Murillo-Escobar Miguel Angel, Meranza-Castillón Manuel Omar, López-Gutiérrez Rosa Martha, Cruz-Hernández César
Electronics and Telecommunication Department, Scientific Research and Advanced Studies Center of Ensenada (CICESE), Ensenada BC 22860, Mexico.
Engineering, Architecture and Design Faculty, Autonomous University of Baja California (UABC), Ensenada BC 22860, Mexico.
Entropy (Basel). 2019 Aug 20;21(8):815. doi: 10.3390/e21080815.
Currently, chaos-based cryptosystems are being proposed in the literature to provide confidentiality for digital images, since the diffusion effect in the Advance Encryption Standard (AES) algorithm is weak. Security is the most important challenge to assess in cryptosystems according to the National Institute of Standard and Technology (NIST), then cost and performance, and finally algorithm and implementation. Recent chaos-based image encryption algorithms present basic security analysis, which could make them insecure for some applications. In this paper, we suggest an integral analysis framework related to comprehensive security analysis, cost and performance, and the algorithm and implementation for chaos-based image cryptosystems. The proposed guideline based on 20 analysis points can assist new cryptographic designers to present an integral analysis of new algorithms. Future comparisons of new schemes can be more consistent in terms of security and efficiency. In addition, we present aspects regarding digital chaos implementation, chaos validation, and key definition to improve the security of the overall cryptosystem. The suggested guideline does not guarantee security, and it does not intend to limit the liberty to implement new analysis. However, it provides for the first time in the literature a solid basis about integral analysis for chaos-based image cryptosystems as an effective approach to improve security.
目前,由于高级加密标准(AES)算法中的扩散效应较弱,文献中正在提出基于混沌的密码系统来为数字图像提供保密性。根据美国国家标准与技术研究院(NIST)的说法,安全性是评估密码系统时最重要的挑战,其次是成本和性能,最后是算法和实现。最近基于混沌的图像加密算法进行了基本的安全性分析,这可能使它们在某些应用中不安全。在本文中,我们提出了一个与基于混沌的图像密码系统的全面安全性分析、成本和性能以及算法和实现相关的综合分析框架。基于20个分析点提出的指导方针可以帮助新的密码设计者对新算法进行综合分析。未来新方案在安全性和效率方面的比较可以更加一致。此外,我们还介绍了有关数字混沌实现、混沌验证和密钥定义的方面,以提高整个密码系统的安全性。所提出的指导方针不能保证安全性,也无意限制实施新分析的自由度。然而,它首次在文献中为基于混沌的图像密码系统的综合分析提供了坚实的基础,作为提高安全性的有效方法。