Authors :
Idowu Mayowa Opakunle; Ojoawo Akinwale Olusola; Oladeji Oluwakayode Paul; Alabi Adewale Abayomi
Volume/Issue :
Volume 11 - 2026, Issue 7 - July
Google Scholar :
https://tinyurl.com/yua8dff5
Scribd :
https://tinyurl.com/y5d76ehc
DOI :
https://doi.org/10.38124/ijisrt/26jul1487
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
This paper examines symmetric-key encryption as a layered security construction, tracing how cryptographic
guarantees propagate from primitive to protocol. The study is conducted as a structured literature review of foundational
and recent (2021–2025) cryptographic research on block cipher modes of operation and their resistance to chosen-plaintext
and chosen-ciphertext attacks. At the foundation lies the block cipher, modeled as a pseudorandom permutation (PRP)
whose security rests on cryptanalytic conjecture rather than provable hardness. Building on this, modes of operation
including ECB, CBC, CFB, OFB, and CTR combine block-cipher calls to encrypt arbitrary-length messages, with security
formally reduced to the underlying PRP assumption under indistinguishability against chosen-plaintext attack (IND-CPA).
The review finds that while CPA security is necessary, it is insufficient for real-world deployment, since adversaries in
network settings routinely gain oracle-like access to decryption; this is evidenced by recurring vulnerabilities such as
padding-oracle attacks and related exploits against CBC-mode TLS. It further finds that the stronger requirement of
indistinguishability under chosen-ciphertext attack (IND-CCA) is achieved through authenticated constructions such as
Encrypt-then-MAC and, increasingly in current practice, integrated Authenticated Encryption with Associated Data
(AEAD) schemes such as AES-GCM. The paper concludes that authenticated encryption should be the default standard in
protocol design, closing the theoretical–practical gap that has historically enabled real-world cryptographic exploits.
Keywords :
Symmetric-Key Cryptography; Pseudorandom Permutation (PRP); Modes of Operation; Chosen-Plaintext Attack (CPA); Chosen-Ciphertext Attack (CCA); Authenticated Encryption (AEAD); Padding-Oracle Attack
References :
- Albertini, A., Duong, T., Gueron, S., Kölbl, S., Luykx, A., & Schmieg, S. (2022). How to abuse and fix authenticated encryption without key commitment. In Proceedings of the 31st USENIX Security Symposium (pp. 3291–3308). USENIX Association.
- Bellare, M., Desai, A., Jokipii, E., & Rogaway, P. (1997). A concrete security treatment of symmetric encryption. Proceedings of the 38th Annual Symposium on Foundations of Computer Science, 394–403.
- Bellare, M., & Namprempre, C. (2000). Authenticated encryption: Relations among notions and analysis of the generic composition paradigm. In T. Okamoto (Ed.), Advances in Cryptology – ASIACRYPT 2000 (Lecture Notes in Computer Science, Vol. 1976, pp. 531–545). Springer.
- Dworkin, M. J. (2001). Recommendation for block cipher modes of operation: Methods and techniques (NIST Special Publication 800-38A). National Institute of Standards and Technology.
- Goldwasser, S., & Micali, S. (1984). Probabilistic encryption. Journal of Computer and System Sciences, 28(2), 270–299.
- Inoue, A. (2022). Beyond full-bit secure authenticated encryption without input-length limitation. IET Information Security, 16(4), 253–261.
- Jimale, M. A., Z'aba, M. R., Kiah, M. L. B. M., Idris, M. Y. I., Jamil, N., Mohamad, M. S., & Rohmad, M. S. (2022). Authenticated encryption schemes: A systematic review. IEEE Access, 10, 14739–14766.
- Kampanakis, P., Campagna, M., Crocket, E., Petcher, A., & Gueron, S. (2024). Practical challenges with AES-GCM and the need for a new cipher. In Proceedings of the Third NIST Workshop on Block Cipher Modes of Operation. National Institute of Standards and Technology.
- Katz, J., & Lindell, Y. (2020). Introduction to modern cryptography (3rd ed.). CRC Press.
- Kaur, J., Cintas Canto, A., Mozaffari Kermani, M., & Azarderakhsh, R. (2023). A comprehensive survey on the implementations, attacks, and countermeasures of the current NIST lightweight cryptography standard. ACM Computing Surveys.
- Krawczyk, H. (2001). The order of encryption and authentication for protecting communications (or: How secure is SSL?). In J. Kilian (Ed.), Advances in Cryptology – CRYPTO 2001 (Lecture Notes in Computer Science, Vol. 2139, pp. 310–331). Springer.
- Mouha, N. (2021). Review of the Advanced Encryption Standard (NIST Interagency/Internal Report 8319). National Institute of Standards and Technology.
- Mouha, N., & Dworkin, M. (2024). Report on the block cipher modes of operation in the NIST SP 800-38 series (NIST Interagency/Internal Report 8459). National Institute of Standards and Technology.
- National Institute of Standards and Technology. (2023). Advanced Encryption Standard (AES) (FIPS Publication 197, Update 1). U.S. Department of Commerce.
- Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. The BMJ, 372, n71.
- Rogaway, P. (2011). Evaluation of some blockcipher modes of operation. CRYPTREC. https://www.cryptrec.go.jp/en/
- Vaudenay, S. (2002). Security flaws induced by CBC padding: Applications to SSL, IPSEC, WTLS. In L. R. Knudsen (Ed.), Advances in Cryptology – EUROCRYPT 2002 (Lecture Notes in Computer Science, Vol. 2332, pp. 534–545). Springer.
This paper examines symmetric-key encryption as a layered security construction, tracing how cryptographic
guarantees propagate from primitive to protocol. The study is conducted as a structured literature review of foundational
and recent (2021–2025) cryptographic research on block cipher modes of operation and their resistance to chosen-plaintext
and chosen-ciphertext attacks. At the foundation lies the block cipher, modeled as a pseudorandom permutation (PRP)
whose security rests on cryptanalytic conjecture rather than provable hardness. Building on this, modes of operation
including ECB, CBC, CFB, OFB, and CTR combine block-cipher calls to encrypt arbitrary-length messages, with security
formally reduced to the underlying PRP assumption under indistinguishability against chosen-plaintext attack (IND-CPA).
The review finds that while CPA security is necessary, it is insufficient for real-world deployment, since adversaries in
network settings routinely gain oracle-like access to decryption; this is evidenced by recurring vulnerabilities such as
padding-oracle attacks and related exploits against CBC-mode TLS. It further finds that the stronger requirement of
indistinguishability under chosen-ciphertext attack (IND-CCA) is achieved through authenticated constructions such as
Encrypt-then-MAC and, increasingly in current practice, integrated Authenticated Encryption with Associated Data
(AEAD) schemes such as AES-GCM. The paper concludes that authenticated encryption should be the default standard in
protocol design, closing the theoretical–practical gap that has historically enabled real-world cryptographic exploits.
Keywords :
Symmetric-Key Cryptography; Pseudorandom Permutation (PRP); Modes of Operation; Chosen-Plaintext Attack (CPA); Chosen-Ciphertext Attack (CCA); Authenticated Encryption (AEAD); Padding-Oracle Attack