Search
Search Results
-
ALGORITHMS FOR REDUCING THE TIME REQUIRED TO PERFORM OPERATIONS OF THE DOMINGO-FERRER CRYPTOSYSTEM
V.S. Starodubcev , L.К. Babenko150-1592026-09-10Abstract ▼An analysis of the literature on the topic of fully homomorphic encryption is carried out. A brief description of the completely homomorphic Domingo-Ferrer cryptographic system based on the number factorization problem is presented, and the time characteristics of the stages of an attack with a known plaintext on this cryptosystem are given. The time characteristics of cryptosystem operations are analyzed, methods and means of their practical implementation are described. New algorithms for implementing the operations of the Domingo-Ferrer cryptosystem are proposed to reduce their execution time. The justification of estimates of the time costs of cryptosystem operations is formed on the basis of theoretical calculations, as well as the results of experimental studies. The aim of the study is to reduce the execution time of the Domingo-Ferrer cryptosystem by developing algorithms for their modification, taking into account the specifics of practical implementation. The main result of this work is a reduction in the execution time of the following operations of the Domingo-Ferrer cryptosystem: encryption by 10-15%, decryption by 2 times, homomorphic multiplication by 64 times for a chain of 200 multiplications using the degree of polynomials of the ciphertext representation d=100 and a slight increase in the time spent on key generation. The conducted research represents a significant contribution to the development of a fully homomorphic Domingo-Ferrer cryptosystem based on the integer factorization problem. This work has practical significance because it significantly improves the performance of homomorphic calculations of this cryptosystem. The results obtained can become the basis for the development of efficient (in terms of required computing costs and the level of security provided) cloud computing software and hardware systems using a fully homomorphic Domingo-Ferrer cryptosystem to ensure the confidentiality of processed information
-
THE LIBRARY OF FULLY HOMOMORPHIC ENCRYPTION OVER THE INTEGERS
L.K. Babenko, I.D. Rusalovsky2020-07-20Abstract ▼The article discusses one of the new directions of cryptography, a homomorphic cryptography.
Its distinctive feature is that this type of cryptography allows you to process encrypted data
without first decrypting it in such a way that the result of operations on encrypted data is equivalent
after decryption to the result of operations on open data. The paper describes the main areas
of application of homomorphic encryption. The analysis of existing developments in the field of
homomorphic encryption is performed. The analysis showed that existing library implementations
only allow processing of bits or arrays of bits and do not support the division operation. However,
to solve applied problems, support for performing integer operations is necessary. The analysis
revealed the need to implement the operation of homomorphic division, as well as the relevance of
developing your own implementation of a library of homomorphic encryption over integers. The
ability to perform four operations (addition, difference, multiplication and division) on encrypted
data will expand the field of application of homomorphic encryption. A method of homomorphic
division is proposed, which allows performing the division operation on homomorphically encrypted
data. A library architecture of completely homomorphic operations on integers is proposed.
The library supports the basic homomorphic operations on integers, as well as the division
operation, thanks to the method of homomorphic division. Based on the proposed method of
homomorphic division and library architecture, a library of homomorphic operations on integers
was implemented. The article also provides measurements of the time required to perform certain
operations on encrypted data and analyzes the effectiveness of the developed library implementation.
Conclusions and possible ways of further development are given. -
METHOD OF IMPLEMENTING HOMOMORPHIC DIVISION
L. K. Babenko, I. D. Rusalovsky2020-11-22Abstract ▼The article deals with the problems of homomorphic cryptography. Homomorphic cryptography
is one of the young directions of cryptography. Its peculiarity lies in the fact that it is possible
to process encrypted data without preliminary decryption in such a way that the result of operations
on encrypted data is equivalent, after decryption, to the result of operations on open data.
The article provides a brief overview of the areas of application of homomorphic encryption. To
solve various applied problems, support for all mathematical operations is required, including the
division operation, and the ability to perform this operation homomorphically will expand the
possibilities of using homomorphic encryption. The paper proposes a method of homomorphic
division based on an abstract representation of the ciphertext in the form of an ordinary fraction.
The paper describes in detail the proposed method. In addition, the article contains an example of
the practical implementation of the proposed method. It is proposed to divide the levels of data
processing into 2 levels – cryptographic and mathematical. At the cryptographic level, a completely homomorphic encryption algorithm is used and the basic homomorphic mathematical operations
are performed – addition, multiplication and difference. The mathematical level is a superstructure
on top of the cryptographic level and expands its capabilities. At the mathematical level,
the ciphertext is represented as a simple fraction and it becomes possible to perform the
homomorphic division operation. The paper also provides a practical example of applying the
homomorphic division method based on the Gentry algorithm for integers. Conclusions and possible
ways of further development are given. -
ALGORITHM OF ENSURING THE SECURITY OF CONFIDENTIAL DATA OF THE MEDICAL INFORMATION SYSTEM FOR STORAGE AND PROCESSING OF EXAMINATION RESULTS
L.K. Babenko, A.S. Shumilin, D.M. Alekseev2021-01-19Abstract ▼The objectives of the study are to develop and assess the effectiveness of the structure of a
cloud platform for storing, processing and organizing medical data, determining a method of protection,
in particular, ensuring confidentiality when transferring and storing examination results.
To achieve this goal, the tasks of analyzing existing models of information processes and structures
in the subject area are being solved, the features of the means for accumulating and processing medical data stored in electronic information systems for patient registration, the architecture
of a cloud platform for distributed data storage and an algorithm for ensuring the safety of
medical data stored in the cloud are being developed. the platform in electronic form in the form
of initial physiological signals (EEG, ECG, EMG, EOG, etc.) recorded during patient examinations;
an integrated cloud platform for distributed storage, analysis and systematization of medical
data and a security system using the developed protection method are being created; the effectiveness
of the proposed algorithm for protecting confidential medical information is analyzed in the
context of integration into the developed cloud platform. The proposed method for protecting a
medical information system involves the use of an original DICOM file and subsequently a converted
PNG image, which is subjected to a pixel encryption algorithm. An algorithm based on
chaos theory is used to encrypt the image. The capabilities of chaos systems can significantly increase
productivity. Hierarchical division of data streams into levels and standardization of data
transfer protocols, as well as their storage formats, allow to form a universal, flexible and reliable
medical information system. The proposed architecture has the ability to integrate into existing
medical systems. In the course of the work, it was found that the considered protection method is
an effective way to ensure the confidentiality of medical system data. -
DEVELOPMENT OF AUTOMATED MALWARE DETECTION SYSTEM
L.К. Babenko, А.S. Kirillov153-1672021-10-05Abstract ▼When research in the field of malware detection, the authors focus exclusively on detection methods, ignoring how these methods could practically be implemented. On the other hand, there are works that reveal some technical details of the implementation or optimization of the process of analyzing the malware sample and collecting data on its work. However, it is necessary to com-bine the results of the concepts of experimental systems and the implementation possibilities that are available. The purpose of the work is description of the implementation of an automated mal-ware detection system based on the method proposed earlier by the authors, thus supplementing the results of previous studies and putting into practice the proposed method for detecting and clustering malware. As a result, the technical requirements for the developed system for detecting malware is described, due to the previously proposed method of detection and clustering. A com-parison of existing behavioral analysis tools was made, Сuckoo Sandbox was chosen as the most suitable one, its main advantage is the open source code, which made it possible to refine both its client part and server part. In particular, the list of controlled system functions has been expand-ed, the source module of the call has been determined, and the call context has been determined. Also, based on the Сuckoo Sandbox, an extension has been developed that implements the method proposed by the authors. The article also reveals the possibility of porting the described system to work with samples of malware developed for various platforms. In particular, it is shown that the proposed methods can be adapted to platforms such as .NET or Android, while the improvements are technical, not fundamental. From a practical point of view, the system is a software package for a security specialist and allows for the rapid detection of previously unknown threats and, at the same time, through clustering, to identify a specific threat in order to implement the most ap-propriate protection measures against this threat. In the proposed form, it can be used as part of the enterprise infrastructure to ensure anti-virus security
-
HYBRID ENCRYPTION BASED ON SYMMETRIC AND HOMOMORPHIC CIPHERS
L. K. Babenko , Е.А. Tolomanenko6-182021-07-18Abstract ▼The purpose of this work is to develop and research a hybrid encryption algorithm based on the joint application of the symmetric encryption algorithm Kuznyechik and homomorphic encryp-tion (Gentry scheme or BGV scheme). Such an encryption algorithm can be useful in situations with limited computing resources. The point is that with the correct expression of the basic operations of the symmetric encryption algorithm through Boolean functions, it becomes possible on the transmitting side to encrypt the data with a symmetric cipher, and the secret encryption key - with a homomorphic one. In this case, manipulations can be carried out on the receiving side so that the original encrypted message is also encrypted only with a homomorphic cipher. In this case, symmetric encryption is removed, but the information remains inaccessible to the node that pro-cesses it. This property of secrecy makes it possible to carry out resource-intensive operations on a powerful computing node, providing homomorphically encrypted data for a low-resource node for the purpose of their subsequent processing in encrypted form. The article presents the developed hybrid algorithm. As a symmetric encryption algorithm, Kuznyechik encryption algorithm is used, which is part of the GOST R34.12 - 2015 standard. In order to be able to apply homomorphic encryption to data encrypted with the Kuznyechik cipher, the Kuznyechik algorithm S-boxes is presented in a boolean form using the Zhegalkin polynomial. Also, the linear transformation L is presented in the sequence form of performing the simplest operations of addition and multiplication on the transformeddata. The primary modeling of the developed algorithm was carried out on a simplified version of the KuzchyechikS-KN1 algorithm.
-
ALGORITHM OF PROTECTING CONFIDENTIAL DATA IN THE CLOUD MEDICAL INFORMATION SYSTEM
L.K. Babenko, A.S. Shumilin, D.M. Alekseev2021-12-24Abstract ▼The aim of the work is the development and implementation of the architecture of a cloud
storage system, systematization and processing of survey results (for example, EEG) and an algorithm
for ensuring the protection of confidential data based on a completely homomorphic cryptosystem.
The object of the research is the technologies of storage, transmission, processing and
protection of confidential information in distributed medical information systems. The architecture
of a cloud platform for distributed storage, processing, systematization and protection of confidential
data (results of medical examinations) has been developed, which makes it possible to interact
with various medical information systems and diagnostic hardware in order to generate big data.
An algorithm has been developed to ensure the safety of medical data stored in a cloud platform in electronic form, recorded during patient examinations in order to calculate the average value for
each of the brain activity rhythms (based on the results of a series of examinations over a long
period of time) using a fully homomorphic encryption algorithm. Based on the test results (analysis
of the execution time of such operations as: encryption, decryption, addition, multiplication,
signal-to-noise ratio of ciphertext to plaintext), the optimal algorithm. According to the results of
the work, it is shown that the fully homomorphic encryption scheme CKKS is the most effective,
especially in the context of the criticality of the requirements for a high level of security of confidential
data, which determines the choice of this scheme for the implementation of the algorithm
proposed in this work. -
DEVELOPMENT OF HOMOMORPHIC DIVISION METHODS
I.D. Rusalovsky, L.K. Babenko, О.B. Makarevich2022-11-01Abstract ▼The article deals with the problems of homomorphic cryptography. Homomorphic cryptography
is one of the young areas of cryptography. Its distinguishing feature is that it is possible to
process encrypted data without decrypting it first, so that the result of operations on encrypted
data is equivalent to the result of operations on open data after decryption. Homomorphic encryption
can be effectively used to implement secure cloud computing. To solve various applied problems,
support for all mathematical operations, including the division operation, is required, but
this topic has not been sufficiently developed. The ability to perform the division operation
homomorphically will expand the application possibilities of homomorphic encryption and will
allow performing a homomorphic implementation of many algorithms. The paper considers the
existing homomorphic algorithms and the possibility of implementing the division operation within
the framework of these algorithms. The paper also proposes two methods of homomorphic division.
The first method is based on the representation of ciphertexts as simple fractions and the
expression of the division operation through the multiplication operation. As part of the second
method, it is proposed to represent ciphertexts as an array of homomorphically encrypted bits, and
all operations, including the division operation considered in this article, are implemented
through binary homomorphic operations. Possible approaches to the implementation of division
through binary operations are considered and an approach is chosen that is most suitable for a
homomorphic implementation. The proposed methods are analyzed and their advantages and disadvantages
are indicated. -
ESTIMATION OF THE SEARCH TIME FOR KEY COMPONENTS IN A KNOWN PLAINTEXT ATTACK ON THE DOMINGO-FERRER CRYPTOSYSTEM
L. К. Babenko , V. S. Starodubcev , N.B. Yelchaninova110-1182025-07-24Abstract ▼This paper provides a brief description of the fully homomorphic Domingo-Ferrer cryptographic system and describes the stages of an attack with a known plaintext on this cryptosystem. The stage of searching for the key components of the attack in question is analyzed, for which existing implementation methods are described, among which the method with minimal computational complexity is determined. The rationale for the computational complexity and time costs of the considered method for implementing the key component search stage is based on theoretical calculations, as well as experimental studies.
The aim of the study is to evaluate the complexity of implementing the stage of searching for key components in an attack with a known plaintext on a fully homomorphic Domingo-Ferrer cryptographic system using the Gauss method, developed for solving systems of linear algebraic equations modulo a prime number. The main result of this work is an assessment of the computational complexity of the key component search stage in a known plaintext attack on the Domingo-Ferrer cryptographic system, implemented using the Gauss method. The complexity estimate is expressed in the number of basic mathematical operations and is confirmed by a number of experimental studies, which allows us to draw reasonable conclusions about the computational complexity of the method under consideration. The conducted research represents a significant contribution to the development of a fully homomorphic Domingo-Ferrer cryptosystem based on the integer factorization problem. It has practical significance, as it allows us to assess the criticality of an attack with a known plaintext on a given cryptosystem. The results obtained can serve as a basis for researchers and cryptographers to develop recommendations for choosing the parameters of the Domingo-Ferrer cryptosystem to ensure the necessary level of security in various applications. -
ESTIMATION OF THE EXECUTION TIME OF ENCRYPTION, DECRYPTION, AND HOMOMORPHIC CALCULATIONS USING THE DOMINGO-FERRER CRYPTOSYSTEM
L.К. Babenko, V. S. Starodubcev6-152024-11-10Abstract ▼This article considers a symmetric probabilistic homomorphic Domingo-Ferrer cryptosystem based
on the problem of number factorization. Currently, homomorphic cryptosystems of two types are relevant:
the Gentry type and those based on the problem of factorization of numbers. A distinctive feature of the
latter, in comparison with Gentry-type cryptosystems, is the lower complexity of performing homomorphic
operations, which significantly expands the scope of their application in practice. However, since
homomorphic cryptosystems based on the number factorization problem have not been widely used and
have not been sufficiently analyzed, unlike Gentry-type cryptosystems, their thorough comprehensive study
is required. For the considered symmetric homomorphic Domingo-Ferrer cryptosystem, descriptions of
key generation, encryption, decryption, and homomorphic computing operations are given. For encryption,
decryption, and homomorphic computing operations, a complexity estimate is given, expressed in the
number of basic mathematical operations, as well as graphs illustrating the dependence of the number of
operations on the selected parameters of the cryptosystem. The aim of the study is to assess the complexity
of performing encryption, decryption and homomorphic calculations by a symmetric probabilistic
homomorphic Domingo-Ferrer cryptosystem based on the number factorization problem. The main result
of this work is an assessment of the complexity and determination of the most time-consuming stages of
encryption, decryption and performing homomorphic calculations using the Domingo-Ferrer cipher, confirmed
by a number of experimental studies. The conducted research represents an important step in the
development of the Domingo-Ferrer cryptographic system based on the problem of factorization of numbers
and has the practical significance of implementing algorithms with the ability to determine the time
costs of encryption, decryption and performing homomorphic calculations. The results obtained can be
used by researchers and programmers in the development of implementations of the Domingo-Ferrer
cryptosystem in programming languages. -
USE OF PARALLEL COMPUTING FOR SECURITY METHOD IMPLEMENTATION BASED ON THE SHAMIR SCHEME IN A MEDICAL INFORMATION SYSTEM
L. K. Babenko , A.S. Shumilin2023-10-23Abstract ▼Medical information systems currently are becoming the most popular tools for processing,
storing, organizing, and transmitting patient medical data. Medical examinations can be presented
in the form of files in various formats and vary greatly in terms of size (from a few bytes to hundreds
of gigabytes). For example, some binary files are small and lightweight because they contain
only doctors' conclusions in the form of a text description. However, records of night video
monitoring of a patient or DICOM files of human organs CT scans containing several hundred
slices, can reach hundreds of gigabytes in size. Accordingly, large files require significant computing
resources when transferred from server to server. In addition, when using the security method,
which is an algorithm of a secret sharing (medical output file) according to the Shamir sharing
scheme, operations to split the secret into parts and merge the parts together may take longer in
serial operation than in parallel way. Therefore, it seems possible to speed up the processing of
big data without reducing the level of security. The main purpose of the work is to confirm the
hypothesis of reducing time to perform the operation of splitting and merging parts of a secret
based on parallel computing tools withing implementing the security method according to the
Shamir secret sharing scheme in a medical information system. The object of the study is a security
method developed by the author for implementation in the information security subsystems of a
medical information system. As part of the study, author analyzed the most effective tools for parallelizing
processes (like MPI and OpenMP). MPI has been used as a tool as much more suitable
for the current purpose. Moreover, several waves of experiments have been run (analysis of time
depending on the number of parallel streams and the number of characters contained in the
DICOM file) and allowed us to prove a concept of parallelizing the secret exchange algorithm
based on the Shamir scheme, achieving almost linear acceleration using the MPI library -
FEATURES OF THE IMPLEMENTATION OF THE CRYPTANALYSIS SYSTEM OF HOMOMORPHIC CIPHERS BASED ON THE PROBLEM OF FACTORIZATION OF NUMBERS
L.К. Babenko, V.S. Starodubcev2024-08-12Abstract ▼This article discusses homomorphic cryptosystems based on the problem of factorization of numbers.
In comparison with Gentry-type cryptosystems, their implementation is less laborious, but it requires
careful verification of durability. The Domingo-Ferrer symmetric cryptosystem is considered as an example
of a homomorphic cryptosystem based on the number factorization problem. For this cryptosystem, the
processes of key generation, encryption, decryption, and performing homomorphic operations are presented.
A description of an attack with a known plaintext on the Domingo-Ferrer cryptosystem is given, as well as a demonstration example of such an attack with a small value of the degree of the polynomials of
the ciphertext representation. For the system architecture under development, the basic requirements and
a general scheme are presented with a brief description of the area of responsibility of individual modules
and their interrelationships. The aim of the study is to identify approaches, techniques and tactics common
to specific cryptanalysis methods of homomorphic cryptosystems based on the problem of factorization of
numbers, and to create a system architecture that would simplify cryptanalysis by providing the cryptanalyst
with a convenient environment and tools for implementing his own cryptanalysis methods. The main
result of this work is the architecture of the cryptanalysis system, which allows for a comprehensive analysis
of vulnerabilities for various attacks and to assess the level of cryptographic strength of the cipher in
question, based on the problem of factorization of numbers, as well as the justification for the use of such
an architecture for the analysis of homomorphic ciphers using the example of the Domingo-Ferrer cryptosystem.
The implementation of a cryptanalysis system based on the proposed architecture will help researchers
and cryptography specialists to study in more detail possible weaknesses in homomorphic ciphers
based on the problem of factorization of numbers and develop appropriate measures to strengthen
their durability. Thus, the ongoing research is important for the development of cryptographic systems
based on the problem of factorization of numbers and provides new tools for cryptanalysts in the field of
analysis of homomorphic cryptosystems. The results obtained can be used to increase the strength of existing
ciphers and develop new cryptographic methods. -
ANALYSIS OF PROBLEMS OF INFORMATION PROTECTION IN SEMANTIC NETWORKS
L.K. Babenko, P.Y. Chudinov, Y.I. Rogozov2023-02-17Abstract ▼The article analyzes the structure, principles and technologies used in the creation of semantic
networks, the methodology for representing knowledge in a semantic network. Special
attention is paid to the analysis of the structure of queries to data stored in the semantic network.
The purpose of the analysis is to determine the structural elements that carry confidential or other
important information for the further formation of a methodology for its protection, considering
the specifics of the semantic network. As a result of the analysis of typical structures of semantic
networks, the fundamental structural elements and concepts that make up the structure of the analyzed
method of knowledge representation are considered. The specialized languages used for its
construction and the structure of the information request to the knowledge base are determined, in
which elements carrying confidential information and potentially vulnerable to attacks by intruders
were identified. Problems in the information security of semantic networks have been identified,
such as: exposure to malicious SPARQL queries, which can be used to obtain information
from the semantic network without appropriate privileges and accesses; data vulnerability in the
transmitted information request, characterized by a weak focus of existing protection methods on
the specifics of semantic networks; the problem of assessing the level of confidence in the received
data of the semantic network. One of the approaches to solve these problems can be the creation
of a distributed system for evaluating the trust in nodes and data in the semantic network, as well
as the implementation of mechanisms for protecting information and information requests.
The results obtained as a result of the analysis on the structure of the transmitted data are an integral
part of the process of developing information security tools in semantic networks.








