Image encryption schemes based on chaotic maps offer strong statistical properties but are vulnerable to quantum attacks, and their integration with post-quantum cryptography has not been sufficiently explored. This paper presents a post-quantum secure image encryption framework integrating ML-KEM (FIPS 203), standardized by NIST in 2024, with a two-dimensional Sinh-Logistic chaotic map, HKDF-SHA256 nonce-based key derivation, feedback diffusion, and a novel Seismic Wave Permutation (SWP). The scheme derives channel-specific encryption keys from ML-KEM shared secrets using random, channel-specific nonces via HKDF-SHA256, ensuring plaintext independence and avoiding metadata-based leakage. The proposed SWP effectively breaks spatial correlations by displacing pixels according to a chaotic SWP model. RGB images are processed with independent ML-KEM encapsulation and HKDF-derived key material per channel, enabling multi-channel encryption without cross-channel leakage. Experiments on 512 × 512 test images have demonstrated Shannon entropy exceeding 7.999 bits per pixel across all channels, NPCR of at least 99.59%, UACI between 33.41% and 33.53%, and near-zero pixel correlations, further validated across 14 standard SIPI test images. An IND-CPA game simulation using four independent distinguishers, including a learned classifier trained via chosen-plaintext oracle access, over 5000 rounds per image, showed a maximum adversary advantage of 0.0186, consistent with random prediction. ML-KEM encapsulation contributes between 3.9% (ML-KEM-512) and 8.0% (ML-KEM-1024) of total encryption latency at 512 × 512 resolution, remaining a minority cost across all security levels while keeping the total encryption time within a narrow 227-258 ms range. The proposed architecture bridges standardized post-quantum cryptography with chaos-based image security for privacy-preserving image transmission.
To address the limitations of existing chaotic systems such as complex structure and potential chaotic degradation, this paper proposes a novel four-dimensional discrete chaotic system (4D-DCS) and an image encryption algorithm based on it. The 4D-DCS is constructed by integrating a feedback controller and modulo operation into a linear discrete-time system, featuring a simple structure without the need for intricate matrix reconstruction or memristor circuits. Mathematical analysis confirms its chaos in the sense of Li-Yorke and numerical simulations including Lyapunov exponent (LE) analysis, 0-1 test, and NIST SP 800-22 test demonstrate its hyperchaotic characteristics and excellent pseudorandomness. Based on the 4D-DCS, the proposed encryption algorithm employs SHA-256 to generate initial states for key uniqueness, combines row-column permutation to disrupt pixel correlation, and adopts a reversible neural network for diffusion to enhance confusion capability. Comprehensive security analysis shows that the algorithm achieves an NPCR of ∼99.61% and a UACI of ∼33.46%, a key space of 2216, information entropy close to 8, and correlation coefficients of encrypted images near 0. It also exhibits strong robustness against differential, cropping, noise, and chosen-plaintext attacks. Comparative analysis with state-of-the-art algorithms validates the 4D-DCS's advantages in structural simplicity and stability, and the encryption algorithm's superiority in security and practicality, making it suitable for security-critical applications such as image encryption.
Mix networks play a vital role in enhancing security and privacy within the communication channel. Mix networks are anonymous communication channels that provide a practical solution to the traffic analysis problem. This manuscript presents an algorithm for a mix network consisting of five nodes. The algorithm employs the Elliptic Curve Integrated Encryption Scheme (ECIES) algorithm for both encryption and decryption processes while utilizing XOR shuffling to permute the messages. The algorithm effectively manages the data flow, encompassing encryption, decryption, and shuffling operations, while also calculating the load factors for each node. By conducting MATLAB simulations, we assess the flow of data within the mix network, considering the encryption, decryption, and XOR shuffling operations at each node. The integration of ECIES encryption and XOR shuffling within the algorithm exemplifies its effectiveness in ensuring secure and anonymous communication over untrusted networks. This research conducted a comparative analysis of load factor percentages across various key sizes, revealing nuanced efficiency differences among nodes. One of the outcomes of the research was that we were able to identify the optimal key among the five different keys supported by the ECIES algorithm. For all system tests, the 224 bits key demonstrated optimal security with reasonable performance. Our results show that the ECIES 224 bits key works well for building a scalable and efficient Mix Network. The research endeavour contributes significantly to the advancement of secure communication protocols, providing a fundamental framework for the implementation and analysis of mix networks.
Diffractive security images, constructed with micro-nano structures, are widely used in anti-counterfeiting due to their inherent high spatial frequency resolution and dynamic color variation. However, traditional diffraction anti-counterfeiting labels (DALs), typically based on acrylic ester materials, are susceptible to counterfeiting due to their simple encryption structures and the limited information capacity of single-channel encryption. Furthermore, in harsh environments such as high temperature or high humidity, they are prone to deformation, which can lead to loss of verification functionality. To address these limitations, we propose constructing eight high-resolution, angular-switchable, independent diffraction images on photosensitive polyurethane (Pho-PU) films through buckling structures that reveal different encrypted images as the viewing angle changes, through sample rotation, or varied illumination. We discuss the designability and controllability of periodic buckling structures and demonstrate how common information and secret keys can be integrated through this angle-multiplexing strategy. This systematic approach to multi-image encryption based on buckling structures provides an effective alternative for fabricating high-security DALs.
Conventional liquid-crystal (LC)-based anti-counterfeiting labels often rely on passive optical or thermal responses, which limits information capacity and access control. Herein, we report a flexible electro-optical-thermal multiresponsive LC encryption device based on a vertically integrated two-layer architecture. The upper layer is a magnesium oxide nanoparticle (MgO NP)-doped polymer-dispersed liquid crystal (PDLC) film that functions as an electrically switchable optical gate, while the lower layer consists of microfluidically generated core-shell cholesteric liquid crystal (CLC) droplets doped with spiropyran (SP). By tuning the concentration of the chiral dopant S811, the CLC formulation exhibited a thermochromic reflection shift of 236 nm over 28-32 °C. The isolated core-shell droplets retained 86.1% of their UV-triggered optical signal after 60 photochromic cycles. In the integrated device, repeated electrical-optical-thermal decoding identified the thermochromic channel as the lifetime-limiting component, mainly due to poly(vinyl alcohol) (PVA)matrix dehydration, droplet aggregation, and disruption of CLC helical order. The MgO NP-doped PDLC layer achieved a threshold voltage of 14 V and a saturation voltage of 38 V, enabling active gating of the lower encrypted droplet array. By assembling seven types of functional droplets, three encrypted patterns, "CSU", "596", and "930", were sequentially decoded through a prescribed electrical-optical-thermal stimulus sequence. No single stimulus could reveal the complete information. The device further showed recognizable information readout over 30°-90°. This work provides a proof-of-concept access-controlled colloidal LC platform for multilevel flexible information encryption.
Ultra-broadband photodetectors (UB-PDs) represent a key technological frontier for optical communication and thermal monitoring owing to their monolithically integrated, wide-spectrum photoresponsivity. However, photocurrent degradation caused by charge-carrier recombination, which primarily arises from lattice mismatch and interface defects in heterostructures, remains a major limitation on improving the sensitivity and response speed of UB-PDs. Here, we demonstrate a self-powered ultra-broadband UB-PD based on a p-p multi-walled carbon nanotubes (MWCNTs)/PdO/p-Si homomorphic heterostructure with enhanced photoelectronic characteristics for dual-channel encrypted optical communication and thermal monitoring. The device exhibits exceptional photoelectronic performance across an exceptionally broad spectral range (365 nm to the mid-infrared, MIR) at room temperature, achieving a self-powered responsivity (R) of 0.72 A/W, detectivity (D*) of 5.85×1013 Jones, and Ilight/Idark ratio exceeding 106 under 0 bias. The enhanced photoresponse is attributed to three synergistic effects: (i) suppression of non-radiative charge-carrier recombination, (ii) increased photocurrent and accelerated response speed enabled by the p-p heterostructure, and (iii) improved MIR absorption driven by the MWCNTs. We also design a dual-channel encrypted optical communication system which implemented the ultra-broad spectral cooperative encryption communication with enhanced security on a single device. We further apply the MWCNTs/PdO/p-Si heterojunction photodetector to develop a distance-independent colorimetric thermal monitoring system.
The proliferation of cloud-based data outsourcing has intensified the need for efficient semantic retrieval over encrypted data. Existing searchable encryption schemes often face a coupled bottleneck: (i) semantic index can be unstable or overly coarse, yielding loose pruning bounds and high query cost, and (ii) semantic query expansion can easily introduce noise, forcing an unfavorable accuracy-efficiency trade-off. To address these issues, we propose SES-HI, a Semantically Enhanced Searchable Encryption scheme with a stability-oriented hierarchical index for efficient ranked semantic search over encrypted cloud data. SES-HI contains three core innovations. First, it constructs a balanced ω-ary hierarchical index using a two-stage clustering pipeline (Ward → k-means) to produce semantically compact groups and more representative node vectors, enabling tighter pruning bounds. Second, it performs topic-guided query expansion using LDA and applies Word2Vec-based similarity filtering to enrich semantic coverage while suppressing expansion noise. Third, it introduces a dual-pruning strategy that couples a global threshold with top-k competitive pruning to reduce traversal and ranking overhead without sacrificing recall. We formally prove that SES-HI is secure against adaptive chosen-keyword attacks under an explicit leakage profile. Extensive experiments on the TREC dataset demonstrate that SES-HI consistently improves the accuracy-latency trade-off compared with state-of-the-art baselines, supporting practical semantic search for privacy-sensitive cloud applications.
With the widespread adoption of digital images in network transmission and storage, the demand for image privacy protection keeps rising. We propose a robust scheme combining a four-dimensional variable-order fractional hyperchaotic system (4D-VOFHS) and a chess-game play-inspired dynamic mechanism. Firstly, we construct 4D-VOFHS, to overcome inherent limitations of constant-order systems: unlike constant-order systems that are vulnerable to deep-learning-based parameter identification attacks, this system introduces time-varying orders and high-dimensional coupling to enrich nonlinear dynamics. Secondly, inspired by the dynamic strategic interactions within chess gameplay, we design a synchronous encryption framework with a tightly coupled permutation-diffusion mechanism. This design not only significantly enhances the nonlinear complexity, confusion and diffusion performance of the algorithm, but also enables parallel synchronous processing to improve computational throughput. Finally, we propose a block-based collaborative scrambling strategy with multi-chess-piece rules, wherein traversal rules and scrambling operations are not predefined; instead, they are dynamically updated according to the real-time state evolution of the 4D-VOFHS. Through comprehensive correlation analysis and differential attack tests, the presented encryption framework achieves outstanding performance metrics: an average NPCR of 99.6%, a UACI of 33.4%, and an average information entropy of 7.9993. Overall, these results verify the strong cryptographic robustness and practical applicability of the scheme, highlighting its great potential for deployment in real-world color image encryption systems.
Recently, a conservative chaotic system with dissipative terms has been proposed, providing a new perspective on the generation mechanism of conservative chaos. However, the dynamic behavior, circuit implementation, and practical application potential of this system still require further investigation. Therefore, this paper delves into the dynamic characteristics of this system, completes its physical implementation, and designs a novel encryption algorithm. Specific research includes: analysis of equilibrium points, exploration of coexistence phenomena, construction of the physical circuit, design of a pseudo-random number generator, and a novel encryption scheme based on this system. Results show that parameter variations play a decisive role in the number and stability of the system's equilibrium points, and a multi-stability phenomenon of coexistence between conservative chaos and invariant tori is widely observed in the system. The pseudo-random sequences generated by the designed pseudo-random number generator successfully pass the NIST and TestU01 tests. Security evaluations demonstrate that the proposed encryption algorithm exhibits good robustness against various attacks.
One of the major challenges in securing medical image communication systems is the secure and efficient management of cryptographic key material. In this paper, we propose a multi-layer image encryption algorithm that addresses image security while reducing per-image key-storage and transmission overhead under a pre-shared protected-generator model. The proposed algorithm integrates a Generative Adversarial Network, a Piecewise Linear Chaotic Map, DNA complement operations, and bit-level zigzag permutation. A distinguishing feature of the proposed algorithm is that the key image is generated from an image-specific 100-dimensional noise vector, which serves exclusively as the input to the trained generator, while the chaotic parameters and diffusion materials are derived from the generated key image. In this approach, under the assumption of a pre-shared protected generator, transmitting only the image-specific 100-dimensional noise vector that bears no structural relationship to the key image reduces per-image key storage and transmission overhead. Comprehensive numerical evaluations were performed on eleven images, comprising both standard test images and medical images, to assess the security and robustness of the proposed algorithm. The experimental results demonstrate entropy values exceeding 7.996 bits, along with NPCR and UACI values of 99.60% and 33.46%, respectively. Adjacent pixel correlations are reduced to near-zero levels across all tested images. The proposed algorithm exhibits strong robustness against common attacks, including up to 75% cropping and 50% salt-and-pepper noise. The proposed algorithm achieves competitive performance compared with several existing encryption methods. Successful decryption requires the correct image-specific noise vector and the original trained generator.
Encryption as a Service (EaaS) is a practical solution for resource-constrained Internet of Things (IoT) devices that cannot efficiently execute costly cryptographic tasks locally. This paper presents a cloud-native EaaS platform implemented on Kubernetes and designed to support scalable encryption, decryption, and key-management services for IoT environments. The paper describes the functional architecture of the platform, defines its main service workflow, and introduces two deployment modes, namely cloud-based and fog-based deployment. The proposed platform is evaluated in terms of processing time, deployment time, and end-to-end response time. The results show that the fog-based deployment reduces the response time by at least [Formula: see text] for small payloads and by up to [Formula: see text] for larger payloads compared with the cloud-based mode. The deployment analysis also shows that increasing the number of replicas from 1 to 5 leads to a deployment-time increase of more than [Formula: see text], while increasing the workload to 11 replicas results in an increase of about [Formula: see text]. In addition, the results indicate that the Key Manager is the most resource-intensive component and has the highest impact on pod readiness time. Overall, the findings show that the proposed Kubernetes-based EaaS platform can provide flexible and scalable cryptographic support for IoT systems, while fog-based placement offers clear latency advantages in the evaluated prototype setting.
Physical-layer encryption based on metasurfaces has emerged as a promising alternative to conventional algorithmic cryptography by embedding security into physical processes. However, most existing metasurface-based encryption schemes operate within single-stage or static frameworks, where correct physical illumination directly reveals the hidden information, leaving them vulnerable once the physical key is exposed. Here, we propose a hierarchical physical-cyber cryptographic framework that synergistically integrates meta-hologram with dynamic digital protocols to overcome these limitations. The system employs a polarization-multiplexed metasurface to generate two independent holographic keys through spin-decoupling wavefront control, establishing a three-stage cyber-decryption protocol to combine hardware-level unclonability with digital algorithmic security. To address the intrinsic noise of physical channels, a robust extraction interface based on amplitude thresholding and grid statistics is further introduced, bridging physical outputs with digital logic and enabling reliable recovery of structured keys from holographic reconstructions under practical interference conditions. Experimental validation in the microwave band confirms stable decryption performance with strong noise resilience, successfully recovering concealed information through sequential physical reconstruction and cryptographic processing. Owing to its inherent frequency-band universality, the proposed scheme is readily extendable to terahertz and optical frequencies, offering a scalable paradigm for multi-band secure communication systems. By embedding cryptographic strength in physically unclonable processes, this work not only provides a versatile and intrusion-resistant framework for next-generation information protection.
A color image encryption scheme is developed by integrating a two-dimensional nonlinear exponential chaotic system (2D-NECS), Queen-driven permutation, and indexed row-column diffusion. The proposed 2D-NECS generates highly sensitive pseudo-random sequences for constructing dynamic permutation indices and diffusion parameters. A Queen-driven traversal mechanism achieves multi-directional pixel scrambling and enhanced cross-channel coupling, while indexed row-column diffusion propagates local changes throughout the entire image. Experimental results show that the encrypted images exhibit uniform histogram distributions, low pixel correlations, and information entropy values close to the theoretical ideal. Moreover, differential, chosen-plaintext, and known-plaintext attack analyses verify the strong security of the proposed scheme. These results demonstrate that the proposed method provides effective resistance against various cryptographic attacks while ensuring accurate image reconstruction.
Clustered federated learning (CFL) is an effective paradigm for handling statistical heterogeneity by grouping clients with similar data characteristics and learning cluster-specific models. However, existing CFL methods often expose sensitive clustering signals or cluster-specific updates to the server, which may reveal latent client similarity relations and weaken privacy protection. To address this issue, we propose Privacy-Preserving Clustered Federated Learning (PPCFL), a split-stream framework that integrates adaptive Gaussian perturbation with threshold Paillier encrypted aggregation. In PPCFL, backbone updates are protected by adaptive Gaussian perturbation before plaintext aggregation, while clustering signatures and cluster-head updates are first perturbed by stream-specific adaptive Gaussian mechanisms and then uploaded under threshold Paillier encryption. The server performs ciphertext-domain aggregation for clustering prototypes and cluster-head updates, whereas plaintext prototypes and cluster-level decrypted aggregates are recovered by a qualified threshold-decryption client subset without giving the server decryption capability. In addition, PPCFL adopts round-wise budget growth, utility-aware refinement, and adaptive clipping-threshold updates to improve the privacy-utility trade-off under dynamic Non-IID settings. Experiments on MNIST, Fashion-MNIST, and CIFAR-10 show that PPCFL achieves the highest final-round accuracy among the evaluated methods in the reported settings while providing enhanced protection for clustering-related information and cluster-specific updates. Under the representative Dirichlet setting [Formula: see text], PPCFL improves the final accuracy over DP-FedAvg by 0.33, 1.73, and 2.62 percentage points on MNIST, Fashion-MNIST, and CIFAR-10, respectively, and over IFCA by 0.98, 8.28, and 10.24 percentage points.
This study proposes a fractional-order NbOx memristor model and, based on this, introduces a novel fractional-order bicyclic crossed memristive neural network. The dynamic behaviors and firing patterns of this neural network are analyzed, with an emphasis on the Neimark-Sacker bifurcation induced by the fractional-order parameter: it is demonstrated that by keeping the system parameters constant and varying only the fractional order, a Neimark-Sacker bifurcation can be induced. The chaotic characteristics and bifurcations of this network are leveraged in a newly proposed image encryption algorithm that successfully passes various security analyses. Additionally, a synchronization controller is designed to regulate the generation of specific chaotic sequences by other neural networks, with the objective of approximating the chaotic sequences produced by the proposed neural network.
Fractional-order quaternion inertial neural networks have shown great potential for secure communications, as evidenced by the capability of efficiently capturing the dynamic characteristics of high-dimensional data. This article focuses on studying the quasi-projective synchronization problem of a class of delayed fractional-order quaternion-valued inertial neural networks. Firstly, a simple and efficient controller is designed without decomposing the quaternion-valued neural networks into multiple subsystems. Moreover, unlike previous studies, the non-reduced order method is adopted to analyze inertial neural networks directly. Secondly, a class of Lyapunov functions for quaternion states and their fractional-order derivatives is constructed, along with several inequalities. On this basis, a sufficient criterion for achieving quasi-projective synchronization of the constructed model, and an upper bound on the system synchronization error are estimated. A more complex form of controller is also proposed, and the synchronization of the studied system is achieved using the same proof method as before. Finally, the validity of the theoretical results is verified through a numerical example. This research has been successfully applied to the encryption and decryption of color images, demonstrating strong practical application prospects.
Solvent-triggered structural transitions offer critical insights into luminescence modulation in metal halides. Herein, two novel and stable zero-dimensional copper(I) halides were synthesized, exhibiting controllable phase transitions and concurrent luminescence switching upon methanol stimulation, highlighting their promising potential for information encryption and white-light-emitting (WLED) applications.
Thermally oxidized Ga2O3/GaN heterojunctions offer a cost-effective route for ultraviolet (UV) detection. However, their application is often hindered by the high driving voltage required for effective near-UV (365 nm) response due to the transparency of the top wide-bandgap layer. Herein, a high-performance dual-band UV photodetector fabricated by decorating Ag nanoparticles (Ag NPs) onto an in situ thermally oxidized Ga2O3/GaN heterojunction is proposed. The Ag NPs, introduced via a solid-state dewetting process, induce a localized surface plasmon resonance (LSPR) effect that yields a dual-gain mechanism. Specifically, it enhances solar-blind (254 nm) responsivity through local field amplification and enables sensitive 365 nm detection at low bias via a hot-electron injection pathway. Leveraging this unique bias-tunable spectral response, reconfigurable optoelectronic logic gates (OR, NOR, and XNOR) are successfully constructed within a single device, overcoming the rigidity of traditional single-function logic units. Furthermore, a basic hardware-based optical encryption scheme based on XNOR logic and high-contrast single-pixel dual-color UV imaging are successfully realized. This work not only presents a strategy for low-power, high-performance UV detection but also paves the way for developing intelligent, secure, and in-sensor computing optoelectronic systems.
In this paper, we propose a novel image encryption algorithm that integrates a six-dimensional hyperchaotic system with the forward diffusion process of denoising diffusion probabilistic models (DDPMs). The proposed framework synergistically combines the hyperchaotic system's high sensitivity to initial conditions with the DDPM's Markov chain-based skipping-step diffusion mechanism, thereby enabling dual-level confusion-diffusion operations at both the pixel and bit levels. This dual-strategy approach significantly enhances plaintext sensitivity and ciphertext randomness. Comprehensive simulations demonstrate that the algorithm achieves superior performance in key space expansion, histogram uniformity, adjacent pixel correlation reduction, information entropy optimization, and resistance to differential attacks. The algorithm exhibits strong resilience against various attack vectors, including brute-force attacks, statistical analysis, chosen-plaintext attacks and common image degradation factors (e.g., noise contamination and cropping). These characteristics establish the proposed method as a highly secure and practical solution for image data protection in cloud-IoT environments.
The rapid expansion of the Internet of Things (IoT) has developed various security vulnerabilities, as conventional defense mechanisms often struggle based on heterogeneity and resource constraints of smart devices. This research aims in designing a robust and high-performance security framework, which integrates an advanced deep learning with optimized cryptography to protect IoT networks from malware threats. The proposed methodology employs a novel Adaptive and Deformable Attention-based Elman Residual Recurrent Neural Network (ADA-El-RRNN) for precise malware detection, whereas the hyperparameters are fine-tuned by using Opposition Humboldt Squid Optimization (OHSO) to prevent local optima and premature convergence. Following detection, secure data transmission is ensured through Optimal Key-based Elliptic Curve Cryptography (OKECC), which utilizes OHSO for efficient key generation to minimize computational overhead and memory usage. The experimental results across four standard datasets demonstrate the framework's superior performance, achieving peak malware detection accuracies up to 97.4% and a specificity of 98.5%, significantly outperforming existing models like LSTM, RNN and standard ECC. This work is significant as it provides a scalable, low-latency solution that enhance the data confidentiality and integrity, effectively safeguarding sensitive information in dynamic real-world IoT environments.