Double-layer embedded high-capacity ciphertext domain reversible information hiding method based on ElGamal

Through the dual-layer embedding technology based on ElGamal, it uses its plaintext redundancy and homomorphic characteristics to achieve efficient and secure reversible data hiding, solving the problems of high computing complexity and low embedding rate in the prior art, and realizing high-capacity ciphertext domain and plaintext domain information embedding.

CN120416403APending Publication Date: 2025-08-01ENG UNIV OF THE CHINESE PEOPLES ARMED POLICE FORCE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510662107.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing homomorphic public key encryption technology based on Paillier and LWE has limitations in terms of computing complexity and embedding rate, and it is difficult to achieve efficient and secure reversible data hiding in a big data environment, especially in the ElGamal cryptographic system, the research on reversible information hiding in the ciphertext domain of the ElGamal cryptographic system is relatively limited.

Method used

The double-layer embedding high-capacity ciphertext domain reversible information hiding method based on ElGamal is adopted, and the plaintext redundancy and homomorphic characteristics of ElGamal encryption are used to achieve efficient and secure reversible data hiding in encrypted images through the double-layer embedding technology. The embedded information is extracted in the ciphertext domain and then extracted in the plaintext domain after decryption.

Benefits of technology

It realizes efficient and secure reversible data hiding, the embedding capacity reaches the highest level of similar algorithms, the ciphertext domain embedding rate reaches 10bpp, and the plaintext domain embedding rate reaches 1016bpp, and the image can be recovered losslessly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416403A_ABST
    Figure CN120416403A_ABST
Patent Text Reader

Abstract

The invention provides an ElGamal-based double-layer embedded high-capacity ciphertext domain reversible information hiding method. The method comprises the following steps: S1, generating system public and private keys and a double-layer embedded key for subsequent image encryption, decryption and message embedding; s2, acquiring an original image, performing encryption and embedding processing on the first embedded message, and encrypting the image embedded with the first message to obtain a marked ciphertext image; s3, encrypting the second embedded message, and then embedding the second message ciphertext into the marked ciphertext image to obtain a double-layer marked ciphertext image; and S4, carrying out message extraction on the double-layer marked ciphertext image, carrying out decryption by using the embedded key to obtain a second message, carrying out decryption on the double-layer marked ciphertext image to obtain a decrypted image, carrying out message extraction on the decrypted image, carrying out decryption by using the embedded key to obtain a first message, and recovering the decrypted image to obtain an original image. According to the method, efficient and safe reversible data hiding is realized in an encrypted image, and the comprehensive embedding capacity reaches the highest level of similar algorithms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption transmission, and particularly relates to a double-layer embedding high-capacity reversible information hiding method in ciphertext domain based on ElGamal. Background Art

[0002] With the rapid development of cloud computing technology, a large amount of data is uploaded to the cloud to maximize its value. However, due to privacy protection or regulatory requirements, especially in applications such as medical image analysis and cloud computing, data should be encrypted before uploading. Managing un-decrypted ciphertext is challenging because the storage system needs to securely process and embed metadata for management (e.g., authentication, auditing, tracking, retrieval, etc.). Reversible data hiding technology (RDH-EI) solves this problem by embedding additional information in the encrypted domain. When needed, these embedded information can be extracted for authentication, retrieval, or compliance auditing, while achieving lossless recovery of the original carrier. In recent years, with the increasing demand for ciphertext computing in federated learning, privacy computing, and edge computing, the research on RDH-EI algorithms has mainly focused on homomorphic public key encryption technology.

[0003] Homomorphic public key encryption technology can perform computational operations directly on ciphertext while encrypting data without prior decryption, which greatly improves the flexibility and efficiency of data processing and effectively protects data privacy. Secondly, homomorphic public key encryption technology is constructed based on the computational difficulty of mathematical problems, such as Paillier, LWE, etc., making it difficult for attackers to crack the ciphertext, thus ensuring the security of data during storage and transmission in the cloud. In addition, homomorphic public key encryption technology provides the possibility to achieve complex information embedding in the encrypted domain, which helps to meet the requirements of ciphertext data processing and management in different application scenarios.

[0004] Currently, most RDH-EI algorithms based on homomorphic encryption focus on Paillier and LWE. The former has a high computational complexity, while the latter has a low embedding rate. These limitations hinder their applications when a large amount of data needs to be embedded. At the same time, the research on reversible information hiding in ciphertext domain based on the widely used ElGamal cryptosystem is relatively limited. Summary of the Invention

[0005] Aiming at the above technical problems, the present invention proposes a double-layer embedding high-capacity reversible information hiding method in ciphertext domain based on ElGamal. By using the plaintext redundancy and homomorphic characteristics of ElGamal encryption, and adopting double-layer embedding technology, it realizes efficient and secure reversible data hiding in encrypted images, and can extract additional information before and after decryption and losslessly recover the carrier, solving the problems existing in the above prior art.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A double-layer embedding high-capacity reversible information hiding method in ciphertext domain based on ElGamal, comprising the following steps:

[0008] S1 Generate system public and private keys, a first embedding key, and a second embedding key through a key server, publicly disclose the public key, distribute the private key to the image receiving end, distribute the first embedding key to the image providing end, distribute the second embedding key to the data hiding end, and distribute the first and second embedding keys together to the image receiving end;

[0009] S2 Obtain the original image through the image providing end, encrypt the first embedding message according to the first embedding key, expand the original image pixels using the redundancy of the plaintext space, then embed the first message ciphertext, and encrypt the image embedded with the first message according to the system public key to obtain the first marked ciphertext image;

[0010] S3 Use the second embedding key by the data hiding end to encrypt the second embedding message, and embed the second message ciphertext into the first marked ciphertext image using the homomorphism and probability of ElGamal encryption to obtain a double-layer marked ciphertext image;

[0011] S4 Extract messages from the double-layer marked ciphertext image through the image receiving end, decrypt using the second embedding key to obtain the second message, decrypt the double-layer marked ciphertext image to obtain the decrypted image, extract messages from the decrypted image, decrypt using the first embedding key to obtain the first message, and recover the decrypted image to obtain the original image.

[0012] Preferably, generating the system public and private keys, the first embedding key, and the second embedding key in S1 includes the following steps:

[0013] S11 Input security parameters through the key server, select a large prime number p and a primitive root g according to the security parameters; select a random integer x such that 1 ≤ x ≤ p - 2; calculate according to the following algorithm:

[0014] y = g x mod p;

[0015] S13 Take the integer x as the private key, and the public key is the triple (p, g, y); select two secure random numbers as the first embedding key and the second embedding key, denoted as kha and khb respectively.

[0016] Preferably, embedding the first message ciphertext in S2 specifically includes the following steps:

[0017] S201 preprocesses the first message through the image provider side, initializes a CSPRNG (Cryptographically Secure Pseudo-Random Number Generator) using kha as the seed, generates a pseudo-random sequence, and performs bitwise XOR encryption on the first message ma and the generated pseudo-random sequence to obtain the ciphertext ca. The algorithm is as follows:

[0018] ca = ma ⊕ CSPRNG(kha);

[0019] S203 divides the ciphertext ca into segments of every 1016 bits. When it is less than 1016 bits, 0s are padded at the high bits, and each segment is denoted as da; the original grayscale image is input, and each plaintext pixel value m is shifted left by 1016 bits so that it is located in the high 1024 to 1017 bits of the plaintext space; the lower 1016 bits are used to embed the ciphertext segment da of the first message. The embedding process is represented by the algorithm:

[0020] m' = (m << 1016) ⊕ da.

[0021] Optionally, S2 encrypting the image embedded with the first message includes the following steps:

[0022] The image provider side encrypts the image embedded with the first message using the ElGamal algorithm with the system public key to generate an encrypted image. Among them, each plaintext pixel in the image embedded with the first message is encrypted in the raster scan order, and the encryption is carried out according to the following algorithm:

[0023] c1 = g r mod p;

[0024] c2 = m' · y r mod p;

[0025] where g is a primitive root of, y is the public key, and r is a random number selected each time for encryption, satisfying 1 ≤ r ≤ p - 2;

[0026] Thus, the ciphertext pixels (c1, c2) are obtained, and the ciphertext pixels are aggregated to obtain the first marked ciphertext image. Optionally, S3 embedding the second message into the first marked ciphertext image includes the following steps:

[0027] [[ID=3,6]]S31 preprocesses the second message through the data hiding side, generates a pseudo-random sequence of a CSPRNG using khb as the seed, and performs stream cipher encryption on the second message mb and the generated sequence to obtain the ciphertext cb. The algorithm is expressed as follows:

[0028] cb = mb ⊕ CSPRNG(khb);

[0029] S33 divides cb into 10-bit segments, each segment is denoted as db, where 10 is an experimental value; for each ciphertext pixel (c1, c2), each component is multiplied by the component corresponding to the ciphertext of the integer 1 to obtain the new ciphertext (c1′, c2′), as follows:

[0030] c1′=c1·E(1)1;

[0031] c2′=c2·E(1)2;

[0032] Where E(1)1 and E(1)2 represent the two components corresponding to the ciphertext of the integer 1;

[0033] S35 checks whether the least significant 10 bits of c1′ are consistent with the corresponding 10-bit segment db. The checking algorithm is as follows:

[0034] c1′=db mod 2 10 ;

[0035] If c1′ does not match in S37, repeat the process of S31-S35 using the new ciphertext of 1 until c1′ satisfies the above formula;

[0036] S39 aggregates all modified ciphertext pixels to form a double-layer marked ciphertext image.

[0037] Optionally, the message extraction from the double-layer marked ciphertext image in S4S includes the following steps:

[0038] S41 extracts the message from the double-layer ciphertext image using a deterministic polynomial time algorithm at the image receiving end, wherein the first component c1′ of each pixel of the double-layer ciphertext image is calculated according to the raster scanning order:

[0039] db=c1′mod 2 10 ;

[0040] That is, extract each 10-bit segment db from the lower 10 bits of c1′ and concatenate these segments to reconstruct the ciphertext cb;

[0041] S42 cb is bitwise exclusive-ORed with the pseudo-random sequence generated by khb as the seed to obtain the original message mb. The process is represented by the algorithm as follows:

[0042] mb=cb⊕CSPRNG(khb).

[0043] Optionally, decrypting the double-layer ciphertext image using the private key in S4 includes the following steps:

[0044] The image receiving end uses a probabilistic polynomial-time algorithm to decrypt the double-layer labeled ciphertext image using the ElGamal algorithm. For each pair of ciphertext values (c1′, c2′) of the double-layer labeled ciphertext image, the decryption process is as follows:

[0045]

[0046] where x is the private key;

[0047] The decrypted values are aggregated to obtain the decrypted image.

[0048] Optionally, the steps for extracting the message from the decrypted plaintext image in S4 are as follows:

[0049] The image receiving end uses a deterministic polynomial-time algorithm to extract the message and recover the decrypted image:

[0050] For each pixel m of the decrypted image according to the raster scan order l ' is calculated, and the expression is as follows:

[0051] da = m′ mod 2 1016 ;

[0052] The ciphertext segment da of the first message is obtained, and each segment is connected to form the ciphertext ca of the first message;

[0053] The ciphertext ca is bitwise XORed with the pseudorandom sequence generated using kha as the seed to obtain the original message ma, and the operation expression is as follows:

[0054] ma = ca ⊕ CSPRNG(kha).

[0055] Optionally, the steps for recovering the decrypted image in S4 are as follows:

[0056] For each pixel m' of the decrypted image according to the raster scan order l is calculated, and the algorithm expression is as follows:

[0057]

[0058] m′ is shifted back from the high 1024 - 1017 bits to the original 1 - 8 bits to obtain the original pixel m;

[0059] All the original pixels are connected to form the original image.

[0060] Compared with the prior art, the beneficial effects of the present invention are:

[0061] 1. The present invention proposes a novel RDH-EI algorithm based on the ElGamal cryptosystem, which utilizes the plaintext redundancy and homomorphic properties of ElGamal encryption to achieve efficient and secure reversible data hiding in encrypted images;

[0062] 2. The present invention adopts a double-layer embedding technique, enabling the embedded information part to be extracted in the ciphertext domain and other parts to be extracted in the plaintext domain after decryption. This message embedding scheme is very flexible and practical;

[0063] 3. Compared with existing RDH-EI methods, the comprehensive embedding capacity of the present invention reaches the highest level among similar algorithms. The experimental results of specific embodiments show that the maximum embedding rate of the present invention reaches 10 bpp in the ciphertext domain and 1016 bpp in the plaintext domain.

[0064] To more clearly illustrate the structural features and effects of the present invention, the following combines the accompanying drawings and specific embodiments to detail the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 Schematic flow diagram of the double-layer embedding high-capacity ciphertext-domain reversible information hiding method based on ElGamal according to an embodiment of the present invention;

[0066] Figure 2 Schematic diagram of the test image according to an embodiment of the present invention;

[0067] Figure 3 Schematic diagrams of different process images generated by the double-layer embedding high-capacity ciphertext-domain reversible information hiding method based on ElGamal according to an embodiment of the present invention;

[0068] Figure 4 Histograms of different processes of the test images Baboon and Lake of the double-layer embedding high-capacity ciphertext-domain reversible information hiding method based on ElGamal according to an embodiment of the present invention;

[0069] Figure 5 Scatter plots of the four-direction correlations of adjacent pixels in different processes of the test image Baboon according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0070] In order to make the objectives, technical solutions and advantages of the present invention clearer, the following further details the present invention in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0071] The following details the specific implementation of the present invention in conjunction with specific embodiments. Specific Embodiment 1

[0073] As shown in the attachedFigure 1 As described above, the present invention proposes a double-layer embedding high-capacity reversible information hiding method in the ciphertext domain based on ElGamal, which includes the following steps:

[0074] S1: Generate system public and private keys, as well as the first embedding key and the second embedding key through a key server, and make the public key public, distribute the private key to the image receiver, distribute the first embedding key to the image provider, distribute the second embedding key to the data hiding end, and distribute the first and second embedding keys together to the image receiver;

[0075] S2: Obtain the original image through the image provider, encrypt the first embedding message according to the first embedding key, expand the original image pixels using the redundancy of the plaintext space, then embed the first message ciphertext, and encrypt the image embedded with the first message according to the system public key to obtain the first marked ciphertext image;

[0076] S3: The data hiding end encrypts the second embedding message using the second embedding key, and embeds the second message ciphertext into the first marked ciphertext image using the homomorphism and probability of ElGamal encryption to obtain a double-layer marked ciphertext image;

[0077] S4: The image receiver extracts the message from the double-layer marked ciphertext image, decrypts it using the second embedding key to obtain the second message, decrypts the double-layer marked ciphertext image to obtain the decrypted image, extracts the message from the decrypted image, decrypts it using the first embedding key to obtain the first message, and restores the decrypted image to obtain the original image.

[0078] To better understand the technical solution of the present invention, the present invention explains the related work and related principles involved:

[0079] ElGamal Cryptosystem:

[0080] (1) Select a large prime number p such that the discrete logarithm problem is intractable over the finite field GF(p), and select as a primitive element.

[0081] (2) Randomly select an integer x, 1 ≤ x ≤ p - 2, and calculate y = g x mod p; The triple (p, g, y) is the public key, and x is the private key.

[0082] (3) Encryption: For any plaintext m ∈ Z, secretly and randomly select an integer k, 1 ≤ k ≤ p - 2, then the ciphertext can be obtained as:

[0083] c = (c1, c2)

[0084] Where:

[0085] c1 = g kmod p,c2=m·y k mod p

[0086] (4) Decryption: For any ciphertext c = (c1, c2), the plaintext is:

[0087] m=c 2· (c1 x ) -1 mod p

[0088] Redundancy of plaintext space in ElGamal cryptosystem: For secure ElGamal encryption, the National Institute of Standards and Technology (NIST) recommends using a large prime number p of at least 1024 bits as basic security. This means that the plaintext space can be up to 2 1024 -1. However, when encrypting grayscale images, pixel values range from 0 to 255, corresponding to an 8-bit representation. This small range of pixel values only occupies a small portion of the ElGamal plaintext space. The significant difference between the plaintext space and the small pixel value range introduces a significant amount of redundancy. This allows for additional features such as data hiding without compromising security.

[0089] ElGamal cryptographic homomorphism: The homomorphic property of the ElGamal cryptosystem allows certain operations to be performed on ciphertext that correspond to operations on plaintext. Specifically, the ElGamal cryptosystem supports multiplication of plaintext by multiplication of ciphertext.

[0090] Assume there are two plaintexts m1 and m2, and their corresponding ciphertexts (c 11 ,c 12 ) and (c 21 ,c 22 ), these ciphertexts are encrypted under the same public key (p, g, y). The homomorphic property of the ElGamal cryptosystem can be described as follows:

[0091] (1) The ciphertext of plaintext m1 is (c 11 ,c 12 )=(g k mod p,m1y k mod p), where k is some random integer.

[0092] (2) The ciphertext of plaintext m2 is (c 21 ,c 22 )=(g r mod p,m2y r mod p), where r is some random integer.

[0093] Multiplication in homomorphic operations is performed by multiplying corresponding components of the ciphertext:

[0094] (c 11 ,c 12 )·(c 21 ,c 22 ) = (c 11 c 21 mod p,c 12 c 22 mod p)

[0095] Substitute the expressions of c 11 , c 12 , c 21 and c 22 to get:

[0096] (c 11 c 21 mod p,c 12 c 22 mod p) = (g k g r mod p,m1y k ·m2y r mod p) = (g k+r mod p,m1m2y k+r mod p);

[0097] When decrypting the resulting ciphertext using the private key x, the calculation gives:

[0098] Dec((c 11 c 21 mod p,c 12 c 22 mod p)) = m1m2 mod p. Specific Example 2

[0100] Combined with Specific Example 1 and the appendix Figures 1-5 shown, based on the ElGamal cryptosystem, the present invention proposes a high-capacity reversible information hiding scheme with double-layer embedding in the ciphertext domain. The system structure involved in the encryption and transmission process of the technical solution includes:

[0101] This scheme involves three participants, specifically the image provider, the data hiding end, and the image receiver. The image provider preprocesses the original image and embeds the initial data, then encrypts it using the public key and forwards the encrypted image to the data hiding end. The data hiding end embeds additional messages in the ciphertext domain. The image receiver can extract the embedded data from the ciphertext image and decrypt the ciphertext image using the private key. From the decrypted image, the remaining data can be extracted and the original image can be fully restored. The system structure is as shown in the appendix Figure 1 shown.

[0102] A double-layer embedded high-capacity ciphertext domain reversible information hiding method based on ElGamal, comprising the following steps:

[0103] Step 1: Key generation

[0104] Enter the security parameters through the key server, select a large prime number p and The primitive root g of ; select a random integer x such that 1≤x≤p-2; calculate according to the following algorithm:

[0105] y=g x mod p

[0106] Among them, the integer x is the private key, and the public key is the triple (p, g, y);

[0107] Select two secure random numbers as double-layer embedding keys, denoted as kha and khb respectively;

[0108] Step 2: Embed the first message into the original image

[0109] The image provider preprocesses the first message and uses kha as the seed to initialize a CSPRNG (Cryptographically Secure Pseudo-Random Number Generator) to generate a pseudo-random sequence. The first message ma is XOR-encrypted with the generated pseudo-random sequence to obtain the ciphertext ca. The calculation process is as follows:

[0110] ca=ma⊕CSPRNG(kha);

[0111] The ciphertext ca is divided into segments of 1016 bits each. When the ciphertext ca is less than 1016 bits, the high bits are padded with 0s. Each segment is recorded as da. The original grayscale image is input and each plaintext pixel value m is shifted 1016 bits to the left so that it is located between the high 1024 and 1017 bits of the plaintext space.

[0112] The lower 1016 bits are used to embed the ciphertext segment da of the first message. The embedding process is expressed as:

[0113] m′=(m<<1016)⊕da

[0114] Step 3: Encrypt the image embedded in the first message

[0115] The image provider uses the ElGamal algorithm to encrypt the image embedded in the first message using the system public key to generate a secret encrypted image. Specifically, each plaintext pixel in the image embedded in the first message is encrypted in a raster scan sequence. The encryption algorithm is as follows:

[0116] c1=g r mod p

[0117] c2 = m'·y r mod p

[0118] where g is a primitive root of, y is the public key, and r is a random number selected each time for encryption, satisfying 1 ≤ r ≤ p - 2;

[0119] Thus, the ciphertext pixels (c1, c2) are obtained, and the ciphertext pixels are aggregated to obtain the marked ciphertext image;

[0120] Step 4. Embed the second message into the encrypted image in which the first message is embedded

[0121] The data hiding end preprocesses the second message, generates a pseudo-random sequence of a CSPRNG using khb as the seed, and performs stream cipher encryption on the second message mb and the generated sequence to obtain the ciphertext cb. The algorithm is as follows:

[0122] cb = mb ⊕ CSPRNG(khb);

[0123] cb is segmented into segments of 10 bits each, and each segment is denoted as db, where 10 is an experimental value. For each ciphertext pixel (c1, c2), each component is multiplied by the corresponding component of the ciphertext of the integer 1 to obtain the new ciphertext (c1', c2'), as follows:

[0124] c1' = c1·E(1)1

[0125] c2' = c2·E(1)2

[0126] where E(1)1 and E(1)2 respectively represent the two components corresponding to the ciphertext of the integer 1; check whether the least significant 10 bits of c1' are consistent with the corresponding 10-bit segment db. The algorithm expression is as follows:

[0127] c1' = db mod 2 10 ;

[0128] If there is no match, repeat the above process using the new ciphertext of 1 until c1' satisfies the above formula; aggregate all the modified ciphertext pixels to form a double-layer marked encrypted image.

[0129] Step 5. Extract the message from the double-layer marked ciphertext image

[0130] The image receiving end extracts the message from the double-layer marked ciphertext image using a deterministic polynomial time algorithm, where

[0131] According to the raster scan order, calculate the first component c1' of each pixel of the double-layer marked ciphertext image:

[0132] db = c1′ mod 2 10

[0133] That is, each 10-bit segment db is extracted from the lower 10 bits of c1′, and these segments are concatenated to reconstruct the ciphertext cb; subsequently, cb is bitwise XORed with the pseudo-random sequence generated with khb as the seed to obtain the original message mb:

[0134] mb = cb ⊕ CSPRNG(khb)

[0135] Step 6, decrypt the double-layer marked ciphertext image

[0136] The process of decrypting the double-layer marked ciphertext image includes:

[0137] The double-layer marked ciphertext image is decrypted by the image receiver using the probabilistic polynomial-time algorithm with the ElGamal algorithm. For each pair of ciphertext values (c1′, c2′) of the double-layer marked ciphertext image, the decryption process is as follows:

[0138]

[0139] where x is the private key;

[0140] Each decrypted value is aggregated to obtain the decrypted image;

[0141] Step 7, extract the message from the decrypted plaintext image

[0142] The image receiver uses the deterministic polynomial-time algorithm to extract the message and recover the decrypted image:

[0143] According to the raster scan order, for each pixel m l ' of the decrypted image, the calculation is performed, and the expression is as follows:

[0144] da = m′ mod 2 1016

[0145] The ciphertext segments of the first message are obtained, and each segment is concatenated to form the ciphertext ca of the first message; subsequently, ca is bitwise XORed with the pseudo-random sequence generated with kha as the seed to obtain the original message ma:

[0146] ma = ca ⊕ CSPRNG(kha);

[0147] Step 8, recover the decrypted image

[0148] According to the raster scan order, for each pixel m' l of the decrypted image, the calculation is performed, and the expression is as follows:

[0149]

[0150] Shift m′ back from the 1024 - 1017th bit to the original 1 - 8th bit to obtain the original pixel m;

[0151] Finally, all the original pixels are connected to form the original image.

[0152] Simulation experiment

[0153] To evaluate the performance of the proposed scheme, the inventors selected eight 512×512 grayscale images from the USC - SIPI and BOSS - BASE datasets, as shown in the attached figure Figure 2 All experiments were conducted using Python 3.6 on a 64 - bit Windows 10 Professional system equipped with an Intel(R) Core(TM) i7 - 8565U CPU at 1.80 GHz and 8 GB of memory.

[0154] Next, the inventors analyzed and evaluated the correctness, security, and effectiveness of the proposed scheme, and then compared it with the recent classical RDH - EI scheme.

[0155] Correctness evaluation

[0156] The correctness of the proposed scheme depends on two key aspects: the accurate decryption of the double - labeled encrypted image and the precise extraction of the double - layer embedded data. For the former, since the first embedding is performed before encryption and the second makes use of the homomorphic and probabilistic properties of ElGamal encryption, the generated new ciphertext is a valid ElGamal ciphertext. Therefore, the correctness of decryption is not affected. As for the latter, because the displacement operation of the first embedding is reversible and the second operation directly embeds the information into the lowest 10 bits of the ciphertext, direct extraction can be achieved by reading these bits. Therefore, both embeddings are reversible. The attached Figure 3 shows the experimental results of the "Baboon" image at different stages of the scheme with the parameter |p| = 1024. The results confirm successful decryption and lossless recovery of the original image.

[0157] Security evaluation

[0158] The security of the proposed solution in this invention depends on the encryption and embedding processes. It can be divided into two key aspects: (1) the confidentiality of the embedded data, and (2) the preservation of encryption security during the embedding process. Regarding the first point, the confidentiality of the embedded data is ensured through two mechanisms: (1) the data to be embedded is first encrypted using a stream cipher, and (2) the generated double-layer tagged ciphertext maintains the standard ElGamal encryption format. Regarding the second point, we conduct a comprehensive security analysis through experimental methods, using a comparative evaluation framework to examine the key statistical characteristics of the ciphertext: (1) the histogram distribution and information entropy, and (2) the data correlation.

[0159] (1) Histogram and information entropy: Experiments were conducted on the sample images Baboon and Lake. The histograms before and after ciphertext embedding are as Figure 4 shown. The experimental parameters were set as |p| = 1024.

[0160] In addition, we tested the information entropy at different stages. Table 1 lists the average information entropy of the original image, encrypted image, and double-tagged image at different stages.

[0161] [[ID=Eleven]]Table 1 Average information entropy of the original image, encrypted image, and double-tagged image at different stages

[0162]

[0163] As shown in the appendix Figure 4 and Table 1, the original image has a high degree of regularity. After encryption and embedding, the distribution becomes almost uniform, and the entropy approaches the maximum value of 8. In addition, during the entire embedding process, the ciphertext distribution remains stable, maintaining its uniformity.

[0164] (2) Data correlation: In this algorithm, the Pearson correlation coefficients in four directions were calculated: horizontal, vertical, main diagonal, and secondary diagonal, using adjacent pixel values as variables. A total of 2000 random pixel pairs were selected. The results are summarized in Table 2.

[0165] Table 2 Pearson correlation coefficients

[0166]

[0167] Table 2 shows that the correlation coefficient of the original image is close to 1, indicating a strong linear relationship between adjacent pixels. After encryption, the correlation coefficient drops to close to 0, indicating that the linear correlation has been eliminated. The embedding process in the ciphertext results in minimal changes, and the correlation coefficient remains at a level close to 0, confirming that the embedding step has little impact on the correlation of the encrypted data.

[0168] Figure 5 The scatter plots of the data correlation of the test image Baboon at different stages are shown. As Figure 5As shown, the scatter points of the original image gather along y = x, indicating a strong correlation between adjacent pixels. In contrast, the scatter points of the encrypted image are evenly distributed, reflecting a high degree of randomness. After the second embedding, the distribution remains unchanged, without any gathering near x = y or y = -x. This indicates that the embedding process does not introduce ciphertext correlation, thus maintaining the security of the encrypted image.

[0169] Efficiency Evaluation

[0170] The experiment tested the efficiency of the proposed scheme when |p| = 1024. The data to be embedded was randomly generated and matched the maximum embedding capacity. The PSNR and SSIM between the recovered image and the original image were calculated. Table 3 shows the experimental results.

[0171] Table 3 PSNR and SSIM between the recovered image and the original image

[0172]

[0173] Among them, the ER of the first-layer embedding is denoted as ER1, the ER of the second-layer embedding is denoted as ER2, the overall embedding rate is denoted as ER, and the extraction accuracy of the first message ma and the second message mb is denoted as ACC. The experimental results show that when the large prime number p is set to 1024 bits, the ER of the first-layer and second-layer embeddings can reach 1016 bpp and 10 bpp respectively. Both types of data can be extracted with an accuracy of 100%, and all images can be recovered losslessly.

[0174] We used a series of test images and compared the proposed scheme with several existing ElGamal-based RDH-EI algorithms. The proposed scheme achieved a higher ER in both ciphertext and plaintext, outperforming other comparison algorithms.

[0175] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A double-layer embedding high-capacity reversible information hiding method in ciphertext domain based on ElGamal, characterized in that, It includes the following steps: S1: The key server generates the system public and private keys, the first embedding key, and the second embedding key, and makes the public key public, distributes the private key to the image receiver, distributes the first embedding key to the image provider, distributes the second embedding key to the data hiding end, and distributes the first and second embedding keys together to the image receiver; S2: The image provider obtains the original image, encrypts the first embedding message according to the first embedding key, expands the original image pixels using the redundancy of the plaintext space, then embeds the first message ciphertext, and encrypts the image with the first message embedded according to the system public key to obtain the first marked ciphertext image; S3: The data hiding end encrypts the second embedding message using the second embedding key, and embeds the second message ciphertext into the first marked ciphertext image using the homomorphism and probability of ElGamal encryption to obtain a double-layer marked ciphertext image; S4: The image receiver extracts the messages from the double-layer marked ciphertext image, decrypts it using the second embedding key to obtain the second message, decrypts the double-layer marked ciphertext image to obtain the decrypted image, extracts the messages from the decrypted image, decrypts it using the first embedding key to obtain the first message, and restores the decrypted image to obtain the original image.

2. A reversible information hiding method in a double-layer embedded high-capacity ciphertext domain based on ElGamal according to claim 1, characterized in that, The step in S1 of generating the system public and private keys, the first embedding key, and the second embedding key by the key server includes the following steps: S11 inputs security parameters through a key server, selects a large prime number p and a primitive root g of; selects a random integer x such that 1 ≤ x ≤ p - 2; calculates according to the following algorithm: y = g x mod p; S13: Take the integer x as the private key, and the public key is the triple (p, g, y); select two secure random numbers as the first embedding key and the second embedding key, denoted as kha and khb respectively.

3. A reversible information hiding method in a double-layer embedded high-capacity ciphertext domain based on ElGamal according to claim 2, characterized in that The specific step of embedding the first message ciphertext in S2 includes the following steps: S201: The image provider preprocesses the first message, initializes a CSPRNG (cryptographically secure pseudorandom number generator) using kha as the seed, generates a pseudorandom sequence, and performs bitwise exclusive-or encryption on the first message ma and the generated pseudorandom sequence to obtain the ciphertext ca. The algorithm is as follows: S203: Divide the ciphertext ca into segments of every 1016 bits. When it is less than 1016 bits, pad 0 at the high position. Each segment is denoted as da; input the original grayscale image, shift each plaintext pixel value m 1016 bits to the left so that it is located in the high 1024 to 1017 bits of the plaintext space; the lower 1016 bits are used to embed the ciphertext segment da of the first message. The embedding process is represented by the algorithm:

4. A reversible information hiding method based on double-layer embedding in the high-capacity ciphertext domain of ElGamal according to claim 3, characterized in that, The encryption of the image with the first message embedded in S2 includes the following steps: The image provider uses the ElGamal algorithm with the system public key to encrypt the image with the first message embedded to generate an encrypted image. Among them, each plaintext pixel in the image with the first message embedded is encrypted in raster scan order. The encryption is performed according to the following algorithm: c1 = g r mod p; c2 = m′·y r mod p; where g is a primitive root, y is the public key, and r is a random number selected each time for encryption, satisfying 1 ≤ r ≤ p - 2; Thus, the ciphertext pixels (c1, c2) are obtained, and the ciphertext pixels are aggregated to obtain the first marked ciphertext image.

5. A reversible information hiding method in a double-layer embedded high-capacity ciphertext domain based on ElGamal according to claim 4, characterized in that, The step of embedding the second message into the first marked ciphertext image in S3 includes the following steps: S31 pre-processes the second message through the data hiding end, uses khb as the CSPRNG seed to generate a pseudo-random sequence, and performs bitwise XOR encryption on the second message mb and the generated pseudo-random sequence to obtain the ciphertext cb, which is expressed as follows by the algorithm: cb=mb⊕CSPRNG(khb); S33 divides the ciphertext cb into 10-bit segments, each segment is denoted as db, where 10 is an experimental value; for each ciphertext pixel (c1, c2), each component is multiplied by the component corresponding to the ciphertext of the integer 1 to obtain the new ciphertext (c1′, c2′), as follows: c1′=c1·E(1)1; c2′=c2·E(1)2; Where E(1)1 and E(1)2 represent the two components corresponding to the ciphertext of the integer 1; S35 checks whether the least significant 10 bits of c1′ are consistent with the corresponding 10-bit segment db. The checking algorithm is as follows: c1′ = db mod 2 10 ; If c1′ does not match in S37, repeat the process of S31-S35 using the new ciphertext of 1 until c1′ satisfies the above formula; S39 aggregates all modified ciphertext pixels to form a double-layer marked ciphertext image.

6. A reversible information hiding method in a double-layer embedded high-capacity ciphertext domain based on ElGamal according to claim 4, characterized in that, The message extraction from the double-layer marked ciphertext image in S4 comprises the following steps: S41 extracts the message from the double-layer ciphertext image using a deterministic polynomial time algorithm at the image receiving end, wherein the first component c1′ of each pixel of the double-layer ciphertext image is calculated according to the raster scanning order: db = c1′ mod 2 10 ; That is, extract each 10-bit segment db from the lower 10 bits of c1′ and concatenate these segments to reconstruct the ciphertext cb; S42 cb is bitwise exclusive-ORed with the pseudo-random sequence generated by khb as the seed to obtain the original message mb. The process is represented by the algorithm as follows:

7. A reversible information hiding method based on double-layer embedding in high-capacity ciphertext domain using ElGamal according to claim 4, characterized in that, Decrypting the double-layer ciphertext image using the private key in S4 includes the following steps: The image receiving end uses a probabilistic polynomial time algorithm to decrypt the double-layer ciphertext image using the ElGamal algorithm. For each pair of ciphertext values (c1′, c2′) of the double-layer ciphertext image, the decryption process is as follows: Where x is the private key; Sum up each decrypted value to get the decrypted image.

8. A reversible information hiding method based on double-layer embedding in high-capacity ciphertext domain using ElGamal according to claim 7, characterized in that, Extracting messages from the decrypted image in S4 includes the following steps: The image receiving end uses a deterministic polynomial time algorithm to extract the message and restore the decrypted image: For each pixel m of the decrypted image according to the raster scan order l ' is calculated, and the expression is as follows: da = m′ mod 2 1016 ; Obtain the ciphertext segments da of the first message, and concatenate each segment to form the ciphertext ca of the first message; The ciphertext ca is bitwise XORed with the pseudo-random sequence generated by kha as the seed to obtain the original message ma. The operation expression is as follows:

9. A reversible information hiding method in a double-layer embedded high-capacity ciphertext domain based on ElGamal according to claim 7, characterized in that, Restoring the decrypted image in S4 includes the following steps: For each pixel m' of the decrypted image according to the raster scan order l perform calculations, and the algorithm expression is as follows: Move the high 1024-1017 bits of m' back to the original 1-8 bits to obtain the original pixel m; All original pixels are connected to form the original image.