An Empirical Oracle-Game Study of CPA and CCA2 Oriented Tradeoffs in a Chaotic Image Cipher with Nonce-Based and Authenticated Variants


Creative Commons License

İnce C., İNCE K.

Engineering Perspective, cilt.6, sa.4, ss.511-525, 2026 (Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 6 Sayı: 4
  • Basım Tarihi: 2026
  • Doi Numarası: 10.64808/engineeringperspective.1919463
  • Dergi Adı: Engineering Perspective
  • Derginin Tarandığı İndeksler: Scopus
  • Sayfa Sayıları: ss.511-525
  • Anahtar Kelimeler: Authenticated encryption, Chaotic image encryption, IND-CCA1, IND-CCA2, IND-CPA, Security-performance tradeoff, SIPI dataset
  • Açık Arşiv Koleksiyonu: AVESİS Açık Erişim Koleksiyonu
  • İnönü Üniversitesi Adresli: Evet

Özet

Chaotic image cryptography studies, which are quite popular, are often presented with robust statistical metrics, but how a scheme behaves under active attack is rarely analyzed. This paper examines this gap in a fixed chaotic image encryption kernel by considering three versions derived from the same design: a deterministic basis, a random number-based variant, and an authenticated variant. The variants are diversified without altering the internal permutation-diffusion stages, making the effect of random number insertion and ciphertext authentication directly observable. Experiments were performed on 39 images from the USC SIPI miscellaneous set. To maintain a common processing path, grayscale images were converted to RGB form where necessary, and 325 dimensionally compatible left-right oracle pairs were generated. The evaluation was designed to combine three components: traditional statistical image encryption metrics, empirical oracle game experiments compatible with CPA, CCA1, and CCA2-focused attack settings, and cost-of-implementation metrics. Across the three variants, the statistical profile remained broadly similar. Mean ciphertext entropy stayed near 7.992, while effective one-pixel NPCR and UACI averages remained near 99.61% and 33.46%, respectively, very close to ideal values. Full dataset ablation that retained three null-perturbation cases yielded lower pooled values near 91.94% and 30.89%. However, the security results provided a clearer differentiation between the variants. While the deterministic basis was observed to be completely vulnerable, the nonce-based variant eliminated deterministic replay vulnerability but remained distinguishable in CPA and CCA1-aligned experiments, with average success rates of 0.7754 and 0.7292, respectively. The authenticated variant did not eliminate distinguishability on the CPA side, but the modified challenge reduced the CCA2-aligned success rate to 0.4969, consistent with random guessing, and rejected all tampering attempts tested. This added layer of protection resulted in a limited additional cost. The ciphertext expansion increased from 0.02722% to 0.03903%, and the average total latency increased by approximately 1.16 ms. When the results are considered together, it is concluded that strong statistical image encryption performance alone does not necessarily translate to stronger practical security; the decisive improvement stems from the addition of ciphertext authentication.