<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Data Protection Standards in the Business Environment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Miloš Milašinović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nemanja Veselinović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Miloš Jovanović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Aca Aleksić</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Chad Ehrlich</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Academy of Technical and Art Applied Studies, School of Electrical and Computer Engineering</institution>
          ,
          <addr-line>Belgrade</addr-line>
          ,
          <country country="RS">Serbia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Belgrade Metropolitan University, Faculty of Information Technology</institution>
          ,
          <addr-line>Tadeuša Košćuška 63, Belgrade</addr-line>
          ,
          <country country="RS">Serbia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Whitman School of Management, Syracuse University</institution>
          ,
          <addr-line>Syracuse, NY</addr-line>
          ,
          <country country="US">United States of America</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper considers the strategy of protecting important data from attacks caused by the external or internal environment, as well as attacks carried out using social engineering methods. Encrypting data ensures a high level of protection. When developing an encryption strategy, it is necessary to know data flows at the application level and to have access controls to keys and places to store them. The influence of cryptographic algorithms on the operation of the database is also analyzed. The applied solutions show the strategy of raising protection in databases in the business world, which today has become unavoidable in all environments. The paper presents frameworks with an emphasis on legal and technical aspects that are necessary for the company's compliance process with the GDPR. With regard to the necessary implementation of technological solutions, the paper presents suggestions for the development of application support that will be applicable during the company's compliance with the GDPR.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Data protection</kwd>
        <kwd>Cryptography</kwd>
        <kwd>Encrypting</kwd>
        <kwd>Key management</kwd>
        <kwd>GDPR</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>companies’ credibility and customer relations. The only
way to protect the company’s assets is to implement
cerThe development of information technologies today, in tain measures and regulations for protection. Security
addition to a number of positive efects, has also caused measures include encryption of data exchanged over the
an incredible growth of data collections on almost all network and data stored on storage devices. Another
individuals around the world. Billions of data are being reliable method of protection is based on access control
collected in the virtual world at any moment, sold as a that protects data and information from insiders in the
commodity, misused in many ways. Every individual is environment. Data protection strategy is important and
faced with the fact that various state institutions, private complex. As an additional guarantee and prerequisite for
companies and individuals collect, process and use their realistic assessments of the level of security and the use of
personal data. Due to the incredible ease and speed with reliable supporting software components whose source
which data can be collected and misused, and the large code is available. One of the intermediate conditions for
number of individuals who can be afected by it, one of the success of the solution is its ease of use.
the most important issues of the 21st century is the issue The ideal, in concrete solutions, is that end users feel
of data protection. In professional information systems, the presence of cryptographic solutions as little as
possidata protection plays an important role. The goal of every ble, i.e. that their work is not complicated and that time
organization is to protect sensitive data in databases. resources are not significantly changed when executing</p>
      <p>Network databases are the heart of any organization. business processes.</p>
      <p>They contain business information, transaction infor- Implementing protection over the database itself
promation, financial data and customer information. The vides an excellent method for protecting sensitive data,
above types of data and information are often the tar- but on the other hand, it leads to a decrease in
perforget of attackers. A successful attack can cause huge fi- mance and complicates use. This means that only some
nancial losses to a company and damage its corporate important data can be encrypted, such as e.g. credit card
reputation. More frequent targets of attacks are trans- numbers, customer information, etc.
actions based on the web environment, which threaten This paper deals with the implementation of
encryption within the database, as well as the implementation
SBeIScuErCit’2y2,:D1e3ctehmIbnetrer0n3a,t2io0n22a,l BCeolngfreardeen,cSeeorbniaBusiness Information of the encryption process on the application server side.
* Corresponding author. These solutions ofer the availability of source code,
pri$ milos.milasinovic@metropolitan.ac.rs (M. Milašinović); marily the extension of available encryption algorithms
milos.milasinovic@metropolitan.ac.rs (N. Veselinović); with their own algorithm. Through the analysis of the
milos.jovanovic@metropolitan.ac.rs (M. Jovanović); performance of the mentioned solutions, the complexity
cmdielohsr.lmici@lagsimnoaivli.cco@mm(eCtr.oEphorlliitcahn).ac.rs (A. Aleksić); of the implementation and the load on the processor are
© 2023 Copyright for this paper by its authors. Use permitted under Creative Commons License analyzed in detail.</p>
      <p>CPWrEooUrckReshdoinpgs IhStpN:/c1e6u1r3-w-0s.o7r3g ACttEribUutRion W4.0oInrtekrnsahtioonpal (PCCroBYce4.0e).dings (CEUR-WS.org)</p>
    </sec>
    <sec id="sec-2">
      <title>2. Data protection by Encrypting</title>
      <sec id="sec-2-1">
        <title>The goal of any business environment is to protect the</title>
        <p>data of its clients. Due to the large number of places
where sensitive data is located within a business
environment, it is necessary to protect archived data, which
are located on employees’ computers or on some long
media.</p>
        <p>
          When developing a strategy, in order to be sure that
the data will be protected, we must fulfill two basic
conditions. The first is the use of reliable cryptographic
mechanisms, and the second is the precisely defined
management of access to cryptographic keys. Only by fulfilling
these conditions, the protection of confidential data can
be secure [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>The next step is to create a strategy for the encryption
process, and for its implementation it is important to do
the following:
• decide whether the encryption process is
performed inside or outside the database
• precisely optimize the system in order to reduce
the number of users who have access to
cryptographic keys
• determine a safe place to store cryptographic keys
• separate the ciphers from the cryptographic keys
in (in which case the ciphers in the hands of the
attacker are completely useless),
• strike a balance between performance and
application</p>
      </sec>
      <sec id="sec-2-2">
        <title>A precise policy of access control and management</title>
        <p>
          of cryptographic keys builds a high level of trust and
control over the information infrastructure [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>Access to decrypted data should be strictly limited
by access control and users who have access to such
data must be monitored by a system for monitoring and
analyzing log files.</p>
        <sec id="sec-2-2-1">
          <title>2.1. Planning Data Encryption Strategy</title>
        </sec>
      </sec>
      <sec id="sec-2-3">
        <title>Before starting to design an encryption strategy in</title>
        <p>databases it is necessary to understand:
• how cryptographic mechanisms work
• what the data flows look like in the application i
• how database protection fits into the
organization’s security policy</p>
      </sec>
      <sec id="sec-2-4">
        <title>So there are two strategies:</title>
        <p>• use of functional encryption mechanisms within
the database (DBMS)
• use of functional application-side encryption
mechanisms</p>
      </sec>
      <sec id="sec-2-5">
        <title>Each of these approaches has its advantages and dis</title>
        <p>
          advantages. It is important to make a good overview of
both, and depending on the organizational
infrastructure, choose the one that best fits the functioning of the
organization [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <sec id="sec-2-5-1">
          <title>2.2. Social Engineering as an Essential</title>
        </sec>
        <sec id="sec-2-5-2">
          <title>Factor in Strategy Development</title>
          <p>creating a database protection strategy. Without strong
identity verification, application-side technologies open
the way to access to data decryption mechanisms.</p>
          <p>
            A big problem is database administrators and business
application developers who know how to access that
information, as well as disgruntled employees who find
a way through social engineering to access passwords.
Many employees have compromised their companies by
revealing monthly earnings, social security numbers, cell
phone numbers, information about external partners, and
more [
            <xref ref-type="bibr" rid="ref2">2</xref>
            ].
          </p>
          <p>
            Database protection is not only the protection of
important data, but also the protection of employees from
this type of exploitation. You should think about
developing a security strategy in time, primarily the protection of
important data, such as encryption, access control, event
monitoring and log monitoring [
            <xref ref-type="bibr" rid="ref3">3</xref>
            ].
          </p>
        </sec>
        <sec id="sec-2-5-3">
          <title>2.3. Impact of Encrypted Data on the</title>
        </sec>
        <sec id="sec-2-5-4">
          <title>Database</title>
        </sec>
      </sec>
      <sec id="sec-2-6">
        <title>Encryption provides a high level of protection and is accepted as a best practice in restrictions for protecting important information, but it has an impact on data and the database.</title>
        <p>Encryption increases the amount of data and reduces
the performance of the application. When planning the
development of the application, it is important to
anticipate possible impacts caused by the use of encryption
systems.</p>
        <p>
          By knowing which data should be protected, we get
more flexibility and better performance. When
processing a credit card, we can encrypt the entire number or
just the last four digits [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>
          Based on the knowledge of the amount of data that
needs to be protected, the application is designed.
Encryption afects data size. The algorithm can often change the
size of the fixed data from the database, so that the data is
not saved. Especially the encryption of some small data
can greatly increase its size, and this leads to an increase
in the column sizes of the relational database [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>Encryption is a process in which we transform
characters into binary meaningless strings that can afect the
size if we transform the encrypted data into characters.</p>
        <p>By using the BASE64 algorithm, we can convert the
encrypted data into a string of characters, but this would
increase the size of the data by one third. When selecting
the fields in the database tables, which will be encrypted,
it is important to take care of the search process. Cryptography is based on cryptographic keys, which</p>
        <p>
          If every search, in large databases, is followed by a depend on the storage of encrypted data in databases.
process of encryption and decryption, it can degrade the They have secret places where they are archived and who
performance of applications, as well as their function- can access them. Cryptographic key management control
ing, encryption can complicate the initial process and is generally envisaged when developing a strategy for
cause frustration for the user at the beginning, and this database protection [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
requires hard new considerations and planning around The most important roles in planning a key control
the selection encryption fields [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. strategy:
        </p>
        <sec id="sec-2-6-1">
          <title>3.1. Cryptographic Key Management Strategy</title>
          <p>• the number of keys required for encryption
• the way they are used
• the place where they are stored
• protected and limited access to them
• change of keys</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Cryptography and</title>
    </sec>
    <sec id="sec-4">
      <title>Cryptographic Algorithms</title>
      <sec id="sec-4-1">
        <title>Data, in order to reach the highest level of security, must</title>
        <p>be stored in an encrypted form. The goal of encryption
is to make them unreadable by unauthorized readers and
protect them from decryption in the event of an attack. 4. Required Number of Keys and</p>
        <p>
          The encryption operation is performed with randomly Modes of Management
generated cryptographic keys. Which make the cipher
secure and dificult to attack or decipher. Keys are usually The problem of cryptographic key management is
difstored in encrypted form [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. ifcult to solve. Using the same key in an application is
        </p>
        <p>Not all encryption averages are the same. The security easy to implement and maintain, but if that key becomes
of encrypted data depends on various factors such as the compromised, the data will become vulnerable.
length of the cryptological key, and the algorithm and If there are a large number of users, requiring access to
the way it is implemented in the system used. diferent applications, the scenario becomes more
com</p>
        <p>
          Many databases use AES and DES algorithm to pro- plex because encrypted data can only be decrypted with
tect fields with important data, but DES has long been the appropriate key, and each system or application must
considered insecure for protection. When choosing a have access to the appropriate key [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
cryptographic algorithm, it is important to find a reliable The more applications that have access to the keys,
supplier of commercial algorithms or decide on your own the greater the risk of attack, so they should be kept in
solution [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. a secure management system. A good practice is to use
        </p>
        <p>
          Apart from the quality of the cryptographic algorithm, a smaller number of encryption keys, it is a simpler key
a quality strategy for managing cryptographic keys is management solution, but because of this the critical
also very important. In such systems there is a constant point becomes the key [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
tension in the spheres of protection between control and
access. In any case, the system must have access to the 4.1. Safe Place to Keep Keys
keys to decrypt something, and their distribution is
complicated and leads to a decrease in performance and
sometimes security [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ].
        </p>
        <p>Administrators and developers are at a loss if they
implement such security measures.</p>
      </sec>
      <sec id="sec-4-2">
        <title>When developing a key control strategy, consider a safe</title>
        <p>place to store the keys. One solution is to store it in a
separate database or in a file with strictly limited access.</p>
        <p>With such solutions, the problem is administrators who
have authorized access to the keys and can decrypt the
data and then cover their tracks. In this case, the security also data such as search history, meta data on files
creof the database does not depend on best practices, but on ated by a natural person, which they can reveal identity,
the honesty and honor of the employees. information about health, movement, habits [12].</p>
        <p>
          To reduce risk and have better control, it is best if only Personal data means any combination of personal facts
one person has access to the keys. The next possibil- that accurately determines an individual, i.e., among
othity to consider is to separate the keys from the database ers, first and last name, personal identification number,
and store them in an encrypted form on some hardware location data, physical, physiological, genetic, mental,
devices. It is important that the key cannot leave the economic, social, cultural or any other factors.
hardware device, that access is controlled, and that nei- The GDPR regulation on the management of personal
ther the administrator nor the attacker can get to it and data is based on the following principles:
take it [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>The security of keys depends on good management
and a place to store them. According to a 2005 survey,
one-third of organizations store their sensitive data with
keys.</p>
        <p>Without a strategy for separating database keys and
storing them in secure places with limited access, the
entire system is at great risk to many users, developers,
and database administrators.</p>
        <p>
          Systems that do not have this strategy survive due
to the quality of the applied authentication methods for
identity verification and access control [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
• Legal and transparent processing of personal data
        </p>
        <p>of European Union residents is required.
• Collection of personal data for specific, precisely
defined purposes. The company must not process
data in a way that is inconsistent with the stated
purpose. Storing only minimally necessary data.
• The company does not have the authority to
ask the individual for additional information that
goes beyond the defined purpose of data
collection and processing.
• The company is not authorized to keep data</p>
        <p>longer than defined.
• It is necessary for the company to implement
certain security measures, • Personal data must
be accurate and updated.
• In an adequate way, it is necessary to ensure the
corresponding level of security of personal data,
including protection against unauthorized
processing. It is necessary to ensure data
confidentiality.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Data protection Law</title>
      <sec id="sec-5-1">
        <title>Along with the development of theories about the un</title>
        <p>derstanding of privacy and the protection of the right to
privacy before the courts in Europe, from the seventies
of the twentieth century until today, legal regulations
were developed that regulate the issue of data protection
and create a complex system of data protection.</p>
        <p>In the beginning, these were the legal regulations of The GDPR regulation requires a review of business
certain European countries, and then the main role in models in companies that ofer their goods and services
the creation of the data protection system was taken by to natural persons resident in the European Union [13].
the European Union [11]. A company that collects personal data before
process</p>
        <p>The legal system of data protection in Europe, based ing must obtain the consent of the individual for their use,
on the Data Protection Directive from 1995, was not suf- and it is necessary that the natural person who gives
conifcient to adequately respond to the accelerated develop- sent be informed about the purpose of collecting personal
ment of technology and numerous ways of inadequate data. One of the simpler ways of adapting a company to
collection and processing of personal data, and for this the GDPR regulation is by engaging third parties -
agenreason, in January 2012, a legislative procedure for the cies that have legal and technical knowledge for security
adoption of a regulation that would comprehensively and data protection.
regulate issues of the right to data protection. They will be able to adequately and professionally</p>
        <p>After a long public discussion and harmonization of nu- fulfill their obligations to companies in terms of eficient
merous proposals and consideration of over 4,000 amend- privacy protection [13].
ments, the text of the General Data Protection Regulation
was agreed and adopted in April 2016. This regulation
came into force on May 25, 2018 [12]. The GDPR regula- 6. Application of Application
tion provides individuals with greater control over per- Support for GDPR
sonal data and imposes many obligations on companies
that collect and analyze personal data. The regulation Implementation
under private data includes all those data from which
the identity of a person can be determined, then data on In order to improve the protection of personal data,
compolitical, sexual orientation, race, property status, but panies will improve their IT infrastructure, implementing
the necessary protective measures for the process of phys- structured data in which it is easier to recognize
identiical control of access to data, storage and the process of fiers such as: first name, last name, phone number, JMBG,
data archiving. etc.</p>
        <p>The regulation mentions the need for archiving and These data are found in databases such as accounting
data access records. This will lead companies to focus ERP systems or customer relationship management
syson data protection processes. The necessary alignment tems CRM. Within the organization, it is necessary to
of domestic companies with the GDPR regulation will define that both IP and MAC addresses are also personal
increase market demands for specialized application sup- data. In order for the search system to be able to work
port [14] with such data, it is necessary to note that these data have</p>
        <p>The Regulation does not explicitly state which tech- control digits and from them it can be concluded that a
nology must be used for data protection activities. The series of numbers (JMBG, MAC address, etc.) belongs
Regulation mentions the mandatory continuous moni- to personal data. It is suggested to use machine
learntoring of personal data and the necessary activities of ing systems, because they will independently recognize
search, management, protection, monitoring of personal within similar documents whether something is specific
data and reporting activities. to the organization [15].</p>
        <p>The technology that would help companies in the Thus, the optimal application support system will be
GDPR compliance process can be arbitrary. The first able to recognize what is personal data from a large
numand basic phase of the implementation of the GDPR reg- ber of documents and contracts. It is necessary to use
ulation is the phase of searching existing personal data. application support with search mechanisms in order for</p>
        <p>It is necessary to enable the search of the competent the company to determine where personal data is located.
scope of personal data. In addition, it is necessary to de- It is necessary to search all hardware data storage units,
termine identifiers that will clearly define personal data, as it is possible that copies of personal data are located on
such as: first name, last name, email, address, telephone, multiple storage units. Structured data will be easier to
JMBG, etc. After determining these identifiers of per- ifnd, but for unstructured data it is necessary to develop
sonal data, the data to be searched will be divided into new search algorithms within e-mails or the cloud [15].
structured and unstructured . Structured data is found
in tables in which names, surnames, JMBG numbers, etc.
are structurally listed [14]. 7. Conclusion</p>
        <p>It is necessary to search complete databases in order
to separate those files that contain structured data with Attacks on databases, from year to year, are on the rise,
defined identifiers of personal data. Application support which increases the risk of compromise. Today,
finanwill help companies to find as many personal data as cial service providers and healthcare organizations must
possible based on certain search rules. Once the data is strictly comply with data privacy laws.
determined, then it needs to be classified. Users of these services due to concerns about data</p>
        <p>Personal data can be marked by type (structured/un- disclosure or misuse will inevitably expand the
responsistructured), by secrecy (public data, secret data). Every bilities of each organization to provide certain services.
user of the personal data base should get access to this The negative efects, caused as a result of the attack,
tool. He will manually or mechanically classify data (files, would be reflected in the form of legal liability, negative
ofice documents, photos, video, audio, email). publicity, lost trust in the public, and loss of money and</p>
        <p>The classification of data will make it possible to deter- productivity. In order to avoid the mentioned negative
mine the types of data processed by business processes efects in our environment, it is inevitable to plan an
within the company: whether the data is personal data encryption strategy in databases to protect important
at all, whether it needs encryption, a digital signature, data and a strategy against attacks and other abuses.
and the like. In order to reveal the largest percentage of Implementers of application support will have
procepersonal data that the company has in its databases, it is dures for compliance with the GDPR regulation.
Hownecessary to define - what all needs to be searched [15]. ever, users will be required to clearly define changes in</p>
        <p>The search tool should be able to search photos, as an business processes. Companies must be aware that IT
important identifier of personal data, as well as data from ifrms will not take the risk and responsibility on
themsocial networks, various online identifiers: such as user selves. IT companies will proceed from the assumptions
logins, MAC data, and GPS data about the user’s geolo- that they avoid taking risks due to large fines and due to
cations. In order for the data search system to be able to often unclear points within the GDPR regulation.
ifnd a larger percentage of personal data, it is necessary IT companies will implement application support
acto define a larger spectrum of identifiers that the GDPR cording to the requests received from clients and thus
regulation recognizes as personal data. It is necessary to avoid the risk related to the GDPR regulation.
Theredefine the method of data search. It is possible to search fore, it is important that company managers undergo
the necessary training in order to be able to implement phy algorithms, International Journal of Scientific
compliance with the GDPR regulation. An IT company and Research Publications 8 (2018) 495–516.
that develops application support must be aware that its [11] K. Hjerppe, J. Ruohonen, V. Leppänen, The general
clients are subject to the GDPR and that the very fact data protection regulation: Requirements,
architecthat companies use their application support to enter tures, and constraints, in: 2019 IEEE 27th
Internapersonal data creates an obligation for them to comply tional Requirements Engineering Conference (RE),
with the GDPR regulation. IEEE, 2019, pp. 265–275.</p>
        <p>Some of the principles that the application support [12] M. Goddard, The eu general data protection
regulamust adhere to are: it is necessary to implement the tion (gdpr): European regulation that has a global
necessary settings for the protection of personal data impact, International Journal of Market Research
in the application support, as well as the possibility of 59 (2017) 703–705.
competent deletion of personal data. It is necessary that [13] C. Tankard, What the gdpr means for businesses,
all interfaces to third-party systems comply with the rules Network Security 2016 (2016) 5–8.
of personal data protection. [14] J. P. Albrecht, How the gdpr will change the world,</p>
        <p>It is necessary to simplify the process of changing cus- Eur. Data Prot. L. Rev. 2 (2016) 287.
tomers’ personal data, in such a way that from one place [15] W. B. Tesfay, P. Hofmann, T. Nakamura, S.
Kiythe change is reflected in all places in the company’s omoto, J. Serna, Privacyguide: towards an
impledatabases. It is necessary to ofer a printout of the Con- mentation of the eu gdpr on internet privacy policy
sent to be signed by the respondents in the application. evaluation, in: Proceedings of the Fourth ACM
The process of user logging into the system is also chang- International Workshop on Security and Privacy
ing. It is important that each user accesses the system Analytics, 2018, pp. 15–21.
with his or her own unique user login that only he or she
uses.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M. E.</given-names>
            <surname>Smid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. K.</given-names>
            <surname>Branstad</surname>
          </string-name>
          ,
          <article-title>Data encryption standard: past and future</article-title>
          ,
          <source>Proceedings of the IEEE</source>
          <volume>76</volume>
          (
          <year>1988</year>
          )
          <fpage>550</fpage>
          -
          <lpage>559</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>R.</given-names>
            <surname>Davis</surname>
          </string-name>
          ,
          <article-title>The data encryption standard in perspective</article-title>
          ,
          <source>IEEE Communications Society Magazine</source>
          <volume>16</volume>
          (
          <year>1978</year>
          )
          <fpage>5</fpage>
          -
          <lpage>9</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D.</given-names>
            <surname>Coppersmith</surname>
          </string-name>
          ,
          <article-title>The data encryption standard (des) and its strength against attacks</article-title>
          ,
          <source>IBM journal of research and development 38</source>
          (
          <year>1994</year>
          )
          <fpage>243</fpage>
          -
          <lpage>250</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>D. E.</given-names>
            <surname>Standard</surname>
          </string-name>
          , et al.,
          <article-title>Data encryption standard</article-title>
          ,
          <source>Federal Information Processing Standards Publication</source>
          <volume>112</volume>
          (
          <year>1999</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>E. F.</given-names>
            <surname>Schaefer</surname>
          </string-name>
          ,
          <article-title>A simplified data encryption standard algorithm</article-title>
          ,
          <source>Cryptologia</source>
          <volume>20</volume>
          (
          <year>1996</year>
          )
          <fpage>77</fpage>
          -
          <lpage>84</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>G. C.</given-names>
            <surname>Kessler</surname>
          </string-name>
          , An overview of cryptography,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D.</given-names>
            <surname>Dolev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Dwork</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Naor</surname>
          </string-name>
          ,
          <article-title>Non-malleable cryptography</article-title>
          ,
          <source>in: Proceedings of the twenty-third annual ACM symposium on Theory of computing</source>
          ,
          <year>1991</year>
          , pp.
          <fpage>542</fpage>
          -
          <lpage>552</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>W.</given-names>
            <surname>Difie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. E.</given-names>
            <surname>Hellman</surname>
          </string-name>
          ,
          <article-title>New directions in cryptography</article-title>
          ,
          <source>in: Democratizing Cryptography: The Work of Whitfield Difie and Martin Hellman</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>365</fpage>
          -
          <lpage>390</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>K.-H.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.-L.</given-names>
            <surname>Chiu</surname>
          </string-name>
          ,
          <article-title>An extended visual cryptography algorithm for general access structures</article-title>
          ,
          <source>IEEE transactions on information forensics and security 7</source>
          (
          <year>2011</year>
          )
          <fpage>219</fpage>
          -
          <lpage>229</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>O. G.</given-names>
            <surname>Abood</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. K.</given-names>
            <surname>Guirguis</surname>
          </string-name>
          , A survey on cryptogra-
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>