1. Introduction
The widespread use of the Internet has greatly facilitated the transmission of digital images. However, its inherent openness also exposes these images to risks of interception and data leakage during transmission [
1]. As a result, enhancing the security of digital images has become a critical concern in the field of network information security [
2]. Image encryption serves as a key technique for safeguarding image content. Such encryption algorithms typically introduce confusion and diffusion into the original image, rendering it unrecognizable. Even if an encrypted image is intercepted, an attacker who is unable to break the encryption algorithm can gain no meaningful information from it.
Traditional cryptography algorithms, including the RSA algorithm, Advanced Encryption Standard (AES), Data Encryption Standard (DES), etc., are designed for text information [
3]. Theoretically, these encryption algorithms can also be used for digital image encryption. However, there are disadvantages such as low efficiency and a complex calculation process [
4], which is due to the characteristics of image data, including large amounts of information, high redundancy, and strong correlation. These traditional algorithms cannot meet the requirements of real-time image encryption. Many image encryption algorithms have been proposed to protect the security of image content. These are based on various techniques, such as compressed sensing [
5,
6,
7], wavelet transform [
8,
9], S-box [
10], chaotic systems [
11,
12,
13], and image recognition [
14]. Among them, chaotic systems are widely used for image encryption due to their high computational efficiency [
15]. Additionally, Gandelman presents a compact, tabletop emulation of the six-state protocol, implemented with a pulsed laser source and bulk polarization optics to reproduce the essential protocol-level logic and expected basis-dependent statistics of quantum key distribution in a controlled classical setting [
16].
Recently, chaotic-systems-based cryptography has become very popular and is applied in different image encryption techniques. Chaotic systems show the behavior of pseudo randomness and possess a number of important features: unpredictable orbital growth, increased sensitivity to initial circumstances and factors, and ease of hardware and software implementation to boost the rate of encryption [
17]. Chaotic systems can generally be divided into one-dimensional (1D) chaos and high-dimensional chaos. High dimensional chaotic systems usually have better performance and higher security, but at the same time their structure is complex and the calculation costs are high. In contrast, 1D chaotic mapping is preferred because of its simple structure, easy implementation, and low computational complexity [
18]. Zheng et al. constructed a cascade two-dimensional (2D) chaotic map and obtained a good chaos effect, but they did not associate
x and
y with each other [
19]. In essence, they constructed two independent 1D chaotic systems. Xiong et al. also made the same mistake when constructing high-dimensional chaotic systems [
20], and at the same time, they did not make corresponding analysis of the constructed chaotic map and could not show its performance. Wang and his colleagues proposed a modified Chebyshev chaotic map, which offers a more even distribution of chaotic sequences compared to the conventional Chebyshev map [
21]. Nevertheless, its chaotic interval still contains numerous periodic windows. Meanwhile, Zhu et al. [
22] built a one-dimensional piecewise quadratic polynomial chaotic map by combining the Logistic and Sine maps. Unfortunately, this map fails to remain chaotic when its control parameters are set to small values. Consequently, these one-dimensional chaotic maps suffer from several limitations, including a narrow range of control parameters, poor randomness in the generated pseudo-random sequences, and the existence of periodic windows. Chen et al. proposed a cascade chaotic system based on the Cubic map and Cosine map, which has a larger parameter range and a wider chaotic region [
23]. Wang et al. combined the Logistic map with the Sine map and introduced the delayed-state x
i−1. Chaos x
i+1 is not only disturbed by the current state variable, but is also affected by the previous state, so the new chaotic map obtains excellent performance [
24].
Most image encryption algorithms include the scrambling and diffusion stages [
25]. At the scrambling stage, the pixel positions are changed and the correlation of the original pixels is broken. The diffusion stage is required to change the pixel value so as to improve security performance. The two stages of scrambling and diffusion have a clear division of labor, which can usually produce a better result, but the operation complexity is higher. In contrast, the unusual structure of simultaneous scrambling–diffusion can reduce the algorithmic complexity and obtain good results [
26].
Zhu et al. adopted the Rubik’s cube model. They divided the original image into 8 × 8 small blocks and transformed the pixels to the bit-level to form several 8th-order Rubik’s cubes [
27]. The three-directional (3D) rotation controlled by chaos can fully disturb the Rubik’s cube, and because it is a bit-level operation, it can realize the effect of simultaneous scrambling–diffusion. Chen et al. adopted a DNA-level Rubik’s cube model to reduce the complexity of the simultaneous scrambling–diffusion stage [
28]. However, due to the introduction of DNA operation, it is time-consuming in the coding and decoding stages, so the overall efficiency of the algorithm is not ideal. Sheng et al. proposed a simultaneous scrambling–diffusion algorithm based on a Latin square [
29]. They used a Latin square to select the concatenation pixel matrix and the key stream matrix and combined them to complete diffusion. This algorithm represents higher innovation and results in a better encryption effect. On the basis of 2D index scrambling, Wen et al. added spiral scanning to change the order, and at the same time changed the pixel value with optional operations such as addition, subtraction, or cyclic shift [
30]. The operation was relatively simple and achieved good results.
To ensure the security of images and improve the efficiency of encryption, an image 3D encryption method inspired by the 3D histogram model is proposed in this paper. The main contributions of this paper are highlighted below.
- (1)
A novel hyperchaotic system is proposed, and a series of performance analyses are conducted to demonstrate its excellent ergodicity and randomness.
- (2)
A 3D image encryption method is constructed by extending conventional 2D images into a 3D model. The definitions of 3D histogram scrambling and diffusion are presented, and image confusion is achieved via 3D histogram operations.
- (3)
A 3D histogram simultaneous scrambling–diffusion system is proposed. Based on the designed 3D histogram model and the corresponding scrambling–diffusion operations, an image encryption algorithm based on chaotic maps and the 3D histogram model is proposed.
The remainder of this paper is organized as follows.
Section 2 presents the novel chaotic map, analyzes its performance, and provides a brief introduction to the image three-dimensional histogram model.
Section 3 details the proposed novel image encryption algorithm.
Section 4 describes the experimental setup and results.
Section 5 presents a comprehensive analysis of the algorithm. Finally,
Section 6 draws conclusions and outlines future research directions.
2. Preliminary Work
2.1. Chaotic System
Traditional 1D chaotic maps have a simple structure, but suffer from inherent drawbacks such as narrow chaotic parameter ranges, weak randomness of generated sequences, and numerous periodic windows. Most existing 2D chaotic maps fail to achieve strong cross-coupling between state variables; they are essentially two independent 1D chaotic maps spliced together, and can hardly meet the security requirements of high-security image encryption.
This paper selected cosine and arccosine functions to construct the chaotic system based on the dual considerations of practicality and security. The two functions are inverse to each other, so their value ranges are naturally matched during calculation, which avoids problems like invalid iteration and numerical deviation, and ensures the stable operation of the whole system. According to the subsequent chaotic performance analysis, their combination can produce a sufficiently strong nonlinear effect, and the generated random sequence has higher randomness for better encryption security.
On this basis, this paper takes the cosine and arccosine functions as the nonlinear kernel, introduces a bidirectional cross-coupled structure, and proposes a novel 2D Cosine-Arccosine Cross-Combined Map (2D-CACCM). Its mathematical expression is shown in Equation (1):
where |·| is absolute value function and
a,
b are the control parameters; we set
a,
b ∈ (0.1, 100) in this paper. When the initial values of the system are in (0, 1),
the sequences generated by 2D-CACCM iteration are evenly distributed in (0, 1).
2.2. Chaotic Performance Analysis
2.2.1. Bifurcation Diagram
Figure 1a,b describe the bifurcation diagrams of the Logistic map and Sine map separately; their initial values are set as
x0 = 0.5.
Figure 1c–f present the bifurcation diagrams of the proposed 2D-CACCM, with the initial values set as
x0 = 0.2 and
y0 = 0.8. Specifically, in
Figure 1c,d, the control parameter
b is fixed at 0.2, and the diagrams depict the variation of state variables
x and
y with the control parameter
a. In
Figure 1e,f, the control parameter
a is fixed at 0.6, and the diagrams illustrate the variation of state variables
x and
y with the control parameter
b. This figure demonstrates that the proposed 2D-CACCM maintains uniform chaotic distribution in the full parameter range, with no obvious periodic windows, which is significantly superior to the classic 1D chaotic maps.
It can be seen from the bifurcation diagrams that the chaotic values are evenly distributed across all intervals of the control parameters. This demonstrates that 2D-CACCM exhibits excellent chaotic characteristics and complex chaotic dynamics over the entire parameter range, which is significantly superior to the classic 1D chaotic maps.
2.2.2. Lyapunov Exponent
The Lyapunov exponent (LE) is used to quantify the average divergence rate of two trajectories and is a numerical metric for evaluating the complexity of the dynamic system [
31]. The LE is defined as follows:
where
f(
xi) denotes a chaotic system. We calculate the LEs of the proposed 2D-CACCM and conducts a comparative analysis with classic one-dimensional (1D) chaotic maps. As shown in
Figure 2a,b, the LEs of the Logistic map and Sine map are positive only within a narrow parameter range, and this positive characteristic is discontinuous, which results in unstable and poor chaotic performance. In contrast, the Lyapunov exponent plots of the 2D-CACCM in
Figure 2c,d demonstrate that the proposed system maintains positive LEs over a wide parameter range when
a,
b is in (0.1, 20). These results verifies that the 2D-CACCM exhibits excellent and stable chaotic behavior under all tested control parameters.
2.2.3. Spectral Entropy Complexity
Spectral entropy (SE) provides a quantitative measure for assessing the complexity of iterative sequences generated from chaotic dynamics [
32].
When SE is positive, the generated sequence is irregular. With the increase in SE, the regularity of the generated sequence decreases, the randomness increases, and the chaotic behavior becomes more complex. The SE of 2D-CACCM is shown in
Figure 3, and its SE value is significantly greater than that in the Sine and Logistic maps, indicating that 2D-CACCM has better chaos performance.
2.2.4. Sensitivity
Sensitivity to the initial states means that even small differences in the initial states can result in completely different trajectories in the chaotic map, which is a necessary property for a qualified chaotic system [
32]. When we slightly change the initial states of the chaotic map, including the initial values and control parameters, its evolution will quickly deviate from the original trajectory, eventually leading to completely different behavior.
Figure 4a,c show the difference of the output of the chaotic system after 50 iterations with the same control parameters and different initial values, where (
x0,
y0,
a,
b) = (0.2, 0.8, 50, 50), (
x0a,
x1a,
aa,
ba) = (0.2 + 10
−10, 0.8, 50, 50) and (
x0b,
x1b,
ab,
bb) = (0.2, 0.8 + 10
−10, 50, 50).
Figure 4e describes the difference of the output trajectory with (
x0c,
x1c,
ac,
bc) = (0.2, 0.8, 50 + 10
−10, 50) after 50 iterations.
Figure 4b,d,f are the difference values of the chaotic trajectory in (a), (c), and (e), respectively.
It is evident that when the initial state of 2D-CACCM is slightly disturbed, the chaotic trajectory quickly deviates from the original trajectory after a very short overlap, which is negligible in amounts of iteration. It indicates that 2D-CACCM has excellent sensitivity to initial state changes.
2.2.5. The NIST SP800-22 Test
NIST SP800-22 can be used to evaluate the randomness of chaotic sequences in a probabilistic manner [
33]. It contains 15 tests, each of which generates a
p-value. A sequence is deemed to be random if its corresponding
p-value exceeds 0.01.
A long chaotic sequence of sufficient length is generated by the 2D-CACCM and converted into a binary stream for testing. As can be seen from the test results in
Table 1, the bit stream passed all the tests. It can be concluded that the sequences generated by 2D-CACCM are highly randomized.
2.2.6. 0–1 Test
The 0–1 test [
34] avoids the need for phase space reconstruction. To determine whether chaos exists in discrete data, one can compute the linear growth rate
K() of a transformed variable. Given a discrete time series
θ(
n),
n = 1, 2, …,
N and an arbitrary constant
c ∈ (0, π), the test statistic
K(
c) is obtained as follows:
where
and
The closer the value of
K is to 1, the more chaotic the sequence is. With
N = 100 and
c ∈ (π/5, 4π/5), the corresponding 0–1 test results are shown in
Figure 5. The
K value of the Logistic map and Sine map fluctuate and are close to 1 in a small range. The 0–1 test results of 2D-CACCM converge to 1 for all parameters. Therefore, 2D-CACCM has better chaos characteristics.
2.3. Image 3D Histogram Model
Traditional image encryption algorithms typically adopt the scrambling–diffusion structure, which requires two distinct operational phases. In recent years, simultaneous scrambling–diffusion has emerged as an active research direction, enabling the integrated permutation of pixel positions and the alteration of pixel values in a single phase.
Studies have shown that the 3D histogram of a digital image and the particle tower model share structural similarities in their 3D architectures, both exhibiting a 3D distribution consisting of spatial coordinates and grayscale values (or particle-stacking properties).
Figure 6 shows a particle tower model. Through our design, this 3D structure can be utilized to achieve simultaneous scrambling–diffusion for digital images.
A 3D histogram-based image encryption algorithm is defined as an algorithm that extends the dimensionality of a digital image, modifies the pixel positions and values in the image matrix from the perspective of 3D histograms, and thereby completes the scrambling and diffusion processes. A 2D digital image is converted into a 3D representation and is subsequently observed and encrypted from this three-dimensional perspective: each point on the plane with pixel value
p can be seen as a stack of
p particles, and the entire image can be seen as consisting of 256 grayscale planes.
Figure 7a shows the original 4 × 4 2D grayscale image, where each grid represents a pixel with its corresponding grayscale value.
Figure 7b presents the 3D histogram representation of the 4 × 4 image, where the X and Y axes correspond to the spatial coordinates of pixels in the original 2D image, and the Z axis corresponds to the grayscale value of the pixel at the corresponding coordinate.
Figure 8 shows the ‘Boat’ image and its 3D format.
The specific steps for extending the plain image to 3D space and merge to 2D are described as follows:
Step 1: Acquiring the image size parameters
Read the original image
I and acquire its size parameters using
Step 2: Generating a 3D zero matrix
Create a 3D zero matrix
with the size of
m ×
n × 256.
Step 3: Traversing and filling the 3D space
Traverse the original image
I, and assign the grayscale value
I(
x,
y) to
I′(
x,
y,
I(
x,
y) + 1).
Given that MATLAB’s matrix indices start at 1, the grayscale value is incremented by 1 to align with this convention. This adjustment ensures that index values correspond accurately to MATLAB’s indexing scheme when manipulating matrices or arrays in its environment.
Step 4: Permuting pixel positions and diffuse grayscale values
Perform 3D simultaneous permutation and diffusion using
where
f (·) and
g(·) denote spatial permutation functions acting on the coordinate system, and
h(·) denotes the intensity diffusion function operating on grayscale values. The proposed algorithm uses
to acquire the
z index and reduce computational complexity.
Step 5: Merging the 3D matrix and recover the original image.
Since the 3D matrix consists of zeros and the original grayscale values in the
z direction, the original pixel value can be calculated by summing the values along the
z-axis.
To maintain consistency with Equation (6) and successfully recover the plaintext image, a subtraction of 1 is applied to
s. Algorithm 1 describes the extension and merging process based on the 3D model, where notations are represented by ‘%’ in MATLAB language.
| Algorithm 1: Extending and merging based on the 3D histogram model |
Input: the plain image I and the chaos sequences f (·), g (·), and h (·) Output: the permuted matrix E 1: % Extending
2: [m, n] ← size(I)
3: ← zeros(m, n, 256)
4: for i ← 1 to m do
5: for j ← 1 to n do
6:
(i, j, I(i, j) + 1) ← 1
7: end
8: end
9: for i ← 1 to m do
10: for j ← 1 to n do
11: s ← find(I’(i, j,:))
12:
13: end
14: end
15: % Merging
16:
)
17: for k ← 1 to 256 do
18: E ← sum(I′(:, :, k) × (k − 1))
19: end |
3. Proposed Image Encryption Algorithm
A communication scenario for encryption and decryption is first defined: the sender and receiver are denoted as Alice and Bob, respectively. The following sections describe the core techniques of the proposed algorithm.
3.1. Alice’s Key Generation Process
The Secure Hash Algorithm 256-bit (SHA-256) is a standardized cryptographic hash function issued by the National Institute of Standards and Technology in the Federal Information Processing Standards Publication 180-4, and is the core member of the SHA-2 family. It accepts an input message of arbitrary length, processes it through an iterative Merkle–Damgård compression structure, and outputs a fixed-length 256-bit irreversible message digest [
35]. This paper combines the generated hash value with user-defined external keys to jointly calculate the initial values and control parameters of the 2D-CACCM chaotic system, so that the final encryption sequence is not only strongly related to the plaintext content, but also can be flexibly adjusted via external keys. Meanwhile, this design greatly expands the key space of the algorithm and further guarantees encryption security.
The proposed algorithm first applies the SHA-256 hash algorithm to compute the hash value Kh of the plaintext image. It then generates the control parameters and initial values of 2D-CACCM by combining Kh with the external keys. The detailed steps for key generating are as follows.
Step 1: Blocking the hash value
Split the 256-bit hash value Kh into 32 equal parts, each 8 bits in length. Let Kh = {k1, k2, …, k32}, with each ki being an 8-bit binary value.
Step 2: Calculating intermediate parameters
The 32 segments are XORed with each other, and four intermediate parameters are derived by following equations:
where
represents the XOR operation.
Step 3: Generating encryption keys
The control parameters
a,
b and the initial values
x0,
y0 of the 2D-CACCM are computed by
where
and
are the user-specific external keys. The generated
are the keys in our algorithm that need to be sent to the receiver along with the encrypted image during data transmission.
3.2. Alice’s Encryption Process
The algorithm adopts a simultaneous scrambling–diffusion method based on the 3D histogram model; the flowchart is shown in
Figure 9. Firstly, the 3D matrix is obtained by extending the plaintext image in accordance with Algorithm 1. Secondly, the chaotic sequences are used for simultaneous scrambling–diffusion. Thirdly, the 3D matrix is merged to obtain the 2D image. Finally, the 2D XOR diffusion is performed to achieve further diffusion to obtain a final encrypted image. Algorithm 2 shows the encryption process, and the detailed steps are as follows.
Figure 9.
Flowchart of the encryption process.
Figure 9.
Flowchart of the encryption process.
| Algorithm 2: The encryption process |
Input: the initial image I and the external keys Output: the encrypted image E 1: % Calculate the initial values and control parameters of the chaotic sequence 2: Kh ← SHA256(I) 3: {k1, k2, …, k32} ← Kh 4: for i ← 1 to 4 do
5: hi
6: end
7: a ← ( + mod(h1,100))/2
8:
← ( + mod(h1,100))/2 9: x0 ← + h2/512 + h3/512
10: y0 ← + h4/256 11: % Generate the chaotic sequences X1, X2 with the length of mn
12: X1, X2 ← 2D-CACCM()
13: X3 ← [X1(1:128), X2(mn − 127, mn)]
14: [~,Y1] ← sort(X1(1:m))
15: [~,Y2] ← sort(X2(mn − n + 1:mn))
16: [~,Y3] ← sort(X3)
17: % Extending to 3D space
18: B ← zeros(m, n, 256)
19: for i ← 1 to m do
20: for j ← 1 to n do
21: B(i, j, I(i, j) + 1) ← 1
22: end
23: end
24: % 3D simultaneous scrambling–diffusion
25: for j ← 1 to n do
26: for I ← 1 to m do
27: s ← find(B(i, j,:))
28:
29: end
30: end
31: % Merging to 2D image
32: for k ← 1 to 256 do
33: D ← sum(C(:, :, k) × (k − 1))
34: end
35: %2D XOR diffusion
36: Z ← mod(floor(X2 × 1015), 256)
37: for i ← 1 to mn do
38:
39: end |
Step 1: Generating encryption keys
The SHA-256 algorithm is applied to the plaintext image
Im×n to produce a 256-bit hash value
Kh. Following the procedure in
Section 3.1, the externally supplied keys are random real numbers that serve as the basis for calculating the control parameters and initial values of the 2D-CACCM.
Step 2: Generating chaotic sequences
Alice iterates the 2D-CACCM for 1000 + m × n iterations. The first 1000 non-chaotic values are discarded. Chaotic sequences X1 and X2, each with a length of m × n, are thus obtained.
Step 3: Separating and sorting chaotic sequences
The chaotic sequence
X3 is derived from
X1,
X2 as follows:
Step 4: Extending plaintext image based on the 3D histogram model
The matrix
I is extended using the 3D histogram model described in
Section 2.3, yielding the extended 3D matrix
B. For the sake of subsequent processing, Equation (6) is revised as follows:
Step 5: Performing 3D histogram simultaneous scrambling–diffusion
3D histogram simultaneous scrambling–diffusion is performed by Equation (14), and the resulting matrix is denoted as
C.
where
Y1,
Y2 are used to scramble 3D matrix
B and
Y3 is used to diffuse the 3D matrix
B.
Step 6: Merging to 2D image
The matrix
D is merged in accordance with Step 4 in
Section 2.3. Due to the revision of Equation (6), Equation (8) is also adjusted to
Step 7: Performing 2D XOR diffusion
2D XOR diffusion operation is performed on the matrix
D after simultaneous scrambling–diffusion using Equation (17).
The resulting matrix E with the size of m × n is the final encrypted image.
3.3. Bob’s Decryption Process
The decryption process is the strictly symmetric inverse operation of the encryption process, and the correctness of decryption is guaranteed by the reversibility of all operations in the encryption framework. The receiver Bob needs to use the exact same control parameters
a,
b and initial values
x0,
y0 of the 2D-CACCM to regenerate the completely consistent chaotic sequences, and then execute the inverse operations in the reverse order of the encryption process. Specifically, the reverse 2D XOR diffusion corresponds to the 2D XOR diffusion step in the encryption process, the reverse 3D simultaneous scrambling–diffusion corresponds to the 3D histogram simultaneous scrambling–diffusion step, and the 3D matrix merging corresponds to the 2D-to-3D extension step.
Figure 10 illustrates the overall flow of the decryption process, and Algorithm 3 lists each step in detail. The detailed execution steps of the full decryption process are described below.
Figure 10.
Flowchart of the decryption process.
Figure 10.
Flowchart of the decryption process.
| Algorithm 3: The decryption process |
Input: the encrypted image E, the initial values and control parameters of chaotic map Output: the decrypted image I
1: % Generate the chaotic sequences X1, X2 with the length of mn
2: X1, X2 ← 2D-CACCM()
3: X3 ← [X1(1:128), X2(mn − 127, mn)]
4: [~, Y1] ← sort(X1 (1:m))
5: [~, Y2] ← sort(X2 (mn − n + 1:mn))
6: [~, Y3] ← sort(X3)
7: % Reverse 2d XOR diffusion
8: Z ← mod(floor(X2 × 1015), 256)
9: for i ← 1 to m do
10: for j ← 1 to n do
11:
12: end 13: end 14: % Extending to 3D space
15: C ← zeros(m, n, 256)
16: for i ← 1 to m do
17: for j ← 1 to n do
18: C(i, j, D(i, j) + 1) ← 1
19: end
20: end
21: % Reverse 3D simultaneous scrambling–diffusion
22: for j ← 1 to n do
23: for i ← 1 to m do
24: Y3(s) ← find(C(i, j,:))
25:
26: end
27: end
28: % Merging to plain image
29: for i ← 1 to 256 do
30: I ← sum(B(:, :, i) × (i − 1)) 31: end |
Step 1: Generating chaotic sequences
Bob iterates the 2D-CACCM for 1000 + mn iterations using the keys a, b, x0, y0, and discards the first 1000 values to obtain chaotic sequences X1, X2 with a length of m × n.
Step 2: Separating chaotic sequences and deriving index sequences
Three chaotic sequences—X1, X2 and X3—are obtained according to Equation (11). Ascending index sequences Y1, Y2, and Y3 are obtained from Equation (13), and Z1 is obtained from Equation (16).
Step 3: Performing reverse 2D XOR diffusion
Reverse 2D XOR diffusion is performed by Equation (18), yielding the matrix D.
Step 4: Extending encrypted image based on 3D histogram model
The matrix
D is extended by Equation (19), yielding the 3D matrix
C.
Step 5: Performing reverse 3D simultaneous scrambling–diffusion
Equation (20) is used to inversely permutate the 3D matrix
C, and the result is denoted as
B.
Step 6: Merging to recover original plaintext image
The matrix
B is merged by Equation (21) and the resulting matrix is denoted as
I—the recovered original plaintext image.
5. Algorithm Analyses
The rapid development of chaotic image encryption has necessitated comprehensive evaluation to assess security performance. Recent reviews in the literature systematically categorize critical evaluation parameters into four dimensions: statistical robustness (histogram uniformity, correlation dissipation, information entropy), differential attack resilience (NPCR/UACI), computational security (key space, sensitivity), and implementation efficiency. To fully prove the stability of the algorithm, we have carried out experiments and analyzed the algorithm considering these aspects.
5.1. Sensitivity Analyses
5.1.1. Key Space Analysis
The key space is the sum of all possible values of unknown parameters in the algorithm, and its size determines the ability of the encryption algorithm to resist exhaustion attacks. If the key space is too small, the attacker may infer the initial key by violent enumeration, and thus crack the encryption algorithm. A key space exceeding 2
100 is generally considered large enough to resist exhaustive search attacks [
37]. The key space of our algorithm is discussed below in terms of two aspects.
(1) The view of the hash value and external keys
The hash value
Kh is a 256-bit binary sequence, and the external keys are
. As is mentioned in
Section 3.1,
and
are set in the experiment. Assuming a computational precision of 10
−14, the total key space of our algorithm is approximately 2
256 × 100 × 10
14 × 100 × 10
14 × 10
14×2 ≈ 2
455.
(2) The view of the chaotic system
The control parameters are a, b ∈ (0, 100) and the initial values are x0, y0 ∈ (0, 1). Assuming a computational precision of 10−14, the total key space of our algorithm is approximately 100 × 1014 × 100 × 1014 × 1014×2 ≈ 2199.
Taking both of the above considerations into account, the minimum key space of our algorithm reaches 2
199, which is far greater than the generally accepted threshold of 2
100 required for cryptographic security.
Table 2 compares the key space of the proposed scheme with those of several other algorithms. Although our algorithm does not outperform all existing methods in this particular metric, it is nevertheless sufficiently large to withstand brute-force attacks.
5.1.2. Key Sensitivity Analysis
A good algorithm must have high key sensitivity to defend against known plaintext attacks. In the analysis of key sensitivity, a pair of security keys containing small differences are used to encrypt the same original image to generate two completely different cryptographic images, and thus the difference between the two cryptographic images is further analyzed [
39]. To verify the key sensitivity of the proposed encryption scheme visually, we test the decrypted results using the correct key and slightly perturbed keys, supposing that the key utilized in the proposed algorithm is
key0 = {
a,
b,
x0,
y0}. Then, 10
−14 increases are made to
r,
x0, and
x1, respectively. The three new key sets are given as follows:
key1 = {
a + 10
−14,
b,
x0,
y0},
key2 = {
a,
b,
x0 + 10
−14,
y0}, and
key3 = {
a,
b,
x0,
y0 + 10
−14}. The encrypted image is then decrypted separately using the three altered key sets. As illustrated in
Figure 12, all decrypted images with perturbed keys are completely noise-like and cannot recover any valid plaintext information, which directly verifies the ultra-high key sensitivity of the proposed encryption algorithm.
Table 3 provides a numerical comparison among them. Even a tiny change in the secret key completely destroys the decrypted image and cannot recover valid plaintext information, which fully demonstrates the high key sensitivity of the proposed algorithm.
5.1.3. Differential Attack Analysis
The resistance of an encryption algorithm against differential cryptanalysis is usually quantified using the Number of Pixels Change Rate (NPCR) and Uniform Average Change Intensity (UACI) [
42]. Their mathematical definitions are provided below.
where
c1(
i,
j) denotes a pixel from the ciphertext image obtained from the original plaintext, while
c2(
i,
j) corresponds to the pixel at the same position in the ciphertext image generated after a single-pixel modification in the plaintext. The ideal theoretical values for NPCR and UACI are 99.6094% and 33.4635%, respectively [
41].
In this test, randomly chosen pixels in the plain image are altered at arbitrary positions. Because different image sizes may affect the test outcomes [
43], we conducted experiments on multiple images of various sizes, with the results listed in
Table 4. The obtained NPCR and UACI figures approximate the theoretical ideals well. Therefore, our algorithm meets the NPCR and UACI requirements and is capable of resisting differential attacks. As can be observed in
Table 5, the performance of the proposed scheme is closer to the theoretical values than that of other algorithms.
5.2. Statistical Analyses
5.2.1. Histogram Analysis
The histogram is the statistic of the distribution frequency of image gray values, which is the most basic statistical feature of an image. If the histogram distribution has obvious statistical properties, an attacker may be able to infer plaintext image information from it. The ciphertext histogram of a good encryption algorithm should be uniform and undifferentiated. The Peppers, Baboon, Boat, and House images are selected, and the histograms of plain images and their corresponding cipher images are shown in
Figure 13. Obviously, the histograms of the encrypted images are more uniform and dispersed than those of the ordinary images, which indicates that the algorithm has good anti-statistical attack ability.
5.2.2. Chi-Squared Test
To avoid visual errors and quantitatively analyze these values more accurately, we introduce a Chi-square test to give a statistical representation of pixel uniformity between gray values.
The Chi-square is defined by
where
oL and
eL are the observed and the expected numbers of the
L-th gray level, respectively.
The Chi-square test results for both the plaintext and ciphertext images are presented in
Table 5. As shown in
Table 6, the χ
2 values of all encrypted images fall below the critical values at the 1% and 5% significance levels [
46].
5.2.3. Correlation Analysis
A characteristic feature of digital images is the strong correlation typically observed between neighboring pixels, which attackers may exploit to extract meaningful information from textural patterns. An effective image encryption algorithm should therefore be capable of breaking such correlations. To evaluate this capability, we randomly select 1000 adjacent pixel pairs from both the plaintext and its corresponding ciphertext, considering horizontal, vertical, and diagonal directions. The correlation coefficient is then computed using the following formula:
where variables
x and
y correspond to the grayscale values of neighboring pixels in either the horizontal, vertical, or diagonal orientation. The quantity mm indicates the size of the selected pixel sample,
D(
x) denotes the variance of
x, and
E(
x) is the expectation of
x.
For plain images, the correlation coefficients are all above 0.9 and approach 1, indicating a very strong correlation among neighboring pixels. In contrast, the correlation coefficients of the encrypted images are close to 0, reflecting a weak or negligible correlation between adjacent pixels.
Figure 14 visually shows the correlated intensities of adjacent pixels. The pixels of the plaintext image are distributed in linear proportions, while those of the encrypted image are distributed randomly, uniformly covering the entire coordinate plane. In addition, it can be seen from the data presented in
Table 7 that the algorithm proposed in this paper has advantages over other algorithms, and that it is difficult for cryptographic images to provide valuable information for attackers. Therefore, our algorithm can achieve sufficient scrambling to protect the image information well.
5.2.4. Information Entropy
The randomness of pixel intensity distribution within an image is commonly measured by information entropy. For an 8-bit grayscale image, information entropy is defined as follows:
where
mi denotes the pixel value, and
P (
mi) is the occurrence probability of the gray value
mi.
The information entropy measurements for the original and encrypted images, as well as those from alternative algorithms, are presented in
Table 8. The entropy results for the ciphertext images are very near the theoretical maximum of 8. When compared to other algorithms, the proposed scheme exhibits superior performance.
5.2.5. Local Shannon Entropy
To assess the randomness of the encrypted image from a localized standpoint, Local Shannon Entropy (LSE) is additionally employed as a qualitative metric. The LSE is defined as follows [
39]:
where
t denotes the number of selected non-overlapping local blocks
Si within the image, and
tB indicates the number of pixels contained in each block. For an 8-bit image, given a significance level of
a = 0.001 with
t = 30 and
tB = 1936, the acceptable range for LSE is theoretically (7.8919, 7.9039) [
42]. As reported in
Table 8, the LSE values obtained for all encrypted images lie within this ideal interval.
5.3. Robustness Analyses
5.3.1. Known Plaintext and Ciphertext Attacks
In our algorithm, the key stream is correlated with the plaintext by the SHA-256 hash algorithm. Simultaneous scrambling–diffusion operations have sufficiently altered the plain image, and the proposed algorithm is unaffected by the known plaintext attack.
Figure 15a–d show the ‘Black’, the ‘White’ and their corresponding cipher images, and
Figure 15e–h are their histograms. Both the chaotic encrypted images and uniform histograms all show that the algorithm can effectively resist the known plaintext attacks.
We conducted the evaluation of this algorithm’s resistance to chosen-plaintext attacks through systematic differential attack testing. During the testing process, we constructed plaintext image pairs (
I1,
I2) with single-pixel differences and encrypted them using identical keys to obtain corresponding ciphertext pairs (
E1,
E2). The diffusion characteristics of the algorithm were quantitatively analyzed by calculating two key metrics: the NPCR and UACI. Experimental results demonstrate that for standard 512 × 512 test images, the proposed algorithm achieves an average NPCR of 99.61% (theoretical ideal value: 99.6094%) and an average UACI of 33.47% (theoretical ideal value: 33.4635%) [
41], with deviations from theoretical values not exceeding 0.003%. These results significantly outperform those reported in comparative studies.
5.3.2. Noise Attack
The encrypted Peppers and Baboon images were superimposed with salt-and-pepper noise at different intensities, i.e., 0.05 and 0.1 The decrypted image is shown in
Figure 16.
Figure 17 shows the encrypted image with noise and the decrypted image, respectively.
The experimental results demonstrate that the proposed algorithm is effective against both salt-and-pepper noise and impulse noise attacks. For images that have been degraded by noise, the Peak Signal-to-Noise Ratio (PSNR) serves as a crucial metric for assessing image quality. A higher PSNR value indicates less distortion and clearer image content. The definitions of the Mean Square Error (MSE) and PSNR are given as follows:
where
P denotes the original plaintext image,
C represents the decrypted image, and
b is the number of bits used to represent each pixel. The resulting PSNR values are reported in
Table 9.
5.3.3. Cropping Attack
Clipping attacks simulate the loss of information that may be experienced during channel transmission. Resistance to this is verified by testing the encrypted images with different cropping positions or cropping sizes. The decrypted results of the Peppers and Baboon images are shown in
Figure 18 and
Figure 19, respectively. The corresponding PSNR values are shown in
Table 10. Obviously, with the increase in the cropping area, the decrypted images still contain the main information, although the quality is reduced. Therefore, the algorithm is robust to clipping attacks.
5.4. Efficiency Analyses and Time Complexity
For encryption algorithms, speed is as important as security.
Table 11 gives a list of the average encryption time and makes comparisons with the speed of other similar algorithms. It shows that a 512 × 512 image takes 0.7 s on average to encrypt with the proposed algorithm. Therefore, our algorithm is efficient.
Through theoretical analysis, we evaluate the computational complexity of the proposed algorithm. In the preprocessing phase, both image reading and SHA-256 hash computation exhibit linear time complexity O(mn), where m and n denote the image height and width, respectively. Chaotic sequence generation employs an improved 2D-CACCM system requiring 1000 + 2mn iterations, maintaining O(mn) complexity.
Sorting mn chaotic elements contributes O(mnlog(mn)) complexity, constituting the dominant factor in this phase. The extension of the 2D image to a 3D m × n × 256 matrix involves traversing each pixel once to populate its spatial position, resulting in O(mn) complexity. The 3D simultaneous scrambling–diffusion step traverses the 3D matrix, applying permutation and diffusion via precomputed index sequences, which preserves O(mn) complexity since each pixel is processed once. The 2D XOR diffusion has the same complexity of O(mn). Finally, merging the 3D matrix into a 2D encrypted image by summing values along the z-axis per pixel is also an O(mn) operation. The overall time complexity is dominated by the sorting operation during chaotic-sequence processing, yielding O(mn). This efficiency demonstrates the algorithm’s suitability for real-time image-transmission applications.