<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Families of Square Commutative 2х2 Matrices</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Anatoly Shcherba</string-name>
          <email>a.shcherba@chdtu.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Emil Faure</string-name>
          <email>e.faure@chdtu.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Skutskyi</string-name>
          <email>a.b.skutskyi.asp21@chdtu.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Kharin</string-name>
          <email>o.kharin@chdtu.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Cherkasy State Technological University</institution>
          ,
          <addr-line>460 Shevchenko blvd., Cherkasy, 18006</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>State Scientific and Research Institute of Cybersecurity Technologies and Information Protection</institution>
          ,
          <addr-line>3 M. Zaliznyak str., Kyiv, 03142</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>289</fpage>
      <lpage>296</lpage>
      <abstract>
        <p>The objective of this study is to define and investigate the families of square matrices of order 2 with a commutative multiplication operation to be used in cryptographic information transformation. The general linear group of order n over the prime field of integers modulo p has been investigated. Six families of matrices from the general linear group of order 2 for which the multiplication operation is commutative have been defined. The current study has found the cardinalities of these families. The study has also regarded the family of matrices from the general linear group of order 2 with a commutative multiplication operation, extended by an identity matrix. The research has revealed that this matrix family is a multiplicative abelian group. For this purpose, the authors have proved that the axioms of the group are fulfilled, confirmed that the multiplication is commutative, and demonstrated the order of the group. The results of this study create prerequisites for using the obtained multiplicative abelian groups of square matrices of order 2 while solving the tasks of constructing cryptographic key agreement protocols, asymmetric encryption algorithms, and three-pass cryptographic protocols.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Matrix family</kwd>
        <kwd>commutative transformation</kwd>
        <kwd>commutative encryption</kwd>
        <kwd>multiplicative abelian group</kwd>
        <kwd>key agreement</kwd>
        <kwd>cryptography</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Commutative operations play an essential role
in cryptographic information transformation
algorithms widely used in modern information
and communication systems, smart
technologies, and the Internet of Things. In
particular, key agreement procedures,
asymmetric encryption, and three-pass
cryptographic protocols apply commutative
cryptographic transformations [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5">1–5</xref>
        ]. Some of
the classic cryptographic schemes that deploy
commutative exponentiation in modular
arithmetic (modular exponentiation) are the
      </p>
      <sec id="sec-1-1">
        <title>Diffie-Hellman key agreement protocol [6], RSA</title>
        <p>
          [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ], SRA [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ], Massey-Omura cryptosystem [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>
          The scientific search for commutative
cryptographic transformations is still relevant
today. Algorithms whose strength relies on the
computational complexity of factorization and
discrete logarithm procedures are not
protected against attacks with quantum
computers and can be broken over polynomial
time [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>
          Moldovyan et al. [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] refer to the literature
[12] as one of the first attempts to solve the
problem of building a post-quantum
commutative cipher. The proposed approach is
based on the hidden discrete logarithm
problem, however, this approach does not
achieve an increase in cryptographic strength
[13]. Methods for applying forms of the hidden
discrete logarithm problem have been
developed in studies [14–16] and are based on
operations in a multidimensional vector space.
        </p>
      </sec>
      <sec id="sec-1-2">
        <title>In the study [14], the authors propose a secure encryption method based on commutative transformations. The three basic components</title>
        <p>
          of this method are the following cryptographic
protocols: Diffie-Hellman key agreement
protocol [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ], Pohlig-Hellman commutative
encryption algorithm [17], and Shamir
threepass protocol [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. An exponentiation cipher is
used to perform commutative encryption.
        </p>
      </sec>
      <sec id="sec-1-3">
        <title>Kryvyi [18] has demonstrated a method for</title>
        <p>constructing a symmetric cryptosystem based
on the properties of finite
associativecommutative rings with unity and discusses
conditions for using discrete logarithm
functions in the rings.</p>
      </sec>
      <sec id="sec-1-4">
        <title>The study [19] develops encryption using</title>
        <p>cryptography methods such as Diffie-Hellman,
commutative supersingular isogeny, and
group action inverse problems.</p>
      </sec>
      <sec id="sec-1-5">
        <title>Examples of using commutative encryption</title>
        <p>to protect secret key exchange are offered in
the studies [20–21]. Research undertaken by</p>
      </sec>
      <sec id="sec-1-6">
        <title>Sihare [22] further develops the schemes and offers a dynamic multi-party quantum key agreement protocol.</title>
      </sec>
      <sec id="sec-1-7">
        <title>Studies [23–26] use permutations to</title>
        <p>represent data, and operations on permutations
to construct key agreement protocol [27] and to
improve three-pass cryptographic protocol,
including for use in noisy channels [28–30].</p>
        <p>A previous study [31] suggests using
publickey cryptography based on commutative
semirings of tropical circular matrices, where
multiplication is the ordinary addition of
numbers and there is no ordinary
multiplication of numbers in the tropical
semiring.</p>
      </sec>
      <sec id="sec-1-8">
        <title>Shamir’s three-pass random matrix</title>
        <p>ciphering mechanism [32] uses a three-pass
protocol with encryption operators that are
random commutative matrices.</p>
        <p>The current study focuses on identifying
and researching families of square matrices
with commutative multiplication. The matrices
will be limited by 2×2 dimension, and their
elements will belong to the prime field of
integers modulo p.
2. Families of Commutative 2×2</p>
        <p>Matrices</p>
      </sec>
      <sec id="sec-1-9">
        <title>We first introduce a definition.</title>
        <p>
          Definition 1 [
          <xref ref-type="bibr" rid="ref12">33–34</xref>
          ]. A general linear
group of order n over any field F or ring R is
a group of invertible matrices n  n containing
elements from F (or R ) with ordinary matrix
fixed,
fixed,

  1
3 = t  
  0 ak +1
a  t, a, k  Z p ,t  0,
,  , k is
ak +1  0 
multiplication as the group multiplication
operation.
        </p>
        <p>GL (n, F ) will denote the general linear
group of order n over the field F .</p>
      </sec>
      <sec id="sec-1-10">
        <title>Note that the square matrix A is invertible if</title>
        <p>
          and only if its determinant A  0 [
          <xref ref-type="bibr" rid="ref13">35</xref>
          ].
        </p>
        <p>Here,
we
consider
the
group
  a b  
 =  A =  , a,b,c, d  Z p , A  0 , where
  c d  </p>
        <sec id="sec-1-10-1">
          <title>Z p is the prime field of integers modulo p .</title>
          <p>Then,  = GL (2, Z p ) .</p>
          <p>Theorem 1. Multiplication is commutative
for the following families of matrices  :
  1 0  
1 = t   0 a ,t, a  Z p ,t  0, a  0 ,

  1
2 = t  
  a ak + 1
0  t, a, k  Z p ,t  0,
,  , k is</p>
          <p>ak + 1  0 

  a 1  t, a,b  Z p ,
4 = t   ,  , a , b are fixed,
  b 0  t  0,b  0 

  0 1  t, a,b  Z p ,
5 = t   ,  , a , b are fixed,
  b a  t  0,b  0 
  a 1  t, a,b, k  Z p ,t  0,b  0,
6 = t   b a + k , a (a + k ) − b  0 
, b , k are fixed.</p>
          <p>Proof.</p>
        </sec>
      </sec>
      <sec id="sec-1-11">
        <title>Note that in the general case,  is non</title>
        <p>abelian.</p>
      </sec>
      <sec id="sec-1-12">
        <title>Consider the following cases:</title>
        <p>b = c = 0 , ad  0
b = 0 or c = 0 , ad  0
bc  0 , ad = 0
ad  0 , bc  0 .</p>
        <p>Case 1: b = c = 0 , ad  0 .</p>
      </sec>
      <sec id="sec-1-13">
        <title>In this case,</title>
        <p>
           a b   a 0   1 0 
A =   =   = a   . The set of
 c d   0 d   0 d a 
such diagonal non-degenerate matrices is
equivalent to the set
  1 0  
1 = t   0 a ,t, a  Z p ,t  0, a  0 ,
which
forms an abelian group [
          <xref ref-type="bibr" rid="ref14">36</xref>
          ]: for A, B  1 ,
AB = BA is true.
        </p>
        <p>Case 2: b = 0 or c = 0 , ad  0 .</p>
        <p>
          Let b = 0 and ad  0 . Then, matrix
 a b   a 0   1 0 
A =   =   = a   . The set of
 c d   c d   c a d a 
such matrices is a family of
nondegenerate lower triangular matrices
  1 0 t, a,b  Z p ,
 = t   , . According to [
          <xref ref-type="bibr" rid="ref14">36</xref>
          ],
  a b  t  0,b  0 
 forms a group by multiplication.
        </p>
        <p> 1 0  1 0 
Let A, B and A =   , B =   .</p>
        <p> a b   x y 
 1 0 
The product A  B =  a + bx by . The product
 1 0 
B  A =  x + ay by  .</p>
      </sec>
      <sec id="sec-1-14">
        <title>Value</title>
        <p>A B = B  A , if a + bx = x + ay or
x (b −1) = a ( y −1) . If a = x = 0 ,  degenerates
into 1 , which is abelian. If a, x  0 , we assume
that
b −1 y −1</p>
        <p>=
a x
b = ak +1,
= k , k  Z p . Then </p>
        <p> y = xk +1;
 1 0   1 0 
and matrices A = 
 a ak +1 , B = 
 x xk +1 ,
where a  0 , x  0 , ak +1  0 , xk +1  0 ,
k  Z p .</p>
        <p>  1 0  t, a, k  Z p ,t  0,</p>
        <p>Then 2 = t   a ak +1, ak +1  0 
is an abelian group, where a and t values may
be arbitrary, while k value is a fixed
parameter of group 2 .</p>
        <p>Adopting that c = 0 , ad  0 , and reasoning
by analogy, we can prove that a group of
nondegenerate upper triangular matrices of
 a b 
A =   type is abelian if it forms the group
 0 d 
  1

3 = t  </p>
        <p>  0 ak +1
Case 3: bc  0 , ad = 0 .</p>
        <p>Let bc  0 and d = 0 .</p>
        <p> a b   a b   a b 1
A =   =   = a   .</p>
        <p> c d   c 0  c b 0
a  t, a, k  Z p ,t  0,
,  .</p>
        <p>ak +1  0 </p>
      </sec>
      <sec id="sec-1-15">
        <title>Then</title>
      </sec>
      <sec id="sec-1-16">
        <title>Such</title>
        <p> a 1 
A = </p>
        <p> b a + k  ,
matrices define

  a 1  t, a,b  Z p ,
 = t   ,  .</p>
        <p>  b 0 t  0,b  0 

  a
6 = t  
  b a + k 
1  t, a,b, k  Z p ,t  0,b  0,
,  is
a (a + k ) − b  0 </p>
        <p> a 1   x 1 
Let A, B and A = t   , B = s  
 b 0  y 0
. An equality A B = B  A means
 ax + y a   ax + b x  x = a,
 bx b  =  ay y  or  y = b.
Therefore, if bc  0 and d = 0 the commutative

  a 1 t, a,b  Z p ,
family is the set 4 = t   ,  ,
  b 0 t  0,b  0 
where a and b are fixed.</p>
        <p>Taking bc  0 , a = 0 , it can be shown by
analogy that the commutative family is the set

  0 1  t, a,b  Z p ,
5 = t   ,  , where a and b
  b a  t  0,b  0 
are fixed.</p>
        <sec id="sec-1-16-1">
          <title>Note that the families 4 , 5 are not closed</title>
          <p>under multiplication, so they do not form a
group.</p>
          <p>Case 4: ad  0 , bc  0 .</p>
          <p> a b   a b 1 
Since b  0 , A =   = b  .</p>
          <p> c d   a c a d 
The set of such matrices forms the set of
nondegenerate matrices

  a 1 t, a,b,c  Z p ,t  0,
 = t   ,
  b c  b  0, ac − b  0  .</p>
          <p> a 1  x 1 
Let A, B and A =   , B =   .</p>
          <p> b c   y z 
 ax + y a + z 
The product A  B =  bx + cy b + cz  . The
 ax + b x + c 
product B  A =  ay + bz y + cz  .
is
achieved if</p>
          <p>Equality A B = B  A
ax + y = ax + b;
a + z = x + c;

bx + cy = ay + bz;
b + cz = y + cz.</p>
          <p>Let
c − a = z − x = k ,
 y = b;</p>
        </sec>
        <sec id="sec-1-16-2">
          <title>It follows that </title>
          <p>c − a = z − x.
k  Z p .</p>
          <p> x 1 
B = 
 b x + k  ,</p>
        </sec>
      </sec>
      <sec id="sec-1-17">
        <title>Then</title>
        <p>and
a commutative family, wherein a and t values
may be arbitrary, while b and k values are 6
fixed parameters.</p>
        <sec id="sec-1-17-1">
          <title>Now, we have got all 1 − 6 families of</title>
          <p>matrices
from
 = GL (2, Z p ) ,
which
multiplication is commutative.</p>
        </sec>
      </sec>
      <sec id="sec-1-18">
        <title>The theorem is proved.</title>
        <p>The cardinality of each 1 − 3 family is
equal to ( p −1)2 , and the cardinality of each
4 − 5 family is equal to p −1, while the
cardinality of 6 family is ( p −1)( p − l ) , where
l = 0;1;2 is the number of integer roots of the
equation a2 + ka − b = 0(mod p) concerning
the variable a . The l value is defined by b and
k parameters.
3. Commutative Family of 2×2</p>
        <p>Matrices with Identity Matrix
Consider the matrix family 6 supplemented by
an identity matrix, as well as the case when b = 0
, since it does not affect the commutativity of the
matrices from 6 . We will denote this family by
  a 1   1 0 
t   b a + k , s   ,
 0 1  
CGLb,k (2, p ) =  t, s, a,b, k  Z p ,t, s  0, .</p>
        <p> a (a + k ) − b  0 </p>
      </sec>
      <sec id="sec-1-19">
        <title>Theorem 2. The matrix family</title>
        <p>CGLb,k (2, Z p ) is a commutative (abelian)
group under multiplication.</p>
        <p>Proof.</p>
      </sec>
      <sec id="sec-1-20">
        <title>We will prove that the group axioms are</title>
        <p>fulfilled for CGLb,k (2, Z p ) and demonstrate
that the multiplication
CGLb,k (2, Z p ) is commutative.
operation
in
 1 0
element: E =   .</p>
        <p> 0 1 </p>
      </sec>
      <sec id="sec-1-21">
        <title>2. The operation of multiplying elements in</title>
        <p>CGLb,k (2, Z p ) is associative since this is a
general property for matrices.</p>
        <p>3. For each matrix ACGLb,k (2, Z p ) , there
is an inverse matrix
A A−1 = A−1  A = E .</p>
      </sec>
      <sec id="sec-1-22">
        <title>Thus, if</title>
        <p>A−1 CGLb,k (2, Z p ) :</p>
        <p> 1 0
A = s    ,
 0 1 
then
A−1 = s   1 0−1   . In Z p , for
 = s−1   1 0
  0 1  0 1
each s  Z p , there is an inverse element s−1 :
s  s−1 = s−1  s = e =1, that is unique. Further,
while proving this theorem, we will neglect
multipliers s and t without limiting the
generality of the foregoing.</p>
        <p> a 1 
Let A = </p>
        <p> b a + k  .</p>
      </sec>
      <sec id="sec-1-23">
        <title>Then</title>
        <p>A−1 =  ba a +1 k −1 = a (a +1k ) − b  a−+bk −a1 .</p>
        <p>Let us assume that t ' =
−1
a (a + k ) − b
 0 ,
a' = −a − k . Then,
A−1 = t '  ab' a '1+ k  CGLb,k (2, Z p ) .</p>
        <p>Moreover, it follows therefrom that
 a 1  c 1 −1
 b a + k  b c + k  = E if and only if a = c .

is
closed
under
4.</p>
        <p>CGLb,k (2, Z p )
multiplication.
this property is obvious.</p>
        <p>Let A, B CGLb,k (2, Z p ) . If A = E or B = E ,
Consider the situation when A =  a 1 
 b a + k 
 x 1 
 b x + k  for arbitrary a, x  Z p .
and B = 
 a 1  x 1 
A  B = </p>
        <p> b a + k  b x + k  =
 ax + b a + x + k 
=  b(a + x + k ) b + (a + k )( x + k ) .</p>
        <p>If</p>
        <p> ax + b
A  B = </p>
        <p> 0</p>
      </sec>
      <sec id="sec-1-24">
        <title>Since</title>
        <p>A  0
a + x + k = 0 ,
0   1 0
ax + b  = (ax + b)    .</p>
        <p> 0 1 
and B  0 ,
then
then
1. CGLb,k (2, Z p ) has a single identity</p>
      </sec>
      <sec id="sec-1-25">
        <title>Product</title>
        <p>A  B = A  B  0 and ax + b  0
correspondingly. From whence it follows that
A  B CGLb,k (2, Z p ) .</p>
        <p>If a + x + k  0 , then
A  B = 1  aa+xx++bk 1  . Let
a + x + k  b k + aa+xx++bk 
t = 1  0 and
a + x + k
 y 1 
 b y + k  CGLb,k (2, Z p ) .</p>
        <p>A  B = t 
y = ax + b . Then
a + x + k
5. CGLb,k (2, Z p ) is an abelian group.</p>
        <p>If A = E , then A B = E  B = B = B  E = B  A</p>
        <p>Let A =  a 1   x 1 
 b a + k  and B = </p>
        <p> b x + k  .</p>
        <p> ax + b a + x + k 
Then A  B =  b(a + x + k ) b + (a + k )( x + k )
and B  A =  b(aa+x +x b+ k ) b + (ax ++ kx)+(ak + k ) ,
from where it follows that A B = B  A .</p>
      </sec>
      <sec id="sec-1-26">
        <title>The theorem is proved.</title>
      </sec>
      <sec id="sec-1-27">
        <title>To exponentiate the square matrix</title>
        <p>
           a b 
A =   , we will use the following
 c d 
expression from [
          <xref ref-type="bibr" rid="ref15">37</xref>
          ]:
        </p>
        <p>An =  un+1 − dun
 cun</p>
        <p>
          bun 
un+1 − aun  ,
(1)
where
un+1 = (a + d )un − A un−1 = tr ( A)un − A un−1 ,
tr ( A) is a trace of the matrix A [
          <xref ref-type="bibr" rid="ref16">38</xref>
          ];
u0 = 0 , u1 = 1 .
        </p>
      </sec>
      <sec id="sec-1-28">
        <title>For a matrix</title>
        <p> a 1 
 b a + k  CGLb,k (2, Z p ) ,
A = 
group</p>
        <p>element
we
obtain
tr ( A) = 2a + k ,</p>
        <p>A = a (a + k ) − b  0 . Then
un+1 = (2a + k )un − (a (a + k ) − b)un−1
and
An =  un+1 − (a + k )un</p>
        <p> bun
Note that An = A n  0 .</p>
        <p>un  .
un+1 − aun </p>
        <p>Since CGLb,k (2, Z p ) is a commutative group
under multiplication,</p>
      </sec>
      <sec id="sec-1-29">
        <title>According to (1): If</title>
        <p>An =  un0+1</p>
        <p>If
un = 0 , then
0   1 0
un+1  = un+1  0 1  CGLb,k (2, Z p ) .
un  0 ,
then
An CGLb,k (2, Z p ) .</p>
        <p>An = un  uunn+1 − a − k 1 
 CGLb,k (2, Z p ) .

 b uunn+1 − a </p>
      </sec>
      <sec id="sec-1-30">
        <title>Theorem 3. The order of the matrix group</title>
        <p>CGLb,k (2, Z p ) for D = k 2 + 4b  u2  Z p is
p2 −1.</p>
        <p>Proof.</p>
      </sec>
      <sec id="sec-1-31">
        <title>It is appropriate at this point to recall that</title>
        <p>  a 1   1 0 
CGLb,k (2, p ) =  t,sb, a,ba,+k kZ, sp ,t, s  0, .
t   ,</p>
        <p> 0 1  
 a (a + k ) − b  0 </p>
        <p>Values b and k are fixed for the group, then
t, a, s  Z p , t, s  0 are variable. Then, the
number of different values that matrices
 a 1 
t  </p>
        <p> b a + k  may take on is equal to the
number of different possible pairs t, a with
the given restraints. The value t may take on
p −1 different values from p (t  0) . Value a
is restricted by the condition a (a + k ) − b  0 .
For D = k 2 + 4b  u2  Z p , this equation does
not have integer roots concerning the variable
a , therefore, it can take on p different values
with Z p .</p>
      </sec>
      <sec id="sec-1-32">
        <title>The number of different values that matrices</title>
        <p> 1 0
s    may take on is equal to the number
 0 1 
p −1 of different possible values s  Z p , s  0 .</p>
      </sec>
      <sec id="sec-1-33">
        <title>Therefore, the order of the matrix group</title>
        <p>CGLb,k (2, Z p ) is ( p −1) p + p −1 = p2 −1.</p>
      </sec>
      <sec id="sec-1-34">
        <title>The theorem is proved. 293</title>
      </sec>
      <sec id="sec-1-35">
        <title>Thus, for</title>
        <p>D = k 2 + 4b  u2  Z p .</p>
        <p>CGLb,k (2, Z p ) is a multiplicative abelian group
of order p2 −1.</p>
        <p>
          Remark 1 [
          <xref ref-type="bibr" rid="ref17">39</xref>
          ]. For prime p  3 , the
number of nonzero values D  Z p : D = u2  Z p
and the number of D  Z p : D  u2  Z p values
coincide and are equal to
        </p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Conclusion</title>
      <p>p −1
2</p>
      <sec id="sec-2-1">
        <title>The paper defines six families of matrices from</title>
        <p>the general linear group GL (2, Z p ) with order</p>
      </sec>
      <sec id="sec-2-2">
        <title>2 over the prime field of integers modulo p</title>
        <p>with commutative multiplication operation.</p>
      </sec>
      <sec id="sec-2-3">
        <title>The set cardinality for the defined families has</title>
        <p>been determined.</p>
        <p>The research results indicate that the matrix
  a 1  
 t   , 
set   b a + k   supplemented by the
t, a,b, k  Z p ,t  0,
a (a + k ) − b  0 
matrix set s   1 0 </p>
        <p>, s  Z p , s  0 forms an
  0 1  
abelian group under multiplication. The order of
this group is p2 −1.</p>
      </sec>
      <sec id="sec-2-4">
        <title>Further studies of square matrix groups</title>
        <p>commutative under multiplication, may
involve the selection of matrix parameters, as
well as their application in cryptographic
transformation operations.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>5. Acknowledgments</title>
      <sec id="sec-3-1">
        <title>This research was funded by the Ministry of</title>
      </sec>
      <sec id="sec-3-2">
        <title>Education and Science of Ukraine under grant 0123U100270.</title>
        <p>[12] D. Moldovyan, Non-Commutative Finite Systems, Sensors 22(14) (2022). doi:
Groups as Primitive of Public-Key 10.3390/s22145391.</p>
        <p>Cryptoschemes, Quasigroups Relat. Syst. [24] J. Al-Azzeh, et al. Permutation-Based
18(2) (2010) 165–176. Frame Synchronization Method for Data
[13] A. Kuzmin, et al., Cryptographic Transmission Systems with Short
Algorithms on Groups and Algebras, J. Packets, Egyptian Inform. J. 23(3) (2022)
Math. Sci. 223(5) (2017) 629–641. doi: 529–545. doi: 10.1016/j.eij.2022.05.005.
10.1007/s10958-017-3371-y. [25] E. Faure, A. Shcherba, B. Stupka,
[14] N. Nguyen, et al., No-Key Protocol for Permutation-Based Frame
Deniable Encryption, Inf. Syst. Des. Intel. Synchronisation Method for Short
Appl. 672 (2018) 96–104. doi: Packet Communication Systems, 11th
10.1007/978-981-10-7512-4_10. IEEE Int. Conf. Intell. Data Acquisition
[15] D. Moldovyan, et al., Post-quantum Adv. Comput. Syst. Technol. Appl. (2021)
Commutative Encryption Algorithm, 1073–1077. doi: 10.1109/IDAACS53288.
Context-Aware Systems and 2021.9660996.</p>
        <p>Applications, and Nature of Computation [26] J. Al-Aazzeh, et al., Telecommunication
and Communication (2019) 205–214. Systems with Multiple Access Based on
doi: 10.1007/978-3-030-34365-1_16. Data Factorial Coding, Int. J. Commun.
[16] N. Moldovyan, A. Moldovyan, Antenna Propagation 10(2) (2020) 102–
V. Shcherbacov, Post-Quantum No-Key 113. doi: 10.15866/irecap.v10i2.17216.
Protocol, Buletinul Academiei de Stiinte [27] E. Faure, et al., Cryptographic Key
a Republicii Moldova, Matematica 85(3) Exchange Method for Data Factorial
(2017) 115–119. Coding, in: International Workshop on
[17] M. Hellman, S. Pohlig, Exponentiation Cyber Hygiene vol. 2654 (2020) 643–</p>
      </sec>
      <sec id="sec-3-3">
        <title>Cryptographic Apparatus and Method, 664.</title>
        <p>(1984). [28] E. Faure, et al., Concept for Using
[18] S. Kryvyi, Application of Commutative Permutation-Based Three-Pass
Rings with Unity for Construction of Cryptographic Protocol in Noisy
Symmetric Encryption System, Cybern Channels, Systems, Decision and Control
Syst. Anal. 58(3) (2022) 319–330. doi: in Energy V (2023) 99–113. doi:
10.1007/s10559-022-00464-z. 10.1007/978-3-031-35088-7_7.
[19] K. Dey, et al., A Post-Quantum [29] E. Faure, et al., A Method for Reliable
Signcryption Scheme Using Isogeny Permutation Transmission in
ShortBased Cryptography, J. Inf. Secur. Appl. Packet Communication Systems,
69 (2022). doi: 10.1016/j.jisa.2022.1032 Information Technology for Education,
80. Science, and Technics (2023) 177–195.
[20] Z. Sun, J. Huang, P. Wang, Efficient doi: 10.1007/978-3-031-35467-0_12.</p>
        <p>Multiparty Quantum Key Agreement [30] A. Shcherba, E. Faure, O. Lavdanska,
Protocol Based on Commutative Three-Pass Cryptographic Protocol
Encryption, Quantum Inf. Process 15(5) Based on Permutations, IEEE 2nd Int.
(2016) 2101–2111. doi: 10.1007/s11128- Conf. Adv. Trends Inf. Theory (2020)
016-1253-8. 281–284. doi: 10.1109/ATIT50783.
[21] R. Mohajer, Z. Eslami, Cryptanalysis of a 2020.9349343.</p>
        <p>Multiparty Quantum Key Agreement [31] H. Huang, C. Li, L. Deng, Public-Key
Protocol Based on Commutative Encryp- Cryptography Based on Tropical Circular
tion, Quantum Inf. Process 16(8) (2017). Matrices, Appl. Sci. 12(15) (2022). doi:
doi: 10.1007/s11128-017-1647-2. 10.3390/app12157401.
[22] S. Sihare, Dynamic Multi-Party Quantum [32] F. Dupont, A New Shamir’s Three Pass
Key Agreement Protocol Based on Random Matrix Ciphering Mechanism, J.
Commutative Encryption, Int. J. Theor. Comput. Virology Hacking Techniques,
Physics 61(9) (2022). doi: (2023) 1–12. doi:
10.1007/s11416-02310.1007/s10773-022-05203-w. 00467-0.
[23] E. Faure, et al., Permutation-Based Block [33] T. Springer, Linear Algebraic Groups,
Code for Short Packet Communication Modern Birkhäuser Classic, 2nd ed.,</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <article-title>CSIKE-ENC Combined Encryption Scheme with Optimized Degrees of Isogeny Distribution</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>36</fpage>
          -
          <lpage>45</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Modeling</surname>
            <given-names>CSIKE</given-names>
          </string-name>
          <article-title>Algorithm on Non-Cyclic Edwards Curves</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3288</volume>
          (
          <year>2022</year>
          )
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <article-title>Implementation of the CSIDH Algorithm Model on Supersingular Twisted and Quadratic Edwards Curves</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3187</volume>
          , no.
          <issue>1</issue>
          (
          <year>2022</year>
          )
          <fpage>302</fpage>
          -
          <lpage>309</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <article-title>Implementation of the CSIDH Algorithm Model on Supersingular Twisted and Quadratic Edwards Curves</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3187</volume>
          , no.
          <issue>1</issue>
          (
          <year>2022</year>
          )
          <fpage>302</fpage>
          -
          <lpage>309</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <source>Computing of Odd Degree Isogenies on Supersingular Twisted Edwards Curves, in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>W.</given-names>
            <surname>Diffie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hellman</surname>
          </string-name>
          , New Directions in Cryptography,
          <source>IEEE Transactions on Information Theory</source>
          <volume>22</volume>
          (
          <issue>6</issue>
          ) (
          <year>1976</year>
          )
          <fpage>644</fpage>
          -
          <lpage>654</lpage>
          . doi:
          <volume>10</volume>
          .1109/TIT.
          <year>1976</year>
          .
          <volume>1055638</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>R.</given-names>
            <surname>Rivest</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shamir</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Adleman</surname>
          </string-name>
          ,
          <article-title>A Method for Obtaining Digital Signatures</article-title>
          and
          <string-name>
            <surname>Public-Key</surname>
            <given-names>Cryptosystems</given-names>
          </string-name>
          ,
          <source>Communications of the ACM</source>
          <volume>21</volume>
          (
          <issue>2</issue>
          ) (
          <year>1978</year>
          )
          <fpage>120</fpage>
          -
          <lpage>126</lpage>
          . doi:
          <volume>10</volume>
          .1145/359340. 359342.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A.</given-names>
            <surname>Shamir</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Rivest</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Adleman</surname>
          </string-name>
          , Mental Poker,
          <source>The Mathematical Gardner</source>
          (
          <year>1981</year>
          )
          <fpage>37</fpage>
          -
          <lpage>43</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-1-
          <fpage>4684</fpage>
          -6686-
          <issue>7</issue>
          _
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J.</given-names>
            <surname>Massey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Omura</surname>
          </string-name>
          ,
          <article-title>Method and Apparatus for Maintaining the Privacy of Digital Messages Conveyed by Public Transmission (</article-title>
          <year>1986</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>P.</given-names>
            <surname>Shor</surname>
          </string-name>
          ,
          <article-title>Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer</article-title>
          ,
          <string-name>
            <given-names>SIAM J.</given-names>
            <surname>Comput</surname>
          </string-name>
          .
          <volume>26</volume>
          (
          <issue>5</issue>
          ) (
          <year>1997</year>
          )
          <fpage>1484</fpage>
          -
          <lpage>1509</lpage>
          . doi:
          <volume>10</volume>
          .1137/S00975397952931 72.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Moldovyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Moldovyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Moldovyan</surname>
          </string-name>
          ,
          <string-name>
            <surname>Post-Quantum Commutative Encryption Algorithm</surname>
          </string-name>
          ,
          <source>Comput. Sci. J. Moldova</source>
          <volume>81</volume>
          (
          <issue>3</issue>
          ) (
          <year>2019</year>
          )
          <fpage>299</fpage>
          -
          <lpage>317</lpage>
          . Berlin (
          <year>1998</year>
          ). doi:
          <volume>10</volume>
          .1007/978-0-
          <fpage>8176</fpage>
          -4840-4.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>A.</given-names>
            <surname>Baker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Matrix</given-names>
            <surname>Groups</surname>
          </string-name>
          . An Introduction to Lie Group Theory, Springer (
          <year>2002</year>
          ). doi:
          <volume>10</volume>
          .1007/978-1-
          <fpage>4471</fpage>
          -0183-3.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lipschutz</surname>
          </string-name>
          ,
          <article-title>Schaum's Outline of Theory and Problems of Linear Algebra</article-title>
          , 2nd ed.,
          <string-name>
            <surname>McGraw-Hill</surname>
            ,
            <given-names>NY</given-names>
          </string-name>
          (
          <year>1991</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>F.</given-names>
            <surname>Gantmacher</surname>
          </string-name>
          ,
          <source>The Theory of Matrices</source>
          , Reprinted,
          <source>American Mathematical Society</source>
          , Providence, RI (
          <year>1959</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>J.</given-names>
            <surname>Laughlin</surname>
          </string-name>
          ,
          <article-title>Combinatorial Identities Deriving from the n-th Power of a 2x2 Matrix, Integers 4 (</article-title>
          <year>2004</year>
          )
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          . doi:
          <volume>10</volume>
          .48550/ARXIV.
          <year>1812</year>
          .
          <volume>11168</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>V.</given-names>
            <surname>Arnold</surname>
          </string-name>
          , Fermat Dynamics, Matrix Arithmetics, Finite Circles, and Finite Lobachevsky Planes,
          <source>Functional Analysis Its Appl</source>
          .
          <volume>38</volume>
          (
          <issue>1</issue>
          ) (
          <year>2004</year>
          )
          <fpage>1</fpage>
          -
          <lpage>13</lpage>
          . doi:
          <volume>10</volume>
          .1023/B:FAIA.
          <volume>0000024863</volume>
          .06462.68.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>S.</given-names>
            <surname>Wright</surname>
          </string-name>
          ,
          <source>Quadratic Residues and NonResidues, Lecture Notes in Mathematics 2171</source>
          (
          <year>2016</year>
          ). doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          - 45955-4.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>