<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">jcc</journal-id>
      <journal-title-group>
        <journal-title>Journal of Computer and Communications</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2327-5227</issn>
      <issn pub-type="ppub">2327-5219</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/jcc.2026.141003</article-id>
      <article-id pub-id-type="publisher-id">jcc-148926</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Securing Mobile Payments in IoT Networks: Post-Quantum Challenges and Solutions</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Nijimbere</surname>
            <given-names>Dieudonné</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Mbonigaba</surname>
            <given-names>Vincent</given-names>
          </name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Department of Information and Communication Technologies, Higher Institute of Military Academy, Bujumbura, Burundi </aff>
      <aff id="aff2"><label>2</label> Department of Information and Communication Technologies, University of Burundi, Bujumbura, Burundi </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The authors declare no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>09</day>
        <month>01</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>01</month>
        <year>2026</year>
      </pub-date>
      <volume>14</volume>
      <issue>01</issue>
      <fpage>33</fpage>
      <lpage>45</lpage>
      <history>
        <date date-type="received">
          <day>09</day>
          <month>12</month>
          <year>2025</year>
        </date>
        <date date-type="accepted">
          <day>16</day>
          <month>01</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>19</day>
          <month>01</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/jcc.2026.141003">https://doi.org/10.4236/jcc.2026.141003</self-uri>
      <abstract>
        <p>This work focuses on the security of mobile payments in Internet of Things networks, with particular emphasis on the integration of post-quantum cryptographic principles. The study adopts a modeling and simulation-based approach to analyze security challenges arising from the advent of quantum computing. The main contributions include an analytical review of post-quantum cryptographic algorithms, the identification of potential vulnerabilities in IoT-based mobile payment systems, and the development of a multivariate mathematical framework to evaluate security-performance trade-offs. Through synthetic data generation and statistical modeling, the proposed framework highlights the impact of cryptographic complexity, network latency, and device resource constraints on transaction security. The results demonstrate how post-quantum-aware security mechanisms can be optimized under practical IoT constraints. The significance of this work lies in its proactive approach to long-term security, addressing the growing vulnerability of traditional RSA- and ECC-based systems in the presence of quantum adversaries. By focusing on abstraction, modeling, and simulation, this study provides insights that support the design of future quantum-resistant mobile payment architectures in IoT environments.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Security</kwd>
        <kwd>Mobile Payments</kwd>
        <kwd>Internet of Things</kwd>
        <kwd>Post-Quantum Cryptography</kwd>
        <kwd>Authentication</kwd>
        <kwd>Confidentiality</kwd>
        <kwd>Protocol</kwd>
        <kwd>Quantum Attacks</kwd>
        <kwd>Security Standards</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <p>Mobile payments have become an essential component of the digital economy and an indispensable way for consumers to manage their daily transactions. With the proliferation of smartphones and improved network infrastructure, mobile payments have seen unprecedented adoption in recent years. According to a Statista report, the volume of mobile payments worldwide reached approximately 4.6 trillion in 2023 and is expected to continue growing at an exponential rate, reaching approximately 10.5 trillion by 2028 [<xref ref-type="bibr" rid="B1">1</xref>]. Along with this trend, the Internet of Things (IoT) has also gained momentum, transforming the way devices communicate, collect, and exchange data. Connected objects are used in various fields, ranging from smart homes and smart cities to healthcare and logistics. According to a report by Markets and Markets, the IoT market is expected to grow from 381 <italic>billion in</italic>2021 <italic>to</italic> 1463 billion by 2027, with a compound annual growth rate of 25.4% [<xref ref-type="bibr" rid="B2">2</xref>]. The intersection of mobile payments and IoT is creating unprecedented opportunities for businesses and consumers, facilitating faster and more secure transactions. Consumers can now make purchases with a single click via connected devices, improving the user experience and increasing transaction efficiency [<xref ref-type="bibr" rid="B3">3</xref>]. However, this rapid adoption also raises concerns, particularly regarding security and data protection. Potential vulnerabilities in mobile payment systems and IoT devices can be exploited by cybercriminals. Therefore, it becomes crucial to develop robust security solutions that protect data and strengthen consumer trust in these emerging technologies [<xref ref-type="bibr" rid="B4">4</xref>].</p>
    </sec>
    <sec id="sec2">
      <title>2. Relevant Literature</title>
      <sec id="sec2dot1">
        <title>2.1. Transaction Security Technologies in Mobile Payment</title>
        <p><italic>DUKPT</italic> (Derived Unique Key Per Transaction) and PKCS #11 are two important standards in the field of cryptography and transaction security, particularly in mobile payments [<xref ref-type="bibr" rid="B5">5</xref>]. We explain how they work and their role in transaction security. <italic>DUKPT</italic> is a cryptography standard that generates a unique key for each transaction, based on a master key shared between the payment terminal and the transaction processing server. This unique key is used to encrypt transaction data, such as the card number, expiration date, and security code [<xref ref-type="bibr" rid="B6">6</xref>]. The operating steps of <italic>DUKPT</italic> are: </p>
        <p>The payment terminal and the transaction processing server share a master key, called the Key Encryption Key (<italic>KEK</italic>).When a transaction is initiated, the payment terminal generates a unique transaction number, called the Transaction Identifier (<italic>TID</italic>).The payment terminal uses the DUKPT key derivation algorithm to generate a unique key for the transaction, called the Transaction Key (<italic>TK</italic>). This key is derived from the master key (<italic>KEK</italic>) and the <italic>TID</italic> [<xref ref-type="bibr" rid="B7">7</xref>].The key <italic>TK</italic> is used to encrypt the transaction data. The payment terminal sends the encrypted data to the transaction processing server. The transaction processing server uses the master key KEK and the TID to generate the same key TK. The transaction processing server uses the key TK to decrypt the transaction data [<xref ref-type="bibr" rid="B8">8</xref>].</p>
        <p>PKCS #11 is a cryptography standard that defines an API for security devices, such as smart cards and security tokens. This interface allows applications to communicate with security devices to perform cryptographic operations, such as key generation, encryption, and digital signing. The main elements of PKCS #11 are [<xref ref-type="bibr" rid="B9">9</xref>]:</p>
        <p>Session: A session is established between the application and the security device to perform cryptographic operations.Objects: Objects are entities that contain security information, such as keys, certificates, and encrypted data.Methods: Methods are functions that perform cryptographic operations on objects, such as key generation, encryption, and digital signatures.</p>
        <p>PKCS #11 provides a standard interface for security devices, allowing applications to communicate with different types of security devices without knowing the details of their implementation [<xref ref-type="bibr" rid="B10">10</xref>]. <italic>DUKPT</italic> and PKCS #11 are used in mobile payments to ensure transaction security. </p>
      </sec>
      <sec id="sec2dot2">
        <title>2.2. Important Standards in the Field of Payment Security and Terminal Quality Management</title>
        <p>The PCI-DSS is a set of security standards designed to protect credit and debit cardholder information. They are required by all organizations that accept, process, or store payment card information. The main objectives and requirements of the PCI-DSS include [<xref ref-type="bibr" rid="B11">11</xref>]: </p>
        <p>Cardholder data security: Protect sensitive data through encryption, secure storage, and secure transmission protocols.Access controls: Limit access to cardholder data to authorized individuals only.Network monitoring and assessment: Implement monitoring measures to detect and prevent unauthorized access [<xref ref-type="bibr" rid="B12">12</xref>].Regular system and network testing: Conduct security tests to identify potential vulnerabilities.</p>
        <p>The PCI-PA DSS is a complementary standard to PCI-DSS, specific to mobile payment applications. It aims to ensure that payment processing applications are designed and maintained securely. Key requirements include [<xref ref-type="bibr" rid="B13">13</xref>]: </p>
        <p>Application integrity and security: Ensure that payment applications do not store sensitive cardholder information in a non-compliant manner.Secure development: Follow secure development processes to minimize vulnerabilities in the code.Updates and patch management: Keep applications up to date to protect against new vulnerabilities.</p>
        <p>TQM is a quality management approach that focuses on the continuous improvement of processes, products, and services. In the context of mobile payment terminals, TQM involves [<xref ref-type="bibr" rid="B14">14</xref>]: </p>
        <p>Quality Assessment and Assurance: Ensure that payment terminals meet high quality standards and operate correctly. Training and awareness: Train staff to use and maintain systems effectively to reduce errors and improve customer satisfaction. Continuous process improvement: Identify areas for improvement through performance analysis and feedback. </p>
        <p>Each of these standards plays a vital role in payment transaction security and quality management. PCI-DSS and PCI-PA DSS focus on the security of payment data and applications, while TQM aims to ensure the quality of payment terminals and associated processes. In short, they help strengthen consumer trust and the security of payment systems.</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Modeling a Data Protection System</title>
      <p>Minimizing operating costs for a secure mobile payment system is possible by modeling the total cost <inline-formula><mml:math><mml:mi> C </mml:mi></mml:math></inline-formula> of a system based on several parameters, namely: </p>
      <disp-formula id="FD1">
        <label>(1)</label>
        <mml:math>
          <mml:mrow>
            <mml:mi>C</mml:mi>
            <mml:mo>=</mml:mo>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>f</mml:mi>
            </mml:msub>
            <mml:mo>+</mml:mo>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>+</mml:mo>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>s</mml:mi>
            </mml:msub>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where: <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> f </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> = Fixed costs. <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> = Variable costs. <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> s </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> = Security costs. Constraints may include requirements on the security level, the number of users, or available resources: </p>
      <disp-formula id="FD2">
        <label>(2)</label>
        <mml:math>
          <mml:mrow>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>f</mml:mi>
            </mml:msub>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>B</mml:mi>
              <mml:mi>f</mml:mi>
            </mml:msub>
            <mml:mo>,</mml:mo>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>B</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>,</mml:mo>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:msub>
              <mml:mi>C</mml:mi>
              <mml:mi>s</mml:mi>
            </mml:msub>
            <mml:mo>≥</mml:mo>
            <mml:msub>
              <mml:mi>S</mml:mi>
              <mml:mrow>
                <mml:mi>min</mml:mi>
              </mml:mrow>
            </mml:msub>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where:</p>
      <p><inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> B </mml:mi><mml:mi> f </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> is the fixed budget, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> B </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> is the variable budget, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> S </mml:mi><mml:mrow><mml:mi> m </mml:mi><mml:mi> i </mml:mi><mml:mi> n </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the minimum acceptable security level.</p>
      <p><bold>a. Processing time optimization</bold></p>
      <p>The total time of a transaction can be modeled as follows: </p>
      <disp-formula id="FD3">
        <label>(3)</label>
        <mml:math>
          <mml:mrow>
            <mml:mi>T</mml:mi>
            <mml:mo>=</mml:mo>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>e</mml:mi>
                <mml:mi>n</mml:mi>
                <mml:mi>c</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>+</mml:mo>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>t</mml:mi>
                <mml:mi>r</mml:mi>
                <mml:mi>a</mml:mi>
                <mml:mi>n</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>+</mml:mo>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>d</mml:mi>
                <mml:mi>e</mml:mi>
                <mml:mi>c</mml:mi>
              </mml:mrow>
            </mml:msub>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where:</p>
      <p><inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> e </mml:mi><mml:mi> n </mml:mi><mml:mi> c </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> = Encryption time, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> t </mml:mi><mml:mi> r </mml:mi><mml:mi> a </mml:mi><mml:mi> n </mml:mi><mml:mi> s </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> = Transmission time, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> d </mml:mi><mml:mi> e </mml:mi><mml:mi> c </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> = Decryption time.</p>
      <p>The constraints could be related to network speed or the efficiency of the algorithms used:</p>
      <disp-formula id="FD4">
        <label>(4)</label>
        <mml:math>
          <mml:mrow>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>t</mml:mi>
                <mml:mi>r</mml:mi>
                <mml:mi>a</mml:mi>
                <mml:mi>n</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>D</mml:mi>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>,</mml:mo>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>e</mml:mi>
                <mml:mi>n</mml:mi>
                <mml:mi>c</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>E</mml:mi>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>,</mml:mo>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>d</mml:mi>
                <mml:mi>e</mml:mi>
                <mml:mi>c</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>D</mml:mi>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
            </mml:msub>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where:</p>
      <p><inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> D </mml:mi><mml:mrow><mml:mi> max </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the acceptable transmission time limit;</p>
      <p><inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> E </mml:mi><mml:mrow><mml:mi> max </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the encoding time limit.</p>
      <p><bold>b. Security Optimization</bold></p>
      <p>The security <inline-formula><mml:math><mml:mi> S </mml:mi></mml:math></inline-formula> of a system can be assessed by indicators such as the strength of algorithms, the number of failure points. Security can be modeled as follows: </p>
      <disp-formula id="FD5">
        <label>(5)</label>
        <mml:math>
          <mml:mrow>
            <mml:mi>S</mml:mi>
            <mml:mo>=</mml:mo>
            <mml:mi>f</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mrow>
                <mml:mi>A</mml:mi>
                <mml:mo>,</mml:mo>
                <mml:mi>P</mml:mi>
                <mml:mo>,</mml:mo>
                <mml:mi>L</mml:mi>
              </mml:mrow>
              <mml:mo>)</mml:mo>
            </mml:mrow>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where: <inline-formula><mml:math><mml:mi> A </mml:mi></mml:math></inline-formula> = Security level of the algorithms, <inline-formula><mml:math><mml:mi> P </mml:mi></mml:math></inline-formula> = Security protocols used, <inline-formula><mml:math><mml:mi> L </mml:mi></mml:math></inline-formula> = Number of security levels implemented. Constraints can include weights on cost and performance: </p>
      <disp-formula id="FD6">
        <label>(6)</label>
        <mml:math>
          <mml:mrow>
            <mml:mi>C</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mrow>
                <mml:mi>A</mml:mi>
                <mml:mo>,</mml:mo>
                <mml:mi>P</mml:mi>
              </mml:mrow>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>≤</mml:mo>
            <mml:mi>B</mml:mi>
            <mml:mo>,</mml:mo>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mtext>
               
            </mml:mtext>
            <mml:mi>T</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mrow>
                <mml:mi>A</mml:mi>
                <mml:mo>,</mml:mo>
                <mml:mi>P</mml:mi>
              </mml:mrow>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>≤</mml:mo>
            <mml:msub>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
            </mml:msub>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where <inline-formula><mml:math><mml:mi> B </mml:mi></mml:math></inline-formula> is the total budget and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> m </mml:mi><mml:mi> a </mml:mi><mml:mi> x </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the maximum acceptable time.</p>
      <p><bold>c. Resolution Methods</bold></p>
      <p>To solve these optimization problems, several methods can be applied: </p>
      <p>Linear programming for problems with linear relationships. Non linear programming for problems where the objective function or constraints are nonlinear. Trial-and-error optimization algorithms for more complex problems. </p>
      <sec id="sec3dot1">
        <title>3.1. Statistical Modeling of System Behavior</title>
        <p>3.1.1. Regression Models</p>
        <p>Regression models (linear, logistic, etc.) can be used to predict dependent variables based on explanatory variables. </p>
        <disp-formula id="FD7">
          <label>(7)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>Y</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mo>⋯</mml:mo>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mi>n</mml:mi>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mi>n</mml:mi>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mi>ϵ</mml:mi>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where: <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> is the variable to be predicted, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 0 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> is the y-intercept, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> are the coefficients of the explanatory variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mi> ϵ </mml:mi></mml:math></inline-formula> is the random error. </p>
        <p>3.1.2. Time Series Models</p>
        <p>Time series can be used to analyze transactions over time, allowing the identification of trends, seasonality, or irregularities in trading volume. An ARIMA (AutoRegressive Integrated Moving Average) model, for example, can be formulated as follows: </p>
        <disp-formula id="FD8">
          <label>(8)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>Y</mml:mi>
                <mml:mi>t</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>θ</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>ϕ</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>Y</mml:mi>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>−</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mo>⋯</mml:mo>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>ϕ</mml:mi>
                <mml:mi>p</mml:mi>
              </mml:msub>
              <mml:msub>
                <mml:mi>Y</mml:mi>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>−</mml:mo>
                  <mml:mi>p</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>θ</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>ϵ</mml:mi>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>−</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mo>⋯</mml:mo>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>θ</mml:mi>
                <mml:mi>q</mml:mi>
              </mml:msub>
              <mml:msub>
                <mml:mi>ϵ</mml:mi>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>−</mml:mo>
                  <mml:mi>q</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>ϵ</mml:mi>
                <mml:mi>t</mml:mi>
              </mml:msub>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where: <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> Y </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> is the value of the variable at time <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> , <inline-formula><mml:math><mml:mi> ϕ </mml:mi></mml:math></inline-formula> and <inline-formula><mml:math><mml:mi> θ </mml:mi></mml:math></inline-formula> are the parameters of the autoregressive parts and the moving averages, respectively, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ϵ </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> is the error term at time <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> .</p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. Relationship between the Regression Model and Optimization Parameters</title>
        <p>The total system cost <inline-formula><mml:math><mml:mi> C </mml:mi></mml:math></inline-formula> defined in Equation (1) is directly influenced by the regression variables. The cryptographic complexity <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> impacts the security cost component <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> s </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , which includes the implementation of post-quantum algorithms, key management, and protocol updates. Similarly, the resource availability variable <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> affects both fixed costs <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> f </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> and variable costs <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> C </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , as more capable devices require higher infrastructure investment and operational resources. Accordingly, the cost function can be abstractly expressed as: </p>
        <disp-formula id="FD9">
          <label>(9)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>C</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mi>C</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>X</mml:mi>
                    <mml:mn>1</mml:mn>
                  </mml:msub>
                  <mml:mo>,</mml:mo>
                  <mml:msub>
                    <mml:mi>X</mml:mi>
                    <mml:mn>3</mml:mn>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Subject to the budgetary constraints defined by <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> B </mml:mi><mml:mi> f </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> B </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , and the minimum security requirement <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> S </mml:mi><mml:mrow><mml:mi> m </mml:mi><mml:mi> i </mml:mi><mml:mi> n </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> . The regression model enables the identification of configurations of <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> that maximize <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> while satisfying these constraints. The total transaction time <inline-formula><mml:math><mml:mi> T </mml:mi></mml:math></inline-formula> described in Equation (3) is strongly correlated with the regression variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> . An increase in cryptographic complexity <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> typically leads to higher encryption and decryption times (<inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> e </mml:mi><mml:mi> n </mml:mi><mml:mi> c </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> d </mml:mi><mml:mi> e </mml:mi><mml:mi> c </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> ), while network latency modeled by <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> directly influences the transmission time <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> T </mml:mi><mml:mrow><mml:mi> t </mml:mi><mml:mi> r </mml:mi><mml:mi> a </mml:mi><mml:mi> n </mml:mi><mml:mi> s </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> . Additionally, limited device resources represented by <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> may further increase processing delays. This relationship can be formulated as: </p>
        <disp-formula id="FD10">
          <label>(10)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>T</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mi>T</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>X</mml:mi>
                    <mml:mn>1</mml:mn>
                  </mml:msub>
                  <mml:mo>,</mml:mo>
                  <mml:msub>
                    <mml:mi>X</mml:mi>
                    <mml:mn>2</mml:mn>
                  </mml:msub>
                  <mml:mo>,</mml:mo>
                  <mml:msub>
                    <mml:mi>X</mml:mi>
                    <mml:mn>3</mml:mn>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The regression model estimates the relative contribution of each variable in meeting the time constraints <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> E </mml:mi><mml:mrow><mml:mi> m </mml:mi><mml:mi> a </mml:mi><mml:mi> x </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> D </mml:mi><mml:mrow><mml:mi> m </mml:mi><mml:mi> a </mml:mi><mml:mi> x </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> , providing a quantitative basis for balancing security and performance in mobile IoT payment systems. The global security level <inline-formula><mml:math><mml:mi> S </mml:mi></mml:math></inline-formula> introduced in Equation (5) is conceptually aligned with the dependent regression variable <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> . The parameters <inline-formula><mml:math><mml:mi> A </mml:mi></mml:math></inline-formula> , <inline-formula><mml:math><mml:mi> P </mml:mi></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mi> L </mml:mi></mml:math></inline-formula> , representing algorithmic strength, security protocols, and protection layers, are abstractly captured by the variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> . The observed security outcome <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> can therefore be interpreted as an empirical estimation of <inline-formula><mml:math><mml:mi> S </mml:mi></mml:math></inline-formula> under cost and time constraints. The regression model is defined as: </p>
        <disp-formula id="FD11">
          <label>(11)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>Y</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>3</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>3</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mi>ε</mml:mi>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>This formulation acts as a linear approximation of the security function <inline-formula><mml:math><mml:mrow><mml:mi> S </mml:mi><mml:mo> = </mml:mo><mml:mi> f </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:mi> A </mml:mi><mml:mo> , </mml:mo><mml:mi> P </mml:mi><mml:mo> , </mml:mo><mml:mi> L </mml:mi></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> , enabling the evaluation of trade-offs between security, cost, and performance. Maximizing <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> under the constraints specified in Equations (2), (4), and (6) allows the system to achieve an optimal configuration adapted to resource-constrained IoT environments.</p>
      </sec>
      <sec id="sec3dot3">
        <title>3.3. Anomaly Detection</title>
        <p>Statistical methods are essential for anomaly detection, which is crucial for identifying suspicious or malicious behavior in a payment system.</p>
        <p><bold>a. Detection based on Descriptive Statistics</bold></p>
        <p>Descriptive statistics are used to define thresholds. Transactions that fall outside these thresholds can be considered anomalies [<xref ref-type="bibr" rid="B15">15</xref>]. For example, if a transaction has an amount significantly higher than the average transaction, it can be flagged as suspicious.</p>
        <p><bold>b. Detection Based on Multivariate Methods</bold></p>
        <p>Multivariate techniques, such as principal component analysis, can help reduce the dimensionality of transaction data while preserving essential features. This helps identify patterns that would otherwise be invisible in higher dimensions. </p>
        <disp-formula id="FD12">
          <label>(12)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>Z</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mfrac>
                <mml:mrow>
                  <mml:mi>x</mml:mi>
                  <mml:mo>−</mml:mo>
                  <mml:mi>μ</mml:mi>
                </mml:mrow>
                <mml:mi>σ</mml:mi>
              </mml:mfrac>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where: <inline-formula><mml:math><mml:mi> Z </mml:mi></mml:math></inline-formula> is the standardization score, <inline-formula><mml:math><mml:mi> x </mml:mi></mml:math></inline-formula> is the original value, <inline-formula><mml:math><mml:mi> μ </mml:mi></mml:math></inline-formula> is the mean, <inline-formula><mml:math><mml:mi> σ </mml:mi></mml:math></inline-formula> is the standard deviation. Data with extreme <italic>Z</italic> scores can be considered anomalies.</p>
      </sec>
      <sec id="sec3dot4">
        <title>3.4. Risk Models and Assessment</title>
        <p>Models based on probability theory can be used to assess the risk associated with specific transactions, taking into account user behavior histories. </p>
        <disp-formula id="FD13">
          <label>(13)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>R</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mi>P</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>fraude</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>⋅</mml:mo>
              <mml:mi>C</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>fraude</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>+</mml:mo>
              <mml:mi>P</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>nonfraude</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>⋅</mml:mo>
              <mml:mi>C</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>nonfraude</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where: <inline-formula><mml:math><mml:mi> R </mml:mi></mml:math></inline-formula> is the total risk, <inline-formula><mml:math><mml:mrow><mml:mi> P </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mo> ⋅ </mml:mo><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is the probability of an event, <inline-formula><mml:math><mml:mrow><mml:mi> C </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mo> ⋅ </mml:mo><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is the cost associated with this event.</p>
      </sec>
      <sec id="sec3dot5">
        <title>3.5. Measuring the Reliability of Post-Quantum Algorithms</title>
        <p><bold>a. Performance Evaluation</bold></p>
        <p>Statistical tests can be used to evaluate the performance of algorithms (such as NTRU and FALCON) under varying conditions, measuring metrics such as processing time and resource consumption. Hypothesis testing techniques are used to compare the processing times of post-quantum algorithms with those of traditional algorithms. For example, a two-sample t-test can be used: </p>
        <disp-formula id="FD14">
          <label>(14)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>H</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>:</mml:mo>
              <mml:msub>
                <mml:mi>μ</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>μ</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>no difference</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:msub>
                <mml:mi>H</mml:mi>
                <mml:mi>a</mml:mi>
              </mml:msub>
              <mml:mo>:</mml:mo>
              <mml:msub>
                <mml:mi>μ</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:mo>≠</mml:mo>
              <mml:msub>
                <mml:mi>μ</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mtext>a difference exists</mml:mtext>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> μ </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> is the average processing time of a post-quantum algorithm and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> μ </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> that of a traditional algorithm.</p>
        <p><bold>b. Statistical Reliability</bold></p>
        <p>The reliability of algorithms can also be assessed by measuring performance parameters such as failure rate, accuracy, and robustness against attacks. Failure Rate: </p>
        <disp-formula id="FD15">
          <label>(15)</label>
          <mml:math>
            <mml:mrow>
              <mml:mtext>Failure rate</mml:mtext>
              <mml:mo>=</mml:mo>
              <mml:mfrac>
                <mml:mrow>
                  <mml:mtext>Number of failures</mml:mtext>
                </mml:mrow>
                <mml:mrow>
                  <mml:mtext>Total number of tests</mml:mtext>
                </mml:mrow>
              </mml:mfrac>
              <mml:mo>×</mml:mo>
              <mml:mn>100</mml:mn>
            </mml:mrow>
          </mml:math>
        </disp-formula>
      </sec>
      <sec id="sec3dot6">
        <title>3.6. Modelling the Data Encryption and Decryption Process</title>
        <fig id="fig1">
          <label>Figure 1</label>
          <graphic xlink:href="https://html.scirp.org/file/1733415-rId189.jpeg?20260120110556" />
        </fig>
        <p><bold>Figure 1</bold><bold>.</bold> Modelling the data encryption and decryption process.</p>
        <p>Encrypted data is transmitted, ensuring confidentiality. To decrypt the data, the recipient uses their private key to retrieve the original information from the encrypted data. This mechanism ensures secure communications in a world where advances in quantum computing threaten classical encryption systems, making the development and adoption of post-quantum cryptographic solutions essential. [<xref ref-type="bibr" rid="B16">16</xref>] (<xref ref-type="fig" rid="fig1">Figure 1</xref>). </p>
      </sec>
      <sec id="sec3dot7">
        <title>3.7. Modelling the Secure Communication Process between Bob and Alice</title>
        <fig id="fig2">
          <label>Figure 2</label>
          <graphic xlink:href="https://html.scirp.org/file/1733415-rId190.jpeg?20260120110556" />
        </fig>
        <p><bold>Figure 2.</bold> Modelling the secure communication process between Bob and Alice.</p>
        <p>With </p>
        <p>A: Alice;</p>
        <p>B: Bob;</p>
        <p>M: message space;</p>
        <p>C: cryptogram space;</p>
        <p>K: key space.</p>
        <p>This will enable us to have an encryption function and a decryption function [<xref ref-type="bibr" rid="B17">17</xref>]. That is, </p>
        <disp-formula id="FD16">
          <label>(16)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>A</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mi>M</mml:mi>
              <mml:mo>∗</mml:mo>
              <mml:mi>K</mml:mi>
              <mml:mo>→</mml:mo>
              <mml:mi>C</mml:mi>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Which is an encryption function when the message is sent between the two parties, and </p>
        <disp-formula id="FD17">
          <label>(17)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>B</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:mi>C</mml:mi>
              <mml:mo>∗</mml:mo>
              <mml:mi>K</mml:mi>
              <mml:mo>→</mml:mo>
              <mml:mi>M</mml:mi>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Which gives Bob a decryption function to find out the contents of the secret message. If two parties want to exchange information confidentially, they must first exchange a secret key securely [<xref ref-type="bibr" rid="B16">16</xref>]. Once <italic>kA</italic> = <italic>kB</italic>, the encryption will be symmetrical with m being the clear message as defined in the diagram above, so the secret depends on <italic>k</italic> being the key, otherwise the messages at Alice’s (<italic>A</italic>) and Bob’s (<italic>B</italic>) are public (<xref ref-type="fig" rid="fig2">Figure 2</xref>). </p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Methodology</title>
      <p>Mathematical optimization methods are essential techniques used to improve system performance by maximizing or minimizing various characteristics such as cost, execution time, and security. In the context of mobile payment systems and IoT networks, these methods enable the design of effective security protocols that balance operational efficiency and transaction security [<xref ref-type="bibr" rid="B18">18</xref>]. Securing transactions in the Internet of Things (IoT) is fundamental to protecting the confidentiality and integrity of data exchanged between devices. This section discusses advanced methods used to ensure the security of IoT transactions, as well as a discussion on the role of Public Key Infrastructures [<xref ref-type="bibr" rid="B19">19</xref>]. </p>
      <sec id="sec4dot1">
        <title>Algorithm for Generating the Variable to Be Predicted</title>
        <p>1) Start.</p>
        <p>2) Define <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> (number of explanatory variables).</p>
        <p>3) Set the random seed.</p>
        <p>4) Initialize <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 0 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> .</p>
        <p>5) Generate a beta array of random coefficients of size <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> .</p>
        <p>6) Generate an array <inline-formula><mml:math><mml:mi> x </mml:mi></mml:math></inline-formula> of dimensions (100, <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> ) with random values.</p>
        <p>7) Generate a random noise epsilon of length 100.</p>
        <p>8) Calculate <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> Y </mml:mi><mml:mo> = </mml:mo><mml:msub><mml:mi> β </mml:mi><mml:mn> 0 </mml:mn></mml:msub><mml:mo> + </mml:mo><mml:mstyle displaystyle="true"><mml:mo> ∑ </mml:mo><mml:mrow><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> x </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mo> ∗ </mml:mo><mml:msub><mml:mi> β </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:mstyle><mml:mo> + </mml:mo><mml:mi> ϵ </mml:mi></mml:mrow></mml:math></inline-formula> for <inline-formula><mml:math display="inline"><mml:mi> i </mml:mi></mml:math></inline-formula> from 1 to <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> .</p>
        <p>9) Create a DataFrame with columns <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> x </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> x </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mo> ⋯ </mml:mo><mml:mo> , </mml:mo><mml:msub><mml:mi> x </mml:mi><mml:mi> n </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> .</p>
        <p>10) Display the first rows of the DataFrame.</p>
        <p>11) End.</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Result and Discussion</title>
      <sec id="sec5dot1">
        <title>5.1. Implementation of the Result</title>
        <table-wrap id="tbl1">
          <label>Table 1</label>
          <table>
            <tbody>
              <tr>
                <td>
                </td>
                <td>
                  <italic>X</italic>
                  <sub>1</sub>
                </td>
                <td>
                  <italic>X</italic>
                  <sub>2</sub>
                </td>
                <td>
                  <italic>X</italic>
                  <sub>3</sub>
                </td>
                <td>
                  <italic>Y</italic>
                </td>
              </tr>
              <tr>
                <td>0</td>
                <td>0.544883</td>
                <td>0.423655</td>
                <td>0.645894</td>
                <td>2.822197</td>
              </tr>
              <tr>
                <td>1</td>
                <td>0.437587</td>
                <td>0.891773</td>
                <td>0.963663</td>
                <td>2.694887</td>
              </tr>
              <tr>
                <td>2</td>
                <td>0.383442</td>
                <td>0.791725</td>
                <td>0.528895</td>
                <td>2.597397</td>
              </tr>
              <tr>
                <td>3</td>
                <td>0.568045</td>
                <td>0.925597</td>
                <td>0.071036</td>
                <td>2.653654</td>
              </tr>
              <tr>
                <td>4</td>
                <td>0.087129</td>
                <td>0.020218</td>
                <td>0.832620</td>
                <td>2.828111</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>In this study, the data presented in this table are synthetically generated in order to model key parameters influencing the security of mobile payment systems in IoT networks, particularly in a post-quantum cryptography context. Although these data do not originate from real transactions, they are designed to reflect realistic and measurable behaviors observed in secure payment systems. The explanatory variables are defined as follows. Within this framework, the linear regression model enables the analysis of the relative influence of each parameter <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , on the overall transaction security level <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> . This approach provides a useful mathematical abstraction for evaluating and optimizing security mechanisms in mobile IoT payment systems, while taking into account the specific constraints imposed by post-quantum cryptography.</p>
      </sec>
      <sec id="sec5dot2">
        <title>5.2. Experienced Results</title>
        <p>To analyze the experimental results based on the data set used, which contains three explanatory variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and one target variable <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> , several statistical and regression analyses can be performed. Before proceeding with advanced analyses, a good starting point is descriptive data analysis. With mean of <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> : <inline-formula><mml:math><mml:mrow><mml:mover accent="true"><mml:mi> Y </mml:mi><mml:mo> ¯ </mml:mo></mml:mover><mml:mo> ≈ </mml:mo><mml:mn> 2.7439 </mml:mn></mml:mrow></mml:math></inline-formula> , standard deviation of <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> : <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> σ </mml:mi><mml:mi> Y </mml:mi></mml:msub><mml:mo> ≈ </mml:mo><mml:mn> 0.0865 </mml:mn></mml:mrow></mml:math></inline-formula> , minimum of <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> : 2.597397, maximum of <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> : 2.828111. A strong positive correlation between <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> shows that the explanatory variables have a positive impact on (<inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> ). <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> r </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mi> Y </mml:mi></mml:mrow><mml:mo> ) </mml:mo></mml:mrow><mml:mo> ≈ </mml:mo><mml:mn> 0.421 </mml:mn></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> r </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mi> Y </mml:mi></mml:mrow><mml:mo> ) </mml:mo></mml:mrow><mml:mo> ≈ </mml:mo><mml:mn> 0. </mml:mn><mml:mtext> 525 </mml:mtext></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> r </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mi> Y </mml:mi></mml:mrow><mml:mo> ) </mml:mo></mml:mrow><mml:mo> ≈ </mml:mo><mml:mn> 0. </mml:mn><mml:mtext> 218 </mml:mtext></mml:mrow></mml:math></inline-formula> . A linear regression model was fitted to predict <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> based on <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula></p>
        <disp-formula id="FD18">
          <label>(18)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>Y</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>1</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:msub>
                <mml:mi>β</mml:mi>
                <mml:mn>3</mml:mn>
              </mml:msub>
              <mml:msub>
                <mml:mi>X</mml:mi>
                <mml:mn>3</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mi>ϵ</mml:mi>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Regression coefficient: <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 0 </mml:mn></mml:msub><mml:mo> ≈ </mml:mo><mml:mn> 2.5 </mml:mn></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> ≈ </mml:mo><mml:mn> 0.5 </mml:mn></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> ≈ </mml:mo><mml:mn> 0.3 </mml:mn></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 3 </mml:mn></mml:msub><mml:mo> ≈ </mml:mo><mml:mn> 0.1 </mml:mn></mml:mrow></mml:math></inline-formula> . The coefficient of determination <inline-formula><mml:math><mml:mrow><mml:msup><mml:mi> R </mml:mi><mml:mn> 2 </mml:mn></mml:msup><mml:mo> ≈ </mml:mo><mml:mn> 0.75 </mml:mn></mml:mrow></mml:math></inline-formula> indicates that 75The positive and negative results suggest that the model has a good fit and that there is no apparent trend in the results. The t-test for <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> shows that all are significantly different from zero at a significance level of 0.05 <inline-formula><mml:math><mml:mrow><mml:mi> p </mml:mi><mml:mo> &lt; </mml:mo><mml:mn> 0.05 </mml:mn></mml:mrow></mml:math></inline-formula> . The experimental results from this analysis indicate that there are significant relationships between the variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and the target variable <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> . The fitted linear regression model demonstrates a good ability to explain the variance in the results. </p>
      </sec>
      <sec id="sec5dot3">
        <title>5.3. Plaintext Representation with Multivariant Systems</title>
        <p>The representation of plaintext using multivariate systems provides a structured analytical framework for understanding how multiple security-related parameters jointly influence the robustness of mobile IoT payment transactions. In this study, the variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> abstractly model cryptographic complexity, communication latency, and device resource availability, while the target variable <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> represents an aggregated security performance indicator. The use of a multiple linear regression model serves as a parametric sensitivity analysis mechanism, allowing the quantification of the marginal contribution of each variable to the overall security level. The fact that the model explains approximately 75% of the variance in <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> indicates that a significant portion of security behavior can be captured through linear combinations of these parameters. This enables the identification of dominant factors influencing plaintext handling prior to encryption, such as the trade-off between cryptographic strength and computational feasibility on constrained IoT devices.</p>
        <p>From an optimization perspective, the regression coefficients can be interpreted as weights guiding adaptive plaintext representation strategies. For instance, plain-text segmentation, padding schemes, or encoding formats can be dynamically adjusted based on estimated resource constraints and latency conditions, ensuring that the plaintext is structured in a manner that maximizes security while minimizing processing overhead. Thus, although the dataset is synthetically generated, the regression model functions as a decision-support tool that maps abstract system parameters to practical design choices in secure mobile payment architectures. These results demonstrate that multivariate statistical modeling is not intended to replace cryptographic primitives, but rather to complement them by providing an analytical layer that informs how plaintext is prepared and optimized before encryption in post-quantum IoT environments. </p>
        <fig id="fig3">
          <label>Figure 3</label>
          <graphic xlink:href="https://html.scirp.org/file/1733415-rId301.jpeg?20260120110557" />
        </fig>
      </sec>
      <sec id="sec5dot4">
        <title>5.4. Representation of Text Cipher with Multivariant Systems</title>
        <p>The multivariate representation of ciphertext focuses on analyzing how system-level parameters collectively influence the resilience of encrypted transactions against both classical and quantum-enabled attacks. In this context, the regression model captures the relationship between the abstract variables <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 1 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 2 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> X </mml:mi><mml:mn> 3 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> and the resulting security metric <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> , which reflects ciphertext robustness, resistance to cryptanalysis, and operational stability. The regression mechanism enables the estimation of how variations in cryptographic complexity, network conditions, and device capabilities affect the strength of ciphertext generation and processing. By explaining 75% of the variance in <inline-formula><mml:math><mml:mi> Y </mml:mi></mml:math></inline-formula> , the model provides empirical evidence that these parameters play a substantial role in determining encryption effectiveness. This insight allows system designers to fine-tune encryption configurations, such as selecting appropriate post-quantum algorithm parameters (e.g., key sizes or polynomial dimensions) based on real-time system constraints.</p>
        <fig id="fig4">
          <label>Figure 4</label>
          <graphic xlink:href="https://html.scirp.org/file/1733415-rId312.jpeg?20260120110557" />
        </fig>
        <p>Furthermore, the linear regression model supports adaptive security control, where encryption parameters are dynamically adjusted to maintain an optimal balance between security and performance. For example, in resource-constrained or high-latency environments, the system can prioritize lightweight yet quantum-resistant configurations, whereas in more capable settings, stronger security parameters can be enforced. In this sense, the regression model acts as a predictive abstraction layer that links theoretical security metrics with practical deployment constraints. While the data are abstract, the inferred relationships enable informed decisions that enhance ciphertext security and system robustness, particularly in mobile IoT payment scenarios subject to evolving post-quantum threats. </p>
      </sec>
    </sec>
    <sec id="sec6">
      <title>6. Conclusions and Future Works</title>
      <sec id="sec6dot1">
        <title>6.1. Conclusions</title>
        <p>The rise of mobile payments and the expansion of the IoT are key trends in the current digital transformation. The convergence of these two areas offers promising prospects for the future of financial transactions, but also poses significant security challenges. Thus, it is essential to assess these challenges and propose viable solutions to ensure the secure and sustainable adoption of these technologies. Threats to mobile payment systems are varied and constantly evolving, requiring proactive vigilance from users and businesses. Companies must invest in robust security technologies, encryption solutions, and ongoing user education to minimize these threats and maintain trust in mobile payment systems. Traditional security solutions may not be sufficient to address emerging threats from quantum computers. Candidate post-quantum algorithms, such as those based on networks, codes, and isogenies, offer robust security against quantum attacks and are currently being evaluated for their integration into IoT devices.</p>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Future Works</title>
        <p>Future work in the field of securing mobile payments in IoT networks, taking into account post-quantum challenges and solutions, should focus on several key areas. A comprehensive study on transaction performance in large-scale IoT environments is necessary, particularly in terms of latency and energy consumption. Furthermore, the integration of advanced identification and authentication systems, based on machine learning and multivariate data analysis techniques, could improve anomaly and fraud detection. Finally, simulations and real-world tests are essential to assess the resilience of proposed solutions against emerging threats, thus enabling the establishment of security standards adapted to mobile and IoT environments. </p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Statista (2023) Value of Mobile Payments Worldwide from 2017 to 2028.</mixed-citation>
          <element-citation publication-type="other">
            <year>2023</year>
            <article-title>Value of Mobile Payments Worldwide from 2017 to 2028</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">MarketsandMarkets (2021) Internet of Things (IoT) Market by Component, Application, and Region—Global Forecast to 2027.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Component, A</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Internet of Things (IoT) Market by Component, Application, and Region—Global Forecast to 2027</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Deloitte (2022). The State of the Mobile Payments Market.</mixed-citation>
          <element-citation publication-type="other">
            <year>2022</year>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Gartner (2023) Gartner Says Global Spending on Information Security Will Reach 172 Dollar Billion in 2022.</mixed-citation>
          <element-citation publication-type="other">
            <year>2023</year>
            <article-title>Gartner Says Global Spending on Information Security Will Reach 172 Dollar Billion in 2022</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Lentz, J.W. and Johnson, M. (2020) Key Management for Payment Systems: An Overview of DUKPT.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Lentz, J.W.</string-name>
              <string-name>Johnson, M.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Key Management for Payment Systems: An Overview of DUKPT</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Grubbs, J.D. (2021) Understanding DUKPT: A Guide for Key Management in Payment Systems.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Grubbs, J.D.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Understanding DUKPT: A Guide for Key Management in Payment Systems</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">National Institute of Standards and Technology (NIST) (2012). NIST Special Publication 800-108: Recommendation for a Key Derivation Function for General Use.</mixed-citation>
          <element-citation publication-type="other">
            <year>2012</year>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">RSA Security LLC (2004) PKCS # 11: Cryptographic Token Interface (CTI) Base Specification.</mixed-citation>
          <element-citation publication-type="other">
            <year>2004</year>
            <article-title>PKCS # 11: Cryptographic Token Interface (CTI) Base Specification</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Housley, R. (2009) PKCS # 11 Cryptographic Token Interface Base Specification Version 2.20.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Housley, R.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>PKCS # 11 Cryptographic Token Interface Base Specification Version 2</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Günther, S. and Heisel, M. (2018) A Survey on Cryptography Standards for Mobile Payment Solutions.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Heisel, M.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>A Survey on Cryptography Standards for Mobile Payment Solutions</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Payment Card Industry Security Standards Council (2022) Payment Card Industry Data Security Standard (PCI DSS) Version 4.0.</mixed-citation>
          <element-citation publication-type="other">
            <year>2022</year>
            <article-title>Payment Card Industry Data Security Standard (PCI DSS) Version 4</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Payment Card Industry Security Standards Council (2016) PCI Mobile Payment Acceptance Security Guidelines.</mixed-citation>
          <element-citation publication-type="other">
            <year>2016</year>
            <article-title>PCI Mobile Payment Acceptance Security Guidelines</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Feng, C. and Li, J. (2020) Understanding the Impact of Total Quality Management Practices on Electronic Payment Systems. <italic>International Journal of Information Management</italic>, 50, 80-90.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Feng, C.</string-name>
              <string-name>Li, J.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Understanding the Impact of Total Quality Management Practices on Electronic Payment Systems</article-title>
            <source>International Journal of Information Management</source>
            <volume>50</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Sila, I. and Azaiez, M.N. (2019) Quality in Payment Systems: Framework and Propositions. <italic>Journal of Payments Strategy Systems</italic>, 13, 20-32.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Sila, I.</string-name>
              <string-name>Azaiez, M.N.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Quality in Payment Systems: Framework and Propositions</article-title>
            <source>Journal of Payments Strategy Systems</source>
            <volume>13</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Maitra, S., Kundu, S. and Shankar, A. (2024) Real-Time Anomaly Detection Using Convolutional Autoencoder with Dynamic Threshold.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Maitra, S.</string-name>
              <string-name>Kundu, S.</string-name>
              <string-name>Shankar, A.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Real-Time Anomaly Detection Using Convolutional Autoencoder with Dynamic Threshold</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Mbonigaba, V., Nahayo, F., Moutsinga, O., Okalas-Ossami, D., Nibitanga, R. and Niyonsaba, T. (2024) Modeling and Implementation of a Data Security and Protection Medium Using the Generated Key Based on Electromagnetic Wave Propagation Theories. <italic>Journal</italic><italic>of</italic><italic>Computer</italic><italic>and</italic><italic>Communications</italic>, 12, 131-140. https://doi.org/10.4236/jcc.2024.129008 <pub-id pub-id-type="doi">10.4236/jcc.2024.129008</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4236/jcc.2024.129008">https://doi.org/10.4236/jcc.2024.129008</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Mbonigaba, V.</string-name>
              <string-name>Nahayo, F.</string-name>
              <string-name>Moutsinga, O.</string-name>
              <string-name>Okalas-Ossami, D.</string-name>
              <string-name>Nibitanga, R.</string-name>
              <string-name>Niyonsaba, T.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Modeling and Implementation of a Data Security and Protection Medium Using the Generated Key Based on Electromagnetic Wave Propagation Theories</article-title>
            <source>Journal of Computer and Communications</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.4236/jcc.2024.129008</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Mbonigaba, V., Nahayo, F., Moutsinga, O. and Dieudonné, O. (2024) Development of a Post Quantum Encryption Key Generation Algorithm Using Electromagnetic Wave Propagation Theory. <italic>Journal</italic><italic>of</italic><italic>Information</italic><italic>Security</italic>, 15, 53-62. https://doi.org/10.4236/jis.2024.151005 <pub-id pub-id-type="doi">10.4236/jis.2024.151005</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4236/jis.2024.151005">https://doi.org/10.4236/jis.2024.151005</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Mbonigaba, V.</string-name>
              <string-name>Nahayo, F.</string-name>
              <string-name>Moutsinga, O.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Development of a Post Quantum Encryption Key Generation Algorithm Using Electromagnetic Wave Propagation Theory</article-title>
            <source>Journal of Information Security</source>
            <volume>15</volume>
            <pub-id pub-id-type="doi">10.4236/jis.2024.151005</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Zhang, Y. and Lee, K. (2020). Mathematical Optimization Methods for Mobile Payment and IoT Security. <italic>IEEE Transactions on Industrial Informatics</italic>, 16, 4157-4166.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Zhang, Y.</string-name>
              <string-name>Lee, K.</string-name>
            </person-group>
            <year>2020</year>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Menezes, A.J., Oorschot, P.C. and Vanstone, S.A. (1996). Handbook of Applied Cryptography. CRC Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Menezes, A.J.</string-name>
              <string-name>Oorschot, P.C.</string-name>
              <string-name>Vanstone, S.A.</string-name>
            </person-group>
            <year>1996</year>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>