<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Tech.</journal-title>
      </journal-title-group>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.28925/2663</article-id>
      <title-group>
        <article-title>of the graphic model of the points of the elliptic curve in the Edward form</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Serhii Abramov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Sokolov</string-name>
          <email>v.sokolov@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vadym Abramov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudryavska str., 04053 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>and Telecommunication Systems II</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2022</year>
      </pub-date>
      <volume>3</volume>
      <issue>15</issue>
      <fpage>148</fpage>
      <lpage>163</lpage>
      <abstract>
        <p>Elliptic curves in Edwards form, known for their speed and efficiency, are highly promising for asymmetric cryptosystems. The CSIDH protocol is particularly notable for post-quantum cryptography. Recent studies classify these curves and demonstrate CSIDH's implementation on quadratic and twisted Edwards curves, highlighting their unique properties through graphical models like the wheel representation of point exponentiation. The model in the form of a graph of points of an elliptic curve in the form of Edwards was studied. The algorithm for the reconstruction of the series of points kP of all groups of points of the Edwards curve without the use of a group operation for 1/8 of the known points has been refined. The possibility of reconstructing the order of these points is also shown. post-quantum cryptography, elliptic curve, point exponentiation, exponentiation graph, point reconstruction, reconstruction pattern 1 † These authors contributed equally.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Elliptic curves in Edwards’s form [1], which have been
studied and modernized by the authors of the work [2],
today are the fastest and most promising in asymmetric
cryptosystems. One of the promising protocols for
postquantum cryptography is CSIDH [3]. In work [4] a new
classification of these curves is proposed, and in works [5,
6] the implementation of the CSIDH algorithm on quadratic
and twisted</p>
      <sec id="sec-1-1">
        <title>Edwards’s curves is substantiated</title>
        <p>and
illustrated with examples. In works [7, 8] an analysis of the
special properties of quadratic and twisted
Edwards
supersingular curves is carried out and a graphic model of
the process of exponentiation of curve points in the form of
a wheel is used. In [8], a method for finding all points of the
scalar product kP of a point  is proposed if a segment of
1/8 of all points is known. Additional studies of the method
of reconstruction of the points of these curves make it
possible to further simplify and speed up the finding of
these points and their orders.</p>
        <p>An elliptic curve in the generalized Edwards form is
defined by the equation [4]
 , : 
+</p>
        <p>= 1 +    ,
{ ,  } ∈  ∗,  ≠  ,  ≠ 1.</p>
        <p>In case  ( ) = 1,  ( ) =  ( ) = 1 there is an
isomorphism of the curve (1) with the quadratic Edwards
curve [4]. The curve has a parameter  , which is defined as
a quadratic excess, in addition, and for these curves, it is
usually accepted  = 1 . According to the classification [4],
the quadratic curve is described by the equation:
 : 
+ 
= 1 +    ,  ( ) = 1,  ≠ 1.
(1)
(2)
CPITS-II 2024: Workshop on Cybersecurity Providing in Information
1 −</p>
        <p>+ 
1 +     
2( ,  ) =</p>
        <p>−  
1 −</p>
        <p>2 
1 +</p>
        <p>The law of doubling the point ( ,  ), accordingly, has
the form
(3)
(4)


1
√</p>
        <p>Quadratic Edwards’s curves (2) have a noncyclic
subgroup of the 4th order, which includes three points of the
2nd order and a neutral element of the group of points О.
Two of these points are special and have an infinite second
coordinate. Curves (2) also have two singular points of the</p>
      </sec>
      <sec id="sec-1-2">
        <title>4th order.</title>
      </sec>
      <sec id="sec-1-3">
        <title>Special points of the second order</title>
        <p>, =
±
, ∞
at
= 1.</p>
      </sec>
      <sec id="sec-1-4">
        <title>Special points of the 4th order</title>
        <p>±
=
∞, ±
at
= 1.</p>
        <p>When implementing crypto algorithms, it is necessary
to know the order of the used points of the curve. The order
of the point P is determined in the process of exponentiation
of the point by multiplication by a scalar number  ( =
1 … )</p>
        <p>and construction of the exponentiation group
() = {, 2, 3, … , , … , }
the point if  = О(1,0)
, where the K-order of
, and numbers , 2, … , 
form a
group of curve points  = {| = 1 … }
[4].</p>
        <p>Curve (2) with a minimum cofactor of 8 has an order 
=
8 ( is odd), while the maximum order of the point is equal
0000-0002-5145-2782 (S. Abramov);
0000-0002-9349-7946 (V. Sokolov);
0000-0002-8026-1475 (V. Abramov)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
        <p>CEUR</p>
        <p>ceur-ws.org
to 4 . Let  = ( ,  ), Ord  = 4 . Then, for example, a
subgroup 〈 〉 = {| = 1 … 4 } is cyclic and runs through
all points kP where  = 1 … 4 . At the same time, there are
4 basis points  =  , 2 =  , 3 = − , 4 =  =
(1,0). It is convenient to represent the cyclic subgroup of
the curve (2) in the form of a wheel of exponentiation points
(Bessalov’s wheel) [4].</p>
        <p>The exponentiation of curve points is carried out using
expressions (3,4), which are quite complex, and therefore
the creation of methods for simplifying and accelerating
exponentiation is relevant for research [9–13]. In work [8],
based on the interconnection of families of high-order
points, the kP points of the Edwards curve are reconstructed
without the use of group operations, reducing the number
of point calculations to 1/8 of the order of the group.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Method description</title>
      <p>This paper considers some features of the exponentiation
process that can further simplify calculations.</p>
      <p>Consider an example from work [14], which uses the
Edwards quadratic curve (2) with parameters  = 1,  =
5 mod 23 = 2. At р = 23, it is supersingular and has an
order  = 24,  = 3 . The curve has base points ± =
(0, +1),  = (−1,0),  = (1,0), special points
(9, ∞), (−9, ∞), (∞, 9), (∞, −9) and two families of 8
nonbasic points of high order in each
(±5, ±10), (±10, ±5), (±6, ±11), (±11, ±6). Table 1
shows the coordinates of the points of all its subgroups of
orders 4 = 12 and 2 = 6 .</p>
      <p>A family of points of high order is eight points of a curve
(±, +) , (±, ±) which lie on a plane х—у on one circle
with a radius not equal to one (wheel of points). Fig. 1 shows
an example of placing a family of points of high order in
affine coordinates ,  . The family includes four points
(±, ±) and four points where x and y coordinates are
interchanged (±, ±) . For convenience, the first 4 points
can be called the initial subfamily, and the last four points
can be called swap points (swap subfamily). Each family is
located symmetrically for both the  -axis and the y-axis. We
will call each family modulo the coordinates of the first
point, which we will call the initial point.</p>
      <p>
        Curve (2) of order  = 24 at  = 23 has four families
of non-basis points of order 3, 6, and 12. These points are
generators of cyclic exponentiation subgroups (rows). Table 1
shows these points and subgroups of their exponentiation.
The curve under consideration has the following families:
(
        <xref ref-type="bibr" rid="ref4">5,10</xref>
        ) it includes starting points (
        <xref ref-type="bibr" rid="ref4">5,10</xref>
        ) and swap points
(
        <xref ref-type="bibr" rid="ref4">10,5</xref>
        ) (where the coordinates x, y have changed places),
return points (5, −10) and (
        <xref ref-type="bibr" rid="ref4">10, −5</xref>
        ), as well as a mirror
(
        <xref ref-type="bibr" rid="ref4">−5,10</xref>
        ) and (−10, 5). Similarly, the family (
        <xref ref-type="bibr" rid="ref5">6,11</xref>
        ) =
(
        <xref ref-type="bibr" rid="ref5">6,11</xref>
        ) + (
        <xref ref-type="bibr" rid="ref5">11,6</xref>
        ).
      </p>
      <p>
        In Table 2, we can observe interesting features, for
example, all doubling points of all groups (column 2P) are
exclusively points of the family (
        <xref ref-type="bibr" rid="ref4">5, 10</xref>
        ) and then the points
of this family also completely occupy columns 4Р, 8Р, and
10Р.
3. Wheel of exponentiation
For clarity and convenience of working with cyclic groups,
all their points are offered 1, 2, … ,  arranged in a
circle—Bessalov’s exponentiation wheel [4] (Fig. 2).
      </p>
      <p>The points of the wheel show the scalar coefficients
multiplied by the point  is the generator of the group &lt;
 &gt; . The coordinates of the points of the group are located
on the outside of the wheel, and the order of the
corresponding points is on the inside. The difference from
Fig. 1 is that the points of the curve in Bessalov’s wheel are
in the order of their location in the exponentiation group
and their number is equal to the order of the corresponding
group. At the same time, the properties related to symmetry
are similar. To construct each group of order K, it is
necessary to carry out  operations of multiplication by a
scalar coefficient  = 1 …  [4].
has diametrical points  and  ∗ located at the ends of the
wheel diameter:
 +</p>
      <p>= ( ,  ) + (−1,0) = (− , − ) =  ∗.</p>
      <p>Vertical (mirror) symmetry is formed
by
points
symmetrical about the vertical axis. These points are from
the same family with the same y coordinate, and the x
coordinate changes sign: these are points ( ,  ) and (− ,  ).
similarly using the reverse (inverse) point at which the sign
of the coordinate changes  : − = ( , − ).</p>
      <p>
        In Table 2, point families (
        <xref ref-type="bibr" rid="ref4">10, 5</xref>
        ) and (
        <xref ref-type="bibr" rid="ref5">6, 11</xref>
        ) generate
subgroups of maximum order 12 and 3 = 
= (∞, 9) a
singular point of the 4th order. Point  = (9, ∞) is a singular
point of the 2nd order. Consider the family (
        <xref ref-type="bibr" rid="ref4">10, 5</xref>
        ) without
singular points, its points are of order 12, and the wheel of
points is presented in Fig. 2.
Inverse points with different signs of the y coordinate are
located symmetrically on the horizontal axis, and points
from the same family but different groups are located
symmetrically on the vertical axis, i.e., they have the same
y coordinate and the x coordinate has a different sign.
Opposite points are located at the ends of the diagonal,
where all coordinates have different signs.
      </p>
      <p>
        Other groups of this family can be presented in the form
of a transformed first wheel. The transformation consists of
the fact that at odd points (1 , 3 , … ) we invert the sign of
the  coordinate, and at even points (2 , 4 , … ) is the 
coordinate (Figs. 2b, 3b).
4. Wheel template of a cyclic group
The wheel in Fig. 2 shows the exponentiation of the points
(
        <xref ref-type="bibr" rid="ref4">10,5</xref>
        ) and (
        <xref ref-type="bibr" rid="ref4">10, −5</xref>
        ), the other two groups (Fig. 2b) of this
family, formed by the points (−10,5) and (−10, −5), can
be presented in the form of a wheel that can be built by
transforming the first wheel. The family at each point
remains the same as in the previous wheel. It is possible to
create (reconstruct) the wheel of other groups of this family
based on the first group of the family without a table and
complex calculations. Each of the 4 points of any subfamily
(initial or swap) is located in different sectors. In each sector,
there are points from different subfamilies, one from each,
and the subfamilies themselves are not repeated. The wheel
of all cyclic groups of the same order has the same
arrangement of points. (Figs. 2, 3). This is convenient to use
to create a wheel template of a given order. At the same
time, you need to know the order of the exponentiation
group. Fig. 4 shows a 12-order wheel template. Inside the
wheel, the order of points is shown, valid for any group of
this order. A more convenient view of the wheel of a large
order is presented in the form of Fig. 5.
      </p>
      <p>
        As with the wheel, Fig. 5 presents the points of the
curve, the exponentiation factor k, and the order of the
points r. To construct the entire group, as it was said in [4],
it is enough to find the points of the first half-sector (1/8
part of all points of the wheel). Next, you should fill out the
template according to certain rules.
5. Example of constructing the
wheels of all cyclic groups of the
Edwards curve
Consider an example from work [7], this is an Edwards
curve of order 
From the solution of the equation, we get a complete set of
curve points. In Table 3, the points are arranged in
ascending
order of the 
coordinate. For ease of
consideration, we write the  &gt; 9 coordinate as  =  −
28 points in total, curve order 28. It is convenient to use
of order 4, it becomes clear that there is also point 2 of order
cyclic subgroups to find the order of points. Consider the
cyclic subgroup formed by the point (
        <xref ref-type="bibr" rid="ref3">2,9</xref>
        ), which is shown
14 (−1,0), point 4 of order 21 (0, −1), and point  (1,0).
Total 7 × 4 = 28 points.
in Table 4 (
26
8
4
7
–8
–4
14
13
27
–2
9
28
2
–9
28
14
      </p>
      <p>
        –1
28
0
2
1
0
1
The subgroup has order 28 and includes all points of the
curve. The table has base points with a known order: points
7 and 21 order 4, 14 order 2, and neutral point (1,0).
Non-base points can have an order of 28, 14, and 7, you can
find their orders using a minimum number of calculations.
There are 28 points in the table and it ends with the point
(1, 0), so the order of the generator point (
        <xref ref-type="bibr" rid="ref3">2,9</xref>
        ) will be 28.
The doubled point 2 has order 14, i.e., the point 2 must
be multiplied by 14 to get the point О(1, 0) = 28 because
2 is a divisor 28, а  = 28/ = 14. Point 4 is transformed
into point 28P by multiplying by 7 (7 steps), i.e., regardless
of the order of point  , point 4 has order 7, since 28 =
4 × 7. From the points where k is a divisor of 28, you can
reach zero in s steps by going through  cycles subgroups
28 =  , that is, when the integer  = 28 / . Here  is
the divisor of 28 . In this equation, for a given and minimal
r, we have an integer  .
      </p>
      <p>For example, for the third point 3 we have to 3 then
 =  ×  / = 28 ×  /3 = 2 × 2 × 7 ×  /3. There are no
common factors and the integer s can be at  =  = 3, then
the order of this point is  = 28. For point 6 we have  =
6 = 2 × 3 then  = 2 × 2 × 7 ×  /2 × 3, we reduce by a
common factor of 2 and get  = 14.</p>
      <p>Applying this rule further, we will get a suitable
template for each order of the group, for example, the
following template for the point of order 28. Here the wheel
is shown in the form of a table, the cells of the table are more
convenient for filling with data (Fig. 6).
6. Rules for reconstruction of points
Now in this template, you need to place the points that
depend on the first point of 1 . Rules and formulas to
simplify this process are developed in [4]:</p>
      <p>For a curve of order  , there can be subgroups of order
 |  , and the first point 4 of the order  , if any, will
appear on the step ( /4) × Р.</p>
      <p>Algorithm for constructing the wheel of the cyclic
subgroup of the point P of the Nth order curve.</p>
      <p>1.
2.</p>
      <sec id="sec-2-1">
        <title>The point P of the curve is the input.</title>
        <p>Using the expressions (3,4), we find the points
2 , 4 , 8 , … , 2 , etc.</p>
        <p>If the last dot appeared from a family that was already
significant, we moved to the second sector of the
wheel. And point  is between the last k and
penultimate ( − 1) points  &lt; ( | ) &lt;  − 1.
Hence, the order  of the point  is determined.
Choose the appropriate wheel template and fill it
with points accordingly [4].</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>7. Reconstruction of points of all curve groups</title>
      <p>Let’s consider some properties of the wheel.</p>
      <p>Examining the points of various curves, it is possible to
identify some regularities. Yes, points from the same family
are not repeated in each sector.</p>
      <p>
        If the group has points of orders 2 and 4, then the order
of this group is a maximum of 4 . Then, on the border of
the half-sector, we get points from swap families. For
example, in groups (3,5) (Table 5), the boundary of the
semi-sector passes between points 3 and 4, and these points
of families (
        <xref ref-type="bibr" rid="ref2">4,8</xref>
        ) and (
        <xref ref-type="bibr" rid="ref2">8,4</xref>
        ), respectively. When the
calculation reaches point 4 , we can find the remainder [4]
without calculation, and determine the order of the group
and all points.
      </p>
      <p>
        If the group does not have a point of order 4, then the
order of this group is 2 . For example, in groups (5,3), the
border of sectors 1 and 2 passes between points 3 and 4
(Table 6), where the first mirror point from the families
appears (
        <xref ref-type="bibr" rid="ref2">8,4</xref>
        ).
      </p>
      <p>
        If there are no points of order 2 and 4, then the order of
this group is  . For example, in groups (
        <xref ref-type="bibr" rid="ref3">9,2</xref>
        ), the boundary
between the upper and lower semicircle passes between
points 3 and 4 (Table 7). These are also mirror points of the
family (5,3).
      </p>
      <p>Points of the same family are not repeated within the
sector.
8
coordinates of the points are shown on the green background,
the scalar exponentiation factor is on the yellow, and the
orders of the points are on the gray Рk. All the properties
described above are present. There is a neutral point  (1,0),
two special points of the 4th order (∞, ±35), and point 2 of
the order. There is an opportunity for 1/8 of all points to
reconstruct other points. Based on the obtained data, it is
possible to reconstruct the rest of all groups of this family
without even knowing 1/8 of its points.</p>
      <p>For any group  ×</p>
      <p>of order # ( ,  ) regardless of the
coordinates of the points, the orders are arranged in the same
way. Of the order factors of the group # ( ,  ) =

× 
× … ×</p>
      <p>remove the elements that coincide with
the multipliers of the scalar 
= 
× 
× …, and the
remaining factors give the value of the order of the points. For
example, in our example with # ( ,  ) = 40 = 2 × 2 × 2 ×</p>
      <sec id="sec-3-1">
        <title>5 for a point 8</title>
        <p>= 2 × 2 × 2 have  (8 ) = 2 × 2 × 2 ×
5 = 5. And for a symmetrical point 12 = 2 × 2 × 3 have
2 × 2 × 2 × 5 = 10. The orders of the remaining symmetric
points coincide.</p>
        <p>Consider one of the groups of maximal order, let its
reconstruct the exponentiation points and their orders, for</p>
        <p>Even points are taken from the initial families and
odd ones from the swap families.</p>
        <p>Coordinate signs are arranged as follows: at the
second point, the sign of the x coordinate is
inverted, at the 3rd point, both coordinates are
inverted, at the 4th point, the coordinate is inverted,
at the 5th point, the signs do not change, so the
process is repeated until the sector is filled [15].</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>8. Conclusions</title>
      <p>The considered properties make it possible to find all kP
points of all groups of the curve by the value of 1/8 of the
points of only one group (wheel). With the known order of
the group, each exponentiation coefficient k corresponds to
its order of the point, which does not depend on the
coordinates of the point, but only on the order of the group
and  . This can be used to create a template from which to
example, when modeling algorithms.
properties of Edwards curves.</p>
      <p>In the future, we plan to continue to explore the</p>
      <sec id="sec-4-1">
        <title>Amer.</title>
      </sec>
      <sec id="sec-4-2">
        <title>Math. Soc. 44(3) (2007) 393–422. doi:</title>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>W.</given-names>
            <surname>Castryck</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>CSIDH:</surname>
          </string-name>
          <article-title>An efficient post-quantum H. Edwards, A Normal Form for Elliptic Curves</article-title>
          , Bull. prime field,
          <source>Probl. Inf. Transm</source>
          .
          <volume>4</volume>
          (
          <issue>51</issue>
          ) (
          <year>2015</year>
          )
          <fpage>391</fpage>
          -
          <lpage>397</lpage>
          . doi:
          <volume>10</volume>
          .1134/S0032946015040080.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Cigankova</surname>
          </string-name>
          ,
          <article-title>Correlation of Big Order Points Sets of the Edwards Curves Over Prime Field, Ukrainian Inf</article-title>
          .
          <source>Secur. Res. J</source>
          .
          <volume>17</volume>
          (
          <issue>1</issue>
          ) (
          <year>2015</year>
          )
          <fpage>73</fpage>
          -
          <lpage>80</lpage>
          . doi:
          <volume>10</volume>
          .18372/
          <fpage>2410</fpage>
          -
          <lpage>7840</lpage>
          .
          <fpage>17</fpage>
          .8327.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>V.</given-names>
            <surname>Dolhov</surname>
          </string-name>
          , А. Nelasaia,
          <article-title>Methods for Increasing the Speed of Cryptographic Transformations on Elliptic Curves, Radioelectron</article-title>
          . Inform. Manag.
          <volume>2</volume>
          (
          <year>2004</year>
          )
          <fpage>72</fpage>
          -
          <lpage>78</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>I.</given-names>
            <surname>Dychka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Onai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Drozda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Modified</given-names>
            <surname>Windowed</surname>
          </string-name>
          <article-title>Method for Multiplying a Point of an Elliptic Curve by a Scalar in a Field GF(p), Radioelectron</article-title>
          . Inform. Manag.
          <volume>2</volume>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          ,
          <article-title>A Method for Finding the Order of the Point of a Twisted Edwards Curve</article-title>
          ,
          <source>Radioengineering</source>
          <volume>186</volume>
          (
          <year>2016</year>
          )
          <fpage>110</fpage>
          -
          <lpage>118</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [12]
          <string-name>
            <surname>О. Tsygankova</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Tsygankov</surname>
          </string-name>
          ,
          <article-title>Animation of Exponentiation Points of Edwards Curve, in: XV AllUkrainian Scientific</article-title>
          and Practical Conference of Students, Aspirants and Young Scientists “Theoretical and Applied Problems of Physics, Mathematics and Informatics,” VPI VPK “Politechnika” (
          <year>2017</year>
          )
          <fpage>114</fpage>
          -
          <lpage>116</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Е. Kachko</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Svinarev</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Golovashich</surname>
          </string-name>
          ,
          <article-title>Methods and Algorithms for Accelerating Computations in Asymmetric Transformations on Elliptic Curves</article-title>
          , Radiotekhnika,
          <volume>114</volume>
          (
          <year>2000</year>
          )
          <fpage>69</fpage>
          -
          <lpage>74</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , S. Abramov,
          <article-title>Special Properties of the Law of Addition of Points of Non-Cyclic Edwards Curves, Cybern</article-title>
          .
          <source>Syst. Anal</source>
          .
          <volume>58</volume>
          (
          <issue>6</issue>
          ) (
          <year>2022</year>
          )
          <fpage>3</fpage>
          -
          <lpage>14</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Modeling</surname>
            <given-names>CSIKE</given-names>
          </string-name>
          <article-title>Algorithm on Non-Cyclic Edwards Curves</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3288</volume>
          (
          <year>2022</year>
          )
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>