping input message into an
element of group using a conversion key. Formalization of computations is given by
the following definition [12]. Definition 1 (cover (logarithmic signature) mappings).
Let  =  A1,..., As  be a cover (logarithmic signature) of type (r1, r2 ,..., rs ) for G with
Ai = ai,1, ai,2 ,..., ai,ri  , where m = is=1 ri . Let m1 = 1 and mi = ij−=11 rj for i = 2,..., s .</p>
      <sec id="sec-3-1">
        <title>Let  denote the canonical bijection</title>
        <p>Then the surjective (bijection) mapping  ′: ℤ
→  induced by is
 : ℤ 1 × ℤ 2 ×. . .× ℤ  → ℤ ,</p>
        <p>s
 ( j1, j2 ,..., js ) =  ji  mi .</p>
        <p>i=1
 '( x) = a1 j1  a2 j2  asjs
where ( j1, j2 ,..., js ) = −1 ( x) .</p>
        <p>More generally, if  =  A1,..., As  is a logarithmic signature (cover) for, then each
element g  G ∈ can be expressed uniquely (at least one way) as a product of the form
g = a1  a2    as ,
for ai  Ai [7].</p>
        <p>Let G is ultimate nonabelian group with nontrivial center Z , such that G does not
decompose over Z . Suppose that Z is quite large, such that the search is over Z is
computational impracticable.</p>
        <p>The cryptographic hypothesis, which is the basis for the cryptosystem, is that if
 = [A1, A2 ,..., As ] := (ai, j ) – accidental cover for a "large" matrices S at G , then
search for the layout g = a1 j1 a2 j2    asjs for any element g  G relatively  is, in
general, not a solvable problem. There are several encryption algorithms for MST
cryptosystems. One of the latest versions of MST3 presented in [13] has the following
implementation.The main steps of the encryption algorithm. Public and private key
calculation step:
• generating a tame logarithmic signatures  = [B1, B2 ,..., Bs ] := (bij ) the class
•
•
•
•
(r1 ,r2 ,...,rs ) for ℤ;
generating a random cover  = [A1, A2 ,..., As ] := (ai, j ) the same class as і 
for some subset J from G such that A1,..., As  G \ Z ;
generating a set of elements t0 , t1..., ts  G \ Z ;
definition of the homomorphism to calculate : 
→ ℤ;
calculating  := (hij ) = (ti−−11 f (aij )bijti ) for i = 1,..., s , j = 1,..., ri .</p>
        <p>Will get public key – ( = (aij ), = (hij ), f ) and private key – ( = (bij ), (t0 ,...., t s ))
Encryption step. Set a random number R  Z . Let the message to be encrypted
x  Z Z . Calculate</p>
        <p>y1 =  '(R)  x ,
y2 =  (R) = t0−1 f ( '(R))b '(R)ts .</p>
        <p>Transmit y = ( y1, y2 ) .</p>
        <p>Decryption step. For decryption we have the cipher text y = ( y1, y2 ) , private key
( = (bij ), (t0 ,...., t s )) and the function of the homomorphism f : G →
.</p>
        <p>Let's calculate  (R) = y2ts−1 f ( y1 )−1t0 . Checking is determined by the fact that
y2 =  (R) = t0−1 f (a1 j1 (R))b1 j1 (R)t1    ts−−11 f (asjs (R))bsjs (R)ts
= b1 j1 (R)t0−1 f (a1 j1 (R))t1    bsjs (R)ts−−11 f (asjs (R))ts =  (R)t0−1 f ( (R))ts =  (R)t0−1 f ( y1 )ts
Recover R with  (R) using  −1 , because  is simple.</p>
        <p>Calculate x =  '(R)−1  y1 .</p>
        <p>Complexity analysis.The main costs of implementation in the MST3 cryptosystem
are determined by the volume a logarithmic signature over the finite field of the group
representation.</p>
        <p>The long-term key is defined by a logarithmic signature array  and vectors
t0 , t1..., ts  G \ Z .</p>
        <p>Let type a logarithmic signatures over the finite field F , q = 2n is ( r1,..., rs ) and
q
is=1 ri = 2n .</p>
        <p>Suppose that the values ri are approximately equal ri = 2n/s , then the size V of the
logarithmic signature will have an estimate s2n/s . For q = 2512 and s = 25 , 26 , 27 , 28 we
obtain, respectively, V = 221, 214 , 211, 210 of the 512 bit strings.</p>
        <p>The large size of the logarithmic signature is a drawback to the practical
implementation of the MST3 cryptosystem.</p>
        <p>On the other hand, the large size of the logarithmic signature determines the
potentially very large entropy of the long-term key for cryptographic transformations.</p>
        <p>Security Analysis. Message x masked by a logarithmic signature on the arrays
 = (aij ) ,  = (hij ) which is calculated for a random number R .</p>
        <p>The function of the homomorphism  :  → ℤ moves the group element to the center
of the group. The random values R are actually a session keys. Calculation
 (R) = y2ts−1 f ( y1)−1t0 and the subsequent recovery of R is possible due to the
commutativity of the center. Commutative calculations in the center reduce the secrecy
of the MST3 cryptosystem based on Suzuki 2-group to evaluate  (q2 ) .
4</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>MST3 cryptosystems based on the generalized Suzuki 2 groups</title>
      <p>We apply the above construction to build the MST3 cryptosystem based on the
generalized Suzuki group.</p>
      <p>Very large generalized Suzuki groups can be constructed over a finite field of fixed
dimension. This allows to achieve a compromise between practical implementation and
the cryptosystem secrecy. Description of the Scheme. Let’s consider basic encryption
steps in MST3 cryptosystem based on the generalized Suzuki group.</p>
      <p>Key Generation:
Input: a large group Al (n, ) = S (a1, a2 ,..., al ) | ai  Fq  , q = 2n with the center Z
 f , ( k , k )
with
corresponding
private
key
Output: a
public</p>
      <p>key
 k , (t0(k) ,..., ts(k) </p>
      <p>) , k = 1, l / 2 .</p>
      <p>Choose
a
tame
logarithmic
signatures
 k = B1(k) ,..., Bs(k)  = (bij )k = S (0,.., 0,bij(l /2+k ) , 0,..., 0) of type (r1(k) ,..., rs(k) ) , i = 1, s ,
j = 1, ri(k ) , bij(l/2+k )  Fq , k = 1, l / 2 . The tame logarithmic signature is defined as a
bijective and factorizable map of  k ( R ) . Select a random cover</p>
      <p> k =  A1(k) ,..., As(k)  = (aij )k = S (0,..., 0, ai(j1()k), 0,..., 0, ai(j2(l)/2+k) , 0,..., 0)
of the same type as  , where aij  Al (n, ) , ai(j1()k) , ai(j2()k)  Fq \ 0 , i = 1, s , j = 1, ri(k ) ,
k = 1, l / 2 .</p>
      <p>Choose t0(k),t1(k),...,ts(k)  Al(n, ) \ Z , ti(k) = S(ti1(k),...,til(k)) , tij(k)  F , i = 0,s ,
j =1,l , k =1,l / 2 . Let’s ts(v) = t0(v+1) , v =1,l / 2−1.</p>
      <p>Construct
a
homomorphism
f
defined
by
f (S(a1,...,al)) = S(0,...,0,a'l/2+1 = a1,...,a'l = al/2).</p>
      <p>Compute  k = h1(k),...,hs(k) = (h ) = t(−i1−1)(k) f ((a ) )(bij )k ti(k) , i =1,s , j =1,ri ,
ij k ij k
k =1,l / 2 , where f ((aij )k )(bij )k = S (0,...,0,(ai(j1) )l/2+k +(bij )l/2+k
,0,...,0).</p>
      <p>Output public key  f ,(k, k), and private key k,(t0(k),...,ts(k) ) , k =1,l / 2 .</p>
      <sec id="sec-4-1">
        <title>Encryption:</title>
        <p>Input: a message xGl/2+1, and the public key  f ,(k, k), k =1,l / 2 .</p>
      </sec>
      <sec id="sec-4-2">
        <title>Compute:</title>
        <p>Output: a ciphertext ( y1, y2 ) of the message x .</p>
        <p>
          Choose a random R = (R1,R2,...,Rl/2) ,  1, 2,...,  /2 ∈ ℤ|  |.
y1 = '(R)x =1 '(R1)2 '(R2 )3 '(R3)l/2 '(Rl/2 ) x
= S (a1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R1),a2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R2 )+,...,al(1/2) (Rl/2 )+,al(/22)+1 (R1)+ xl/2+1 +,...,al(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) (Rl/2 )+ xl +).
        </p>
        <p>The components of () in the formula are determined by cross-calculations in the
group operation of the product.</p>
        <p>
          Compute:
y2 = '(R) =1 '(R1) 2 '(R2 )l/2 '(Rl/2 )
= S (,,...,,al(/12)+1 (R1)+l/2+1 (R1)+,...,al(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (Rl/2 )+l (Rl/2 )+).
        </p>
        <p>Here, the () components are determined by cross-calculations in the group
operation of the product of t0(k),...,ts(k), k =1,l / 2 .</p>
        <p>Output ( y1, y2 ).</p>
        <p>
          Decryption:
Input: a ciphertext ( y1, y2 ) and private key k,(t0(k),...,ts(k) ) , k =1,l / 2 .
Output: the message xGl/2+1 corresponding to ciphertext ( y1, y2 ).
To decrypt a message x , we need to restore random numbers R = (R1,R2,...,Rl/2)
The parameter a1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R1) is known from the y1 as the first parameter and it is included
in the l / 2 +1 component of y2 , because al(1/2)+1 (R1) = a1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R1) . Compute:
D(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )(R1,R2,...,Rl/2) = t0(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  y2ts−(1l/2)
= S (0,...,0,al(1/2)+1(R1)+l/2+1 (R1),...,al(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (Rl/2 )+l (Rl/2 )).
        </p>
        <p>
          D(R) = D(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )(R1,R2,...,Rl/2) f (y1)
= S (0,...,0,l/2+1(R1),al(1/2)+2 (R2 )+l/2+2 (R2 )+,...).
        </p>
        <p>Restore R1 with l/2+1 (R1) using l/2+1 (R1)−1 , because  is simple.</p>
        <p>For further calculations, it is necessary to remove the components of the arrays
1 '(R1) and 1 '(R1) from ciphertext ( y1, y2 ).</p>
        <p>
          Compute:
y1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) =1 '(R1)−1  y1 =2 '(R2 )3 '(R3)l/2 '(Rl/2 ) x
= S (0,a2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R2 ),a3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R3)+,...,al(1/2) (Rl/2 )+,
xl/2+1 +,al(/22)+2 (R2 )+ xl/2+2 +,...,al(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) (Rl/2 )+ xl +)
y2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) =1 '(R1)−1 y2 =2 '(R2 )l/2 '(Rl/2 )
= S (,,...,,al(1/2)+2 (R2)+l/2+2 (R2)+,...,al(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (Rl/2 )+l (Rl/2 )+).
        </p>
      </sec>
      <sec id="sec-4-3">
        <title>Repeat the calculations</title>
        <p>
          D(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )(R2,...,Rl/2) = t0(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )  y2ts−(1l/2)
= S (0,...,0,al(1/2)+2 (R2 )+l/2+2 (R2 ),...,al(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (Rl/2 )+l (Rl/2 ))
        </p>
        <p>
          D(R) = D(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )(R2,...,Rl/2) f (y1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) )
= S (0,...,0,l/2+2 (R2 ),al(1/2)+3 (R3)+l/2+3 (R3)+,...).
        </p>
        <p>Restore R2 with l/2+2 (R2 ) using l/2+2 (R2 )−1 .</p>
        <p>Repeating iteratively calculating after l / 2 steps, we obtain the recovery of
R = (R1,R2,...,Rl/2) and the message x from y1.</p>
        <p>Example. We will show the correctness of the obtained expressions in the following
simple example. Fix the generalized Suzuki group G = A4(n, ) over the finite field
Fq , q = 210 . Assume that  is the Frobenius automorphism of Fq, : → 2.</p>
        <p>Let’s define A4(n, ) =S(a1,a2,a3,a4) | ai Fq .</p>
        <p>Group operation is defined as a product of two matrices</p>
        <p>S(a1,a2,a3,a4)S(b1,b2,b3,b4) =</p>
        <p>S(a1 +b1,a2 + a12b1 +b2,a3 + a22b1 + a14b2 +b3,a4 + a32b1 + a24b2 + a18b3 +b4).
The inverse element is determined as</p>
        <p>S(a1,a2,a3,a4)−1 = S(a1,a2 + a12a1,a3 + a22a1 + a14(a2 + a12a1),
a4 + a32a1 + a24(a2 + a12a1)+ a18(a3 + a22a1 + a14(a2 + a12a1))) =</p>
        <p>S(a1,a2 + a13,a3 + a22a1 + a14a'2,a4 + a32a1 + a24a'2+ a18a'3)
where a'2 = a2 + a13 , a'3 = a3 + a22a1 + a14a'2 .</p>
        <p>Let`s construct a tame
k = B1(k),...,Bs(k) = (bij )k = S (0,..,0,bij(l/2+k),0,...,0) of type (r1(k),...,rs(k) ) , i =1,s ,
logarithmic
signatures
j =1,ri(k) , bij(l/2+k)  Fq , k =1,l / 2 .</p>
        <p>
          We have l = 4 , k =1,2 . Let`s define two arrays as follows
1 = B1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ,..., Bs(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  = (bij )1 = S (0, 0, bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) , 0) ,
 2 = B1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., Bs(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )  = (bij )2 = S (0, 0, 0, bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) )
and bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) , bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          )  F .
        </p>
        <p>q</p>
        <p>
          Logarithmic signatures 1 and  2 in a group representations define bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) and bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          )
coordinates. Types (r1(k) ,..., rs(k) ) and logarithmic signatures 1 and  2 are chosen
independently. Let`s logarithmic signatures 1
and  2
have a same type
(r1(k) ,..., rs(k) ) = (r1,..., rs ) .
        </p>
        <p>
          As an example, (r1,..., rs ) = (22 , 22 , 23 , 23 ) . Arrays bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) , bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) consist of four
subarrays with a number of rows equal to ri . You can select any fragmentation of arrays
with the condition is=1 ri = q . In our case we have is=1 ri = 210 . Each row bij it`s an
element of the field F .
        </p>
        <p>q
The construction of arrays of logarithmic signatures is presented in [17].</p>
        <p>First stage is to generate a tame logarithmic signature with the dimension of
corresponding selected type (r1(k) ,..., rs(k) ) and finite field Fq .</p>
        <p>In
our</p>
        <p>case
 k = B1(k) , B2(k) , B3(k) , B4(k)  .</p>
        <p>(r1(k) ,..., rs(k) ) = ( 22 , 22 , 23 , 23 ) ,</p>
        <p>q = 210
Since
1
and
 2
have
a
same
and
type
(r1(k) ,..., rs(k) ) = (r1,..., rs ) we will get the same  k , k = 1, 2 on the first stage.</p>
        <p>Let's set a tame logarithmic signature with entries Bi.</p>
        <p>
          β(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )=
        </p>
        <p>B1
B2
B3
B4</p>
        <p>
          To calculate  ( R )−1 it is enough to select groups of bits in the vector according to
the type
 ( R)−1 = 10 00 010 101 = ( R1, R2 , R3 , R4 ) = (
          <xref ref-type="bibr" rid="ref1 ref2 ref5">1, 0, 2, 5</xref>
          )
and recover R .
        </p>
        <p>Bits positions in a logarithmic signature vector  ( R ) are uniquely associated with
subarrays Bi(k ) and bit values at these positions with the row number of the subarray
Bi(k ) . To increase the security of arrays  k various cryptographic transformations can
be used. For example, simple ones like adding noise vectors, permutations of strings in
subarrays Bi , merge of arrays Bi , their permutation, matrix transformations.</p>
        <p>
          In our example, we use noising of β(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) and merge of arrays Bi . This allows to
construct two different logarithmic signatures 1 and  2 . Perform random noising of β(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )
in accordance with the above mentioned rule
β(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )=
        </p>
        <p>B1
B2
B3
B4</p>
        <p>
          Here the noise bits are in bold. For R = (
          <xref ref-type="bibr" rid="ref1 ref2 ref5">1, 0, 2, 5</xref>
          ) we get the logarithmic signature
vector
 ( R) = B1 ( R1 ) + B2 ( R2 ) + B3 ( R3 ) + B4 ( R4 ) =
Let`s define a highest group of bits in the vector for the calculation of  ( R )−1 in
accordance with type  ( R)−1 = 0110 000 101 → (,,, 5) and by the combination of
101 we will recover R4 . Select the sixth row from the array B4 and deduct it from the
original vector
        </p>
        <p> ( R)−1 = 0110000101 + 0100010000 = 0010 010 101 → (, , 2, 5).</p>
        <p>
          Repeat this procedure until the last subarray of the logarithmic signature and restore
( R1, R2 , R3 , R4 ) = (
          <xref ref-type="bibr" rid="ref1 ref2 ref5">1, 0, 2, 5</xref>
          ) . Apply the merge procedure for the subarrays B1, B2 , B3 , B4
within a rule of C1 = ( B1, B4 ) , C2 = B2 , C3 = B3 . The first logarithmic signature 1
has the type ( r1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ,..., rs(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ) = (25 , 22 , 23 ) and imagine these permutations on the next map
1 2 3 4 
1 =   . In the field representation 1 has the following form
 4 1 2 3
β1= B1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {25,103,380,332,666,173,820,814,385,525,195,
261,787,364,151,830,81,908,528,765,612,47,
588,442,258,705,330,846,751,397,989,136}
B2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {77,154,10,957}
        </p>
        <p>
          B3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {154,232,309,620,849,654,578,404}
        </p>
        <p>
          The numerical values of arrays determine the degree indicators of the generating
element of the field  =  i , whose binary representation are strings β1. Representation
of 0 defines single element 0 of the field Fq . Similarly, we construct the second
logarithmic signature  2 . We represent these permutations by a mapping of the form
1 2 3 4 
 2 =   . We got a new type ( r1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., rs(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ) = (22 , 25 , 23 ) of a logarithmic
1 4 2 3
signature  2 .  2 has the following form in the field representation
β2= B1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) {00,0,1,77}
        </p>
        <p>
          B2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) {258,705,330,846,751,397,989,136,577,45,
1009,592,704,921,941,187,680,667,643,84,
295,869,978,903,233,214,468,548,852,465,
333,475}
        </p>
        <p>
          B3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) {154,232,309,620,849,654,578,404}
        </p>
        <p>
          Arrays of logarithmic signatures 1 and  2 in the group representation, defines the
coordinates bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) and bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) , respectively
1 = B1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ,..., Bs(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  = (bij )1 = S (0, 0, bij(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) , 0) ,
 2 = B1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., Bs(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )  = (bij )2 = S (0, 0, 0, bij(
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) ) .
        </p>
        <p>
          Construct random covers  k , for the same type as 1 и  2
1 =  A1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ,..., As(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  = (aij )1 = S (ai(j1()1) , 0, ai(j1()3) , 0)
 2 =  A1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., As(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )  = (aij )2 = S (0, ai(j2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )), 0, ai(j2(
          <xref ref-type="bibr" rid="ref4">4</xref>
          )) ) ,
where aij  Al (n, ) , ai(j1()k) , ai(j2(k) +2)  Fq \ 0 , i = 1, s , j = 1, ri(k) , k = 1, 2 .
        </p>
        <p>Each cover  k defined by only two arrays (ai(j1()k) , ai(j2()k+2) ) with non-zero entries.
Let`s generate random covers  1 ,  2 .</p>
        <p>
          α1= A1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {(15,40),(
          <xref ref-type="bibr" rid="ref3">3,400</xref>
          ),(215,82),(990,633),
(1017,597),(212,67),(788,14),(101,35),
(876,505),(12,15),(21,44),(72,590),
(
          <xref ref-type="bibr" rid="ref4">4,319</xref>
          ),(161,431),(41,30),(181,1008),
(87,938),(427,713),(112,37),(611,147),
(
          <xref ref-type="bibr" rid="ref8">8,42</xref>
          ),(188,652),(98,744),(366,96),
(251,388),(349,726),(170,833),(110,897),
(429,616),(331,647),(298,801),(221,529)}
A2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {(717,101),(21,95),(977,1344),(170,195)}
A3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) {(454,865),(335,550),(881,677),(458,704),
        </p>
        <p>(644,233),(689,439),(329,934),(188,457)}
and
α2=</p>
        <p>
          A1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
A2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
A3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
{(111,1010),(51,349),(756,953),(337,527)}
{(210,243),(309,833),(221,133),(889,126),
(535,129),(909,565),(728,441),(572,375),
(15,637),(71,228),(
          <xref ref-type="bibr" rid="ref9">215,9</xref>
          ),(108,553),
(473,240),(348,570),(369,731),(213,416),
(648,799),(451,606),(713,587),(909,436),
(520,314),(19,52),(564,871),(11,531),
(449,277),(392,688),(265,1002),(78,93),
(223,924),(558,748),(372,975),(513,185)}
{(204,882),(69,633),(779,354),(988,754),
(2277,553),(419,894),(291,632),(551,15)}
Choose random t0(k) ,t1(k) ,...,ts(k)  Al (n, ) \ Z , s = 3 , l = 4 , k = 1, 2 and t3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) = t0(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) .
 1 = h1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ,..., h3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  = (hij )1 = t(−i1−1)(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) f ((aij )1 )(bij )1 ti(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )
 2 = h1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., h3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )  = (hij )2 = t(−i1−1)(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) f ((aij )2 )(bij )2 ti(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
Construct a homomorphism f defined by f ( S(a1, a2 , a3 , a4 )) = S(0, 0, a1, a2 ) .
For example, let R1 = ( R1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) , R2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) , R3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ) = (
          <xref ref-type="bibr" rid="ref1 ref1 ref5">1,1,5</xref>
          ) = 673 and
        </p>
        <p>
           1 (673) = h1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) h2(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) h3(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (
          <xref ref-type="bibr" rid="ref5">5</xref>
          ) = S (516,578,850,374) .
        </p>
        <p>
          Let R2 = ( R1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) , R2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) , R3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ) = (
          <xref ref-type="bibr" rid="ref2 ref2 ref6">2, 6, 2</xref>
          ) = 354 . Compute  2
        </p>
        <p>
           2 (354) = h1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) h2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) (
          <xref ref-type="bibr" rid="ref6">6</xref>
          ) h3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) = S (487, 227, 651,318) .
Output: the message x  G3 corresponding to ciphertext ( y1, y2 ) .
        </p>
        <p>To decrypt a message x , we need to restore random numbers R = (R1, R2 ) .
Compute</p>
        <p>
          D(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R1, R2 ) = t0(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) y2ts−(12) = t0(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) S (30, 766, 734,871)ts−(12) = S (0, 0, 459, 233).
D (R) = D(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) (R1, R2 ,..., Rl/2 ) f ( y1 ) = S (0,..., 0,l/2+1 ( R1 ), al(1/2)+2 ( R2 ) + l/2+2 ( R2 ) + ,...)
S (0, 0, 459, 233) S (0, 0,139,814) = S (0, 0, 235,950).
        </p>
        <p>We get 1 ( R1 ) =  235 = (0 0 0 0 1 1 1 1 0 0) .</p>
        <p>
          Recovery of R1 was done earlier R = ( R1, R2 , R3 ) = (
          <xref ref-type="bibr" rid="ref1 ref1 ref5">1,1,5</xref>
          ) .
        </p>
        <p>For further calculations, it is necessary to remove the components of the arrays
1 '( R1 ) and  1 '( R1 ) from ciphertext ( y1, y2 ) .</p>
        <p>
          Compute:
y(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) =  1 '( R1 )−1 y2 = S (516,578,850,374)−1 S (30, 766, 734,871) =
2
        </p>
        <p>
          Perform inverse calculations  2 ( R2 )−1 . Select bit groups in vector  ( R) according
to type (r1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ,..., rs(k2 ) = (22 , 22 , 23, 23 ) . We use the same calculations as in the example
for 1 ( R1 )−1 , and we get
11|11|110|011
00|11|100|011
11|00|010|000
01|00|010|000
10|00|000|000
11|00|000|000
01|00|000|000
        </p>
        <p>
          R2=(*,*,*,6)
row from β(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
R2= (*,*,2,6)
row from β(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
R2= (*,0,2,6)
row from β(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
        </p>
        <p>
          R2= (
          <xref ref-type="bibr" rid="ref2 ref2 ref6">2,0,2,6</xref>
          )
 2 ( R ')−1 = 11 00 010 011 = ( R1 ', R2 ', R3 ', R4 ') = (
          <xref ref-type="bibr" rid="ref2 ref2 ref6">2, 0, 2, 6</xref>
          ) .
        </p>
        <p>
          The resulting vector along with the concatenation of array entries B2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) , B4(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) due to
their merging, we write in the following bit representation
        </p>
        <p>
           2 ( R ')−1 := 2 (
          <xref ref-type="bibr" rid="ref2 ref2 ref6">2, 0, 2, 6</xref>
          ) → (
          <xref ref-type="bibr" rid="ref2 ref2">2, 6 0, 2</xref>
          ) = (01, 01100, 010) .
        </p>
        <p>
          The
transition
from
bit
to
numeric
gives
the
desired
value
R2 = ( R1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) , R2(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) , R3(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ) = (
          <xref ref-type="bibr" rid="ref2 ref2 ref6">2, 6, 2</xref>
          ) . Receive a message
x =  '( R)−1 y1 =  2 '( R2 )−1 1 '( R1 )−1  y1
= S (0, 693, 0, 418) S (139, 787, 0,148) S (139,814,393, 699) = S (0, 0, 299,824).
Output: the message x = (0, 0, 299,824) .
        </p>
        <p>
          Security Analysis. An attack on the cryptosystem is possible by solving the
 (R1, R2 ,..., Rl/2 ) = t0(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )  y2ts−(1l/2) f ( y1 ) equation by selecting t0(k) and ts(k) vectors.
        </p>
      </sec>
      <sec id="sec-4-4">
        <title>There are l / 2 such vectors.</title>
        <p>The success of an attack is determined by the selection of t0(k) and ts(k) vectors and
has complexity proportional to the l / 2 power of the group Al (n, ) due to the
noncommutativity of the generalized Suzuki group. Brute force attack is possible by
selection R1 , R2 ,..., Rl /2l </p>
        <p>. The complexity is determined by the value l / 2 , finite
field power Fq in proportion to l / 2 Fq . Complexity analysis. Fix the generalized
Suzuki group G = Al (n, ) and the logarithmic signature for the type ( r1 ,..., rs ) over the
finite field F , q = 2n . Suppose that the values ri are approximately equal ri = 2n/ s .</p>
        <p>q
Early show</p>
        <p>that the size of the logarithmic signature has the estimate
V = ls Al (n, ) 1/ls . For q = 264 , Al (n, ) = 2512 , l = 8 and s = 23 , 24 , 25 we obtain,
respectively, V = 214 , 211, 210 of the 64 bit strings.
5</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Conclusions</title>
      <p>The proposed design of the MST3 cryptosystem based on the generalized Suzuki
group provides potentially higher privacy and optimizes the cost of key data. The
difference from the well-known MST3 construction is the iterative key recovery from
calculations in the large normal subgroup of the generalized Suzuki group.
11. A. Garcia, H. Stichtenoth, C.-P.Xing, “On Subfields of the Hermitian Function Field”,</p>
      <p>Kluwer Academic Publishers, Compositio Mathematica 120: pp.137–170, 2000.
12. W. Lempken and T. van Trung, “On minimal logarithmic signatures of finite groups”,
Experimental Mathematics,vol.14, no. 3, pp. 257–269, 2005.
13. H.Hong, J.Li, L.Wang, Y. Yang, X.Niu “A Digital Signature Scheme Based on MST3
Cryptosystems” Hindawi Publishing Corporation, Mathematical Problems in Engineering ,vol
2014, 11 pages, http://dx.doi.org/10.1155/2014/630421
14. G.Khalimov, Y. Kotukh, S.Khalimova “MST3 cryptosystem based on the automorphism
group of the hermitian function field”, 2019 2019 IEEE International Scientific-Practical
Conference: Problems of Infocommunications Science and Technology, PIC S and T 2019
– Proceedings
15. G. Khalimov, T.T.Simon, A.M.Adrees, E.Kotukh “MST3 cryptosystem based on a small
Ree groups” 3rd IEEE international conference advanced information and communication
technologies-2019 “Next-generation networking for the Internet of Things: 5g, sdn, nfv and
cloud computing” 2~6 july, 2019 ,Lviv, Ukraine
16. A.Hanaki “A CONDITION ON LENGTHS OF CONJUGACY CLASSES AND</p>
      <p>CHARACTER DEGREES” Osaka J. Math. 33 pp.207-216, 1996
17. P. Svaba, “Covers and logarithmic signatures of finite groups in cryptography”, Dissertation,
https://bit.ly/2Ws2D24</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>N.R.</given-names>
            <surname>Wagner</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.R.</given-names>
            <surname>Magyarik</surname>
          </string-name>
          , “
          <article-title>A public-key cryptosystem based on the word problem”</article-title>
          ,
          <source>Proc. Advances in Cryptology - CRYPTO</source>
          <year>1984</year>
          , LNCS 196, Springer-Verlag (
          <year>1985</year>
          ), pp.
          <fpage>19</fpage>
          -
          <lpage>36</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. 2K.H.
          <string-name>
            <surname>Ko</surname>
            ,
            <given-names>S.J.</given-names>
          </string-name>
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>J.H .</given-names>
          </string-name>
          <string-name>
            <surname>Cheon</surname>
            ,
            <given-names>J.W .</given-names>
          </string-name>
          <string-name>
            <surname>Han</surname>
            ,
            <given-names>J</given-names>
          </string-name>
          . Kang, and
          <string-name>
            <given-names>C.</given-names>
            <surname>Park</surname>
          </string-name>
          , “
          <article-title>New public-key cryptosystem using braid groups”</article-title>
          ,
          <source>in Advances in cryptology-CRYPTO</source>
          <year>2000</year>
          ,vol.
          <source>1880of Lecture Notes in Computer Science</source>
          , pp.
          <fpage>166</fpage>
          -
          <lpage>183</lpage>
          , Springer, Berlin, Germany,
          <year>2000</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>B.</given-names>
            <surname>Eick</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Kahrobaei</surname>
          </string-name>
          , “
          <article-title>Polycyclic groups: a new platform for cryptology”</article-title>
          , http://arxiv.org/abs/math/0411077.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>V.</given-names>
            <surname>Shpilrain</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Ushakov</surname>
          </string-name>
          , “
          <article-title>Thompsons group and public key cryptography”</article-title>
          ,
          <source>in Applied Cryptography and Network Security</source>
          , vol.
          <volume>3531</volume>
          of Lecture Notes in Computer Science, pp.
          <fpage>151</fpage>
          -
          <lpage>164</lpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. 5D.
          <string-name>
            <surname>Kahrobaei</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Koupparis</surname>
            , and
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Shpilrain</surname>
          </string-name>
          , “
          <article-title>Public key exchange using matrices over group rings”</article-title>
          , Groups, Complexity, and Cryptology ,vol.
          <volume>5</volume>
          ,no.
          <issue>1</issue>
          ,pp.
          <fpage>97</fpage>
          -
          <lpage>115</lpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>S.S.</given-names>
            <surname>Magliveras</surname>
          </string-name>
          , “
          <article-title>A cryptosystem from logarithmic signatures of finite groups”</article-title>
          ,
          <source>in Proceedings of the 29th Midwest Symposium on Circuits and Systems</source>
          , pp.
          <fpage>972</fpage>
          -
          <lpage>975</lpage>
          ,
          <string-name>
            <surname>Elsevier</surname>
            <given-names>Publishing</given-names>
          </string-name>
          , Amsterdam, The Netherlands,
          <year>1986</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>W.</given-names>
            <surname>Lempken</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.S.</given-names>
            <surname>Magliveras</surname>
          </string-name>
          , Tran van Trung and
          <string-name>
            <given-names>W.</given-names>
            <surname>Wei</surname>
          </string-name>
          , “
          <article-title>A public key cryptosystem based on non-abelian finite groups”</article-title>
          ,
          <source>J. of Cryptology</source>
          ,
          <volume>22</volume>
          (
          <year>2009</year>
          ),
          <fpage>62</fpage>
          -
          <lpage>74</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>S.S.</given-names>
            <surname>Magliveras</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.R.</given-names>
            <surname>Stinson</surname>
          </string-name>
          , and T.vanTrung, “
          <article-title>New approaches to designing public key cryptosystems using one-way functions and trapdoors in finite groups”</article-title>
          ,
          <source>Journal of Cryptology</source>
          , vol.
          <volume>15</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>285</fpage>
          -
          <lpage>297</lpage>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>S.S.</given-names>
            <surname>Magliveras</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Svaba</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T. Van</given-names>
            <surname>Trung</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and P.</given-names>
            <surname>Zajac</surname>
          </string-name>
          , “
          <article-title>On the security of a realization of cryptosystem MST3”</article-title>
          ,
          <source>Tatra Mountains Mathematical Publications</source>
          ,vol.
          <volume>41</volume>
          ,pp.
          <fpage>65</fpage>
          -
          <lpage>78</lpage>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. H.Stichtenoth, “
          <article-title>Über die Automorphismengruppe eines algebraischen Funktionenkörpers von Primzahlcharakteristik” I, II, Arch</article-title>
          . Math.
          <volume>24</volume>
          , pp.
          <fpage>524</fpage>
          -
          <lpage>544</lpage>
          and pp.
          <fpage>615</fpage>
          -
          <lpage>631</lpage>
          ,
          <year>1973</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>