Source-linked AI summary
When an attacker meets a cipher-image in 2018: A Year in Review
Chengqing Li, Yun Zhang, Eric Yong Xie
TL;DR
Image-encryption research faced persistent security and privacy challenges, while 2018 produced many protective schemes and a smaller body of cryptanalysis. This paper reviews and classifies representative designs and attacks, then summarizes challenges for both sides. It highlights concerns about widely used security-assessment metrics and recurring weaknesses in some encryption constructions.
Problem
Security and privacy protection of image data remains a persistent challenge, while security-assessment metrics used in many chaos-based schemes are described as unconvincing.
Method
The paper selects and classifies representative 2018 image-protection and cryptanalytic works according to essential structures and reviews nearly all image-cryptanalysis publications from that year.
Results
The review identifies technical challenges on both the design and analysis sides, including weaknesses in some schemes and misuse of security-test metrics.
Takeaways & Limitations
The paper summarizes challenges intended to promote progress in image-data protection and improve attention to scenario-oriented image-security problems.
Takeaways & Limitations
The reviewed survey is bounded by the technical limitations and assumptions of particular schemes, including constructions where plaintext sensitivity can be canceled.
Abstract
from arXiv · showhide
This paper aims to review the encountered technical contradictions when an attacker meets the cipher-images encrypted by the image encryption schemes (algorithms) proposed in 2018 from the viewpoint of an image cryptanalyst. The most representative works among them are selected and classified according to their essential structures. Almost all image cryptanalysis works published in 2018 are surveyed due to their small number. The challenging problems on design and analysis of image encryption schemes are summarized to receive the attentions of both designers and attackers (cryptanalysts) of image encryption schemes, which may promote solving scenario-oriented image security problems with new technologies.
1. Introduction
Image-data security remained a major challenge in 2018, alongside substantial activity in designing encryption schemes and analyzing cipher-images. This paper selects and classifies representative protective and cryptanalytic works to identify challenges for both designers and attackers.
- About 1,000 image-encryption-related publication records appeared in 2018, with additional work in conferences such as ISCAS and ICME.
- Many image-encryption schemes followed permutation-then-diffusion without substitution-boxes, while only a small number used S-boxes.Chaotic maps were commonly used to generate pseudo-random number sequences controlling basic encryption operations.
- The paper selects and classifies representative methods for protecting and disclosing image data and summarizes challenges from a senior cryptanalyst’s perspective.
- Few schemes addressed specific applications such as wireless communication and surveillance, motivating an annual review of confrontation between image-data attackers and protectors.
- The paper reviews 2018 encryption designs, surveys cryptanalytic work, summarizes challenges, and concludes with implications for image security.
2.1. Image encryption schemes based on chaos
Chaos-based image-encryption schemes in 2018 explored improved chaotic systems, diverse operation structures, multi-image designs, optimization, and compressive sensing. The reviewed designs also exposed recurring weaknesses, including plaintext-sensitivity cancellation in some constructions.
- 2018 chaos-based schemes were coarsely classified into five subsections according to essential structure and methodology.
- Designers used cascaded maps, higher-dimensional Cat matrices, combined nonlinear operations, anti-control, and hyper-chaotic systems to address chaotic-map degradation and improve PRNS randomness.
- Finite-field periodicity and state-mapping-network analysis were used to examine chaotic-map behavior and the resulting digital-computer systems.
- Single- and multi-round schemes combined permutation, diffusion, XOR, modular arithmetic, bit-plane operations, S-boxes, and diverse chaotic PRNS sources.
- Plaintext sensitivity can be canceled in some schemes because selected pixels do not influence others or because modular addition is commutative.
- Other designs encrypted multiple images, image sequences, color channels, transform coefficients, or compressed measurements using chaotic systems and related processing methods.
2.2. Designing image encryption schemes based on DNA encoding
DNA-encoding image-encryption research remained active in 2018, combining DNA operations with chaotic PRNS generation, scrambling, and specialized image-processing settings.
- About twenty technical papers on DNA-based image encryption were published in 2018, and representative works were reviewed.
- Representative schemes combined pixel permutation, DNA-based bit substitution, and DNA-based bit permutation under control of chaotic or neural-network PRNS generators.
- Other designs applied DNA encoding to optical images, pixel- and bit-level scrambling, DNA-rule control, saliency-based encryption, and DCT-domain embedding.
2.3. Encrypting image in transform domain
Transform-domain methods in 2018 addressed optical, hyperspectral, QR-code, DCT, JPEG, and homomorphic-encryption settings. The reviewed approaches combined transforms with scrambling, masking, coding, or stream-cipher operations.
- Most optical-image encryption schemes were digitally simulated because of limitations in optical devices.
- One quaternion Fourier-transform method was reported superior to eight existing algorithms on key space, key sensitivity, statistical analysis, and robustness.
- Transform-domain schemes covered hyperspectral images with gyrator transforms and QR codes with shearlet and spiral phase transforms.
- A DCT-domain framework used block-wise permutation and XOR with a stream cipher, while a JPEG scheme cascaded bitstream operations with negligible size expansion.
2.4. Signal processing in the encrypted domain
The paper reviews methods for processing encrypted images, including reversible data hiding, homomorphic transforms, and compression-oriented reconstruction. These approaches aim to preserve or recover image information while operating in the encrypted domain.
- Encrypted-domain processing: Encrypted-domain processing includes fast real and complex Walsh-Hadamard transforms with parallelization strategies to reduce homomorphic-encryption complexity.The methods target computational acceleration of transforms applied directly to cipher-images.
- Reversible data hiding: Reversible data hiding in encrypted images allows cloud-side embedding while enabling authorized receivers to perfectly reconstruct the plaintext image.Reviewed schemes use private-key or public-key homomorphism, MSB prediction, and embedding-room reservation strategies.
- Compression and reconstruction: Compression-oriented methods address encrypted JPEG bitstreams, low-frequency wavelet coefficients, and encrypted binary images using lossless recovery or iterative reconstruction.The reviewed approaches combine rate-distortion optimization, Markov Random Fields, or iterative recovery with encrypted-image compression.
2.5. Generating cipher-images in other application scenarios
The review covers application-oriented cipher-image generation beyond conventional encryption, including secret sharing, privacy-preserving multimedia services, quantum representations, and permutation methods resistant to jigsaw-puzzle attacks.
- Secret sharing: XOR-based (k, n)-visual secret sharing schemes allow any k shares to reveal a secret image, while k−1 or fewer shares reveal nothing.The reviewed constructions also support revealing the image when more than k shares are available.
- Privacy-preserving applications: Privacy-preserving image applications include friend recommendation, biometric authentication, and searchable symmetric encryption over encrypted multimedia data.These methods use encrypted feature vectors, zero-knowledge proofs, locality-sensitive hashing, homomorphic encryption, or pseudo-random position permutations.
- Quantum image encryption: Quantum image-encryption research proposes quantum representations and a quantum 3D Arnold transform for simultaneously encrypting multiple plaintext images.Numerical simulations are used to show the performance of a multi-image encryption scheme combining the quantum transform.
- Permutation against attacks: Encryption-then-compression with encrypted blocks can preserve compression performance and resist conventional ciphertext-only attacks based on jigsaw-puzzle solvers.The approach encrypts each block with limited statistical influence before permuting the encrypted blocks across the image.
3. Survey on image cryptanalysis in 2018
The survey examines about 30 image-cryptanalysis papers from 2018, covering attacks on simple and complex chaotic schemes, optical systems, side channels, and encrypted-domain data hiding. It emphasizes that commonly used security metrics can be ineffective and that attack methods depend on scheme structure and scenario.
- Scope and metrics: Four deliberately insecure schemes showed that correlation, entropy, histogram variance, NPCR, UACI, key sensitivity, and randomness tests can provide ineffective security assessments.The paper reports that quantitative results on these metrics were insufficient for reliable security analysis.
- Attacks on chaotic schemes: Chosen-plaintext attacks recover equivalent keys or unknown parameters in several one-round PTDWOS and chaotic schemes by exploiting modulo addition, XOR, permutations, or mask operations.Examples include cancellation of plaintext sensitivity, recovery from known plaintext–ciphertext pairs, and attacks on Ikeda-map and APFM-based designs.
- Complex structures: More complex structures increase cryptanalytic difficulty, but attacks still target limited-round PTDWOS, static permutations, S-box and PRNS recovery, and scenario-specific weaknesses.The survey notes that repeating operations or adding S-boxes complicates analysis without eliminating the need for structural attacks.
- Optical cryptanalysis: Optical encryption systems are attacked using phase retrieval, filtering, normalization, or deep neural networks trained on plaintext–ciphertext pairs.The reviewed attacks cover double-image optical encryption, phase-truncated Fourier systems, and random-phase encoding.
- Other attack methods: Side-channel and gate-level analyses reveal intermediate values or distinguish operations affecting resistance, with Fredkin gates reported as effective against the supported chosen-ciphertext attack.Other reviewed work attacks chaotic stream ciphers through parameter estimation or nominal-matrix recovery.
- Other attack methods: A ciphertext-only attack can recover an approximate plaintext with good visual quality from bit-plane correlations in XOR-encrypted reversible-data-hiding images.The attack exploits strong correlations among neighboring bits in natural-image bit-planes.
4. The challenges on design and analysis of image encryption schemes
The paper identifies design and analysis challenges including weak application alignment, inadequate handling of image formats, neglected S-boxes and chaotic randomness, misused security metrics, and insufficient use of cryptanalytic lessons. It calls for stronger analysis and scenario-aware design.
- Design challenges: Most image-encryption schemes target no specific application, preventing explicit balancing of computational load, required security level, and attack cost.Only a few schemes address scenarios such as surveillance, IIoT, and social media.
- Design challenges: Many schemes treat images as ordinary textual data despite the need to combine encryption with compression and accommodate formats such as DICOM.One cited medical-image approach encrypts only the region of interest with one permutation-and-substitution round for real-time processing.
- Design challenges: S-boxes are seldom adopted even though lookup-table substitution can obscure the relationship between secret keys and cipher-images.The paper presents this as a neglected design component in image encryption.
- Randomness and assessment: Chaos-based pseudorandom sequences can have weak randomness under finite-precision digital computation, requiring further theoretical analysis of chaotic maps.The paper specifically points to period analysis and extensions from Z_2 to Z_2^e using tools such as Hensel’s lifting lemma.
- Randomness and assessment: Widely used image-encryption security metrics are described as unconvincing, motivating the establishment of convincing security-assessment methodologies.The critique includes metrics commonly used in chaos-based schemes and is linked to findings from cryptanalysis.
- Lessons from cryptanalysis: Designers may ignore prior cryptanalytic lessons, allowing plaintext-dependent PRNS sensitivity mechanisms to be canceled with specially constructed plaintexts.The paper cites repeated reports of this weakness across image-encryption schemes.
- Lessons from cryptanalysis: Cryptanalysis should emphasize attack conditions, computational cost, and space complexity rather than requiring attackers to propose defensive modifications.The paper distinguishes statistical testing from cryptanalysis and notes that successful attackers may not possess comprehensive design knowledge.
- Analysis challenges: Advanced methods from classic text cryptanalysis should be applied to seemingly complex schemes such as multi-round PTDWOS.The recommendation addresses the difficulty of analyzing structures whose complexity increases through repeated operations or substitution.
5. Conclusion
The paper reviews representative 2018 works on protecting and attacking image data, classifies them, highlights creative methods, and summarizes challenges in image-encryption design and analysis.
- The review examines representative 2018 image-data protection and attack works from a senior image cryptanalyst’s viewpoint.
- It classifies works on both sides of image-data protection and attack while highlighting creative ideas and methods.
- It summarizes challenges in designing and analyzing image-encryption schemes to promote progress in image-data protection in cyberspace.