A new secret-key-sharing cryptosystem using optical phase-shifting digital holography is proposed. The proposed secret-key-sharing algorithm is based on the Diffie-Hellman key-exchange protocol, which is modified to an optical cipher system implemented by a two-step quadrature phase-shifting digital holographic encryption method using orthogonal polarization. Two unknown users’ private keys are encrypted by two-step phase-shifting digital holography and are changed into three digital-hologram ciphers, which are stored by computer and are opened to a public communication network for secret-key-sharing. Two-step phase-shifting digital holograms are acquired by applying a phase step of 0 or π/2 in the reference beam’s path. The encrypted digital hologram in the optical setup is a Fourier-transform hologram, and is recorded on CCDs with 256 quantized gray-level intensities. The digital hologram shows an analog-type noise-like randomized cipher with a two-dimensional array, which has a stronger security level than conventional electronic cryptography, due to the complexity of optical encryption, and protects against the possibility of a replay attack. Decryption with three encrypted digital holograms generates the same shared secret key for each user. Schematically, the proposed optical configuration has the advantage of producing a kind of double-key encryption, which can enhance security strength compared to the conventional Diffie-Hellman key-exchange protocol. Another advantage of the proposed secret-key-sharing cryptosystem is that it is free to change each user’s private key in generating the public keys at any time. The proposed method is very effective cryptography when applied to a secret-key-exchange cryptosystem with high security strength.
Recently, information security of the public network has become a much more important issue, as public networks develop. However, digital information on the public network tends to be insecure against unauthorized attack, because of the fast development of computers. To maintain information security in a communication network, various kinds of encryption algorithms have been introduced for cryptosystems. In general, an electronic encryption system requires much time to compute the encryption procedure, if the encryption key is long and the message is large. On the contrary, an optical encryption system has the advantages of fast computation and vast data handling, owing to the inherent two-dimensional (2-D) parallel signal-processing capability. Another advantage of the optical encryption system is that a large key length can be made easily with the 2-D format, rendering brute-force attacks almost impossible. For these reasons, various cryptosystems using optical methodology have been increasingly studied in recent years. Since an optical encryption method using double-random-phase encoding (DRPE) was proposed [1], a variety of encryption systems based on DRPE have been developed over the past two decades by applying it to the fractional Fourier transform [2], discrete cosine transform [3], Fresnel domain [4], gyrator transform domain [5], and photon counting [6] to enhance cryptosystem security. In addition, optical encryption with coherent diffractive imaging [7], 3-D phase-retrieval [8], and phase-truncated strategy [9] for optical encryption have been established. Multiple-image encryption [10] is also a new optical encryption method. Another example of progress in optical security systems is the combination of optical and digital encrypting techniques that are based on joint transform correlators (JTC) [11], digital holography [12, 13], or optical XOR logic-operation techniques [14-16]. Moreover, polarization encryption [17, 20] has been reported as an optical encryption method.
For the purpose of establishing a secure encryption system, the most important thing is that the encryption key must not be known to unauthorized persons, and must be hard to break by attacks. A symmetric private-key algorithm such as DES (Data Encryption Standard) carries the risk that attackers may cryptanalyze the symmetric key, because this type of cryptosystem has only one key. To solve this problem, asymmetric cryptography such as the Diffie-Hellman (D-H) secret-key-sharing algorithm was introduced [18]. In this protocol, two users who are unknown to each other can open a public key for their asymmetric key-exchange cryptosystem and share a secret key together. However, this shared secret key can be revealed by a “meet in the middle” attack, because this shared secret key is used to encrypt messages by applying symmetric cryptography. Therefore, to realize a higher level of security, an advanced algorithm using a double-key encryption technique must be introduced as a method of solving this problem.
In our recent studies of optical encryption systems, modified D-H secret-key-exchange algorithms using Boolean-logic-based optical operations were reported [15, 16]. In this paper, an application to an optical secret-key-sharing cryptosystem using phase-shifting digital holography and its optical implementation are proposed. The objective of this paper is to present and verify the feasibility and effectiveness of the proposed optical system for secret-key-exchange cryptography. Section II describes the proposed secret-key-sharing cryptography algorithm based on the D-H secret-key-sharing protocol, and the optical implementation of the proposed cryptosystem. In Section III, the feasibility of the proposed optical system and the performance of applying it to a secret-key-sharing cryptosystem are proven by computer simulations. Finally, the conclusions are briefly summarized in Section IV.
The secret-key-sharing algorithm introduced by Diffie and Hellman in 1976 [18] is a kind of public-key crypto-graphic method for two users to exchange their encrypted private keys by generating a shared secret key over a public communication network, without any prior secrets between them. As a result, plain messages can be encrypted into cipher messages by using this symmetric shared secret key. In this protocol, two users agree upon and make public two numbers
In the conventional D-H secret-key-sharing cryptosystem, the main drawback of this algorithm is that it suffers from the “meet in the middle” attack problem. This implies that the authenticity of private keys is essential. If we turn the private-key information into double-encrypted information by pre-encrypting the private key with a shared random number, then enhanced security strength will be acquired, although attackers may know the encrypted private-key information and the common key opened to the public. In this paper, a new optical secret-key-sharing cryptosystem combined with pre-encryption and phase-shifting holographic encryption is proposed with this idea. The pre-encryption to enact double encryption is carried out by applying the optical XOR logic operation before the phase-shifting digital holographic encryption. The proposed secret-key-sharing cryptographic algorithm can be described as follows.
Two users share a common key number
One user A chooses a random number
Similarly, user B chooses a random number
User A decrypts user B’s private-key information of
Similarly, user B decrypts user A’s private-key information of
User A computes a shared secret key by Boolean XOR logic with user A’s own private key
Similarly, user B computes a shared secret key by Boolean XOR logic with user B’s own private key
Now both users have the same shared secret key, namely
Figure 1(b) shows the proposed secret-key-sharing cryptosystem algorithm, and Fig. 2 shows the flow charts of the procedure for the proposed secret-key-sharing method. As shown in Figs. 1 and 2, the first step is pre-encryption of the user’s private key with generator
The optical information processing deals with a 2-D data array, and has the advantage of fast parallel computation. This implies that an optical encryption system can have a very long key to enhance security strength, and can process massive amounts of data quickly. Moreover, if an encryption system has a key length of a 2-D array with M × N bits, it means that 2M×N brute-force attacks are required to discover the correct key. The principal idea in this paper is that optical phase-shifting digital holography can be applied to a secret-key-sharing cryptosystem by modifying the conventional D-H secret-key-sharing algorithm. The mathematical modulo-arithmetic encryption in the D-H secret-key-sharing is replaced with a digital holographic method. The encryption of a private key is carried out using two-step quadrature phase-shifting digital holography based on orthogonal polarization to generate ciphers, and these ciphers are used to generate a shared secret key by the corresponding decryption process.
Referring to the proposed secret-key-sharing cryptosystem algorithm shown in Figs. 1 and 2, Fig. 3 shows the optical schematic for the proposed secret-key-sharing cryptosystem using two-step quadrature phase-shifting digital holography. In this configuration, the optical setup contains two Mach-Zehnder-interferometer paths and consists of a spatial filter (SF), a collimating lens (CL), two shutters (S), three linear polarizers (P), four beam splitters (BS), two mirrors (M), a λ/4-plate, two convex lenses (L), a random phase mask (RPM), five spatial light modulators (SLM), and two charge-coupled devices (CCD). This scheme makes it possible to acquire two-step quadrature phase-shifting digital holograms with π/2 phase shift between
In the beginning, the pre-encryption of user A’s private key is achieved by optical XOR operation in the inner Mach-Zehnder-interferometer setup. As for user A, two random numbers
The two-step phase-shifting digital holographic encryption process is accomplished by the outer Mach-Zehnder-interferometer. Let
Let |
The Fourier-transformed functions of Eqs. (9) and (10) are taken to be
Then the two-step quadrature phase-shifting digital holographic method gives two intensity patterns recorded on the CCDs in the form of a digital hologram:
where ∆
Thereby, three ciphers as one group are acquired, stored in a computer, and transmitted through the communication network as a cipher group of open public keys.
After receiving the open public keys of these ciphers, the decryption process is accomplished as follows. The phase difference ∆
From Eqs. (17) and (18), the complex hologram with encryption information is expressed as
By using this complex hologram
In the last process, XOR logic is carried out between the restored function
Similarly, user B’s shared secret key is achieved by the same encryption and decryption process, which generates the same result as user A’s shared secret key of Eq. (22).
Encryption and decryption flow charts for the two-step phase-shifting digital holographic cryptosystem are shown in Fig. 4.
Computer simulations using the MATLAB program are presented to prove the performance of the proposed cryptosystem. In this method, 2-D arrays of binary data, or images, of size 256 × 256 pixels are used for simulation convenience. Schematically in the optical system, the number of 2-D array data can be expanded to larger array depending on the SLM specification. A larger array provides stronger security strength, due to the larger encryption-key length. Figures 5(a)~5(d) show the binary data and images to be used in the secret-key-sharing cryptosystem. Figures 5(a) and 5(b) show randomly generated binary data images as generator
An optical phase-shifting digital holographic encryption technique is applied to a secret-key-sharing cryptosystem. The proposed secret-key-sharing algorithm is optically implemented by a pre-encryption technique with XOR operation and a two-step quadrature phase-shifting digital holographic encryption technique using orthogonal polarization. Encrypted digital holograms in the optical holographic encryption system are Fourier-transform holograms, and are recorded on CCDs with 256 gray levels of quantized intensity. These ciphered digital holograms show an analogtype noise-like randomized pattern with a 2-D array, which has a stronger security level than conventional electronic cryptography due to the complexity of optical encryption, and protects against the possibility of a replay attack. Three digital-hologram ciphers with each private key’s information are opened to the public network for secret-key exchange, and are decrypted into the same secret key by the proposed algorithm. The optical encryption system has the advantage of increasing key length easily. The optical encryption setup can provide longer 2-D key length, resulting in a higher-security cryptosystem than a conventional system with one-dimensional key length. Schematically, the proposed optical secret-key-sharing method uses pre-encryption of the user’s private key in combination with randomly generated binary data (called a generator) before digital holographic encryption, which provides a kind of layered security system with a double key and enhances security strength, compared to the conventional Diffie-Hellman key-exchange protocol. Another advantage of the proposed secret-key-sharing cryptosystem is that it is free to change each user’s private key in generating the public keys at any time. This alteration enables the cryptosystem to protect the secret key against reuse attack. Computer simulations present results verifying that the proposed method is feasible for application in secret-key-sharing cryptography.