<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Classical and post-quantum encryption for GDPR⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Maksim Iavich</string-name>
          <email>miavich@cu.edu.ge</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oksana Kovalchuk</string-name>
          <email>oksana.kovalchuk@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergiy Gnatyuk</string-name>
          <email>s.gnatyuk@nau.edu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yuliia Khavikova</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff5">5</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Sokolov</string-name>
          <email>v.sokolov@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2, Bulvarno-Kudriavska str., 04053 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>CQPC-2024: Classic</institution>
          ,
          <addr-line>Quantum, and Post-Quantum Cryptography</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Caucasus University</institution>
          ,
          <addr-line>1 Paata Saakadze str., 0102 Tbilisi</addr-line>
          ,
          <country country="GE">Georgia</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>1 Liubomyra Huzara ave., 03058 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>Sokhumi State University</institution>
          ,
          <addr-line>61 Politkovskaya str., 0186 Tbilisi</addr-line>
          ,
          <country country="GE">Georgia</country>
        </aff>
        <aff id="aff5">
          <label>5</label>
          <institution>State University of Trade and Economics</institution>
          ,
          <addr-line>19 Kyoto str., 02156 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>70</fpage>
      <lpage>78</lpage>
      <abstract>
        <p>In the dynamic digital landscape, the General Data Protection Regulation (GDPR) stands as a transformative force, which aims to secure individual privacy and redefine organizational practices in personal data handling. This paper analyzes the multifaceted layers of GDPR in detail, it elucidates its principles, rights for data subjects, and obligations for data controllers and processors. The main attention is paid to encryption standards, with specific recommendations for data protection in both classical and postquantum epochs. In the classical setting, the paper aims to employ AES-128 in data storage, striking a balance between security and performance. For communication, the SSL protocol is used, with a caveat to transition to TLS for contemporary applications. In the post-quantum epoch, where there will be fullyfledged quantum computers, the paper proposes a shift to AES-256 for data storage and introduces CRYSTALS-Kyber, an asymmetric cryptography algorithm secure against quantum attacks, for secure communication. The recommendations emphasize the need for creating precise cryptographical recommendations, particularly in the face of evolving threats. Compliance with GDPR and other data protection regulations remains very important, ensuring the security and integrity of data in the 21st century.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;GDPR</kwd>
        <kwd>AES-256</kwd>
        <kwd>encryption</kwd>
        <kwd>post-quantum cryptography</kwd>
        <kwd>cryptographical application1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Because of the rapid evolution of digital technologies,
the security of data has become very important [1, 2]. As
people have to share their personal information online,
concerns about data privacy and security have become
impor-tant. In response to these concerns, the Euro-pean
Union (EU) has elaborated the General Data Protection
Regulation (GDPR), a land-mark legislation designed to
secure the rights and privacy of individuals in the digital
realm.</p>
      <p>
        The GDPR, which came into effect on May 25, 2018,
represents a paradigm shift in data protection,
emphasizing transparency, accountability, and
individual empowerment. Its main goal is to provide
individuals with greater control over their data while
imposing strict rules on organizations that process such
information. Because of the importance of GDPR, this
paper aims to analyze the regulatory framework,
exploring its fundamental principles, the rights it affords
to data subjects and the obligations it places upon data
controllers and processors [3–5].
As we study GDPR, it becomes evident that this
regulation is not a legal framework but a catalyst for an
important organizational shift towards a more
privacyoriented approach. By understanding the nuances and
implications of the GDPR, businesses, policymakers, and
individuals can actively contribute to the responsible
and ethical use of personal data in the digital era [
        <xref ref-type="bibr" rid="ref7 ref8 ref9">6–8</xref>
        ].
      </p>
      <p>This paper studies the multifaceted layers of the
GDPR, providing a comprehensive of these layers.
Through this exploration, we aim to foster a deeper
understanding of the GDPR’s significance, its impact on
various stakeholders, and the evolving landscape of data
protection in the 21st century. The main aim of the paper
is to analyze the encryption standards for data
protection. Based on the analysis the goal of the paper is
to offer a detailed recommendation for data encryption
in ongoing and post-quantum epochs.</p>
    </sec>
    <sec id="sec-2">
      <title>2. GDPR layers</title>
      <p>Let’s mention analyze the various layers of the GDPR
and their implications:</p>
      <p>0000-0002-3109-7971 (M. Iavich); 0000-0002-2354-6545
(O. Kovalchuk); 0000-0003-4992-0564 (S. Gnatyuk); 0000-0003-1017-3602
(Y. Khavikova); 0000-0002-9349-7946 (V. Sokolov)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
      <sec id="sec-2-1">
        <title>2.1. Principles</title>
        <p>Lawfulness, Fairness, and Transparency: This principle
ensures that organizations process personal data legally
and transparently. It emphasizes the importance of
informing individuals about the processing activities
and the reasons behind them, fostering trust and
accountability.</p>
        <p>Purpose Limitation and Data Minimization: These
principles emphasize the need for organizations to clearly
define the purposes for which they collect data and to
collect only the minimum necessary data for those
purposes. This helps prevent the indiscriminate collection
and processing of personal information.</p>
        <p>Accuracy and Storage Limitation: These principles
highlight the importance of maintaining accurate and
up-to-date data and ensuring that personal data is not
stored longer than necessary. This promotes data quality
and relevance.</p>
        <p>Integrity and Confidentiality: Organizations must
implement security measures to protect personal data
from unauthorized access, disclosure, alteration, and
destruction, ensuring the integrity and confidentiality of
the data.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Data subject rights</title>
        <p>The recognition of robust data subject rights empowers
individuals to have control over their data. This includes
the right to access their information, rectify inaccuracies,
and even request the deletion of their data under certain
circumstances. These rights enhance individual
autonomy and privacy.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3. 3. Lawful basis for processing</title>
        <p>Requiring a lawful basis for processing ensures that
organizations have a legitimate reason for collecting and
processing personal data. This prevents arbitrary or
unjustified processing and encourages responsible data
management.</p>
      </sec>
      <sec id="sec-2-4">
        <title>2.4. Consent</title>
        <p>The GDPR introduces a higher standard for obtaining
and managing consent. It ensures that individuals are
fully informed and have given clear affirmative action,
fostering a more transparent and ethically grounded
approach to data processing.</p>
      </sec>
      <sec id="sec-2-5">
        <title>2.5. Data protection officer</title>
        <p>The appointment of a Data Protection Officer (DPO) is a
proactive step toward ensuring that organizations have
a designated person responsible for overseeing data
protection compliance. This demonstrates a
commitment to accountability and effective governance.</p>
      </sec>
      <sec id="sec-2-6">
        <title>2.6. Data processing records</title>
        <p>Maintaining records of data processing activities
promotes transparency and accountability. It helps
organizations keep track of their data processing
practices and facilitates cooperation with data
protection authorities during audits.</p>
      </sec>
      <sec id="sec-2-7">
        <title>2.7. Data protection impact assessments</title>
        <p>Data Protection Impact Assessments (DPIAs) are a
proactive tool for identifying and mitigating potential
risks associated with data processing activities. This
encourages organizations to assess and address privacy
risks before initiating certain processing operations,
aligning with a risk-based approach to data protection.</p>
      </sec>
      <sec id="sec-2-8">
        <title>2.8. Cross-border data transfers</title>
        <p>The restrictions on cross-border data transfers ensure
that personal data leaving the EU enjoys an adequate
level of protection. This protects the privacy rights of
individuals, even when their data is transferred
internationally.</p>
      </sec>
      <sec id="sec-2-9">
        <title>2.9. Data breach notification</title>
        <p>The mandatory reporting of data breaches within 72
hours enhances transparency and enables swift action to
mitigate potential harm. This requirement emphasizes
the importance of timely and effective responses to
security incidents.</p>
      </sec>
      <sec id="sec-2-10">
        <title>2.10. Accountability and governance</title>
        <p>The principles of accountability and governance require
organizations to take responsibility for their data
processing activities. This involves adopting internal
policies, conducting training, and maintaining
documentation, fostering a culture of compliance and
transparency.</p>
        <p>As we can see, the layers of GDPR collectively create
an interesting and important framework that prioritizes
the rights and privacy of individuals, fosters
transparency, and promotes responsible data
governance across organizations. Compliance with
these layers not only ensures legal adherence but also
contributes to a more ethical and trustworthy data
ecosystem.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Encryption in GDPR</title>
      <p>The GDPR does not explicitly mandate the use of
specific security technologies like data encryption.
However, GDPR does require organizations to
implement appropriate technical and organizational
measures to ensure a level of security appropriate to the
risk. Encryption is recognized as one of the security
measures that can help protect personal data, and it is
explicitly mentioned in several articles of the regulation.
Here are the four most relevant aspects of GDPR related
to data encryption:
1. Security of Processing (Article 32):</p>
      <p>Article 32 of the GDPR outlines the security of
processing requirements. It states that controllers and
processors must implement appropriate technical and
organizational measures to ensure a level of security
appropriate to the risk. This includes the
pseudonymization and encryption of personal data.
2. Pseudonymization (Recital 78):</p>
      <p>Recital 78 of the GDPR specifically mentions
pseudonymization as a security measure.
Pseudonymization is a process that involves replacing or
encrypting personal data in a way that prevents
attributing it to a specific data subject without additional
information.</p>
      <p>3. Notification of a Personal Data Breach to the
Supervisory Authority (Article 33):</p>
      <p>In the event of a personal data breach, Article 33
requires the data controller to notify the supervisory
authority without undue delay, unless the breach is
unlikely to result in a risk to the rights and freedoms of
individuals. Encryption is mentioned as a measure to
mitigate the risks associated with a data breach.</p>
      <p>4. Communication of a Personal Data Breach to the
Data Subject (Article 34):</p>
      <p>Article 34 states that, in certain cases, the data
controller is required to communicate the personal data
breach to the data subject without undue delay.
However, this communication is not necessary if the
data is unintelligible due to encryption or other security
measures.</p>
      <p>In summary, while GDPR doesn’t explicitly mandate
data encryption, it strongly encourages its use as part of
a broader set of security measures. The implementation
of encryption, especially when combined with other
security practices like pseudo-nymization, helps
organizations meet the GDPR’s requirements for
securing personal data and mitigating the risks
associated with data breaches. Organizations should
assess the risks associated with their data processing
activities and implement security measures, including
encryption, based on the principle of proportionality.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Problem statement and solution</title>
      <p>As we can see GDPR does not explicitly mandate data
encryption. Without the recommendation of concrete
encryption standards, it is complicated for organizations
to choose the needed standards. It can lead to security
breaches. For the local data storage, we can use
symmetric encryption.</p>
      <p>AES, which stands for Advanced Encryption
Standard, is a widely used symmetric encryption
algorithm that plays a crucial role in securing data,
including its storage. AES was established as a standard
by the National Institute of Standards and Technology
(NIST) in 2001, replacing the Data Encryption Standard
(DES). AES is known for its efficiency, security, and
versatility, making it a popular choice for encrypting
sensitive information.</p>
      <p>
        Here are key aspects of using AES as a method for
storing data [
        <xref ref-type="bibr" rid="ref10">9</xref>
        ]:
      </p>
      <p>AES is a symmetric encryption algorithm, meaning
the same key is used for both encryption and decryption.
This simplicity in key management makes AES efficient
for storing and retrieving encrypted data. AES supports
key lengths of 128, 192, and 256 bits. Longer key lengths
generally provide stronger security, but they may
require more computational resources. The choice of
key length depends on the desired level of security and
the specific implementation.</p>
      <p>AES operates as a block cipher, encrypting data in
fixed-size blocks. The standard block size for AES is 128
bits. Each block undergoes multiple rounds of
encryption and transformation, contributing to the
algorithm’s security.</p>
      <p>AES can be used in various modes of operation, such
as Electronic Codebook (ECB), Cipher Block Chaining
(CBC), Counter (CTR), and others. The mode of
operation determines how the algorithm encrypts data
blocks and adds a layer of complexity and security.</p>
      <p>The cryptosystem is commonly employed for
dataat-rest encryption, securing data stored on devices such
as hard drives, SSDs, and other storage media.
Encrypting data at rest helps protect sensitive
information from unauthorized access, especially in the
event of physical theft or data breaches.</p>
      <p>AES is often used to meet various security and
compliance standards, including those related to data
protection and privacy. Its acceptance as a secure
encryption algorithm by international organizations and
regulatory bodies makes it a suitable choice for
organizations handling sensitive data.</p>
      <p>AES encryption can be also integrated into various
storage systems, including databases and file systems.
This integration allows organizations to encrypt data at
the storage level, providing an additional layer of
protection beyond application-level encryption.</p>
      <p>The cryptosystem is designed to be computationally
efficient, but the performance impact of encryption can
vary based on factors such as key length, mode of
operation, and the hardware used. Modern processors
often include hardware acceleration for AES, optimizing
performance.</p>
      <p>IT must be mentioned, that effective key
management is crucial when using AES. Safeguarding
encryption keys is essential to maintaining the security
of encrypted data. Organizations should implement
secure key storage and distribution practices.</p>
      <p>Choosing Advanced Encryption Standard (AES) for
GDPR Compliance in the realm of General Data
Protection Regulation (GDPR) compliance, the selection
of a robust encryption standard is obligatory for
securing personal data. As we mentioned above it stands
out as a highly secure and good choice that aligns with
GDPR principles. AES, a symmetric encryption
algorithm, has earned its reputation for security through
rigorous cryptographic analysis. Its implementation
provides sufficient protection for sensitive information,
addressing the GDPR’s mandate for robust data
protection. Especially well-suited for encrypting stored
information, AES’s symmetric nature ensures efficient
and effective encryption, meeting GDPR’s emphasis on
securing data at rest. This approach guarantees that
personal data remains confidential and protected from
unauthorized access. The cryptosystem aligns
seamlessly with GDPR principles, including data
minimization, integrity, and confidentiality. By
employing AES for data encryption, organizations
adhere to GDPR’s mandate to store and manage only
necessary information while maintaining data integrity
and confidentiality through encryption. In the
unfortunate event of a data breach, GDPR necessitates
prompt notification to the supervisory authority and, in
certain cases, to data subjects. The cryptosystem plays
an important role in breach mitigation by rendering the
encrypted data unreadable without the proper
decryption key, reducing the risk of harm to individuals.
GDPR encourages the use of pseudonymization as an
additional security measure. AES, integrated into a
broader pseudonymization strategy, adds an extra layer
of complexity, making it challenging to associate
encrypted data with specific individuals without the
requisite decryption keys. Widely adopted across
industries, AES’s versatility allows for seamless
integration into various systems, databases, and storage
solutions. Its international recognition contributes to a
consistent and effective approach to data encryption,
aligning with GDPR’s emphasis on protecting personal
data regardless of geographical boundaries.</p>
      <p>Therefore, selecting AES as the encryption standard
for GDPR compliance reflects a commitment to the
secure processing and storage of personal data. While
encryption is a crucial aspect of GDPR compliance,
organizations should adopt a holistic approach,
considering additional technical and organizational
measures to ensure comprehensive data protection. The
key size can be chosen as a 128-bit length.</p>
      <p>
        For communication encryption, we offer to use
asymmetric encryption. Using SSL (Secure Sockets
Layer) or its successor, TLS (Transport Layer Security),
for data transfer is a common and recommended
practice to ensure the secure transmission of data, and it
aligns well with GDPR requirements for protecting
personal data during transit [
        <xref ref-type="bibr" rid="ref11">10</xref>
        ]. Here’s an overview of
how SSL/TLS can be considered as an encryption
standard for GDPR compliance:
      </p>
      <p>SSL/TLS protocols are designed to provide a secure
channel for data transmission over the internet. This is
achieved through encryption, which protects the
confidentiality and integrity of the data being
transferred between a user’s browser and a web server.
GDPR emphasizes the principles of data protection,
including the need to process personal data securely.
Using SSL/TLS for data transfer helps organizations
comply with these principles by ensuring that sensitive
information is encrypted during transmission,
preventing unauthorized access or interception.</p>
      <p>SSL/TLS protocols use strong encryption algorithms
to secure data. The choice of encryption algorithms and
key lengths in the configuration of SSL/TLS can be
aligned with GDPR’s emphasis on adopting appropriate
technical measures to protect personal data.</p>
      <p>GDPR grants individuals the right to have their data
processed securely. By implementing SSL/TLS,
organizations contribute to the protection of data
subject rights, especially during data transfer processes
where the risk of interception is higher.</p>
      <p>SSL/TLS contributes to secure communication
between data subjects and data controllers. When
obtaining consent or communicating with individuals
regarding their data, the use of encrypted channels helps
maintain the confidentiality and integrity of the
information exchanged.</p>
      <p>The protocol not only encrypts data but also
provides a mechanism for server authentication.
Verifying the identity of the server helps prevent
manin-the-middle attacks, ensuring that data is transmitted
to and from legitimate sources.</p>
      <p>In the event of a personal data breach, GDPR
mandates timely notification. The use of SSL/TLS can
mitigate the risk of data breaches during transmission,
reducing the likelihood of unauthorized access and the
need for such notifications.</p>
      <p>The protocol is considered a standard and best
practice for securing data in transit. Its widespread
adoption across the internet and acceptance as a secure
communication protocol contribute to its alignment
with industry standards, reinforcing its suitability for
GDPR compliance.</p>
      <p>It’s important to note that while SSL/TLS is crucial
for securing data in transit, a comprehensive GDPR
compliance strategy should encompass other security
measures, including encryption at rest, access controls,
and secure data processing practices. Additionally,
organizations should stay informed about evolving
encryption standards and vulnerabilities to ensure the
ongoing effectiveness of their security measures.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Secure encryption under GDPR</title>
      <sec id="sec-5-1">
        <title>5.1. Encryption as a security measure</title>
        <p>Article 32 of the GDPR explicitly mentions encryption
as a security measure that organizations should consider
to protect personal data. Encryption helps ensure the
confidentiality, integrity, and availability of data by
making it unreadable to unauthorized parties.</p>
        <p>While encryption is not mandatory, it is strongly
recommended, especially for protecting sensitive data.
The GDPR promotes a risk-based approach, where
encryption is one of the methods to mitigate risks to
personal data.</p>
      </sec>
      <sec id="sec-5-2">
        <title>5.2. Data breach notification</title>
        <p>Under Article 34, if a data breach occurs and the personal
data is encrypted, the breach is less likely to pose a high
risk to the rights and freedoms of individuals. As a
result, if the data is properly encrypted, organizations
might not need to notify the affected individuals,
provided the encryption is robust and the decryption
key has not been compromised.</p>
      </sec>
      <sec id="sec-5-3">
        <title>5.3. Data protection by design and by default</title>
        <p>Article 25 encourages organizations to implement
appropriate technical and organizational measures, such
as encryption, from the outset of data processing
activities. This concept, known as “data protection by
design and by default”, aims to integrate privacy
features directly into the processing systems and
services.</p>
      </sec>
      <sec id="sec-5-4">
        <title>5.4. Pseudonymization</title>
        <p>Encryption is often used as a tool for pseudonymization,
a process mentioned in GDPR that reduces the risks to
data subjects. Pseudonymization involves processing
personal data in such a manner that it cannot be
attributed to a specific individual without additional
information, which must be kept separately and
securely.</p>
      </sec>
      <sec id="sec-5-5">
        <title>5.5. Impact on data processing</title>
        <p>When data is encrypted, it may affect how it can be
processed. For instance, encrypted data typically cannot
be searched or analyzed in its encrypted form, which
may necessitate the development of secure and efficient
decryption processes within an organization.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. Solution for post-quantum epoch</title>
      <p>
        Grover’s algorithm is a quantum algorithm that
addresses the problem of unstructured search, and it has
implications for symmetric-key cryptography, including
algorithms like AES. Grover’s algorithm offers a
quadratic speedup for unstructured search problems
[
        <xref ref-type="bibr" rid="ref12">11</xref>
        ].
      </p>
      <p>In the context of symmetric-key cryptography,
Grover’s algorithm can be used to search an unsorted
database or find the key for a symmetric encryption
algorithm. Grover’s algorithm implies that the time
complexity of a brute-force search is reduced from O(2n)
to O(2n/2), where “n” is the key length. This means that
the security strength provided by a key length of “n” bits
against a brute-force search is halved when subjected to
Grover’s algorithm.</p>
      <p>For example, if you have a symmetric key with a
length of 128 bits, classically it would take an exhaustive
search of 2128 operations to find the key. With Grover’s
algorithm, the time complexity is reduced to the square
root of 2128, which is 264 operations. Therefore, the
effective security strength is reduced to 64 bits against a
quantum search. To maintain a certain level of security
against quantum attacks, it’s generally recommended to
use longer key lengths with symmetric key algorithms.
For instance, if you were aiming for 128-bit security
against a quantum attack, you might use a key length of
256 bits with a symmetric algorithm like AES.</p>
      <p>Therefore, we offer to use the key length of 256 bits
for AES to securely store data.</p>
      <p>
        For communication asymmetric cryptography must
be involved. Quantum computers can break the existing
asymmetric cryptography using Shor’s algorithm [
        <xref ref-type="bibr" rid="ref13">12</xref>
        ].
      </p>
      <p>
        Shor’s algorithm is a quantum algorithm designed to
efficiently factorize large numbers and compute discrete
logarithms, which poses a significant risk to widely used
encryption methods like RSA and ECC. In particular,
RSA’s security, dependent on the difficulty of factoring
large numbers, and ECC, relying on the elliptic curve
discrete logarithm problem, are compromised by Shor’s
algorithm on a sufficiently powerful quantum computer
[
        <xref ref-type="bibr" rid="ref14 ref15">13, 14</xref>
        ].
      </p>
      <p>
        On a different front, Grover’s algorithm, a quantum
search algorithm, has implications for symmetric
encryption and impacts the effective key length. While
not directly breaking public-key cryptography, Grover’s
algorithm provides a quadratic speedup for unstructured
search problems, effectively halving the security
provided by symmetric encryption key lengths. This
prompts the need for longer key lengths in symmetric
encryption to maintain equivalent security levels in the
face of quantum threats [
        <xref ref-type="bibr" rid="ref16 ref17 ref18">15–17</xref>
        ].
      </p>
      <p>To counter these quantum risks, ongoing efforts in
postquantum cryptography are focused on developing
encryption algorithms resistant to quantum attacks.
Researchers are exploring alternative mathematical
problems and cryptographic techniques to ensure the
continued security of digital communication in a
quantum computing era.</p>
      <p>Therefore, for asymmetric encryption, we offer to
use already existing NIST standards. GAITHERSBURG,
Md.—The National Institute of Standards and
Technology (NIST), part of the U.S. Department of
Commerce, has taken a significant step in addressing the
potential threat posed by future quantum computers to
digital security. NIST has unveiled the initial group of
encryption tools designed to withstand quantum
computer attacks, which could jeopardize the privacy of
information crucial to daily digital activities such as
online banking and email communication. These
selected encryption algorithms are anticipated to be part
of NIST’s forthcoming post-quantum cryptographic
standard, expected to be finalized within approximately
two years.</p>
      <p>
        Gina M. Raimondo, the Secretary of Commerce,
emphasized the importance of this announcement as a
milestone in fortifying sensitive data against potential
cyber threats from quantum computers. NIST has played
a crucial role in managing a six-year effort that began in
2016, urging cryptographers globally to create and vet
encryption methods capable of resisting attacks from
more powerful quantum computers. The unveiling of
these encryption algorithms marks a pivotal stage in
NIST’s post-quantum cryptography [
        <xref ref-type="bibr" rid="ref19">18</xref>
        ] standardization
project.
      </p>
      <p>Under Secretary of Commerce for Standards and
Technology and NIST Director Laurie E. Locascio
highlighted NIST’s forward-looking approach to
anticipate the needs of U.S. industry and society. The
agency’s post-quantum cryptography program, drawing
on top cryptography experts worldwide, has produced
the first set of quantum-resistant algorithms aimed at
establishing a standard to significantly enhance digital
information security. This initial selection includes four
encryption algorithms designed to resist quantum
attacks. Four additional algorithms are currently under
consideration, with the finalists expected to be
announced in the future. The decision to reveal choices
in two stages is driven by the necessity for a diverse
range of defense tools. Different systems and tasks
utilizing encryption demand tailored solutions, diverse
approaches, and multiple algorithms to address potential
vulnerabilities.</p>
      <p>
        It must be mentioned that encryption is a
fundamental mechanism that employs mathematical
principles to safeguard electronic information and faces
a potential challenge from quantum computers. Unlike
conventional computers, quantum computers could
rapidly solve math problems currently deemed
intractable, rendering existing encryption systems
vulnerable. The selected quantum-resistant algorithms,
designed for general encryption and digital signatures,
rely on math problems that both conventional and
quantum computers should find challenging to solve.
The chosen algorithm for general encryption is
CRYSTALS-Kyber, recognized for its smaller encryption
keys facilitating easy exchange between parties and
operational speed [
        <xref ref-type="bibr" rid="ref20 ref21 ref22 ref23 ref24 ref25">19–24</xref>
        ].
      </p>
      <p>Therefore, we offer to use CRYSTALS-Kyber as
asymmetric encryption.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Final recommendations for</title>
    </sec>
    <sec id="sec-8">
      <title>NIST encryption standards</title>
      <sec id="sec-8-1">
        <title>Classical setting:</title>
        <p>1. Data Storage (AES-128):</p>
        <p>Using AES-128 for data storage is a common and
secure practice. It provides a good balance between
security and performance in most scenarios.</p>
        <p>2. Communication (SSL Protocol):</p>
        <p>
          SSL (Secure Sockets Layer) has been widely used for
securing communication over the internet. Note that the
latest version of SSL is TLS (Transport Layer Security),
and it’s recommended to use TLS instead for modern
applications [
          <xref ref-type="bibr" rid="ref25 ref26 ref27">24–26</xref>
          ].
        </p>
        <p>Post-Quantum Epoch:
Data Storage (AES-256):</p>
        <p>In a post-quantum epoch, where quantum
computers may pose a threat to certain cryptographic
algorithms, it’s prudent to use a higher key size for
encryption. AES-256 provides stronger security
compared to AES-128 and is considered more resilient to
potential quantum attacks.</p>
        <p>Communication (Asymmetric Cryptography—
CRYSTALS-Kyber):</p>
        <p>In a post-quantum era, asymmetric algorithms may
become vulnerable to attacks by quantum computers. As
a result, using asymmetric cryptography that is
considered quantum-resistant becomes essential.
CRYSTALS-Kyber is a post-quantum key exchange
algorithm, and choosing it for communication aligns
with the goal of future-proofing against quantum
threats.</p>
        <p>
          It’s important to stay informed about the latest
developments in cryptography and regularly update
cryptographic protocols and algorithms to maintain the
security of data in changing threat landscapes.
Additionally, compliance with relevant data protection
regulations, such as GDPR, should always be considered
in cryptographic decisions [
          <xref ref-type="bibr" rid="ref28 ref29 ref30 ref31">27–30</xref>
          ].
        </p>
        <p>The pseudo-code for the usage of the offered
technologies can look as follows:
# Import necessary cryptographic libraries
from cryptography.hazmat.primitives.ciphers import
Cipher, algorithms, and modes
from cryptography.hazmat.backends import
default_backend
from crystals_kyber import kyber
# Function to generate AES key based on epoch
def generate_aes_key(epoch):
if epoch == "classical":</p>
        <p>return generate_aes_key_classical()
elif epoch == "post_quantum":</p>
        <p>return generate_aes_key_post_quantum()
else:</p>
        <p>raise ValueError("Invalid epoch specified")
# Function to generate AES-256 key for classical setting
def generate_aes_key_classical():</p>
        <p># Implement the key generation for the classical
setting</p>
        <p>pass
# Function to generate AES-256 key for post-quantum
epoch
def generate_aes_key_post_quantum():</p>
        <p># Implement the key generation for the post-quantum
epoch</p>
        <p>pass
# Function to encrypt data based on epoch and usage
def encrypt_data(data, epoch, usage):
if epoch == "classical":
if usage == "storage":</p>
        <p>return encrypt_data_aes(data,
generate_aes_key_classical())
elif usage == "communication":</p>
        <p>return secure_communication_classical(data)
else:</p>
        <p>raise ValueError("Invalid usage specified")
elif epoch == "post_quantum":
if usage == "storage":</p>
        <p>return encrypt_data_aes(data,
generate_aes_key_post_quantum())
elif usage == "communication":</p>
        <p>return
secure_communication_post_quantum(data)
else:</p>
        <p>raise ValueError("Invalid usage specified")
else:</p>
        <p>raise ValueError("Invalid epoch specified")
# Function to encrypt data using AES-256
def encrypt_data_aes(data, key):</p>
        <p>cipher = Cipher(algorithms.AES(key), modes.ECB(),
backend=default_backend())
encryptor = cipher.encryptor()
encrypted_data = encryptor.update(data)
encryptor.finalize()
return encrypted_data
+
# Function to perform secure communication in a
classical setting
def secure_communication_classical(data):
# Implement TLS/SSL with RSA or ECC
pass
# Function to perform secure communication with
postquantum epoch
def secure_communication_post_quantum(data):
# Implement CRYSTALS-Kyber for key exchange
pass
# Example usage:
plaintext_data = "Sensitive data to be encrypted."
epoch = "post_quantum" # Change this to "classical" for
the classical setting
usage = "communication" # Change this to "storage" for
data storage
# Encryption based on the specified epoch and usage
encrypted_data = encrypt_data(plaintext_data, epoch,
usage)
# Now, encrypted_data can be stored or transmitted
securely.</p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>8. Conclusions and future plans</title>
      <p>Cryptography is an essential tool for GDPR compliance,
providing the means to protect personal data effectively.
By implementing strong cryptographic measures,
organizations can significantly reduce the risk of data
breaches and ensure that they meet the stringent
requirements of the GDPR. The best practices for Using
Cryptography under GDPR are the following:


</p>
      <sec id="sec-9-1">
        <title>Key Management: Proper management of</title>
        <p>encryption keys is critical to ensuring that
encrypted data remains secure. Keys must be
stored and managed securely to prevent
unauthorized access.</p>
        <p>Regular Audits and Updates: Cryptographic
algorithms and their implementations should
be regularly audited and updated to protect
against emerging threats.</p>
        <p>Compliance with Standards: Use cryptographic
methods that comply with recognized
standards, such as those from the NIST or the
European Telecommunications Standards
Institute (ETSI).</p>
        <p>In conclusion, our cryptographic recommendations aim
to establish a robust and adaptable security foundation
for our system. For data storage in the classical epoch,
we offer to use of AES-128, a widely recognized and
efficient symmetric encryption algorithm. This choice
strikes a balance between security and computational
efficiency, making it suitable for protecting stored data
in various scenarios.</p>
        <p>For secure communication, we recommend the use
of SSL/TLS protocols, incorporating modern cipher
suites such as those based on AES in combination with
RSA or ECC for key exchange. SSL ensures the
confidentiality and integrity of data during
transmission, and our approach aligns with current best
practices for secure communication.</p>
        <p>In anticipation of future challenges posed by quantum
computing, our transition to post-quantum algorithms is
exemplified by the adoption of CRYSTALS-Kyber for
secure communication. This step reflects our commitment
to staying ahead of emerging threats and safeguarding
sensitive information.</p>
        <p>In our future research, we think of offering the
postquantum model for SSL.</p>
      </sec>
    </sec>
    <sec id="sec-10">
      <title>Acknowledgment</title>
      <p>This work was funded by the Shota Rustaveli National
Foundation of Georgia (SRNSFG) (NFR-22-14060).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT Infrastructure Audit, in: IEEE 8th International Conference on Problems of Infocommunications, Science and Technology</source>
          (
          <year>2021</year>
          )
          <fpage>213</fpage>
          -
          <lpage>217</lpage>
          . doi:
          <volume>10</volume>
          .1109/picst54195.
          <year>2021</year>
          .
          <volume>9772181</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <article-title>Security Rating Metrics for Distributed Wireless Systems</article-title>
          , in: 8th International Conference on “Mathematics.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Informa-tion Technologies</surname>
          </string-name>
          .
          <source>Education:” Modern Machine Learning Technologies and Data Science</source>
          , vol.
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>222</fpage>
          -
          <lpage>233</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Protecting Objects of Critical Information Infrastructure from Wartime Cyber Attacks by Decentralizing the Telecommunications Network</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>240</fpage>
          -
          <lpage>245</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Increasing the Functional Network Stability in the Depression Zone of the Hydroelectric Power Station Reservoir</article-title>
          ,
          <source>in: Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>169</fpage>
          -
          <lpage>176</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <source>Formation of Dependability and Cyber Protection Model in Information Systems of Situational Center, in: Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>H.</given-names>
            <surname>Li</surname>
          </string-name>
          , Yu L.,
          <string-name>
            <given-names>H.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <source>The Impact of GDPR on Global Technology Development, J. Global Inf. Technol. Manag</source>
          .
          <volume>22</volume>
          (
          <issue>1</issue>
          ) (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1080/ 1097198X.
          <year>2019</year>
          .
          <volume>156</volume>
          9186.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>C.</given-names>
            <surname>Tankard</surname>
          </string-name>
          ,
          <article-title>What the GDPR Means for Businesses, Netw</article-title>
          . Secur.
          <year>2016</year>
          (
          <article-title>6) (</article-title>
          <year>2016</year>
          )
          <fpage>5</fpage>
          -
          <lpage>8</lpage>
          . doi:
          <volume>10</volume>
          .1016/S1353-
          <volume>4858</volume>
          (
          <issue>16</issue>
          )300
          <fpage>56</fpage>
          -
          <lpage>3</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>G.</given-names>
            <surname>Johnson</surname>
          </string-name>
          , S. Shriver,
          <string-name>
            <given-names>S.</given-names>
            <surname>Goldberg</surname>
          </string-name>
          , Privacy and Market Concentration:
          <article-title>Intended and Unintended Consequences of the GDPR, Manag</article-title>
          . Sci.
          <volume>69</volume>
          (
          <issue>10</issue>
          ) (
          <year>2023</year>
          )
          <fpage>5695</fpage>
          -
          <lpage>6415</lpage>
          . doi:
          <volume>10</volume>
          .1287/mnsc.
          <year>2023</year>
          .
          <volume>4709</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J.</given-names>
            <surname>Daemen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Rijmen</surname>
          </string-name>
          , AES Proposal: Rijndael (
          <year>1999</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>D.</given-names>
            <surname>Wagner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Schneier</surname>
          </string-name>
          ,
          <source>Analysis of the SSL 3.0 Protocol</source>
          ,
          <source>The Second USENIX Workshop on Electronic Commerce Proceedings</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ) (
          <year>1996</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>R.</given-names>
            <surname>Jozsa</surname>
          </string-name>
          , Searching in Grover's
          <string-name>
            <surname>Algorithm</surname>
          </string-name>
          (
          <year>1999</year>
          ).
          <source>doi: 10.48550/arXiv.quant-ph/9901021.</source>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>T.</given-names>
            <surname>Monz</surname>
          </string-name>
          , et al.,
          <source>Realization of a Scalable Shor Algorithm, Science</source>
          <volume>351</volume>
          (
          <issue>6277</issue>
          ) (
          <year>2016</year>
          )
          <fpage>1068</fpage>
          -
          <lpage>1070</lpage>
          . doi:
          <volume>10</volume>
          .1126/scien ce.
          <year>aad9480</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>H.</given-names>
            <surname>Wong</surname>
          </string-name>
          ,
          <article-title>Shor's Algorithm, Introduction to Quantum Computing: From a Layperson to a Programmer in 30 Steps</article-title>
          . Cham: Springer International Publishing (
          <year>2023</year>
          )
          <fpage>289</fpage>
          -
          <lpage>298</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [14]
          <string-name>
            <surname>A. M. Patoary</surname>
          </string-name>
          , et al.,
          <article-title>Chaotic Roots of the Modular Multiplication Dynamical System in Shor's Algorithm (</article-title>
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .48550/arXiv.2306.16446.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          , et al.,
          <article-title>High-Speed and Secure PRNG for Cryptographic Applications</article-title>
          ,
          <source>Int. J. Comput. Network Inf. Secur</source>
          .
          <volume>12</volume>
          (
          <issue>3</issue>
          ) (
          <year>2020</year>
          )
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          . doi:
          <volume>10</volume>
          .5815/ijcnis.
          <year>2020</year>
          .
          <volume>03</volume>
          .01.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>M.</given-names>
            <surname>Iavich</surname>
          </string-name>
          , et al.,
          <source>Lattice based Merkle</source>
          ,
          <source>in: International Conference on Information Technologies</source>
          , vol.
          <volume>2470</volume>
          (
          <year>2019</year>
          )
          <fpage>13</fpage>
          -
          <lpage>16</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>S.</given-names>
            <surname>Tynymbayev</surname>
          </string-name>
          , et al.,
          <source>Modular Reduction Based on the Divider by Blocking Negative Remainders, News of the National Academy of Sciences of the Republic of Kazakhstan, Series of Geology and Technical Sciences</source>
          <volume>2</volume>
          (
          <issue>434</issue>
          ) (
          <year>2019</year>
          )
          <fpage>238</fpage>
          -
          <lpage>248</lpage>
          . doi:
          <volume>10</volume>
          .32014/
          <year>2019</year>
          .
          <fpage>2518</fpage>
          -
          <lpage>170x</lpage>
          .
          <fpage>60</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Multifunctional</surname>
            <given-names>CRS</given-names>
          </string-name>
          <article-title>Encryption Scheme on Isogenies of Non-Supersingular Edwards Curves</article-title>
          , in: Workshop on Classic, Quantum, and
          <string-name>
            <surname>Post-Quantum</surname>
            <given-names>Cryptography</given-names>
          </string-name>
          , vol.
          <volume>3504</volume>
          (
          <year>2023</year>
          )
          <fpage>12</fpage>
          -
          <lpage>25</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>M.</given-names>
            <surname>Iavich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Kuchukhidze</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Bocu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A PostQuantum</given-names>
            <surname>Digital</surname>
          </string-name>
          <article-title>Signature Using Verkle Trees</article-title>
          and Lattices,
          <source>Symmetry</source>
          <volume>15</volume>
          (
          <issue>12</issue>
          ) (
          <year>2023</year>
          )
          <fpage>2165</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>M.</given-names>
            <surname>Iavich</surname>
          </string-name>
          , T. Kuchukhidze,
          <string-name>
            <surname>Digital Signature Design Using Verkle Tree</surname>
          </string-name>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>E.</given-names>
            <surname>Dubrova</surname>
          </string-name>
          , et al.,
          <article-title>Breaking a Fifth-order Masked Implementation of Crystals-kyber by Copy-paste</article-title>
          ,
          <source>Proceedings of the 10th ACM Asia Public-Key Cryptography Workshop</source>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>R.</given-names>
            <surname>Avanzi</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>CRYSTALS-Kyber Algorithm</surname>
          </string-name>
          Specifications and Supporting Documentation,
          <source>NIST PQC Round</source>
          <volume>2</volume>
          (
          <issue>4</issue>
          ) (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>43</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>M.</given-names>
            <surname>Moraitis</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Securing</surname>
            <given-names>CRYSTALS</given-names>
          </string-name>
          -
          <article-title>Kyber in FPGA Using Duplication and Clock Randomization</article-title>
          , IEEE Design &amp;
          <string-name>
            <surname>Test</surname>
          </string-name>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          , et al.,
          <article-title>New Secure Block Cipher for Critical Applications: Design, Implementation, Speed</article-title>
          and
          <string-name>
            <given-names>Security</given-names>
            <surname>Analysis</surname>
          </string-name>
          ,
          <source>Advances in Intelligent Systems and Computing</source>
          (
          <year>2020</year>
          )
          <fpage>93</fpage>
          -
          <lpage>104</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Modeling</surname>
            <given-names>CSIKE</given-names>
          </string-name>
          <article-title>Algorithm on Non-Cyclic Edwards Curves</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3288</volume>
          (
          <year>2022</year>
          )
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          , et al.,
          <article-title>Method of Algorithm Building for Modular Reducing by Irreducible Polynomial</article-title>
          , 16th International Conference on Control,
          <source>Automation and Systems</source>
          (
          <year>2016</year>
          )
          <fpage>1476</fpage>
          -
          <lpage>1479</lpage>
          . doi:
          <volume>10</volume>
          .1109/iccas.
          <year>2016</year>
          .
          <volume>7832498</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <article-title>Implementation of the CSIDH Algorithm Model on Supersingular Twisted and Quadratic Edwards Curves</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3187</volume>
          (
          <issue>1</issue>
          ) (
          <year>2022</year>
          )
          <fpage>302</fpage>
          -
          <lpage>309</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>C.</given-names>
            <surname>Papamanthou</surname>
          </string-name>
          , et al.,
          <source>Streaming Authenticated Data Structures</source>
          , Advances in CryptologyEUROCRYPT (
          <year>2013</year>
          )
          <fpage>353</fpage>
          -
          <lpage>370</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -38348-9_
          <fpage>22</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bessalov</surname>
          </string-name>
          , et al.,
          <article-title>CSIKE-ENC Combined Encryption Scheme with Optimized Degrees of Isogeny Distribution</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>36</fpage>
          -
          <lpage>45</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>I.</given-names>
            <surname>Khaburzaniya</surname>
          </string-name>
          , et al.,
          <source>Aggregating and Thresholdizing Hash-Based Signatures Using STARKs, ACM Asia Conf. Comput. Commun. Secur</source>
          . (
          <year>2022</year>
          )
          <fpage>393</fpage>
          -
          <lpage>407</lpage>
          . doi:
          <volume>10</volume>
          .1145/ 3488932.3524128.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>