⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



Constructing a CPA-Secure: Pseudo-Random Permutations and Block Ciphers, Modes of Operation, Security Against Chosen-Ciphertext Attacks (CCA)


Authors : Idowu Mayowa Opakunle; Ojoawo Akinwale Olusola; Oladeji Oluwakayode Paul; Alabi Adewale Abayomi

Volume/Issue : Volume 11 - 2026, Issue 7 - July


Google Scholar : https://tinyurl.com/yua8dff5

Scribd : https://tinyurl.com/y5d76ehc

DOI : https://doi.org/10.38124/ijisrt/26jul1487

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : This paper examines symmetric-key encryption as a layered security construction, tracing how cryptographic guarantees propagate from primitive to protocol. The study is conducted as a structured literature review of foundational and recent (2021–2025) cryptographic research on block cipher modes of operation and their resistance to chosen-plaintext and chosen-ciphertext attacks. At the foundation lies the block cipher, modeled as a pseudorandom permutation (PRP) whose security rests on cryptanalytic conjecture rather than provable hardness. Building on this, modes of operation including ECB, CBC, CFB, OFB, and CTR combine block-cipher calls to encrypt arbitrary-length messages, with security formally reduced to the underlying PRP assumption under indistinguishability against chosen-plaintext attack (IND-CPA). The review finds that while CPA security is necessary, it is insufficient for real-world deployment, since adversaries in network settings routinely gain oracle-like access to decryption; this is evidenced by recurring vulnerabilities such as padding-oracle attacks and related exploits against CBC-mode TLS. It further finds that the stronger requirement of indistinguishability under chosen-ciphertext attack (IND-CCA) is achieved through authenticated constructions such as Encrypt-then-MAC and, increasingly in current practice, integrated Authenticated Encryption with Associated Data (AEAD) schemes such as AES-GCM. The paper concludes that authenticated encryption should be the default standard in protocol design, closing the theoretical–practical gap that has historically enabled real-world cryptographic exploits.

Keywords : Symmetric-Key Cryptography; Pseudorandom Permutation (PRP); Modes of Operation; Chosen-Plaintext Attack (CPA); Chosen-Ciphertext Attack (CCA); Authenticated Encryption (AEAD); Padding-Oracle Attack

References :

  1. Albertini, A., Duong, T., Gueron, S., Kölbl, S., Luykx, A., & Schmieg, S. (2022). How to abuse and fix authenticated encryption without key commitment. In Proceedings of the 31st USENIX Security Symposium (pp. 3291–3308). USENIX Association.
  2. Bellare, M., Desai, A., Jokipii, E., & Rogaway, P. (1997). A concrete security treatment of symmetric encryption. Proceedings of the 38th Annual Symposium on Foundations of Computer Science, 394–403.
  3. Bellare, M., & Namprempre, C. (2000). Authenticated encryption: Relations among notions and analysis of the generic composition paradigm. In T. Okamoto (Ed.), Advances in Cryptology – ASIACRYPT 2000 (Lecture Notes in Computer Science, Vol. 1976, pp. 531–545). Springer.
  4. Dworkin, M. J. (2001). Recommendation for block cipher modes of operation: Methods and techniques (NIST Special Publication 800-38A). National Institute of Standards and Technology.
  5. Goldwasser, S., & Micali, S. (1984). Probabilistic encryption. Journal of Computer and System Sciences, 28(2), 270–299.
  6. Inoue, A. (2022). Beyond full-bit secure authenticated encryption without input-length limitation. IET Information Security, 16(4), 253–261.
  7. Jimale, M. A., Z'aba, M. R., Kiah, M. L. B. M., Idris, M. Y. I., Jamil, N., Mohamad, M. S., & Rohmad, M. S. (2022). Authenticated encryption schemes: A systematic review. IEEE Access, 10, 14739–14766.
  8. Kampanakis, P., Campagna, M., Crocket, E., Petcher, A., & Gueron, S. (2024). Practical challenges with AES-GCM and the need for a new cipher. In Proceedings of the Third NIST Workshop on Block Cipher Modes of Operation. National Institute of Standards and Technology.
  9. Katz, J., & Lindell, Y. (2020). Introduction to modern cryptography (3rd ed.). CRC Press.
  10. Kaur, J., Cintas Canto, A., Mozaffari Kermani, M., & Azarderakhsh, R. (2023). A comprehensive survey on the implementations, attacks, and countermeasures of the current NIST lightweight cryptography standard. ACM Computing Surveys.
  11. Krawczyk, H. (2001). The order of encryption and authentication for protecting communications (or: How secure is SSL?). In J. Kilian (Ed.), Advances in Cryptology – CRYPTO 2001 (Lecture Notes in Computer Science, Vol. 2139, pp. 310–331). Springer.
  12. Mouha, N. (2021). Review of the Advanced Encryption Standard (NIST Interagency/Internal Report 8319). National Institute of Standards and Technology.
  13. Mouha, N., & Dworkin, M. (2024). Report on the block cipher modes of operation in the NIST SP 800-38 series (NIST Interagency/Internal Report 8459). National Institute of Standards and Technology.
  14. National Institute of Standards and Technology. (2023). Advanced Encryption Standard (AES) (FIPS Publication 197, Update 1). U.S. Department of Commerce.
  15. Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. The BMJ, 372, n71.
  16. Rogaway, P. (2011). Evaluation of some blockcipher modes of operation. CRYPTREC. https://www.cryptrec.go.jp/en/
  17. Vaudenay, S. (2002). Security flaws induced by CBC padding: Applications to SSL, IPSEC, WTLS. In L. R. Knudsen (Ed.), Advances in Cryptology – EUROCRYPT 2002 (Lecture Notes in Computer Science, Vol. 2332, pp. 534–545). Springer.

This paper examines symmetric-key encryption as a layered security construction, tracing how cryptographic guarantees propagate from primitive to protocol. The study is conducted as a structured literature review of foundational and recent (2021–2025) cryptographic research on block cipher modes of operation and their resistance to chosen-plaintext and chosen-ciphertext attacks. At the foundation lies the block cipher, modeled as a pseudorandom permutation (PRP) whose security rests on cryptanalytic conjecture rather than provable hardness. Building on this, modes of operation including ECB, CBC, CFB, OFB, and CTR combine block-cipher calls to encrypt arbitrary-length messages, with security formally reduced to the underlying PRP assumption under indistinguishability against chosen-plaintext attack (IND-CPA). The review finds that while CPA security is necessary, it is insufficient for real-world deployment, since adversaries in network settings routinely gain oracle-like access to decryption; this is evidenced by recurring vulnerabilities such as padding-oracle attacks and related exploits against CBC-mode TLS. It further finds that the stronger requirement of indistinguishability under chosen-ciphertext attack (IND-CCA) is achieved through authenticated constructions such as Encrypt-then-MAC and, increasingly in current practice, integrated Authenticated Encryption with Associated Data (AEAD) schemes such as AES-GCM. The paper concludes that authenticated encryption should be the default standard in protocol design, closing the theoretical–practical gap that has historically enabled real-world cryptographic exploits.

Keywords : Symmetric-Key Cryptography; Pseudorandom Permutation (PRP); Modes of Operation; Chosen-Plaintext Attack (CPA); Chosen-Ciphertext Attack (CCA); Authenticated Encryption (AEAD); Padding-Oracle Attack

Paper Submission Last Date
31 - August - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe