The paper considers the concept of a threat model, presents the results of substantiation and development of proposals for building a threat model for asymmetric cryptotransformations such as a promising electronic signature (ES), which can be used in the post-quantum period. The generalized models of threats concerning perspective ES are stated in detail and their estimation is given. Threat models for promising ES using classical and quantum cryptanalysis methods and tools, threat models for synthesis and application of ES in general, as well as threat models for synthesis and application of ES in the post-quantum period are proposed. A list of threats is identified based on the results of the analysis of the methods of synthesis and application of known and promising ES. Proposals are formulated for a list of threats for which protection should be provided. The list of threats is determined using the IT-Grundschutz Catalogues of the German database, and based on this a threat model is formed. It is determined that the threats to the use of classical cryptanalysis in the synthesis and application of EP must be identified in detail unconditionally. The main threats (methods) of classical cryptanalysis that must be taken into account are identified. Possible variants of side channel attacks are considered. The main threats (attacks) using quantum mathematical methods that can be implemented on a quantum computer (of course, if it is built). A comparative analysis of the complexity of factorization for classical and quantum algorithms, as well as a comparative analysis of the complexity of the algorithm of discrete logarithm in a finite field based on the sieve of a numerical field and the Shore algorithm are given. Threats (attacks) are considered on the example of the problem of stability of cryptotransformations based on learning with errors (LWE). In general, attacks on LWE can be divided into 2 major classes – attacks based on bust and attacks based on lattice reduce. Preliminary analysis allows us to conclude that modern versions of LWE mechanisms are based on polynomial rings.
The paper presents the results of substantiation and development of proposals for building a threat model for asymmetric cryptotransformations such as a promising electronic signature (ES), which can be used in the post-quantum period. The generalized models of threats concerning perspective ES are stated in detail and their estimation is given. Threat models for promising ES using classical and quantum cryptanalysis methods and tools, threat models for synthesis and application of ES in general, as well as threat models for synthesis and application of ES in the post-quantum period are proposed. Proposals are formulated for a list of threats for which protection should be provided. The list of possible security threats to existing and future ES is formed from the number of threats available in IT-Grundschutz Catalogs, taking into account hardware, software and hardware-software resources, data processing technologies and cryptographic protection mechanisms in the use of ES, including requirements and conditions of synthesis of promising ES and application of ES in the post-quantum period. The concepts of EUF-CMA and SUF-CMA security are considered. Algorithms of work of each of these schemes are given. The concept of a comprehensive security model is introduced and its components are presented. The model of the violator and its essence are considered. The main threats (attacks) are given using quantum mathematical methods that can be implemented on a quantum computer (of course, if it is built and available for use). Attacks (threats) against a promising ES are presented and considered. The analysis of signature schemes for compliance with the required security models is performed. The terms "forward secrecy" and "perfect forward secrecy" are introduced and used. An analysis of signature schemes that are EUF-CMA and SUF-CMA secure is performed. Signature schemes, that are key-dependent, with evolving keys, are considered in terms of compliance with the EUF-CMA or SUF-CMA security model. The stateless signature algorithm is also considered. Algorithms of operation of such signature schemes are given.
The present paper considers national electronic voting system problems in Ukraine, principles of construction and development prospects. Electronic voting refers to a way to exercise will, in which the voting, counting, and publication of the results processes are carried out by electronic means and systems. Most existing voting systems are built on centralized principles and this allows providing certain advantages, for example, high controllability of the system, its reliability, and autonomy. However, hierarchical systems also have significant drawbacks, in particular, single decision center and centralized storage leads to vulnerability to cyberattacks on them. Also it should be noted, that in centralized systems due to the abuse of administrative resources distortions of the results of expression of will are possible. This is the biggest threat to the modern democratic information society. Research, development, and implementation of new technologies of electronic voting, which would make it impossible to intervene and distort the results of the will through decentralization while maintaining all the system qualities for safety and reliability are promising. This article proposes particular proposals for architecture substantiating as well as a basic model and interaction protocols of a decentralized electronic blockchain voting system. A two-level blockchain voting architecture is proposed, researched and verified through physical prototyping. Its implementation will increase confidence in information resources and services (which is especially important for government agencies) will reduce time and overhead costs; make it impossible for centralized institutions to intervene and possible corrupt practices; will increase the reliability of information storage and the quality of services provided.
The analysis of hashing functions that are applied or can be used in various blockchain systems is carried out. In particular, the most common national and international standards are considered, which contain specifications of world-famous cryptographic hashing algorithms, and various projects for the construction of decentralized blockchain systems where these functions can be applied are investigated.
The analysis of hashing functions that are applied or can be used in various blockchain systems is carried out. In particular, the most common national and international standards are considered, which contain specifications of world-famous cryptographic hashing algorithms, and various projects for the construction of decentralized blockchain systems where these functions can be applied are investigated.