<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">AM</journal-id><journal-title-group><journal-title>Applied Mathematics</journal-title></journal-title-group><issn pub-type="epub">2152-7385</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/am.2013.47142</article-id><article-id pub-id-type="publisher-id">AM-34315</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Physics&amp;Mathematics</subject></subj-group></article-categories><title-group><article-title>
 
 
  New Practical Algebraic Public-Key Cryptosystem and Some Related Algebraic and Computational Aspects
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>.</surname><given-names>K. Rososhek</given-names></name><xref ref-type="aff" rid="aff1"><sub>1</sub></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><label>1</label><addr-line>Faculty of Mathematics and Mechanics, Tomsk State University, Tomsk, Russia</addr-line></aff><author-notes><corresp id="cor1">* E-mail:<email>rososhek@list.ru</email></corresp></author-notes><pub-date pub-type="epub"><day>28</day><month>06</month><year>2013</year></pub-date><volume>04</volume><issue>07</issue><fpage>1043</fpage><lpage>1049</lpage><history><date date-type="received"><day>April</day>	<month>26,</month>	<year>2013</year></date><date date-type="rev-recd"><day>May</day>	<month>26,</month>	<year>2013</year>	</date><date date-type="accepted"><day>June</day>	<month>6,</month>	<year>2013</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
   The most popular present-day public-key cryptosystems are RSA and ElGamal cryptosystems. Some practical algebraic generalization of the ElGamal cryptosystem is considered-basic modular matrix cryptosystem (BMMC) over the modular matrix ring M<sub>2</sub>(Z<sub>n</sub>). An example of computation for an artificially small number n is presented. Some possible attacks on the cryptosystem and mathematical problems, the solution of which are necessary for implementing these attacks, are studied. For a small number n, computational time for compromising some present-day public-key cryptosystems such as RSA, ElGamal, and Rabin, is compared with the corresponding time for the ВММС. Finally, some open mathematical and computational problems are formulated. 
 
</p></abstract><kwd-group><kwd>Public-Key Cryptosystem; Modular Matrix Ring</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Security of some present-day public-key cryptosystems is based on computational complexity of some numbertheoretical problems. Two of these problems are used most often: the integer factorization problem and the discrete logarithm problem. These problems ensure the security of the RSA and ElGamal cryptosystems, as well as of the corresponding digital signature schemes [<xref ref-type="bibr" rid="scirp.34315-ref1">1</xref>].</p><p>However, the true level of the computational complexity of these problems is unknown. That is to say, they are widely believed to be intractable, although no proof of this fact is known.</p><p>In [<xref ref-type="bibr" rid="scirp.34315-ref2">2</xref>], randomized polynomial-time algorithms for computing discrete logarithms and integer factoring were presented for the quantum computer.</p><p>Nevertheless, some alternatives should be proposed. One of possible approaches is to replace number-theoretical cryptosystems by such algebraic cryptosystems that would be resistant to an attack on a quantum computer.</p><p>Let us now consider some scheme of cryptosystems, namely, cryptosystems of group rings.</p><p>In the author’s work [3,4], a scheme of group ring cryptosystems was proposed. The idea to apply group rings in cryptography is based on the fact that if we fix the cardinality of a finite ring R, the cardinality of the group ring RG for a finite group G is an exponent of the cardinality of the group G. Then, a legal user can perform cryptographic transformations separately in the ring R and in the group G using polynomial algorithms and the illegal user has to solve computationally difficult problems in the group ring RG.</p><p>Let us consider the standardization problem in the group ring and two its aspects. The direct standardization problem is to construct a standard automorphism g of the group ring RG from an automorphism a of the group G and automorphism b of the ring R in the following way: if an element х of the group ring RG is represented as a formal linear combination of elements <img src="10-7401524\e86854c8-fce4-4944-a323-d1754e2b3382.jpg" /> of the group G with coefficients r<sub>i</sub> from the ring R, then the image of the element х under the action of g is a formal linear combination of images of the elements g<sub>i</sub> of the group G under the action of a with coefficients that are images of the coefficients r<sub>i</sub> under the action of b.</p><p>The inverse standardization problem is formulated as follows. For a given automorphism g of a group ring RG, find an automorphism a of the group G and an automorphism b of the ring R such that g can be constructed from a and b by the way that was mentioned in the direct standardization problem or prove that such automorphisms a and b do not exist.</p><p>It is easy to see that, in the case of an efficient specification of the automorphism a in the group G and of the automorphism b in the ring R, one can efficiently compute the action of the automorphism g on any element of the group ring RG, i.e., efficiently specify the automorphism g of the ring RG.</p><p>As for the inverse standardization problem, there are some reasons to believe that this problem is computationally difficult. However, there is no proof for this statement.</p><p>In [<xref ref-type="bibr" rid="scirp.34315-ref5">5</xref>] some generalization of group ring cryptosystem is considered in the case of quasigroup ring.</p><p>The question “For which finite commutative rings R and finite groups G all automorphisms of the group ring RG are standard automorphisms?” was partially answered in [6-8]. It should be noted that an inner automorphism of an integral group ring of a finite group is not a standard automorphism as a rule. This is why, together with the standard automorphisms of the group ring<img src="10-7401524\ce9a4585-8e04-4032-9d71-b7cf2c495c32.jpg" />, where G is a finite group, we use inner automorphisms. In [<xref ref-type="bibr" rid="scirp.34315-ref9">9</xref>] the group ring<img src="10-7401524\8fe03583-f430-4f39-b901-3dea98ac01e4.jpg" />, where <img src="10-7401524\632aa60f-8488-40a8-83fc-7ca3282a1fd6.jpg" /> is the permutation group for three symbols, is represented in a matrix form as block diagonal matrices of the fourth degree with two one-dimensional blocks and one two-dimensional block. In [9,10] it is shown that the unit group of the group ring <img src="10-7401524\7fee523b-a41e-4f41-b641-8f87aed0fed0.jpg" /> is a semi-direct product of trivial units <img src="10-7401524\88e92c1f-b854-4c80-84d4-66fde0dfa86b.jpg" /> and a free subgroup of rank 3. Since matrices of the fourth degree from this subgroup contain two identity one-dimensional blocks, we can restrict ourselves by a free group of matrices of the second degree with the free generators [<xref ref-type="bibr" rid="scirp.34315-ref9">9</xref>]:</p><p><img src="10-7401524\3d1a040d-882d-46c2-b3c8-433ea9de5546.jpg" /></p><p>If we fall outside the limits of the matrix representation of<img src="10-7401524\118d8d9f-2352-4cd5-9a0a-9a3373a9971e.jpg" />, we consider arbitrary matrices of the second degree from the ring <img src="10-7401524\fe84c3fb-d269-4184-8d65-255d969af838.jpg" /> and its unit group<img src="10-7401524\462b7ba6-6c16-40de-83fe-d5ed9f7613d8.jpg" />, which contains free rank 3 subgroups <img src="10-7401524\c79850a2-01d1-4981-89e7-6ba9ba277e59.jpg" /> with the free generators</p><p><img src="10-7401524\164ddbba-9cc5-4289-8497-4cca639ee7bf.jpg" /></p><p>where <img src="10-7401524\40b4c91d-d536-4796-9887-76662746e6b0.jpg" /> and <img src="10-7401524\6052b26d-b8a2-4ed3-a8c3-a08332448b04.jpg" /> [<xref ref-type="bibr" rid="scirp.34315-ref11">11</xref>]. For example, if<img src="10-7401524\d3b10b73-53e1-46ac-bdee-cf48e68bac31.jpg" />, we obtain a free rank 3 subgroup <img src="10-7401524\905ddd1c-37a5-4c35-9e90-7f68bc036dd5.jpg" /> with the aforesaid free generators А, В, and С.</p><p>It should be also noted that all automorphisms of the group ring <img src="10-7401524\0d964b0c-cf9a-4c56-b07f-cf110ac1fd04.jpg" /> are inner [<xref ref-type="bibr" rid="scirp.34315-ref12">12</xref>].</p><p>New practical algebraic generalization of the ElGamal cryptosystem will be given in the Section 2, some attacks on this cryptosystem—in the Section 4, new hard computational problems—in the Section 5, comparison of the security level of classical RSA, ElGamal and Rabin cryptosystems with security level of this cryptosystem for the same small number—in the Section 7, some related open mathematical and computational problems— in the Section 8. It should be noted, that some other theoretical algebraic generalizations of the ElGamal cryptosystem are given in [13,14].</p></sec><sec id="s2"><title>2. Basic Modular Matrix Cryptosystem (BMMC)</title><sec id="s2_1"><title>2.1. Key Generation</title><p>User А does the following:</p><p>1) picks large random positive integer n;</p><p>2) picks the random words <img src="10-7401524\38edb299-a934-4c25-96bd-7aeb2f9f53e9.jpg" /> and <img src="10-7401524\330abb80-60b8-4749-b0aa-4efc769019f1.jpg" /> in the alphabet <img src="10-7401524\f1ec5b44-41cc-4519-b8e6-877ea69cb655.jpg" /> in a free rank 3 group with free generators А, В, and С;</p><p>3) computes the noncommuting matrices <img src="10-7401524\682c7fdb-91bb-4dcc-ab22-39053b6f9aab.jpg" /> by replacing the symbols А, В, and С in the words <img src="10-7401524\fc74dec1-1c3b-497f-a479-d619c7bf6f0a.jpg" /> and <img src="10-7401524\ca770c55-f09d-43fa-a617-5511fc2dbfad.jpg" /> by the corresponding matrices</p><p><img src="10-7401524\10b6a453-1215-4c6d-b6d9-d19f3480d40d.jpg" /></p><p>and performing matrix computations modulo n, i.e.,</p><p><img src="10-7401524\177c7f92-bdb3-4c01-a10d-ab698223cee4.jpg" /></p><p>If <img src="10-7401524\9371b405-a99f-466b-9819-ef81f07754e5.jpg" /> and <img src="10-7401524\8c9fe24f-1021-41e6-a4dc-edbf85e43d4b.jpg" /> commute, then return to 2);</p><p>4) let <img src="10-7401524\a1366b16-08cd-4fe1-8e8f-90771ef186fc.jpg" /> be the cardinality of the group <img src="10-7401524\6e884088-65d5-4ad2-a57b-299ced314b66.jpg" /> over <img src="10-7401524\c13fcd47-9b94-4847-a137-8022a166648f.jpg" />-residue ring modulo n, then user A picks the random integers</p><p><img src="10-7401524\4841bd99-0457-4e84-9ccd-e31fa6d794d1.jpg" /></p><p>5) public key of user А is</p><p><img src="10-7401524\92da6dac-9b50-4cae-a9c1-5ea6443b0d1a.jpg" /></p><p>and its private key is</p><p><img src="10-7401524\46d37730-921f-4681-a7d1-d4318335a1f9.jpg" /></p><p>Remark 1. Orders of matrices</p><p><img src="10-7401524\8f15aaf5-c00a-4c3b-aa2e-540802347c8d.jpg" /></p><p>in the group <img src="10-7401524\9b08aabb-3bd8-40f9-b101-597a7ef736d9.jpg" /> are equal to n;</p><p>Remark 2. The cardinality of the group <img src="10-7401524\86bc2e8f-d49d-4717-bd0a-0df97ca0d3ee.jpg" /> in the case<img src="10-7401524\286217c8-4753-4d1d-9c23-ee0390279405.jpg" />, p is a prime number, i is a positive integer, is equals to</p><p><img src="10-7401524\3b247aed-dbc6-48a9-be7d-e20fc2a1e18b.jpg" />[<xref ref-type="bibr" rid="scirp.34315-ref15">15</xref>].</p><p>As consequence in the case <img src="10-7401524\b2c31da0-5178-4c29-96b5-1e37509e8027.jpg" /> are primes, we have</p><p><img src="10-7401524\887691ae-2cfd-4856-b974-1f110fddc628.jpg" /></p></sec><sec id="s2_2"><title>2.2. Encryption</title><p>User В does the following:</p><p>1) writes the plaintext as a sequence of N numbers from<img src="10-7401524\ed27240f-e209-49d3-93fb-1652d128c856.jpg" />, where N is a multiple of 4, <img src="10-7401524\cc1b2467-bfaf-44ab-ad50-66048414f93c.jpg" />, adding, if necessary, numbers from the first quadruple by a cyclic permutation at the end of the sequence;</p><p>2) writes each quadruple of numbers of the obtained sequence similarly as matrix:</p><p><img src="10-7401524\28e2b7ea-5dd6-4108-bba8-1ec6d15f9920.jpg" /></p><p>3) picks session keys-random integers</p><p><img src="10-7401524\d6a8f944-c5fb-432c-86a9-d5826bcc330d.jpg" />for each of <img src="10-7401524\5e66e85d-1369-4727-93f3-48d99516f8f1.jpg" /> obtained matrices<img src="10-7401524\533c73fe-9b88-439e-be03-6fd175ea2b6c.jpg" />;</p><p>4) computes the ciphertext block for each matrix<img src="10-7401524\53058d09-8656-4b20-a09d-22c36bdc9569.jpg" />:</p><p><img src="10-7401524\65a8dc71-fb3e-4ac1-93c0-dbd54a5fd192.jpg" /></p></sec><sec id="s2_3"><title>2.3. Decryption</title><p>Using the private key, user А computes for each ciphertext block<img src="10-7401524\27e49fe8-90fe-4784-a6c8-8b7c93461674.jpg" />:</p><p><img src="10-7401524\8b75f9b4-a05f-438a-a031-21e168c4011f.jpg" /></p><p>After obtaining the sequence of matrices</p><p><img src="10-7401524\0e347ac9-b653-47f2-b9ea-1728f0f1f798.jpg" /></p><p>the sequence of numbers <img src="10-7401524\2b8e5021-19cf-4401-a1b5-782537fdf283.jpg" /> and hence the plaintext can be reconstructed uniquely.</p><p>Theorem. Decryption in the ВММС is correct.</p><p>Proof. It is sufficiently to consider a case of one block of the ciphertext:</p><p><img src="10-7401524\0f556cf3-21bf-417f-9515-6726354a33a1.jpg" /></p><p>It should be noted that algorithms of the BMMC are implemented using the algorithm of matrix modular exponentiation similar to the usual modular exponentiation algorithm in which multiplication of integers is replaced by multiplication of matrices with reduction of their elements modulo n. In addition parallel computations may be used in matrix multiplications to increase the computational efficiency of the cryptosystem.</p><p>Let n be a large 256 bit integer, then the cardinality bit length of the group <img src="10-7401524\73833eb2-d2ed-44d7-8e83-0e06da204a48.jpg" /> would be near 800 bits or more. For comparing in the case of the ElGamal cryptosystem the bit lengths of p and the cardinality of corresponding multiplicative group of residue field <img src="10-7401524\9394c833-5415-48f7-9323-21895527951b.jpg" /> are equal. But one reduction modulo 1024 bit number in the ElGamal cryptosystem costs as some reductions modulo 256 bit number in the BMMC. Therefore, under corresponding choice of parameters the BMMC may be faster than the ElGamal cryptosystem with the same security level, because the gybrid problem and the transformation problem are harder than the discrete logarithm problem in the groups of the same cardinality.</p></sec></sec><sec id="s3"><title>3. Example</title><sec id="s3_1"><title>3.1. Key Generation</title><p>User А does the following:</p><p>1) picks two prime numbers <img src="10-7401524\1fee4d0b-e3da-4797-9cfc-ff8086ca4d34.jpg" /> and <img src="10-7401524\09c7b1fd-b764-4358-80d0-50aed0d433be.jpg" /> and computes<img src="10-7401524\2814c99d-1732-46cd-b482-eb911066d974.jpg" />;</p><p>2) picks the words in the free group:</p><p><img src="10-7401524\55b5b1e4-d013-4cc5-83b3-28406c10a5f6.jpg" /></p><p>3) computes matrices modulo n:</p><p><img src="10-7401524\25d4260f-2736-4948-99f5-4af4e3d22dc4.jpg" /></p><p><img src="10-7401524\e1579598-861a-4b85-8a39-72ccd65ffc71.jpg" /></p><p>matrices <img src="10-7401524\0e72301b-82f6-44da-a50d-d6b085080c1a.jpg" /> and <img src="10-7401524\0b114fb3-20ac-4772-9793-d98b4ba13672.jpg" /> do not commute and, therefore, the user passes to the next step;</p><p>4) picks the integers <img src="10-7401524\5e14a29f-0c84-4fc9-8b66-1cd935135c7e.jpg" /></p><p>5) the public key is</p><p><img src="10-7401524\280cd20c-bf95-4a2f-8bc3-a255d0459127.jpg" /></p><p>the private key is<img src="10-7401524\46a2d5f8-0cda-43db-8fde-fe2fc26a631b.jpg" />.</p></sec><sec id="s3_2"><title>3.2. Encryption</title><p>User В does the following:</p><p>1) writes the plaintext as a sequence of numbers from<img src="10-7401524\d3f25e67-1fb9-4f02-adee-a65d41e3cf33.jpg" />. The length of this sequence is multiple of 4. If necessary, some numbers are added. For example, let the plaintext be</p><p><img src="10-7401524\c1815604-bc42-4673-ae97-9a2af7ca3f52.jpg" /></p><p>here, a number should be added to the last block by shifting the first number cyclically, the user obtains two quadruples of numbers from<img src="10-7401524\06205120-de10-4528-ae17-8be33f65a3af.jpg" />:</p><p><img src="10-7401524\8691bdee-47e1-4585-8ae6-8a543b4fcb77.jpg" /></p><p>2) writes the plaintext as two matrices from<img src="10-7401524\a8e64b9b-b2a6-4718-90c8-bee1f5e23b8d.jpg" />:</p><p><img src="10-7401524\4cf4a773-a92b-4690-b318-5648d52bc9ec.jpg" /></p><p>3) encrypts each block (matrix) separately choosing different session keys. For example, the first block is encrypted as follows;</p><p>4) picks the session key for the first block r<sub>1</sub> = 2, t<sub>1</sub> = 1;</p><p>5) computes the ciphertext of the first block modulo<img src="10-7401524\06c01582-3b67-49c5-8505-9aa28673483b.jpg" />:</p><p><img src="10-7401524\d9ed97d4-5303-443b-9a5c-fd587ba90fb6.jpg" /></p><p><img src="10-7401524\68817878-0e93-4bd6-a604-6ad4158a1813.jpg" /></p><p>The ciphertext of the second block <img src="10-7401524\94989910-6431-4986-9e9e-f130ededcd9a.jpg" /> is computed similarly with the choice of another session key<img src="10-7401524\84fc03bd-b90d-4914-9032-ea85b5509a7d.jpg" />.</p></sec><sec id="s3_3"><title>3.3. Decryption</title><p>User А, having obtained the ciphertext from user В, does the following: using its private key, for each ith block, computes</p><p><img src="10-7401524\7ad509fd-d22f-432a-8275-358c61e0bb0c.jpg" /></p><p>in particular, for the first block, he obtains</p></sec></sec><sec id="s4"><title>4. Some Attacks on ВММС</title><sec id="s4_1"><title>4.1. Find the Private Key <img src="10-7401524\4c6327dc-0238-4cb1-95a9-1ee49ae16d99.jpg" /> by the Public Key <img src="10-7401524\37c7bb5f-74ba-4a19-adb7-65f7dd15cc5b.jpg" /></title><p>1) Let the cardinality of the group <img src="10-7401524\6135d410-d84f-43df-a47e-0d0537eee56d.jpg" /> be</p><p><img src="10-7401524\9d65f66e-7e02-4994-9f07-54cfa6358d4d.jpg" /></p><p>Since<img src="10-7401524\a157853d-777b-44b9-af59-7cb8151e5917.jpg" />, the cryptanalyst can try to solve the equation with two unknowns Y and х:</p><p><img src="10-7401524\46001483-b389-41a6-9157-66c2e2a197f4.jpg" /></p><p>where <img src="10-7401524\42e2d327-7ef5-4eee-9068-af867fa05e31.jpg" /></p><p>2) Since</p><p><img src="10-7401524\46f46c1d-a3cf-4d6a-a63f-3c11681a3d9f.jpg" /></p><p>the cryptanalyst can try to solve the equation with two unknowns Z and х:</p><p><img src="10-7401524\58a33a61-b7fb-48f3-bbb0-30c39e7f6a07.jpg" /></p><p>where<img src="10-7401524\bdeef7ce-c4a8-4b61-9f3d-def62c352ff7.jpg" />, what leads to the private key by applying 1) to each solution <img src="10-7401524\c1f72a4e-de98-4e5d-8700-c4213ad493f9.jpg" /> (which we call the transforming matrix).</p></sec><sec id="s4_2"><title>4.2. Find the Private Key <img src="10-7401524\70625bf8-1718-44a2-a274-0095fa68f8e4.jpg" /> by the Ciphertext <img src="10-7401524\f51dff93-6811-4cfa-a18d-609b3970de75.jpg" /></title><p>Since the private key is applied in the ciphertext <img src="10-7401524\bdddc374-c798-457e-b059-615511f6dc1a.jpg" /> not directly but only via the public key, the knowing of only the ciphertext does not yield additional possibilities to the attacks from 4.1 for the attack on the private key.</p></sec><sec id="s4_3"><title>4.3. Find the Session Key <img src="10-7401524\5e0d3573-5c40-4211-9569-0c6860c1d0e3.jpg" /> by the Ciphertext <img src="10-7401524\46f5df28-67bc-41c3-acad-42aaf8ed0aaf.jpg" /></title><p>1) Since<img src="10-7401524\6e9dca9f-d960-4742-8ebe-c2dedc316680.jpg" />, the cryptanalyst can try to solve the equation with two unknowns Z and у:</p><p><img src="10-7401524\bd133197-bf34-46c0-9a6d-e1e287b580a5.jpg" /></p><p>where <img src="10-7401524\3ab69b4d-6717-43f3-bf8e-7a590cfbdc9a.jpg" /></p><p>2) For any solution <img src="10-7401524\bfea019c-b953-45ca-a8cf-91e9155fc58b.jpg" /> of the equation from 1), the cryptanalyst can try to solve the equation with two unknowns Y and х:</p><p><img src="10-7401524\adce6020-25fe-47d6-ba1c-61070534001c.jpg" /></p><p>where <img src="10-7401524\04cc83f6-4939-473e-b662-8753162c3709.jpg" /></p></sec><sec id="s4_4"><title>4.4. Find the Corresponding Plaintext m or the Session Key <img src="10-7401524\c94e511c-e7da-4741-96ac-628d2a860e3e.jpg" /> by a Chosen Ciphertext <img src="10-7401524\722ddf9c-11f7-41d3-b4b0-aa8350424e63.jpg" /></title><p>Cryptanalyst chooses the random <img src="10-7401524\4699b98c-4f8b-49f8-900f-acd297a635f3.jpg" /> and computes<img src="10-7401524\f2ff37ba-85d1-4ede-a272-cad44bd7eea8.jpg" />, then send it to user A for decryption. User A computes:</p><p><img src="10-7401524\cf578cfb-9271-4615-9fd3-d2bfe56847de.jpg" /></p><p>and send the result to cryptanalyst, which computes the plaintext:</p><p><img src="10-7401524\cc0b72c7-c472-40d5-aa09-b43b14173417.jpg" /></p><p>Hence for protecting cryptosystem the modification of encryption algorithm is:</p><p><img src="10-7401524\dbc16e78-04e4-4419-8dc5-8655a59599f4.jpg" /></p><p>the modification of decryption algorithm is:</p><p><img src="10-7401524\9b4e1045-c484-42cb-977c-5400720b4c3c.jpg" /></p></sec></sec><sec id="s5"><title>5. Computational Problems in Ensuring ВММС Security</title><p>From the consideration of attacks 4.1-4.4 one can formulate some problems, the solution of which is necessary to implement the corresponding attacks.</p><sec id="s5_1"><title>5.1. The Transformation Problem</title><p>Let a matrix <img src="10-7401524\db9164b8-634a-4243-92f6-e017adef5607.jpg" /> be conjugated with an unknown integral power of a matrix <img src="10-7401524\f63a9262-3f4b-4740-8ab8-7f175410a68e.jpg" /> for two given matrices<img src="10-7401524\430546aa-13ca-4c81-ba8a-726708854084.jpg" />. Find all solutions of the equation with two unknowns Z and у:</p><p><img src="10-7401524\c8e4489a-e43d-4177-9385-d59c06896dc4.jpg" /></p><p>where<img src="10-7401524\1c53bae4-d682-43d2-998b-821479e472c5.jpg" />.</p><p>Let us consider a particular case of Problem 5.1.</p><p>1) The conjugation problem.</p><p>For two given conjugated matrices <img src="10-7401524\e89d1e1c-bdb5-4e9a-b84c-041e75ea262c.jpg" /> and <img src="10-7401524\6176923f-71f8-41c9-8c9a-ab4a11666145.jpg" /> from the group<img src="10-7401524\5b75a723-bc0e-4bf7-89ca-f6ca4e558eec.jpg" />, find a transforming matrix<img src="10-7401524\08a4c4b4-9467-4c79-9ba2-2c6683632189.jpg" />, i.e., matrix Т such that</p><p><img src="10-7401524\ff2aa932-0410-4de3-b7f0-f939f4b00cf2.jpg" /></p></sec><sec id="s5_2"><title>5.2. The Hybrid Problem</title><p>Find all solutions of the equation with two unknowns Y and х</p><p><img src="10-7401524\a0d51a3b-b118-4d98-a3be-1002871529f6.jpg" /></p><p>where<img src="10-7401524\d5811cdc-8132-4720-8b28-9a5b23467da4.jpg" /> in the group<img src="10-7401524\57d16768-5f40-4a45-8293-73faffb0f54e.jpg" />.</p><p>Let us also consider two particular cases of Problem 5.2.</p><p>1) The discrete logarithm problem in a cyclic subgroup of the group<img src="10-7401524\447ff335-786d-49e1-bc75-4b434144f257.jpg" />.</p><p>Let <img src="10-7401524\65ad484f-0e95-44ac-9eec-c1619cd12687.jpg" /> be a fixed cyclic subgroup of order j of the group <img src="10-7401524\a384c42b-0895-4a03-b351-230e4f3d43f8.jpg" /> with the generator<img src="10-7401524\6791eb40-b446-41ec-9f70-a52dc55ea28d.jpg" />, <img src="10-7401524\251caad6-8755-49cf-874d-d19d9d726e52.jpg" />be an arbitrary element. Find the unique solution <img src="10-7401524\74499783-c4ca-4bc1-b3b8-17ce32600c8d.jpg" /> of the equation</p><p><img src="10-7401524\d190b36b-17a6-460d-b670-0fb8a5b95f25.jpg" /></p><p>where х is an integer such that<img src="10-7401524\a0622f21-f9a4-426a-a7d8-35b1ba2d13ea.jpg" />.</p><p>2) The problem of extracting a root of the ith power in the group <img src="10-7401524\237adf9d-0ec1-4a04-913e-b326d57efcb7.jpg" /> (the matrix RSA problem).</p><p>Let <img src="10-7401524\30bedd12-0f1d-475f-8a34-e9936f6f789e.jpg" /> be an arbitrary element, <img src="10-7401524\b2871f6f-9b1d-4f58-9671-c5b13c87be64.jpg" />be a fixed integer satisfying the condition <img src="10-7401524\27737ff7-1f31-4cda-8dc5-e0c96c331569.jpg" /> and<img src="10-7401524\0611c85b-6d1a-4667-a3ce-15a497a35605.jpg" />.</p><p>Find all solutions of the equation with a single unknown Y:</p><p><img src="10-7401524\03221726-892e-4694-aa65-b8a1813f0cfd.jpg" /></p><p>According to the Problem 2), in turn, one can also discern the following problem.</p><p>The problem of square-root extraction in<img src="10-7401524\6c5caf9d-1695-46e3-8504-7b416a52177b.jpg" />.</p><p>Find all solutions of the equation with a single unknown Y:</p><p><img src="10-7401524\71c97228-a5be-442e-8b6d-cf37d7ebde05.jpg" /></p><p>where<img src="10-7401524\44b08af1-e7d5-4767-bfd9-c516be2f64a3.jpg" />.</p></sec></sec><sec id="s6"><title>6. Computational Complexity of Problems 5.1, 5.2</title><p>If the order <img src="10-7401524\9276eb07-0f7b-4085-a5cc-9f44ef9329b6.jpg" /> is a large number, then, the fact that the generators in a cyclic group are indistinguishable and random choice of k in the key generation show, on the one hand, that the identification of matrices <img src="10-7401524\82c5b0b9-051f-4637-9b69-de0dad332e52.jpg" /> in Problem 5.1 is a hard problem and, on the other hand, the impossibility to implement the exhausting search in practice for a large number j.</p><p>Considering Problem 5.1 1), it should be noted that this problem is solvable in the free subgroup <img src="10-7401524\7d8d5a31-f1d2-4ecc-b424-49fcd9fe6e23.jpg" /> of the group <img src="10-7401524\cda12ce6-f9d8-49f5-8921-d84851420426.jpg" /> (see [<xref ref-type="bibr" rid="scirp.34315-ref16">16</xref>]). The possibility to extend this algorithm for a subgroup of the group <img src="10-7401524\69ead35d-0068-44e3-9307-3c26a0e91cad.jpg" /> depends on the solution of the following problem: for a given matrix<img src="10-7401524\f5276e5b-7bcb-4418-8b62-7553a67bcf19.jpg" />, find the word <img src="10-7401524\bf486c53-d544-445c-80fb-4ff4164e5fa6.jpg" /> and matrix <img src="10-7401524\1f42f8ea-0613-4944-8317-df88ada58a50.jpg" /> whose reduction modulo n yields the matrix<img src="10-7401524\0f7ec38f-9af2-4986-8500-f592ae5c7923.jpg" />.</p><p>Nevertheless, even in the case of a solved problem of extension, the problem about the existence of an efficient algorithm for solving Problem 5.1 1) remains open.</p><p>Let us now consider Problem 5.2. As it is a problem with two unknowns, this problem is more complicated in the general case than its particular cases, the discrete logarithm problem and the problem of extracting a matrix root modulo n. It is worth to note that the square-root extracting problem is computationally difficult for large number<img src="10-7401524\2a816225-41e2-4ddc-b40d-2057f4b1ea90.jpg" />, p and q are primes.</p><p>Let us now turn to the discussion of the cardinality of the set of secret keys for ВMМС. Note that, for classical cryptosystems, the uniqueness of the secret key can be reached by fitting of parameters. For BMMC, the situation is other. Indeed, if a matrix <img src="10-7401524\5cec9031-13cd-4ba9-baf8-cf72c18875ce.jpg" /> transforms the matrix <img src="10-7401524\202b478f-c701-439a-b0e7-74d9735cebb1.jpg" /> into the matrix<img src="10-7401524\6f099108-0a1c-401f-8492-6431c07246cb.jpg" />, i.e.,</p><p><img src="10-7401524\708f275f-2b95-47ac-9eaf-0814d61fe3b0.jpg" /></p><p>then the matrix <img src="10-7401524\4d5cabfa-a625-4466-aa77-57e98ac570d1.jpg" /> also transforms <img src="10-7401524\e00ae6f5-eac5-4e6f-8f06-6d4fbecdc8cb.jpg" /> into <img src="10-7401524\2d64e820-0a12-4e80-b535-e134db7a53d6.jpg" /> for any matrix<img src="10-7401524\18120d0e-8a80-4a8e-8fa2-065cb87e9169.jpg" />, where <img src="10-7401524\a2b37484-cd53-4b08-99ce-af241dbe484e.jpg" /> is a centralizer of <img src="10-7401524\f1f690fd-833b-4f03-b3d3-8668f1be9ed7.jpg" /> in<img src="10-7401524\542e5e47-290b-494f-94dc-d9edb2d9738f.jpg" />, because</p><p><img src="10-7401524\5a80719a-896d-45c1-b2ed-3e958a73d624.jpg" /></p><p>Thus, if the secret key <img src="10-7401524\887d9cb1-d952-4e82-bc6d-a534a86eed2f.jpg" />is considered as initial, the cryptanalyst can compromise the BMMC by any real key of the form<img src="10-7401524\c45db4ea-8aad-43fb-ba9f-6cf9ce24d739.jpg" />, where<img src="10-7401524\40a55120-ed02-4c7e-b0a4-1354af84fb05.jpg" />. Then, for the cardinality of the set of real keys<img src="10-7401524\4856c15b-9c8a-4e0d-89a6-4b312b88eb2e.jpg" />, we have</p><p><img src="10-7401524\9c9c5ddb-d4bd-402d-a0e4-917960dacd54.jpg" /></p><p>and when generating a key it is necessary to choose matrix <img src="10-7401524\22ab5811-d2ab-4a70-83a9-a9c281842280.jpg" /> so that</p><p><img src="10-7401524\5c95739d-c22b-4914-a744-91fb9f42d09e.jpg" /></p><p>was negligibly small, e.g.,</p><p><img src="10-7401524\390943f1-c766-435a-acfd-7646d7e935e8.jpg" /></p><p>This protects from random guessing of the private key.</p></sec><sec id="s7"><title>7. Comparison of Computational Security of Classical RSA, ElGamal, and Rabin Cryptosystems with ВММС</title><p>For demonstrativeness, we compare the cryptosystems for a very small number<img src="10-7401524\57fa21fb-575f-45c0-86cf-c8f267344dc4.jpg" />.</p><sec id="s7_1"><title>7.1. RSA Cryptosystem</title><p>Let the public key be<img src="10-7401524\89a9aabe-ed38-4403-97a8-9bad828f2f54.jpg" />.</p><p>In this case, the cryptanalyst instantaneously compromises RSA by factorization<img src="10-7401524\316fef3b-19d8-420d-9d2b-f67bc5687141.jpg" />, from which finds<img src="10-7401524\784f7ec7-a2e5-42c4-a33d-45e77de3fd56.jpg" />, and computation of the secret key <img src="10-7401524\37bbbb76-1175-4612-84b5-d4473a6b3801.jpg" /> either by the extended Euclid’s algorithm or by exhaustive search. Then the cryptanalyst finds the secret key:</p><p><img src="10-7401524\c91fca09-15bd-4369-b55a-c6e64abb104c.jpg" /></p></sec><sec id="s7_2"><title>7.2. Modified ElGamal Cryptosystem</title><p>In the unit group <img src="10-7401524\bb06bb71-6718-44bc-8a01-7004e2009ca5.jpg" /> of the ring <img src="10-7401524\6ea77c9e-0aae-4373-a078-07c8ce2bcd92.jpg" /> one has to choose an element of the maximal order. For this purpose, <img src="10-7401524\dceec583-373b-4985-93bb-5d5c737d0be0.jpg" />is factorized as<img src="10-7401524\695147aa-66c8-42ef-bce9-bffc2e7b7f37.jpg" />, and the generators are chosen in the groups <img src="10-7401524\8fb07166-1e0a-48b8-b13f-379bdfc549bd.jpg" /> and<img src="10-7401524\6aad60d9-19c0-41f0-8eb7-b2efab01c647.jpg" />, e.g.,</p><p><img src="10-7401524\2da1e8f4-5fd4-40d7-981b-78181b56cb79.jpg" />and<img src="10-7401524\9ec26c6f-a979-4b09-8788-3708cf76eca0.jpg" />.</p><p>Then the element of maximal order in <img src="10-7401524\cee1047a-15d2-4561-bdac-4ce5d10e6ecc.jpg" /> is obtained from the solution of the following simultaneous congruences either by inspection or by the Chinese reminder theorem:</p><p><img src="10-7401524\25e284fe-34f7-498d-be65-31bc60079f79.jpg" /></p><p>It follows that <img src="10-7401524\12b07a32-e9f7-4621-99a8-f70ba55692b6.jpg" /> and its order is<img src="10-7401524\0bae99d4-5363-40fd-9e34-96fc99e778e2.jpg" />.</p><p>Let one of cyclic subgroups of order 12, for example, <img src="10-7401524\09d63205-d2b5-4879-8d74-1724a57f36fd.jpg" />be chosen in the group<img src="10-7401524\ff29a2de-7983-49ea-9ed0-fbc4a51b347e.jpg" />. In the group G, another generator may be chosen, e.g.,<img src="10-7401524\0edb0504-7ab7-4ee3-bdd4-ede165d53962.jpg" />.</p><p>Let the modified ElGamal cryptosystem be considered in a cyclic group G of order 12 with a generator <img src="10-7401524\4a4054cc-cad2-4f8c-945f-1d61074a6d9b.jpg" /> and let the public key be</p><p><img src="10-7401524\54cca5fd-4542-43ce-81f9-708c31955a9e.jpg" /></p><p>In this case, the cryptanalyst instantaneously compromises the modified ElGamal cryptosystem using exhaustive search in the cyclic group of order 12 finding the secret key а = 5 since<img src="10-7401524\cffe2e09-82a6-40b1-b844-fe79ab4e9443.jpg" />.</p><p>Remark. In the case of choice n as<img src="10-7401524\713fbe54-ec96-4fe2-9948-1f3597aee8c7.jpg" />, where p is a prime number, we compare BMMC with classical ElGamal cryptosystem.</p></sec><sec id="s7_3"><title>7.3. Rabin Cryptosystem</title><p>Let the public key be<img src="10-7401524\9f634805-6ba1-47a2-b031-e7cd1e635d82.jpg" />, then the cryptanalyst instantaneously compromises the Rabin cryptosystem in this case by factorizing the number by prime multipliers<img src="10-7401524\7b1d7e77-82b8-4986-91f8-7f702a65f614.jpg" />.</p><p>One can see that, in all three cases, the cryptanalyst instantaneously compromises these classical cryptosystems for<img src="10-7401524\5a6c9652-9bad-4513-9330-5ad98b462a88.jpg" />. Let us now the case of the BMMC cryptosystem for<img src="10-7401524\d52ce306-01ae-4ab3-a4f1-c1b6c0f25145.jpg" />.</p></sec><sec id="s7_4"><title>7.4. BMMC</title><p>Let the public key be</p><p><img src="10-7401524\9b0ab325-bf8f-4f56-ba7f-7a32566a6b50.jpg" /><img src="10-7401524\0d027e5b-9b3f-44db-8cfd-d6ef9461d729.jpg" /></p><p>be the ciphertext of a certain matrix m.</p><p>Compromising BMMC in this case needs essentially more efforts than for the classical cryptosystems and exhausting search in the space of the search containing 775,760 matrices gives<img src="10-7401524\abb36a47-f342-46d0-a772-7bb896c2d9f1.jpg" />; secret key—</p><p><img src="10-7401524\7f5fe9f1-d7e4-4eb6-9fd7-d49b43c60a80.jpg" />; session key—<img src="10-7401524\9a825523-b92c-46c1-8ef7-f00991b9f050.jpg" />,<img src="10-7401524\50f4d48e-6811-4186-8e78-b057e945e3f8.jpg" />.</p></sec></sec><sec id="s8"><title>8. Some Open Mathematical and Computational Problems</title><p>1) For which finite groups G and rings R the unit group of group ring RG is a semi-direct product of trivial units and a free subgroup of a finite rank?</p><p>2) For which groups G and rings R every automorphism of the group ring RG has a standard form?</p><p>3) For which subgroups of the group <img src="10-7401524\420fe8ee-98f9-4c43-b8b3-f3f1d5e0421b.jpg" /> it takes place the property of small centralizers i.e. every element has a cyclic centralizer?</p><p>Remark. It is well-known [<xref ref-type="bibr" rid="scirp.34315-ref16">16</xref>] that in the free group of finite rank centralizer of any element is a cyclic subgroup.</p><p>4) Is there a polynomial-time algorithm for constructing cyclic centralizer of any element in a free group of finite rank?</p><p>5) Is there a polynomial-time algorithm for solving the membership problem for cyclic subgroup of the a) free group of finite rank, b) subgroup <img src="10-7401524\2f8a18fe-7a01-43ba-9b65-694b8e654e5a.jpg" />by modulo n in a group<img src="10-7401524\023f5435-6944-4c0a-b7dd-cb360ee09817.jpg" />?</p><p>6) Is there a polynomial-time algorithm for solving the modular factorization problem, i.e. to represent every matrix from the subgroup <img src="10-7401524\f03fa955-60f2-45d0-a41e-6bedbda7a6c8.jpg" /> by modulo n in a group <img src="10-7401524\80d5c477-e23a-4e12-a5b5-79c1bb55c69e.jpg" /> as a word in an alphabet of <img src="10-7401524\05991216-b718-42ac-864b-0e3e839db67f.jpg" /> by modulo n?</p><p>7) How to compute the number <img src="10-7401524\9fa2a9af-c111-4839-9c6c-caa30be01d88.jpg" /> for arbitrary positive integers n? More exactly, is there a polynomialtime algorithm for computing<img src="10-7401524\7328156f-7131-4f91-844b-35df424a6769.jpg" />?</p><p>8) Is there a polynomial-time algorithm for computing maximal order elements in a subgroup <img src="10-7401524\f2668aa4-3dfd-4f73-b360-92fdcd8482fd.jpg" /> by modulo n in the group<img src="10-7401524\027bf190-1400-4030-8b95-4170fd0f8fe5.jpg" />? What is a cardinality of this subgroup<img src="10-7401524\29f02e33-6487-4343-b947-53083ae59e68.jpg" />?</p></sec><sec id="s9"><title>9. Conclusion</title><p>The practicality of the BMMC is provided by the absence of the necessity in the computer algebra systems used for computer realization of cryptosystem algorithms and efficient matrix computations by modulo number of essentially less bit length than that are usually used in classical cryptosystems under the same security level.</p></sec><sec id="s10"><title>REFERENCES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.34315-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">A. Menezes, P. van Ooshot and S. Vanstone, “Handbook of Applied Cryptography,” CRC Press, Waterloo, 1996.  
doi:10.1201/9781439821916</mixed-citation></ref><ref id="scirp.34315-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">P. W. Shor, “Algorithms for Quantum Computation: Discrete Logarithm and Factoring,” Proceedings of the IEEE 35th Communications Annual Symposium on Foundations of Computer Science, Santa Fe, 20-22 November 1994, pp. 124-134.</mixed-citation></ref><ref id="scirp.34315-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">S. K. Rososhek, “Cryptosystems in Automorphism Groups of Group Rings of Abelian Groups,” Fundamentalnaya I prikladnaya matematica, Vol. 13, No. 8, 2007, pp. 157-164 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">S. K. Rososhek, “Cryptosystems in Automorphism Groups of Group Rings of Abelian Groups,” Journal of Mathematical Sciences, Vol. 154, No. 3, 2008, pp. 386-391.  
doi:10.1007/s10958-008-9168-2</mixed-citation></ref><ref id="scirp.34315-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">A. N. Gribov, P. A. Zolotykh and A. V. Mikhalev, “A Construction of Algebraic Cryptosystem over the Quasigroup Ring,” Mathematical Aspects of Cryptography, Vol. 1, No. 4, 2010, pp. 23-32 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">K. N. Ponomarev, “Automorphically Rigid Group Alge  bras I. Semisimple Algebras,” Algebra and Logic, Vol. 48, No. 5, 2009, pp. 654-674.  
doi:10.1007/s10469-009-9064-y</mixed-citation></ref><ref id="scirp.34315-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">K. N. Ponomarev, “Automorphically Rigid Group Alge bras II. Modular Algebras,” Algebra and Logic, Vol. 49, No. 2, 2010, pp. 216-237.</mixed-citation></ref><ref id="scirp.34315-ref8"><label>8</label><mixed-citation publication-type="book" xlink:type="simple">K. N. Ponomarev, “Rigid Group Rings,” In: A. G. Pinus and K. N. Ponomarev, Eds., Algebra and Model Theory, 6, Novosobirsk Technical University Press, Novosibirsk, 2007, pp. 73-83 (in Russian).  
doi:10.1007/s10469-010-9086-5</mixed-citation></ref><ref id="scirp.34315-ref9"><label>9</label><mixed-citation publication-type="book" xlink:type="simple">A. Popova and E. Poroshenko, “Units Group of Integral Group Rings of Finite Groups,” In: A. G. Pinus and K. N. Ponomarev, Eds., Algebra and Model Theory, 4, Novosi birsk Technical University Press, Novosibirsk, 2003, pp. 99-106 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">A. Dooms and E. Jespers, “Normal Complements of the Trivial Units in the Unit Group of Some Integral Group Rings,” Communications in Algebra, Vol. 31, No. 1, 2003, pp. 475-482. doi:10.1081/AGB-120016770</mixed-citation></ref><ref id="scirp.34315-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Y. I. Merzlyakov, “Matrix Representations of Free Groups,” Doklady Akademii Nauk, Vol. 238, No. 3, 1978, pp. 527-533 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref12"><label>12</label><mixed-citation publication-type="book" xlink:type="simple">A. Popova, “Group of Automorphisms of the Ring  ,” In: A. G. Pinus and K. N. Ponomarev, Eds., Alge bra and Model Theory, 6, Novosibirsk Technical University Press, Novosibirsk, 2007, pp. 84-90 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">A. Mahalanobis, “A Simple Generalization of the ElGa mal Cryptosystem to Non-Abelian Groups,” Communications in Algebra, Vol. 36, No. 10, 2008, pp. 3878-3889.  
doi:10.1080/00927870802160883</mixed-citation></ref><ref id="scirp.34315-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">S.-H. Paeng, K.-C. Ha, J. N. Kim, S. Chee and C. Park, “New Public Key Cryptosystem Using Finite Non-Abelian Groups,” Proceedings of the Crypto 2001, Lecture Notes in Computer Sciences, Santa Barbara, 19-23 August 2001, pp. 470-485.</mixed-citation></ref><ref id="scirp.34315-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">M. I. Kargapolov and Y. I. Merzlyakov, “Foundations of Group Theory,” Nauka, Moscow, 1977 (in Russian).</mixed-citation></ref><ref id="scirp.34315-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">R. C. Lyndon and P. E. Schupp, “Combinatorial Group Theory,” Springer-Verlag, Berlin, Heidelberg, New York, 1977.</mixed-citation></ref></ref-list></back></article>