ON THE SECURITY OF SOME MULTIMEDIA ENCRYPTION SCHEMES
Li Cheng Qing, Hong Kong · 2008
The security of multimedia data becomes more and more important due to the rapid development of the modern computer, networking and information technologies. Notably, the traditional text encryption schemes fail to protect the multimedia data efficiently because of the special properties of multimedia data. To overcome this difficulty, researchers tried to develop special encryption schemes for multimedia data adopting some related nonlinear theories. However, some new schemes have been found to be insecure from the viewpoint of cryptography, and some general recommendations have been drawn to facilitate the design of more secure multimedia encryption schemes. This thesis is concerned with the security analysis of some multimedia encryption schemes. The security of the schemes against some common attack methods, such as bruteforce attack, known/chosen-plaintext attack and differential attack, is investigated in detail with theoretical analyses and experimental verifications. In addition, some special design defects of the schemes are revealed and discussed. The main contributions of the thesis are summarized as follows: 1. The security problems of a symmetric key block cipher using multiple one-dimensional chaotic maps are cryptanalyzed in detail. Some new findings are: 1) a number of weak keys exists; 2) some important intermediate data of the cipher are not sufficiently random; 3) the whole secret key can be broken by a known-plaintext attack with only 120 consecutive known plain-bytes in one known plaintext; 4) an improved version of the chaotic cipher still suffers from all the same security defects. 2. Recently two encryption schemes were proposed by combining circular bit shift and XOR operations, under the control of a pseudorandom bit sequence (PRBS) generated from a chaotic system. These two schemes are cryptanalyzed together, leading to the following findings: 1) there exist some security defects in both schemes; 2) the underlying chaotic PRBS can be reconstructed as an equivalent key by using only two chosen plaintexts; 3) most elements in the underlying chaotic PRBS can be obtained by a differential known-plaintext attack using only two known plaintexts.