<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Evaluation of Cryptographic Strength and Energy Intensity of Design of Modified Crypto-Code Structure of McEliece with Modified Elliptic Codes</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Serhii Yevseiev</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Olha Korol</string-name>
          <email>olha.korol@hneu.net</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Olga Veselska</string-name>
          <email>oveselska@ath.bielsko.pl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhii Pohasii</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vladyslav Khvostenko</string-name>
          <email>vladyslav.khvostenko@gmail.com</email>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Akademia Techniczno-Humanistyczna</institution>
          ,
          <addr-line>ul. Willowa 2, Bielsku-Białej, 43309</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The computing development in the post-quantum cryptography era puts forward new requirements for cryptographic mechanisms for providing basic security services. The advent of a full-scale quantum computer casts doubt on the cryptographic strength of cryptosystems based on symmetric cryptography and public-key cryptography. One of the promising areas in the opinion of US NIST experts is the use of crypto-code constructions (crypto-code schemes or code-theoretic schemes) by McEliece or Niederreiter. The construction allows one integrated mechanism to provide the basic requirements for cryptosystems - cryptographic stability, speed of cryptoconversion and besides - reliability based on the use of noise-resistant coding. However, their use is difficult due to the large volume of power of the alphabet, and the possibility of hacking based on Sidelnikov's attack. The paper proposes to use non-cyclic noiseresistant codes on elliptic curves in a modified McEliece cryptosystem that are not susceptible to Sidelnikov's attack. The main criteria for constructing a modified crypto code based on the McEliece scheme on elongated elliptic codes are investigated. It is proposed to reduce the energy intensity in the proposed crypto-code design by reducing the power of the Galois field while ensuring the level of cryptographic stability of the modified cryptosystem as a whole with its software implementation. To reduce the field power, it is proposed to use modified elliptic codes, which allows to reduce the field power by 2 times. A comparative assessment of the performance of cryptosystems is carried out. The results of statistical stability studies based on the NIST STS 822 package confirm the cryptographic strength of the proposed cryptosystem on modified elongated elliptic codes. It is proposed to use the method of evaluating the cryptographic strength of various cryptosystems based on the entropy approach.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Asymmetric McEliece Crypto-Code System</kwd>
        <kwd>Crypto-Code Construction on Algebro-geometric Codes</kwd>
        <kwd>Modified (extended) Elliptic Codes</kwd>
        <kwd>Confidentiality</kwd>
        <kwd>Integrity</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The rapid growth of the volume of data being
processed and the development of computing
technology has put forward new requirements for
reliability and data security. Studies on the
influence of quantum computing using quantum
superposition and quantum entanglement to
transmit and process data have shown that
quantum computers that use special algorithms
(for example, Shor’s algorithm) will be able to
factorize numbers in polynomial time [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
Thus, RSA, ECC, DSA cryptographic systems
will be vulnerable to brute force attacks using a
full-scale quantum computer. Therefore, the main
research and development of cryptographic
information security tools (CIST) are currently
aimed at finding solutions that confront quantum
computing and at the same time must be resistant
to attacks using ordinary computers. Such
algorithms are related to the section of
quantumresistant cryptography (quantum secure
cryptography or quantum-resistant cryptography)
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Through the imminent emergence of new
schemes, sufficient attention has not been paid to
the well-known, asymmetric crypto-code systems
(ACCS) based on McEliece's theoretical code
schemes (TCS), which are also quantum-stable.
      </p>
      <p>The advent of a full-scale quantum computer
casts doubt on the cryptographic strength of
cryptosystems based on symmetric cryptography
and public-key cryptography. One of the
promising areas in the opinion of US NIST
experts is the use of crypto-code constructions
(crypto-code schemes or code-theoretic schemes)
by McEliece or Niederreiter. The construction
allows one integrated mechanism to provide the
basic requirements for cryptosystems –
cryptographic stability, speed of cryptoconversion
Pand besides – reliability based on the use of
noise-resistant coding.</p>
      <p>
        The analysis showed that for the provision of
basic security services, crypto-code constructions
are usually used based on the McEliece and
Niederreiter schemes. To ensure the level of
cryptographic strength in post-quantum
cryptography, it is necessary to use the power of
the alphabet in a field of 210-213 degrees, which
is a significant drawback of their practical
application [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Even at the current level of
computer technology, this is a rather difficult task.
      </p>
      <p>
        The second drawback is the hacking attack on
the McEliece scheme based on linear-fractional
transformations and the property of triply
transitivity of the automorphism groups of the
generalized Reed-Solomon code, proposed in the
work of professor Sidelnikov from Moscow State
University. The essence of which is to find the
elements of the generating matrix and remove the
action of masking matrices [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>The orthogonality of the matrices, which is
generative and test, allows us to consider the
effectiveness of the attack on the Niederreiter
scheme. A promising way to eliminate the
identified patterns Sidelnikov proposes to use
cascade or algebraic geometry codes – codes built
based on the algebra of the theory of
noiseresistant coding and geometric parameters of the
curve, in particular elliptic curves.</p>
      <p>The algebraic-geometric code uses the
mathematical apparatus of noise-resistant coding
and the parameters of the spatial curve. This
allows us to provide resistance to Sidelnikov’s
attack and proper (n, k, d) parameters of the
errorcorrecting code, which, under equal conditions of
length n, provides bigger values of the d and k
parameters (allows to transmit more characters in
open text and correct more errors )</p>
      <p>The paper proposes to use non-cyclic
noiseresistant codes on elliptic curves in a modified
McEliece cryptosystem that are not susceptible to
Sidelnikov’s attack. The main criteria for
constructing a modified crypto code based on the
McEliece scheme on elongated elliptic codes are
investigated. It is proposed to reduce the energy
intensity in the proposed crypto-code design by
reducing the power of the Galois field while
ensuring the level of cryptographic stability of the
modified cryptosystem as a whole with its
software implementation. To reduce the field
power, it is proposed to use modified elliptic
codes, which allows to reduce the field power by
2 times. A comparative assessment of the
performance of cryptosystems is carried out. The
results of statistical stability studies based on the
NIST STS 822 package confirm the cryptographic
strength of the proposed cryptosystem on
modified elongated elliptic codes.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Analysis of Recent Studies and</title>
    </sec>
    <sec id="sec-3">
      <title>Publications</title>
      <p>The main advantage of symmetric and
asymmetric Crypto-Code Systems (CCS) is the
high speed of information conversion and the
integrated provision of reliability and information
concealment (confidentiality) that satisfies the
basic security requirements.</p>
      <p>For security reasons, the perspective direction
is the use of asymmetric cryptosystems based on
CCS McEliece integrated (with one mechanism)
providing reliability values at the level of 29 – 212
and cryptostability 230 – 235 group operations
when constructed over the field GF(210).</p>
      <p>Figure 1 shows the classification of
cryptocode structures and the provision of basic security
services.
The main advantage of which is the provision of
cryptographic stability, efficiency and reliability
in the transmission of information in the
postquantum period.</p>
      <p>Table 1 shows the results of comparative
studies of the effectiveness of cryptographic
information security methods at a fixed level of
stability.</p>
      <sec id="sec-3-1">
        <title>Methods of</title>
        <p>cryptographic Security Key length cryptogra Additional
transfonrmatio model [bits t,r[abnpisthsiti/cisoencs features</p>
      </sec>
      <sec id="sec-3-2">
        <title>Speed of</title>
      </sec>
      <sec id="sec-3-3">
        <title>Block</title>
        <p>symmetric
ciphers</p>
      </sec>
      <sec id="sec-3-4">
        <title>Stream</title>
        <p>symmetric
ciphers</p>
      </sec>
      <sec id="sec-3-5">
        <title>Asymmetric</title>
      </sec>
      <sec id="sec-3-6">
        <title>PCAs are similar cryptographic algorithms</title>
        <p>Practical 128, 256, 106 – 109
security 512
Practical 128, 256, 107 – 1010
security 512</p>
      </sec>
      <sec id="sec-3-7">
        <title>None</title>
      </sec>
      <sec id="sec-3-8">
        <title>None</title>
      </sec>
      <sec id="sec-3-9">
        <title>Proof</title>
      </sec>
      <sec id="sec-3-10">
        <title>Security</title>
        <p>SePcruoroifty 0((2,125∙215∙18060)6),6 106 – 108 imrnecolErinaregribat,ooislriirntiyng</p>
        <p>
          In Table 1, there are presented values: average
(the complexity of cryptanalysis is the
bestknown algorithm of at least 2128 operations);
high (the complexity of cryptanalysis is the
bestknown algorithm of at least 2256 operations);
super-high (the complexity of cryptanalysis is the
best-known algorithm of at least 2512 operations)
[
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>Hence, as it follows from the above results of
the comparative analysis (Table 1), asymmetric
cryptographic algorithms using TCS allow the
cryptographic protection of information to be
realized on the technology of public keys. And
thus they provide the speed of crypto-code
transformation of information with the speed of
encryption of block-symmetric ciphers (BSС). In
addition, the practical use of ACCS information
security allows to ensure the security and
reliability of data, based on the integration of
channel coding and encryption mechanisms in a
comprehensive manner.</p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref5 ref6 ref7 ref8">5–8</xref>
          ], the authors propose McEliece
cryptocode systems based on various codes. In [
          <xref ref-type="bibr" rid="ref10 ref11 ref9">9–11</xref>
          ],
an equilibrium coding method based on m-folded
Reed-Solomon codes were proposed; however,
the disadvantage is the lack of a practical
algorithm for decoding the syndrome on the
receiving side and the possibility of hacking based
on a rearranged decoder. In [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], there is proposed
a modification of the Reed-Solomon codes, which
exceeds the Guruswami-Sudan decoding radius 1
– √R of the Reed-Solomon codes at low speeds R.
The idea is to select the Reed-Solomon codes U
and V with the corresponding speeds in (U | U +
V) and decode them using the soft information
decoder Koetter-Vardy.
        </p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref12 ref5">5, 12</xref>
          ], the use of alternating Goppa codes
in the McEliece cryptosystem and the classical
Goppa codes in the Niederreiter cryptosystem are
proposed. In [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], the authors confirm the
complexity of the practical implementation of the
Niederreiter scheme and consider the possibility
of using cryptosystems in VPN channels. In [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]
article proposes a new class of convolutional
codes, which allows an effective algorithm for
algebraic decoding, the use of the McEliece
cryptosystem in a variant. Unlike the classic
McEliece cryptosystems, which use block codes,
the authors propose the use of a convolutional
encoder as part of the public key.
        </p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] the authors propose a new Niederreiter
cryptosystem based on quasi-cyclic codes which
is quantum-secure. This new cryptosystem has a
good transfer rate compared to the one that uses
the Hopp binary codes and uses smaller keys.
        </p>
        <p>
          In the following papers [
          <xref ref-type="bibr" rid="ref12 ref6 ref7">6, 7, 12</xref>
          ], the authors
use low-density quasi-cyclic parity codes
(QCLDPC) [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ] and on codes with the maximum rank
distance [
          <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
          ] to build McEliece and Niederreiter
cryptosystems. In [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], the construction of the
McEliece and Niederreiter schemes based on the
alternating Goppa codes is considered.
        </p>
        <p>
          In computer networks with decisive feedback,
the authors ensure the use of the McEliece
cryptocode design in the G.709 optical transport network
(OTN) infrastructure to provide integrated
requirements for both reliability and security [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
In [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ], the authors proposed to use the
Niederreiter asymmetric crypto-code system on
elliptic codes. This approach provides protection
against possible attacks described in [
          <xref ref-type="bibr" rid="ref19 ref20 ref21">19, 20, 21</xref>
          ]
and the required level of cryptographic strength.
But there are remained unresolved questions of
practical implementation with the necessary
power of the GF(210–213) field to ensure a
guaranteed level of cryptographic strength.
        </p>
        <p>Thus, the analysis showed that crypto-code
constructions belong to the section of
quantumresistant cryptography and can be used instead of
asymmetric cryptosystems soon. In this regard,
their improvement is of wide interest among the
scientific community.</p>
        <p>
          However, all the codes proposed by the
authors are cyclical and prone to Sidelnikov's
attacks [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. The essence of Sidelnikov’s attack
comes down to finding the elements of the
generating matrix and removing the action of
masking matrices based on linear fractional
transformations and the property of triply
transitivity of the automorphism group of the
generalized Reed-Solomon code. As a solution,
Sidelnikov proposes the use of non-cyclic codes
based on cascade or algebraic-geometric codes
(codes on elliptic curves). This approach provides
not only opposition to Sidelnikov’s attack, but
also the ability to reduce key data based on the use
of the coefficients of the equation of the curve as
a secret parameter [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]. Besides, US NIST experts
consider the security (cryptographic strength) of
cryptosystems in post-quantum cryptography
only if they built in the Galois field GF (210–213).
However, the level of computing capabilities of
modern information and communication systems
does not allow them to be fully implemented. To
reduce energy costs, the authors propose using
modified crypto-code constructions on modified
(extended codes). Fig. 2 shows the exchange
protocol based on the modified McEliece
cryptocode system on modified (shortened) elliptic
codes, in Fig. 3 – on modified (extended) codes.
А
А
Formation of
key data
        </p>
        <p>Protocol
Formation of
key data
Protocol</p>
        <p>Secret key a1, , an</p>
        <p>Session key</p>
        <p>|IV1|, е
Private key G, X, P, D</p>
        <p>Public key</p>
        <p>Gx = X × G × P × D
i cX*= i × GX + e</p>
        <p>Encryption</p>
        <p>X-1, P-1, D-1
cX* c` = cX* × D-1 + P-1
c` = i` × G + e`
i = i × X-1
Decryption
i
B</p>
        <p>Property Shortened MEC Extended MEC
(n, k, d) code n = 2 q + q +1− x , n= 2 q +q+1− x+ x1
parameters ,
constructed by k ≥ α – x, d ≥ n – k ≥ α – x + x1,
displaying the α, α=3×degF, d ≥ n – α,
view φ:X→Pk-1 k + d ≥n α = 3 × degF
(n, k, d) code n = 2 q + q +1− x
parameters , n= 2 q +q+1− x+ x1 ,
constructed by k ≥ n – α, d ≥ α, k ≥ n – α, d ≥ α,
displaying the α = 3×degF, k + d α = 3 × degF
view φ:X→Pr-1 ≥ n</p>
        <p>The proposed McEliece MCCS can reduce the
power of the alphabet, which al-lows them to be
implemented in practice, while ensuring the
required level of crypto-graphic strength due to
the introduction of additional initialization
vectors: IV1 – defines shortening characters from
a code word (cryptograms), IV2 – defines
elongation characters (plain text) of a codeword
(cryptogram), see also Fig. 3. Let us con-sider the
results of a study of the basic properties of the
proposed crypto-code systems.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>3. Evaluation of Energy Costs for</title>
    </sec>
    <sec id="sec-5">
      <title>Program Implementation and the</title>
    </sec>
    <sec id="sec-6">
      <title>Complexity of the Proposed</title>
    </sec>
    <sec id="sec-7">
      <title>McEliece MACCS Code</title>
    </sec>
    <sec id="sec-8">
      <title>Transformation</title>
      <p>To estimate time and speed parameters it is
common to use the unit of measurement CPB
(cycles per byte) – the number of processor
cycles, which should be spent to process 1 byte of
incoming information.</p>
      <p>Notes:* duration of 1000 operations in
processor cycles: reading a character – 27 cycles,
com-paring strings – 54 cycles, string
concatenation - 297 cycles.</p>
      <p>** for the calculation, a processor with a clock
frequency of 2 GHz was used, taking into account
the load by the operating system, is taken 5%</p>
      <p>
        Algorithm complexity is calculated from
expression [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]:
      </p>
      <p>Per = UtlCPU_clock/Rate,
where Utl – utilization of the CPU core (%) and
Rate – algorithm bandwidth (bytes/sec).</p>
      <p>In Table 4 there are shown dependency
research results of code length sequence of
algebrogeometric code in McEliece TCS from the
number of processor cycles due to executing
elementary operations in the program realization
of crypto-code systems.</p>
      <p>Table 5</p>
      <sec id="sec-8-1">
        <title>Investigation Results for Evaluating Time and</title>
      </sec>
      <sec id="sec-8-2">
        <title>Speed Parameters of Procedures of Forming and</title>
      </sec>
      <sec id="sec-8-3">
        <title>Decoding Information</title>
        <p>sscCyorsydtpeetmo- lsehCeenonqcdgueet (bRABaalgyntotederwi/thisdmethc), (anuC%ttPii)oUliz i(cAmtCoylgBm,oPpr)Pilteehxr
McEliec 100 46 125 790 56 61,5
e ACCS 1000 120 639 896 56 62,0
100 51 694 662 56 61,7</p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>4. Study of the Properties of the</title>
    </sec>
    <sec id="sec-10">
      <title>McEliece ACCS on the EC and the</title>
    </sec>
    <sec id="sec-11">
      <title>Modified McEliece on MEC</title>
      <p>In order to estimate the parameters of
asymmetric code-theoretic schemes using elliptic
codes, let us introduce the following notation:
• lI – length of the information sequence
(block) arriving at the input of the crypto-code
structure (in bits);
• lK – the length of the public key (in bits);
• lK+ – the length of the private key (in bits);
• ls – the length of the code (in bits);
• OK - the complexity of the formation of
the code (number of group operations);
• OSK – the difficulty of decoding the
cryptogram (the number of group operations);
• OK+ – the complexity of solving the
analysis problem (the number of group
operations).</p>
      <p>For the construction of graphs, conditional
abbreviations (prefixes) were used:
• uk – MACCS with truncated MEС;
• ud – MACCS with elongated MEC.
In calculating the parameters of cryptosystems,
the Galois fields were used:
• for McEliece TCS – GF(210);
• for MACCS with truncated / elongated
MEC – GF(26).</p>
      <p>In the next step, we perform a comparative
analysis of the parameters of the McEliece
asymmetric code-theoretic scheme (MACS) using
EC, with the parameters of the modified MACCS
McEliece on MEC. To estimate the length of the
infor-mation sequence (in bits) arriving at the
input of the MACCS with the algebraic (n, k,
d)code over GF(2m) (where m − the power of the
extended Galois field), we use the expressions:
• lI = k × m, for AСCS on the EC;
• lI = 1/2k × m, for MCCS on truncated
MEC;
• lI = k × m, for MACCS on elongated
MEC.</p>
      <p>In Tab. 6 and in Figure 4 we show the
cryptogram formation complexity from the power
of the field, where code rate (R) stands for the
relative speed of coding R=k/n, the encoder
assigns to each message of k digits a longer
message of n digits called a codeword.</p>
      <p>From the provided data it can be seen that the
cryptogram formation complexity for the chosen
power of the GF 26 on the truncated and elongated
codes is much lower (by 5 times and more) than
in the original realization of MACCS to the EC.
Respectively, the speed of the formation of the
cryptogram will significantly increase.</p>
      <p>• In order to estimate the length of the
cryptogram (in bits), we use the expressions:
• ls = n × m, for ACCS on the EC;
• l_s=(2√q+q+1-1/2k)×m, for MCCS on
truncated MEC;
• l_s=(2√q+q+1-1/2k+1/2k)×m, for MCCS
on elongated MEC.
20
881
of cryptogram formation, shows a significant
increase in the decoding rate when using truncated
and elongated MEC.</p>
      <p>The length of the public key (in bits) is
determined by the sum of the elements of the
matrix and is given by the expressions:
for MCCS on truncated MEC;
lK = k × n × m , for ACCS on the EC:;
  = 21 × (2√ +  + 1 − 1/2 ) ×  ,
  = 21 × (2√ +  + 1 − 21 + 21
) ×


for MCCS on elongated MEC.</p>
      <p>The length of the private key (in bits) is
determined by the sum of the elements of the
matrices X, P, D (in bits) and is given by the
expressions:
lK+ = n2× 2k× mf,or ACCS on the EC;
= 21 [log2(2√ +  + 1)],
for
MCCS on truncated MEC;
= (</p>
      <p>21 − 21 )[log2(2√ +  + 1)],
for MCCS on elongated MEC.</p>
      <p>In Tab. 8 and Figure 5 there are shown the
dependency of the breaking complexity based on
the permutation decoding on the field strength.
Dependence of Breaking Complexity in Various
 ,
•
•
•
•
•
•</p>
      <p>0.75 0.5(ud) 0.75(ud) 0.5(uk) 0.75(uk)
1.056 1.38
2.237 3.017
2.868 4.867
4.843 6.613
  = ( + 1) × (2√ +  + 1 − 21 + 21 ),
for non-systematic:
  = ( + 1) × (2√ +  + 1 − 21 + 21 ).</p>
      <p>The complexity of decoding of a pattern
is defined by expressions:
• for ACCS on EC:</p>
      <p>OSK = 2×n2+k2+4t2 + (t2 + t – 2)2/4,
• for MCCS on truncated MEC:
  = 2(2√ +  + 1 − 21 )2 − 2 2 + 4 2 +
1
( + −2)2.</p>
      <p>4
• for MCCS on elongated MEC:
1
  = 2(2√ +  + 1 − 2 + 1/2 ) −  2
( +  − 2)2
+ 4 2 +
where</p>
      <p>The complexity of the task of the analysis
(decoding) solution is set by expressions:
• for ACCS on EC:</p>
      <p>OK+ =</p>
      <p>× n × r,
Ncov  CCnt −nt k =</p>
      <p>n(n −1)...(n − t −1)
(n − k )(n − k −1)...(n − k − t −1)</p>
      <p>t=[(d–1)/2]</p>
      <p>The potential strength of the
cryptosystem is defined by size ρ×t, and noise
stability of system – (1 – ρ) × t.
• For MCCS on truncated codes:
 
•</p>
      <p>=  × (2√ +  + 1 − 21 ) ×  .</p>
      <p>For MCCS on elongated codes:
  =  × (2√ +  + 1 − 21 + 1/2 ) ×
 .</p>
      <p>In Tab. 9 and Figure 7 it is presented
dependence of complexity of breaking and
complexity of coding for various speeds of the EC
(MEC).</p>
      <p>The results of studies of the dependence of the
software implementation depend-ing on the field
power and the parameters of algebra-geometric
codes are also pre-sented, as can be seen from
Table 11, the use of modified crypto-code
constructions provides a 5-fold reduction in
energy costs for the software implementation, that
allows for their practical implementation</p>
    </sec>
    <sec id="sec-12">
      <title>5. Results of Studies of the Proposed</title>
    </sec>
    <sec id="sec-13">
      <title>Public-Key Cryptosystems Based on the NIST-STS 822 Package</title>
      <p>One of the main components of the evaluation
of the stability of cryptographic algorithms is the
estimation of its statistical security. It is believed
that the algorithm is statistically secure if the
sequence it generates by its properties is not
inferior to a random sequence - such sequences
are called “pseudorandom”. For the experi-mental
estimation of how close the crypto-algorithms
approximate the generators of the “random”
sequences, statistical tests are used. The NIST
STS benchmark pack-age for testing random or
pseudorandom number generators is one of the
approach-es to realizing the task of evaluating the
statistical security of cryptographic primi-tives.</p>
      <p>
        The use of this package makes it possible to
conclude with a high degree of probability as to
how much sequence that is generated by the
investigated primitive is statistically secure. A set
of NIST STS tests was proposed during the
contest for a new national standard for US block
coding in 2000 and developed by the staff of the
National Institute of Standard and Technologies
[
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. This set was used to study the statistical
properties of candidates for a new block cipher.
To date, the test methodology, which is offered by
NIST, is the most common for developers of
cryptographic means of information protection. The
test procedure for an individual binary sequence S
is as follows:
1. A null hypothesis H0 is advanced-the
assumption that the given binary sequence S is
random.
2. From the S sequence, the test statistics
from (S) are calculated.
3. Using the special function and test
statistics, a probability value P=f(c(S)),
P[
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ]
4. The value of probability P is compared
with the level of significance [0.001,0.01].
If P, then the H0 hypothesis is accepted.
Otherwise, an alternative hypothesis is
adopted.
      </p>
      <p>In accordance with the methodology, the
decision to pass statistical testing is taken by the
event that fulfills the following rules:
1. The rule #1. All q tests were executed, (q
=(1,189) ̅), and if the value of the coefficient rj
is inside the confidence interval [0.96, 1.00];
2. The rule #2. All q tests were executed, (q
= q =(1,189) ̅), and if for all tests by the
Pearson 2 criterion the condition is met
P(2)&gt;0.0001.</p>
      <p>For carrying out experimental research about the
properties of the developed code cryptosystems
the program is developed to realize the offered
means of protec-tion of the information.</p>
      <p>The following parameters have been selected
during the tests:
• length of the test sequence n = 106 bits;
• number of tested sequences m = 100.
Thus, the volume of the test sample was N =
106x100 = 108 bits;
• significance level  = 0.01;
• number of tests q = 189.</p>
      <p>Authors have obtained the results of statistical
testing and statistical portraits of the developed
means of information protection. The final values
and results of the best world crypto-algorithms are
summarized in Table 12.</p>
      <p>As it can be seen from the presented data in
Table 12 the proposed crypto-code systems on the
modified codes are not inferior to the statistical
characteristics of the randomness of the code
sequence formation to the world standards of
providing basic services: confidentiality, integrity
and accessibility, while ensuring the required
level of reliability of data transmission.</p>
      <p>Consequently, the practical application of the
developed information protection means allows to
obtain good statistical properties of the generated
sequences and to effectively ensure the security
and reliability of the data being processed and
transmitted.</p>
    </sec>
    <sec id="sec-14">
      <title>6. Analysis of Cryptographic</title>
    </sec>
    <sec id="sec-15">
      <title>Algorithms Based on the Entropy</title>
    </sec>
    <sec id="sec-16">
      <title>Approach</title>
      <p>The proposed express analysis makes it
possible, without significant computational and
energy costs, at the intuitive level, to compare not
only the resistance of various crypto-algorithms
(cryptosystems), but their software
implementation. The algorithm of the entropy
method for assessing crypto-resistance is shown
in Figure 9.</p>
      <p>Table 13 gives the results of the study into the
stability and software effectiveness of the
implementation of block and stream ciphers of
varying complexity. We applied DES, 3DES,
GOST 28147-2015, Kalina-256, AES-256 as
block ciphers. To imple-ment a stream cipher, we
used pseudo-random sequence generators of two
different types: based on the rule “60” of cellular
automata in its classical form, without
modifications, and the cryptographically resistant
generator SecureRandom from Java
cryptolibraries, which is marketed as suitable for
cryptographic applications.
conclusions about the max-imally possible degree
of dispersion as a characteristic of the
architecture.</p>
      <p>Computation of entropy of the original</p>
      <p>message with a specified length
Мi – original message,
Рi– probability of the emergence of the i-th
symbol in Мi,
Li – number of the i-th symbols in Мi,
Нi – entropy of the i-th symbol,
H(M) – entropy M
Computation of entropy of the encrypted</p>
      <p>message with a specified length
C – encrypted message,
sPyi'm–bporloibnaCbi,lity of the emergence of the i-th
Start</p>
      <p>Input Мi
Computation of probabilities (Pi) of the
emergence of each symbol in Мi</p>
      <p>Pi = Li / length(Мi)
Computation of entropy of each symbol (Hi)</p>
      <p>Hi = Pi  log(Pi)
Computation of entropy М (H(М))</p>
      <p>H(М) = −Мi</p>
      <p>Encryption М
i : M ⎯K⎯ii →C
Computation of ent'ropy C (H(C))</p>
      <p>H(C) =−iL=1 Hi'
Computation of difference in the entropies
of the original text and the ouput ciphertext</p>
      <p>HCypher = HC − HM</p>
      <p>End
Computation of probabilities (P') of the
emergence of each symbol iin С</p>
      <p>Pi' = L'i / length(Ci)</p>
      <p>L'i – number of the i-th symbols in C,
Computation of en(Htroi')py of each symbol Hcipi'h–eretnetxrto,py of the i-th symbol in a
Hi' = Pi' log(Pi')</p>
      <p>H(C) – entropy C</p>
      <p>Entrop yEonftrtohpe Pegreceonfta
y of the encrypt Differe entropy,
minepessuatg meeesdsag nce adcditpehhdeebry</p>
      <p>In Table 13, we calculated the entropy of the
input and the encrypted text, differ-ence, as well
as the percentage of entropy added to the entropy
of plaintext by the cipher itself. An analysis of
Table 1 allows us to assess the contribution of the
cipher in the total entropy of the encrypted
message. As they all were tested under identical
conditions, it is possible to judge their relative
performance.</p>
      <p>The AES-like ciphers (SPN-system,
substitution-permutation schemes) are worth
mentioning. Both such ciphers, Kalina and AES,
made the greatest contribution, larger than 103 %,
to the entropy of the plaintext. According to the
given results, both ciphers have the best diffusing
effect. Approximately the same results were
demonstrated by the symmetric block cipher
(SBC) GOST 28147-2015: 72.89 % against 73.04
% for DES/3DES. This probably confirms</p>
      <p>To compare the results, we conducted
experiments using stream ciphers based on two
different generators with a pseudorandom key
sequence. Encryption was per-formed by the rule
of addition for modulo two. In the first case, this
is a generator based on cellular automata (the rule
“60”). This is not a crypto-resistant generator
whose sequence does not pass testing for NIST
STS 822, while the second one is positioned as the
crypto-resistant generator SecureRandom in the
Java crypto-library. In both cases, the obtained
values for entropy are much smaller than those for
classic SBC, which does not allow us to argue
about quality encryption with their help. Thus, the
presented results suggest that a simple entropy
method allows rapid assessment of the quality of
ciphers used without referring to expert
estimations. Such an express technique is
available to anyone with a minimal knowledge of
the information theory.</p>
      <p>Moreover, in this way, one can evaluate
different implementations of ciphers that will
make it possible to select the best (optimal)
software implementation that matches the terms
and requirements of the user. For example, in our
computer ex-periments, we used two
implementations of the DES algorithm. One of
them, given in Table 13 at number 3,
demonstrated a 73.04 % increase in entropy after
encrypting compared to the original text, another
algorithm − 64.4 %. It is obvious that for
practical purposes it makes sense to choose the first
implementation, since it appears that its scattering
characteristics are better. Thus, the
expressanalysis allows assessment of the quality of
implementation of classic (and other)
cryptoalgorithms in order to select an optimal crypto
library out of many commercially available
libraries.</p>
      <p>We shall consider the results obtained in terms
of maximum cryptographic infor-mation
protection. An indicator of such protection is the
entropy of the encrypted binary file, given in
Table 14.</p>
      <sec id="sec-16-1">
        <title>Cipher</title>
      </sec>
      <sec id="sec-16-2">
        <title>Entrop Probabilit</title>
        <p>y of Entropy y of
the of the cryptogra
input encrypted phic
messa message protection
ge , Pc</p>
      </sec>
      <sec id="sec-16-3">
        <title>Cellular automata, 0.4692 0.637079 0.6370799 the rule 76 949 49 "60"</title>
      </sec>
      <sec id="sec-16-4">
        <title>Crypto</title>
        <p>resistant
generator
SecureRan 0.4692 0.747287 0.7472877
dom from 76 753 53</p>
      </sec>
      <sec id="sec-16-5">
        <title>Java</title>
        <p>cryptolibraries
DES
3DES
0.4692
76</p>
      </sec>
      <sec id="sec-16-6">
        <title>Kalina</title>
        <p>AES-256
Perfect
cipher</p>
        <p>
          It is known that the maximum possible
cryptographic protection is provided by the
socalled "perfect cipher" by Shannon, which as a
result of encryption produces a random number
[
          <xref ref-type="bibr" rid="ref23 ref24">23,24</xref>
          ]. Such a file will have maximum entropy,
which in the bina-ry case is equal to unity. We
assume that encryption using a given cipher will
ensure maximal cryptographic protection; we
assume that it equals unity. One can say that the
probability of protection using such a cipher is
equal to unity. It is natural that imperfect ciphers
do not produce such a probability of
cryptographic protection. By using such an
approach, one can rank all the examined ciphers
for the probability of cryptographic protection.
This indicator can be employed for various
procedures for the assessment of the security of
integrated protection systems of different
corporate networks, which testifies to its
universality.
        </p>
        <p>In Figure 10 there are shown the results of
studies of the average entropy of crypto-grams of
different BSS of meaningful plaintext with a
length of M = 108 bits, with an interval of N = 5
× 106 bits.</p>
        <p>Analysis of Figure 10 practically confirms the
possibility of using the express method for the
selection of software security mechanisms based
on cryptoalgorithms.</p>
      </sec>
    </sec>
    <sec id="sec-17">
      <title>7. Conclusions</title>
      <p>As a result of the conducted research, it can be
concluded that</p>
      <p>1. Evaluation by NIST specialists of the
computing capabilities of quantum com-puters
requires a review of the use of traditional
encryption algorithms to provide basic security
services based on symmetric and asymmetric
cryptography. The growth and synergy of modern
threats put forward new requirements for systems
for protecting confidential information. At the
same time, the use of crypto-code constructions
allows us to provide not only the required level of
cryptographic stability, but also the reliability of
the transmitted information. However, their use in
communication devices is associated with
significant energy and computation-al costs,
which does not allow their practical use. Besides,
the proposed Sidelnikov attack does not allow the
use of many well-known codes; to counter it, it is
pro-posed to use algebraic geometries based on
the parameters of elliptic curves.</p>
      <p>2. The overall structure of asymmetric
crypto-code systems based on the McEliece TCS
enabling integrated (with a single device)
provision of the required indicators of reliability,
efficiency and data security was analyzed. A
major shortcoming of ACCS based on the
McEliece TCS is a big volume of key data, that
constricts their use in different communication
system areas (today cryptographic strength on the
level of the provable strength model is provided
while building ACCS in the Galois field
GF(213)). The use of modified (shortened) elliptic
(algebraic) codes helps to reduce the volume of
key data while maintaining the requirements for
cryptographic strength of ACCS. Estimation of
the data conversion performance is comparable to
the speed of direct and inverse cryptographic
conversion of modern BSC, this ensures the
cryptographic strength at the level of asymmetric
cryptosystems (cryptographic strength is based on
the theoretical complexity problem – random
code decoding).</p>
      <p>3. The use of modified crypto-code
constructions in modified (shortened, elongated)
elliptic codes allows to reduce the level of the
alphabet with the required level of cryptographic
strength. For this, additional session keys are used
(initial initializa-tion, which specify the symbols
of correlation and/or extension), as well as valid
codewords on the receiving side. The alphabetical
index of the cryptosystem without reducing the
cryptographic strength of the system as a whole
ensures their practical application and use in the
protocols of Internet resources and infor-mation
and communication systems in the conditions of
post-quantum cryptog-raphy.</p>
    </sec>
    <sec id="sec-18">
      <title>8. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] Report on Post-Quantum Cryptography</source>
          , http://nvlpubs.nist.gov/nistpubs/ir/2016/NIS T.IR.
          <volume>8105</volume>
          .pdf, last accessed:
          <year>2020</year>
          /02/19.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <article-title>[2] Security requirements for cryptographic modules</article-title>
          , https://csrc.nist.gov/publications/fips/fips14 0-
          <fpage>2</fpage>
          /fips1402.pdf,
          <source>last accessed</source>
          <year>2017</year>
          /12/1.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Grischuk</surname>
            ,
            <given-names>R.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Danik</surname>
          </string-name>
          , Yu. G.:
          <article-title>Basics of Cybersecurity</article-title>
          . Zhytomyr: ZhNAEU, p.
          <volume>636</volume>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Hryshchuk</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevseiev</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shmatko</surname>
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Construction methodology of information secu-rity system of banking information in automated banking systems</article-title>
          . Monograph, p.
          <fpage>284</fpage>
          ,
          <string-name>
            <surname>Premier</surname>
            <given-names>Publishing</given-names>
          </string-name>
          , Vienna (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Dinh</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Moore</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Russell</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>McEliece and Niederreiter Cryptosystems that Resist Quantum Fourier Sampling Attacks</article-title>
          . https://dl.acm.org/citation.cfm?id=2033093,
          <string-name>
            <surname>last</surname>
          </string-name>
          ac-cessed
          <year>2020</year>
          /03/10.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Baldi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bianchi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chiaraluce</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rosenthal</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schipani</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <article-title>Enhanced public key se-curity for the McEliece cryptosystem</article-title>
          . https://arxiv.org/abs/1108.2462, last accessed
          <year>2020</year>
          /03/10.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cai</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <article-title>Secure error-correcting (SEC) schemes for network coding through McEliece cryptosystem</article-title>
          . https://link.springer.com/article/10.1007/s10 586-
          <fpage>017</fpage>
          -1294-
          <fpage>5</fpage>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cai</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Universal secure errorcorrecting (SEC) schemes for network coding via McEliece cryptosystem based on QC-LDPC codes</article-title>
          . https://link.springer.com/article/10.1007/s10 586-
          <fpage>017</fpage>
          -1354-x (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Rossi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hamburg</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hutter</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <string-name>
            <given-names>A</given-names>
            <surname>Side-Channel Assisted Cryptanalytic Attack Against</surname>
          </string-name>
          <article-title>QcBits</article-title>
          . https://link.springer.com/chapter/10.1007/97 8-
          <fpage>3</fpage>
          -
          <fpage>319</fpage>
          -66787-
          <issue>4</issue>
          _
          <issue>1</issue>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Dudikevich</surname>
            ,
            <given-names>V.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznetsov</surname>
            ,
            <given-names>O.O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tomashevsky</surname>
            ,
            <given-names>B.P.</given-names>
          </string-name>
          :
          <article-title>Crypto-code protection of infor-mation with non-binary equilibrium encoding</article-title>
          .
          <source>The hour zahist of information, No. 2</source>
          , p.
          <fpage>14</fpage>
          -
          <lpage>23</lpage>
          (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Dudikevich</surname>
            ,
            <given-names>V.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznetsov</surname>
            ,
            <given-names>O.O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tomashevsky</surname>
            <given-names>B.P.</given-names>
          </string-name>
          :
          <article-title>Non-dual equilibrium coding method. Modern information protection</article-title>
          .
          <source>No. 3</source>
          , p.
          <fpage>57</fpage>
          -
          <lpage>68</lpage>
          (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Morozov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Roy</surname>
            ,
            <given-names>P.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sakurai</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>On unconditionally binding code-based commitment schemes</article-title>
          . https://dl.acm.org/citation.cfm?id=3022327 &amp;
          <article-title>dl=ACM&amp;coll=DL, last accessed</article-title>
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Corbella</surname>
            ,
            <given-names>I.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tillich</surname>
            ,
            <given-names>J.-P.</given-names>
          </string-name>
          :
          <article-title>Using ReedSolomon codes in the (U | U + V ) construction and an application to cryptography</article-title>
          . In: IEEE International Symposium on Information, https://ieeexplore.ieee.org/document/754143 5, last accessed
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Rossi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hamburg</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hutter</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marson</surname>
            ,
            <given-names>M.E.: A</given-names>
          </string-name>
          <string-name>
            <surname>Side-Channel Assisted</surname>
          </string-name>
          Cryptana
          <article-title>-lytic Attack Against QcBits</article-title>
          . https://link.springer.com/chapter/10.1007/97 8-
          <fpage>3</fpage>
          -
          <fpage>319</fpage>
          -66787-
          <issue>4</issue>
          _1, last accessed
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Almeida</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Avelli</surname>
            ,
            <given-names>D.N.:</given-names>
          </string-name>
          <article-title>A new class of convolutional codes and its use in the McEliece Cryptosystem</article-title>
          . https://www.researchgate.net/publication/32 4745076_
          <article-title>A_new_class_of_convolutional_c odes_and_its_use_in_the_McEliece_Crypto system</article-title>
          ,
          <source>last accessed</source>
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Kapshikar</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mahalanobis</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>A Quantum-Secure Niederreiter Cryptosystem using Qua-si-Cyclic Codes</article-title>
          . https://www.researchgate.net/publication/32 7660637_
          <article-title>A_QuantumSecure_Niederreiter_Cryptosystem_using_ Quasi-Cyclic_Codes, last accessed</article-title>
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Cho</surname>
            ,
            <given-names>J.Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Griesser</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rafique</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>A McEliece-Based Key Exchange Protocol for Optical Communication Systems</article-title>
          .
          <source>In: Proceedings of the 2nd Workshop on Communication Securi-ty, WCS</source>
          <year>2017</year>
          , pp.
          <fpage>109</fpage>
          -
          <lpage>123</lpage>
          , https://link.springer.com/chapter/10.1007%
          <fpage>2F978</fpage>
          -
          <fpage>3</fpage>
          -
          <fpage>319</fpage>
          -59265-
          <issue>7</issue>
          _8, last accessed
          <year>2019</year>
          /09/1.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Evseev</surname>
            ,
            <given-names>S.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rzaev</surname>
            ,
            <given-names>Kh.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsyganenko</surname>
            ,
            <given-names>A.S.:</given-names>
          </string-name>
          <article-title>Analysis of the software implementation of direct and inverse transformation using the method of nonbinary equilibrium coding</article-title>
          .
          <source>Bezpeka Informatsii 2016</source>
          Volume
          <volume>22</volume>
          #
          <fpage>2</fpage>
          - Kiev “Nash Format”, pp.
          <fpage>96</fpage>
          -
          <lpage>203</lpage>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Sidel'nikov</surname>
          </string-name>
          , V. M.
          <article-title>: Cryptography and coding theory</article-title>
          . In conference materials:
          <article-title>Moskovskij Universitet i razvitie kriptografii v Rossii, MGU</article-title>
          , p.
          <volume>22</volume>
          (
          <year>2002</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Minder</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Cryptography based on error correcting codes</article-title>
          .
          <source>Ph.D. thesis</source>
          , Ecole Polytech-nique Fédérale de Lausanne (
          <year>2007</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Faure</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Minder</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Cryptanalysis of the McEliece cryptosystem over hyperelliptic codes</article-title>
          .
          <source>In: Eleventh International Workshop on Algebraic and Combinatorial Coding Theory</source>
          , pp.
          <fpage>99</fpage>
          -
          <lpage>107</lpage>
          , Pamporovo, Bulgaria (
          <year>2008</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Rukhin</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Soto</surname>
            .,
            <given-names>J.:</given-names>
          </string-name>
          <article-title>A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications</article-title>
          . NIST Special Publication 800-
          <fpage>22</fpage>
          (
          <year>2000</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Hlobaz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Podlaski</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Milczarski</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Enhancements of encryption method used in SDEx</article-title>
          .
          <source>Communications in Computer and Information Science</source>
          Vol.
          <volume>718</volume>
          , pp.
          <fpage>134</fpage>
          -
          <lpage>143</lpage>
          , Springer International Publishing (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Milczarski</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hlobaz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Podlaski</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Analysis of enhanced SDEx method</article-title>
          .
          <source>Proceedings of the 2017 IEEE 9th International Conference on Intelligent Data Acquisition and Ad-vanced Computing Systems: Technology and Applications</source>
          , IDAACS (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>