<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Cybersecurity Providing in Information and Telecommunication Systems, October</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>On Eulerian Transformations and Postquantum Access Control Protocol-Based Algorithms</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vasyl Ustimenko</string-name>
          <email>vasulustimenko@yahoo.pl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Pustovit</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Telecommunications and the Global Information Space</institution>
          ,
          <addr-line>13 Chokolivsky bul., Kyiv, 02000</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Marie Curie-Sklodowska in Lublin</institution>
          ,
          <addr-line>5 Plac Marii Curie-Skłodowskiej, Lublin, 20-031</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>26</volume>
      <issue>2021</issue>
      <fpage>251</fpage>
      <lpage>256</lpage>
      <abstract>
        <p>The paper is dedicated to applications of Noncomutative Cryptography to access control algorithms for Information Systems. The example of usage of the protocol based on multivariate transformations to access control tasks is given. The platforms for such protocols are subsemigroups of affine Cremona semigroup acting on affine space of dimension n with Multicomposition property, i.e. ability to make computation of the composition of n elements from subsemigroup in polynomial time T(n).The implementation of the algorithm is given in the case of platform of Eulerian transformations. The modification of main algorithm is based on the idea of combination of Eulerian Transformations with elements of affine Cremona group of bounded degree and polynomial density. Access control, noncommutative cryptography, multivariate cryptography, multicomposition property, Eulerian transformations, one-time pad.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <sec id="sec-1-1">
        <title>Protocol based approach to control access to information systems in information space is a very</title>
        <p>popular one. With the appearance of the first samples of quantum computers it is very important to
investigate potential of this approach. We study new postquantum resistant multivariate protocols
which can substitute unresistable to quantum computer based attacks Diffie-Hellman algorithm.
Current state of research in Postquantum Multivariate Cryptography is presented on the web page of
the future Satellite Conference “Mathematical Aspects of Post Quantum</p>
      </sec>
      <sec id="sec-1-2">
        <title>Cryptography” of the</title>
        <p>Mathematical Congress 2022 (see https://icm2022.org/satellites). One of the sixth main directions of
the Post Quantum Cryptography is Multivariate Cryptography for which affine Cremona semigroup
named after Luigi Cremona [1] and its multivariate transformations are the main instruments to create
cryptographical algorithms. These transformations are induced by endomorphisms of polynomial ring
K[x1, x2 ,..., xn ] over commutative ring K. The case K=Fq of finite field is very popular in classical</p>
      </sec>
      <sec id="sec-1-3">
        <title>Multivariate</title>
      </sec>
      <sec id="sec-1-4">
        <title>Cryptography. We discover large subgroups of</title>
        <p>CSn(K), n=2,3,…
with
the
Multicomposition property (MCP) which means possibility to compute the composition of N arbitrary
chosen elements of CSn(K) in polynomial time T(n). We assume that each element of CSn(K) is given
in its standard polynomial form xi  fi (x1, x2 ,..., xn ), i=1,2,…n.
2. On</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>Multivariate</title>
    </sec>
    <sec id="sec-3">
      <title>Protocols of</title>
    </sec>
    <sec id="sec-4">
      <title>Noncommutative</title>
    </sec>
    <sec id="sec-5">
      <title>CRYPTOGRAPHY and Access Control</title>
      <sec id="sec-5-1">
        <title>Tahoma protocol was introduced in [2]. It uses two semigroups Sn&lt;SCn(K) and Sm&lt;CSm(K), m&lt;n</title>
        <p>2022 Copyright for this paper by its authors.
elements g'1 , g'2 ,..., g'k from Sn together with elements h1, h2 ,..., hk from Sm conjugated with
 (g'1 ), (g'2 ),..., (g'k ).</p>
        <p>Alice sends pair (gi, hi), i=1, 2,…,k to Bob.</p>
        <p>
          Bob selects sequences w(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )=(i(
          <xref ref-type="bibr" rid="ref1 ref1">1,1</xref>
          ), i(
          <xref ref-type="bibr" rid="ref1 ref2">2,1</xref>
          ), …, i(l(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ),1), w(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )=(i(
          <xref ref-type="bibr" rid="ref1 ref2">1,2</xref>
          ), i(
          <xref ref-type="bibr" rid="ref2 ref2">2,2</xref>
          ), …, i(l(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),2),, ….,
w(s)=(i(1,s), i(2,s), …, i(l(s),s) of elements from {1,2,…,k}
        </p>
        <p>He sends g(j)=gi(1,j)gi(2,j), … gi(l(j),j), j=1,2,…,s to Alice. Bob keeps z(j)=hi(1,j)hi(2,j), … hi(l(j),j),
j=1,2,…,s in his private storage.</p>
      </sec>
      <sec id="sec-5-2">
        <title>Alice restores z(j) because of her knowledge on the input data. Postquantum seсurity of the</title>
        <p>protocol rests on the problem of decomposition of w(i) into generators gi .</p>
        <p>Access control algorithm.</p>
      </sec>
      <sec id="sec-5-3">
        <title>Alice (administrator of information system) forms pseudorandom or genuine random system (p1,</title>
        <p>
          p2,…,pm) from Km and word w in the alphabet z(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ), z(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),…,z(s). Alice sets password as w(p). Bob
enters w(p) and gets access to the system.
        </p>
      </sec>
      <sec id="sec-5-4">
        <title>Algorithm is implemented with various platforms Sn, Sm and homomorphism between them (see</title>
        <p>[3–5]).</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>3. Case of Eulerian Platform</title>
      <sec id="sec-6-1">
        <title>Let us consider the case when Sn and Sm are subsemigroups of semigroups ESn(K) and ESm(K) of</title>
        <p>Eulerian transformations, i.e. transformations moving each variable xi into monomial term
qix1α(i,1)x2α(i,2)…xnα(i,n) (t=n or t=m) where qi are regular elements of K and a(i,j) from Zd ,d=|K*|.
These transformations were used for the development of public key algorithms [6, 7] and key
exchange protocols [8] and key generation algorithm of one time pad encryption [9].</p>
      </sec>
      <sec id="sec-6-2">
        <title>For simplicity we assume that algorithm has two outputs z(1) and z(2) with coefficients qi, a(i,j) and q’i, a’(i,j) respectively. Alice and Bob use generator of pseudorandom sequence (r1, r2 ,…,rm)=r where ri, are from K*.</title>
        <p>
          They form formal word w of kind z(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) α(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) z(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) α(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) z(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) α(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) … or z(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) b(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )z(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) b(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )z(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) b(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) … of length k,
k=O(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) and use w(r) as entrance password.
        </p>
        <sec id="sec-6-2-1">
          <title>It is clear that the execution time of the protocol is O(n 3) which is the time to compute the</title>
          <p>composition of the elements from ESn(K).</p>
        </sec>
        <sec id="sec-6-2-2">
          <title>The computation of the entrance password costs O(m2) because Alice and Bob use publicly known</title>
          <p>
            decomposition of w into hidden z(
            <xref ref-type="bibr" rid="ref1">1</xref>
            ) and z(
            <xref ref-type="bibr" rid="ref2">2</xref>
            ).
          </p>
        </sec>
      </sec>
      <sec id="sec-6-3">
        <title>Assume that Alice and Bob use word w without change and the adversary is able to intercept some</title>
        <p>pairs (r, w(r)) where unknown w is of kind xi →yi x1 y(i,1) x2 y(i,2)… xm y(i,m) , i=1,2, …, n .The word
depends on m2+m unknowns. So Alice and Bob can use unchanged word safely &lt;m+1 times.</p>
      </sec>
      <sec id="sec-6-4">
        <title>With this restrictions the only option for adversary is to break postquantum safe protocol. So Alice</title>
        <p>and Bob can use various words w during practically unlimited time. Noteworthy that they can change
the size of parameter m via new session of the protocol with the same or new platform.</p>
      </sec>
      <sec id="sec-6-5">
        <title>Alternative usage. In this case correspondents can use the protocol with several outputs for the</title>
        <p>generation of password for “multiplicative” one time pad with plainspace (K*) m and encryption
function (x1 , x2 ,…, xm )→( x1p1, x2p2 , …, xmpm) where p=(p1, p2 ,…, pm) is the password.</p>
        <p>They form password via described above process of generation pairs (w , r) and setting p=w(r).</p>
      </sec>
      <sec id="sec-6-6">
        <title>Password has to be used only one time.</title>
        <p>Noteworthy that in the case K=Fq correspondents can use plainspace Kn and additive one time pad
with encryption function (x1 , x2 ,…, xm )→( x1 + p1, x2 + p2 , …, xm + pm).</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>4. An Example of Implementation</title>
      <sec id="sec-7-1">
        <title>Let us consider an Eulerian semigroup ESn(K), which is a subsemigroup of CSn(K) of transformations of kind xi→ti(x1,x2,…,xn), where ti are monomial terms in K[x1,x2,…,xn]. Let LEn(K) be a subsemigroup of ESn(K) of kind</title>
        <p>
          x1→q1x1a(
          <xref ref-type="bibr" rid="ref1 ref1">1,1</xref>
          )
L: x2→q2a21x1a(
          <xref ref-type="bibr" rid="ref1 ref2">2,1</xref>
          )x2a(
          <xref ref-type="bibr" rid="ref2 ref2">2,2</xref>
          )
        </p>
        <p>
          …
xn→qnan1x1a(n,1)x2a(n,2)…xna(n,n)
where qi are regular element of K
together with subgroups UEn(K) of transformations of kind
x1→q1x1a(
          <xref ref-type="bibr" rid="ref1 ref1">1,1</xref>
          )x2a(
          <xref ref-type="bibr" rid="ref1 ref2">1,2</xref>
          )…xna(1,n)
U: x2→q2x1a(
          <xref ref-type="bibr" rid="ref1 ref2">2,1</xref>
          )x2a(
          <xref ref-type="bibr" rid="ref2 ref2">2,2</xref>
          )…xn-1a(2,n-1)
…
xn→qnx1a(n,1)
        </p>
        <sec id="sec-7-1-1">
          <title>Notice that in the case of finite K map L is invertible transformation of (K*)n if a(1,1), a(2,2),…,</title>
          <p>a(n,n) are mutually prime with d=|K*|. Similarly U induces a bijection of K* if a(n,1),
a(n</p>
        </sec>
      </sec>
      <sec id="sec-7-2">
        <title>1,1),…,a(1,1) are mutualy prime with d.</title>
        <p>
          Assume that m&lt;n. We consider a parabolic semigroup Pn,m(K) of all transformations of kind
x1→q1x1a(
          <xref ref-type="bibr" rid="ref1 ref1">1,1</xref>
          )x2a(
          <xref ref-type="bibr" rid="ref1 ref2">1,2</xref>
          )…xma(1,m)
x2→q2x1a(
          <xref ref-type="bibr" rid="ref1 ref2">2,1</xref>
          )x2a(
          <xref ref-type="bibr" rid="ref2 ref2">2,2</xref>
          )…xma(2,m)
        </p>
        <p>…
xm→qm x1a(m,1)x2a(m,2)…xma(n,m)
xm+1→qm+1x1a(m+1,1)x2a(m+1,2)…xma(m+1,n)
xm+2→qm+2x1a(m+2,1) x2a(m+2,2)… xma(m+2,n)</p>
        <p>…
xn→qnx1a(n,1) x2a(n,2) …xna(n,n)</p>
      </sec>
      <sec id="sec-7-3">
        <title>Let φn,m(g) be the restriction of g є Pn,m(K) onto variables x1, x2,…,xm. It is easy to see that φn,m is a</title>
        <p>homomorphism of Pn,m(K) onto ESm(K). We consider a special case of Tahoma protocol presented in
[2].</p>
      </sec>
      <sec id="sec-7-4">
        <title>Alice takes transformations p1, p2,…, pt є Pn,m(K) with pseudorandom coefficient for pi given by</title>
        <p>
          list iq1, iq2,…, iqn, from K* and ia(i,j) from Zd., d=|K*|. Alice takes L є LEn(K) given by coefficients
b(i,j), i≤j, qi є K*, i=1,2,…,n and U є UEn(K) with coefficients c(i,j), j≤i and qi’ є K*, i=1,2,…,n. We
assume that b(
          <xref ref-type="bibr" rid="ref1 ref1">1,1</xref>
          ), b(
          <xref ref-type="bibr" rid="ref2 ref2">2,2</xref>
          ),…, b(n,n) and c(1,n), c(2,n),…, c(n,n) are mutually prime with d=|K*|.
        </p>
        <p>Alice forms elements p1, p2,…, pt ai=ULpiU-1L-1 , i=1,2,…n where U-1 and L-1 are inverse
automorphisms for U and L from AutK[x1,x2,…,xn]. She computes bi=φ(pi) and takes automorphism
U’ є UEm(K) and L’ є LEm(K).</p>
        <p>Alice computes bi=U’L’φ(pi)(U’L’)-1, where U’єUEm(K), L’єULm(K) and sends pairs (ai,bi) to Bob.</p>
        <p>Bob takes sequences rj(1,r), rj(2,r),…, rj(l(r),r)є{1,2,…,t}, r є{1,2,…, k} and forms
wr=aj(1,r)aj(2,r)…aj(l®, r) and wr’= bj(1, r)bj(2,r)…bj(l®, r). He sends wr to Alice and keeps wr’ for himself.</p>
        <p>Alice restores w’r via computation of L-1(U’)-1wr’LU=v, φ(v) and U’L’φ(v)(U’L’)-1. zr=w’r are
collision elements (outputs) of the protocol. The complexity of algorithm is established by the
complexity of composition of two elements from ESn(K) which is O(n3).</p>
      </sec>
      <sec id="sec-7-5">
        <title>The protocol can be used for the presented access control algorithm. Correspondents can use</title>
        <p>strings (r1,r2,…,rm)є(K*)n to form entrance password to the system.</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>5. Algorithm Modification</title>
      <p>Assume that zr is given by the rule
x1→rq1x1 a(1,1,r)x2a(1,2,r)…xm a(1,m,r)
x2→rq2x2a(2,1,r) x2a(2,2,r)… xm a(2,m,r)</p>
      <p>…
xn→rqmxm a(m,1.r)x2a(m,2,r)… xn a(m,m,r)
…
…
We form zr via consideration of
g1(r)=rq1rq1x1a(1,1,r)+ q1rq2x2a(1,2,r)+rq1rqmxma(1,m,r)
r
g2(r)=rq2rq1x1a(1,1,r)+rq2rq2x2a(1,2,r)+rq2rqmxma(1,m,r)
…
and the map</p>
      <p>x1→g1(r),x2→g2(r), …,xn→gn(r)</p>
      <sec id="sec-8-1">
        <title>We define Gi(1)i(2)…i(k) as the rule</title>
        <p>
          x1→g1(i(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ))g1(i(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ))…g1(i(k)),
x2→g2(i(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ))g2(i(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ))…g2(i(k)),
…
xm→gm(i(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ))gm(i(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ))…gm(i(k)).
        </p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>5.1. Modified Access Control Algorithm Based on Protocol</title>
      <p>
        Alice and Bob selects two strings (j(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), j(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…j(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )))є{1,2,…,t}k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) and (i(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), i(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…i(k(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ))
є{1,2,…,t}k(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ).
      </p>
      <p>
        They form composition Zj(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),j(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…,j(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )) of Zj(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), Zj(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ), …, Zj(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )) from ESm(K) and compose it with
Gi(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )i(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )…i(k(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )) єCSm(K). They will use this composition C=C(j(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),j(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…j(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )),i(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),i(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…,i(k(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )) of
Zj(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),j(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…,j(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )) and Gi(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )i(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )…i(k(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )) in affine Cremona group formally, i. e. without computation of the
standard form.
      </p>
      <p>
        In fact they create string r=(r1,r2,…,rm)є(K*)m and compute C=C(r) with the usage of
decomposition C into Z= Zj(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),j(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),…,j(k(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )) and G= Gi(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )i(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )…i(k) and given above formula in the definitions
of Z and G.
      </p>
      <sec id="sec-9-1">
        <title>Notice that standard forms C are of degree αm for some constant α, the density of C, i.e total</title>
        <p>
          number of monomials in its standard form is O(mk(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )+1). So the task of adversary to interpolate C via
interceptions of pairs of kind r, c(r) is impossible task.
        </p>
      </sec>
      <sec id="sec-9-2">
        <title>So the only option for adversary is to break the suggested above postquantum protocol.</title>
      </sec>
    </sec>
    <sec id="sec-10">
      <title>5.2. On the Symbiotic Combination with One Time Pad</title>
      <sec id="sec-10-1">
        <title>Classical one time pad over additive group K+ of the ring K is encryption function on the</title>
        <p>plainspace Kn given by the rule (x1,x2,…xm →(x1,x2,…xm)+(p1,p2,…,pm)= (y1,y2,…,ym) where password
(p1,p2,…,pm) and ciphertext (y1,y2,…,ym).</p>
        <p>
          Alice and Bob can use it via generation of passwords C(j(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ),j(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),…j(k(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )),i(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ),i(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),…,i(k(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ))(r)
generated via suggested above protocol based scheme.
        </p>
        <p>Complexity remarks</p>
      </sec>
      <sec id="sec-10-2">
        <title>1) The complexity of protocol is O(m3)</title>
      </sec>
      <sec id="sec-10-3">
        <title>2) The computation of Z(i) in the point (r1,r2,…,rm) takes O(m2)</title>
      </sec>
      <sec id="sec-10-4">
        <title>3) Generation of g(m) takes O(m2)</title>
      </sec>
      <sec id="sec-10-5">
        <title>The complexity of algorithm is O(m2(k(1)))+O(m2(k(2))). Suggestion: correspondents can select</title>
        <p>
          k(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) and k(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) of size O(m). Then complexity of entire algorithm is O(m3).
        </p>
        <sec id="sec-10-5-1">
          <title>The algorithm is implemented in the cases of finite fields and arithmetical rings of residues</title>
          <p>modulo q. q&gt;2.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-11">
      <title>6. Conclusion</title>
      <sec id="sec-11-1">
        <title>The paper gives an example of application of protocols of Noncommutative Cryptography (see [10–23]) to the problems of Access Control for Information Systems.</title>
      </sec>
      <sec id="sec-11-2">
        <title>The general scheme can be the following one. Alice and Bob use protocol based on the input (IAS)</title>
        <p>and output algebraic systems (OAS) given by some generators a1, a2,…, an and b1, b2, …, bm
respectively. Correspondents elaborate in a secure way some elements c1, c2,…, ct which generates
the special subsystem (RIS) of OIS. They take element w=w(c1, c2,…,ct) which is known function
from hidden generators ci.</p>
      </sec>
      <sec id="sec-11-3">
        <title>Finally they use some ‘’deformation rule” d to form entrance password d(w) for some Information</title>
      </sec>
      <sec id="sec-11-4">
        <title>System IS. 254</title>
      </sec>
      <sec id="sec-11-5">
        <title>For the selection of appropriate protocol recent cryptanalytical results [24–26] can be used.</title>
      </sec>
      <sec id="sec-11-6">
        <title>Flexibility of the method allows generalization for the case of multiuser mode. Descriptions of cryptographical problems in access control technology and alternative solutions reader can find in [27, 28].</title>
      </sec>
    </sec>
    <sec id="sec-12">
      <title>7. References</title>
      <p>[20] G. Kumar, H. Saini, Novel Noncommutative Cryptography Scheme Using Extra Special Group,</p>
      <sec id="sec-12-1">
        <title>Security and Communication Networks ,Volume 2017, Article ID 9036382, 21 pages,</title>
        <p>https://doi.org/10.1155/2017/9036382.
[21] A. Bessalov, et al., Analysis of 2-isogeny properties of generalized form Edwards curves, in:</p>
      </sec>
      <sec id="sec-12-2">
        <title>Proceedings of the Workshop on Cybersecurity Providing in Information and</title>
      </sec>
      <sec id="sec-12-3">
        <title>Telecommunication Systems, July 7, 2020, vol. 2746, pp. 1–13.</title>
        <p>[22] A. Bessalov, V. Sokolov, P. Skladannyi, Modeling of 3- and 5-isogenies of supersingular</p>
      </sec>
      <sec id="sec-12-4">
        <title>Edwards curves, in: Proceedings of the 2nd International Workshop on Modern Machine</title>
      </sec>
      <sec id="sec-12-5">
        <title>Learning Technologies and Data Science, June 2–3, 2020, no. I, vol. 2631, pp. 30–39.</title>
        <p>[23] A. Bessalov, et al., Computing of odd degree isogenies on supersingular twisted edwards curves,
in: Proceedings of the Workshop on Cybersecurity Providing in Information and</p>
      </sec>
      <sec id="sec-12-6">
        <title>Telecommunication Systems, January 28, 2021 vol. 2923, 1–11.</title>
        <p>[24] V. Roman'kov, An improved version of the AAG cryptographic protocol, Groups, Complex.,</p>
        <p>Cryptol, 11, No. 1 (2019), 35-42.
[25] A. Ben-Zvi, A. Kalka, B. Tsaban, Cryptanalysis via algebraic span, in: Shacham H. and</p>
        <sec id="sec-12-6-1">
          <title>Boldyreva A. (eds.) Advances in Cryptology, CRYPTO 2018. 38th Annual International</title>
        </sec>
      </sec>
      <sec id="sec-12-7">
        <title>Cryptology Conference, Santa Barbara, CA, USA, August 19-23, 2018, Proceedings, Part I, Vol.</title>
        <p>10991, 255{274, Springer, Cham (2018).
[26] B. Tsaban, Polynomial-time solutions of computational problems in noncommutative-algebraic
cryptography, J. Cryptol., 28, no. 3, 601-622, 2015.
[27] S. Contiu, et al., IBBE-SGX: cryptographic group access control using trusted execution
environments. In 48th Annual IEEE/IFIP International Conference on Dependable Systems and
Networks, DSN 2018, Luxembourg City, Luxembourg, June 25-28, 2018, 207–218, 2018.2222
[28] J. Kim, S. Nepal, A Cryptographically Enforced Access Control with a Flexible User Revocation
on Untrusted Cloud Storage Data Science and Engineering, vol. 1, 149–160 (2016)</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Max</given-names>
            <surname>Noether</surname>
          </string-name>
          , Luigi Cremona,
          <source>Mathematische Annalen 59</source>
          ,
          <year>1904</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>19</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <article-title>On new symbolic key exchange protocols and cryptosystems based on hidden tame homomorphism</article-title>
          ,
          <source>Dopovidi NAS of Ukraine</source>
          , no
          <volume>10</volume>
          ,
          <fpage>26</fpage>
          -
          <lpage>36</lpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Klisowski</surname>
          </string-name>
          ,
          <article-title>On Noncommutative Cryptography with cubical multivariate maps of predictable density</article-title>
          ,
          <source>in: Intelligent Computing, Proceedings of the 2019 Computing Conference</source>
          , Volume
          <volume>2</volume>
          ,
          <source>Part of Advances in Intelligent Systems and Computing (AISC</source>
          , volume
          <volume>998</volume>
          ), pp.
          <fpage>654</fpage>
          -
          <lpage>674</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Klisowski</surname>
          </string-name>
          ,
          <article-title>On Noncommutative Cryptography and homomorphism of stable cubical multivariate transformation groups of infinite dimensional affine spaces</article-title>
          ,
          <source>Cryptology ePrint Archive</source>
          ,
          <volume>593</volume>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <article-title>On the usage of postquantum protocols defined in terms of transformation semigroups and their homomophisms</article-title>
          ,
          <source>Theoretical and Applied Cybersecurity, National Technical University of Ukraine "Igor Sikorsky Kiev Polytechnic Institute"</source>
          , vol.
          <volume>1</volume>
          , no.
          <issue>2</issue>
          ,
          <fpage>32</fpage>
          -
          <lpage>44</lpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <article-title>On new multivariate cryptosystems based on hidden Eulerian equations</article-title>
          ,
          <source>Reports of Nath. Acad of Sci, Ukraine</source>
          ,
          <volume>5</volume>
          ,
          <fpage>17</fpage>
          -
          <lpage>24</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <article-title>On new multivariate cryptosystems based on hidden Eulerian equations over finite fields</article-title>
          ,
          <source>ePrint Archive</source>
          ,
          <volume>093</volume>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <article-title>On semigroups of multiplicative Cremona transformations and new solutions of Post Quantum Cryptography</article-title>
          , IACR Cryptol,
          <source>ePrint Arch</source>
          ,
          <volume>133</volume>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>V.</given-names>
            <surname>Ustimenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Pustovit</surname>
          </string-name>
          ,
          <article-title>New Cryptosystems of Noncommutative Cryptography based on Eulerian Semigroups of Multivariate Transformations</article-title>
          ,
          <string-name>
            <surname>CPITS</surname>
          </string-name>
          <year>2021</year>
          ,
          <volume>18</volume>
          -
          <fpage>26</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>D. N.</given-names>
            <surname>Moldovyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. A.</given-names>
            <surname>Moldovyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A New</given-names>
            <surname>Hard</surname>
          </string-name>
          <article-title>Problem over Non-commutative Finite Groups for Cryptographic Protocols</article-title>
          ,
          <source>International Conference on Mathematical Methods</source>
          , Models, and
          <article-title>Architectures for Computer Network Security, MMM-ACNS 2010</article-title>
          : Computer Network Security pp
          <fpage>183</fpage>
          -
          <lpage>194</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>L.</given-names>
            <surname>Sakalauskas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Tvarijonas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Raulynaitis</surname>
          </string-name>
          ,
          <article-title>Key Agreement Protocol (KAP) Using Conjugacy and Discrete Logarithm Problem in Group Representation Level</article-title>
          ,
          <string-name>
            <surname>INFORMATICA</surname>
          </string-name>
          ,
          <year>2007</year>
          , vol.
          <volume>18</volume>
          , No 1,
          <fpage>115</fpage>
          -
          <lpage>124</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shpilrain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ushakov</surname>
          </string-name>
          ,
          <article-title>The conjugacy search problem in public key cryptography: unnecessary and insufficient</article-title>
          ,
          <source>Applicable Algebra in Engineering, Communication and Computing</source>
          ,
          <year>August 2006</year>
          , vol.
          <volume>17</volume>
          ,
          <issue>iss</issue>
          . 3-
          <issue>4</issue>
          ,
          <fpage>285</fpage>
          -
          <lpage>289</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Delaram</surname>
            <given-names>Kahrobaei</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Bilal</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <article-title>A non-commutative generalization of ElGamal key exchange using polycyclic groups</article-title>
          ,
          <source>In IEEE GLOBECOM 2006 - 2006 Global Telecommunications Conference</source>
          [
          <volume>4150920</volume>
          ] https://doi.org/10.1109/GLOCOM.
          <year>2006</year>
          .lications
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Myasnikov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Shpilrain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ushakov</surname>
          </string-name>
          , Group-based
          <string-name>
            <surname>Cryptography</surname>
          </string-name>
          . Berlin: Birkhäuser Verlag,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>A. G.</surname>
          </string-name>
          <article-title>Myasnikov; Vladimir Shpilrain and Alexander Ush akov (</article-title>
          <year>2011</year>
          ),
          <article-title>Noncommutative Cryptography</article-title>
          and Complexity of Group-theoretic
          <string-name>
            <surname>Problems</surname>
          </string-name>
          , American Mathematical Society
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Zhenfu</given-names>
            <surname>Cao</surname>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>New Directions of Modern Cryptography</article-title>
          . Boca Raton: CRC Press, Taylor &amp; Francis Group.
          <source>ISBN 978-1-4665-0140-9.</source>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>G.</given-names>
            <surname>Maze</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Monico</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Rosenthal</surname>
          </string-name>
          ,
          <article-title>Public key cryptography based on semigroup actions</article-title>
          .
          <source>Adv. Math. Commun</source>
          .
          <volume>1</volume>
          (
          <issue>4</issue>
          ),
          <fpage>489</fpage>
          -
          <lpage>507</lpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>P. H.</given-names>
            <surname>Kropholler</surname>
          </string-name>
          , et al.,
          <article-title>Properties of certain semigroups and their potential as platforms for cryptosystems</article-title>
          ,
          <source>Semigroup Forum</source>
          ,
          <volume>81</volume>
          :
          <fpage>172</fpage>
          -
          <lpage>186</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>J. A.</given-names>
            <surname>Lopez Ramos</surname>
          </string-name>
          , et al.,
          <article-title>Group key management based on semigroup actions</article-title>
          ,
          <source>Journal of Algebra and its applications</source>
          , vol.
          <volume>16</volume>
          (
          <issue>08</issue>
          ):
          <fpage>1750148</fpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>