The proliferation of image-centric applications in healthcare, defense communication, cloud storage, and social platforms has intensified the demand for encryption schemes that combine strong confusion–diffusion properties with verifiable ciphertext integrity. Existing elliptic curve cryptography–linear fractional transformation (ECC–LFT) image ciphers achieve favorable statistical security but generally omit a standardized authentication mechanism, leaving ciphertexts exposed to undetected tampering. This paper proposes a four-stage hybrid pipeline that closes this gap. Dynamic 8×8 substitution boxes are first constructed over GF(2?) using parameters derived from an elliptic-curve pseudo-random generator and a linear fractional transformation, yielding a nonlinearity score of 112. An elliptic-curve-driven pseudo-random index sequence then permutes the substituted pixels, a ChaCha20 keystream whitens the permuted stream, and AES-256 in Galois/Counter Mode encrypts the whitened stream and appends a 128-bit authentication tag, providing NIST-aligned authenticated encryption. Evaluated on standard test images, the framework achieves information entropy of 7.9990–7.9992, NPCR of 99.60%–99.63%, UACI of approximately 33.41%–33.43%, and adjacent-pixel correlation below 0.06 in all directions, with the constructed S-boxes attaining optimal nonlinearity, balanced output, and zero linear structure. Comparative evaluation against six state-of-the-art schemes indicates competitive or superior statistical security while uniquely providing cryptographic tamper detection through the embedded authentication tag.
Introduction
The text presents a hybrid image-encryption framework designed to protect digital images from both unauthorized access and tampering. The motivation is that images contain large amounts of highly correlated pixel data, so traditional encryption approaches may not adequately address image-specific statistical patterns and authentication requirements.
The proposed system combines Elliptic Curve Cryptography (ECC), Linear Fractional Transformation (LFT), ChaCha20, and AES-256-GCM into a four-stage encryption process:
Key Derivation: PBKDF2-HMAC-SHA256 derives separate AES and ChaCha20 keys from a user password.
ECC–LFT S-Box Substitution: An ECC-based pseudorandom process generates a dynamic 8-bit S-box that substitutes image pixels and provides strong confusion.
ECC-Based Pixel Permutation: Pixels are rearranged using a pseudorandom permutation generated from an ECC-derived seed, reducing spatial correlation.
ChaCha20 Whitening + AES-256-GCM: ChaCha20 removes remaining statistical patterns, while AES-256-GCM provides final encryption and a 128-bit authentication tag that detects any modification of the ciphertext.
Main Contribution
The major contribution is the integration of authenticated encryption (AES-256-GCM) into an ECC–LFT image-encryption pipeline. Previous ECC- and chaos-based image encryption methods often focused on confidentiality and statistical properties but lacked a standardized mechanism for detecting whether encrypted data had been altered. The proposed approach addresses this by verifying the authentication tag before decrypting the image.
Experimental Evaluation
The system was implemented in Python 3.11 using the cryptography library, NumPy, and Pillow. It was tested on five 512×512 RGB images: Lena, Baboon, Chile, Earth, and Women.
The results showed:
The generated S-boxes achieved nonlinearity of 112, matching the AES S-box and representing the practical optimum for 8-bit S-boxes.
SAC and BIC values were close to the ideal value of 0.5.
Linear approximation probability was 0.0625.
Differential approximation probability was 0.015625.
Encrypted images appeared visually similar to random noise and revealed no recognizable information.
Image histograms became nearly uniform after encryption.
Pixel correlations dropped dramatically: plaintext correlations were approximately 0.83–0.97, while encrypted correlations were below 0.055 in magnitude.
The AES-GCM authentication tag allows the receiver to detect ciphertext modification before recovering image data.
Conclusion
This paper presented a hybrid image-encryption framework that combines an ECC-driven Linear Fractional Transformation S-box with AES-256 in Galois/Counter Mode. The four-stage pipeline — dynamic S-box substitution, ECC-based pixel permutation, ChaCha20 whitening, and AES-256-GCM — achieves near-ideal information entropy (7.9990–7.9992), NPCR of 99.60%–99.63%, UACI of 33.41%–33.43%, and adjacent-pixel correlation below 0.06, while the constructed S-boxes attain optimal nonlinearity of 112 with zero linear structure. Comparative evaluation against six state-of-the-art ECC- and chaos-based schemes shows competitive or superior statistical security, and the embedded 128-bit authentication tag provides cryptographic tamper detection that is absent from all compared designs. The framework offers a practical path toward image encryption that is simultaneously confidential and verifiably authentic, suited to telemedicine, satellite communication, and digital forensics. Future work will target GPU-accelerated real-time encryption, post-quantum key encapsulation, and a formal security proof.
References
[1] S. S. Jamal, Z. Bassfar, O. Lahlou, A. Aljaedi, and M. M. Hazzazi, “Image encryption based on elliptic curve points and linear fractional transformation,” IEEE Access, vol. 12, pp. 53335–53347, 2024.
[2] M. I. Haider, A. Ali, D. Shah, and T. Shah, “Block cipher’s nonlinear component design by elliptic curves: an image encryption application,” Multimed. Tools Appl., vol. 1, pp. 1–26, 2020.
[3] S. Ibrahim and A. M. Abbas, “Efficient key-dependent dynamic S-boxes based on permutated elliptic curves,” Inf. Sci., vol. 558, pp. 246–264, 2021.
[4] S. Toughi, M. H. Fathi, and Y. A. Sekhavat, “An image encryption scheme based on elliptic curve pseudo random and advanced encryption system,” Signal Process., vol. 141, pp. 217–227, 2017.
[5] H. U. Rehman, M. M. Hazzazi, T. Shah, A. Aljaeti, and Z. Bassfar, “Color image encryption by piecewise function and elliptic curve over the Galois field GF(2?),” AIMS Math., vol. 9, no. 3, pp. 5722–5745, 2024.
[6] A. Razaq, A. Ullah, H. Alolaiyan, and A. Yousaf, “A novel group theoretic and graphical approach for designing cryptographically strong nonlinear components of block ciphers,” Wireless Pers. Commun., vol. 116, no. 4, pp. 3165–3190, 2021.
[7] Z. Hua, J. Li, Y. Chen, and S. Yi, “Design and application of an S-box using complete Latin square,” Nonlinear Dyn., vol. 104, no. 1, pp. 807–825, 2021.
[8] Z. Jiang and Q. Ding, “Construction of an S-box based on chaotic and bent functions,” Symmetry, vol. 13, no. 4, p. 671, 2021.
[9] H. ur Rehman, T. Shah, M. M. Hazzazi, A. Alshehri, and B. Zaid, “Mordell elliptic curve based design of nonlinear component of block cipher,” Comput. Mater. Continua, vol. 73, no. 2, pp. 2913–2930, 2022.
[10] A. M. Hilal, F. N. Al-Wesabi et al., “Design of nonlinear components over a Mordell elliptic curve on Galois fields,” Comput. Mater. Continua, vol. 71, no. 1, pp. 1313–1329, 2022.
[11] A. A. A. El-Latif and X. Niu, “A hybrid chaotic system and cyclic elliptic curve for image encryption,” AEU Int. J. Electron. Commun., vol. 67, no. 2, pp. 136–143, 2013.
[12] N. Jia, S. Liu, Q. Ding, S. Wu, and X. Pan, “A new method of encryption algorithm based on chaos and ECC,” J. Inf. Hide. Multimed. Signal Process., vol. 7, pp. 637–643, 2016.
[13] O. Reyad, Z. Kotulski, and W. M. Abd-Elhafiez, “Image encryption using chaos-driven elliptic curve pseudo-random number generators,” Appl. Math. Inf. Sci., vol. 10, no. 4, pp. 1283–1292, 2016.
[14] J. Wu, X. Liao, and B. Yang, “Color image encryption based on chaotic systems and elliptic curve ElGamal scheme,” Signal Process., vol. 141, pp. 109–124, 2017.
[15] S.-S. Yu, N.-R. Zhou, L.-H. Gong, and Z. Nie, “Optical image encryption algorithm based on phase-truncated short-time fractional Fourier transform and hyper-chaotic system,” Opt. Lasers Eng., vol. 124, p. 105816, 2020.
[16] L. C. Washington, Elliptic Curves: Number Theory and Cryptography. Boca Raton, FL, USA: CRC Press, 2008.
[17] B. Kaliski, “PKCS #5: Password-based cryptography specification version 2.0,” IETF, Tech. Rep. RFC 2898, 2000.
[18] D. J. Bernstein, “ChaCha, a variant of Salsa20,” in Workshop Record of SASC 2008, 2008, pp. 3–5.
[19] M. Dworkin, “Recommendation for block cipher modes of operation: Galois/Counter Mode (GCM) and GMAC,” NIST, Tech. Rep. SP 800-38D, 2007.
[20] M. I. Haider, T. Shah, A. Ali, D. Shah, and I. Khalid, “An innovative approach towards image encryption by using novel PRNs and S-boxes modeling techniques,” Math. Comput. Simul., vol. 209, pp. 153–168, 2023.