Skip to main content
Scientific Reports logoLink to Scientific Reports
. 2025 Nov 27;15:45473. doi: 10.1038/s41598-025-29168-y

Omega deoxyribonucleic acid cryptography key-based authentication

Chai Wen Chuah 1,✉, Jocelyn Tey 2, Kamaruddin Malik Mohamad 3
PMCID: PMC12749262  PMID: 41310192

Abstract

Deoxyribonucleic acid cryptography is a biologically inspired approach characterized by low computational complexity. It employs biological principles to create cryptographically strong ciphers, making it particularly suitable for protecting sensitive data on resource-constraints devices. However, the existing literature lacks solutions for securing authentication mechanisms tailored for these resource-constrained devices. To bridge this gap, the current study proposes a novel authentication design rooted in deoxyribonucleic acid cryptography, namely omega deoxyribonucleic acid cryptography key-based authentication. The proposed omega deoxyribonucleic acid cryptography-based authentication method aligns with contemporary standards for cryptographic systems and delivers a security level quantified at 256 bits of complexity. To validate its resilience, one tests the collision resistance of the proposed authentication mechanism using the standard Dieharder statistical test suite, where the mechanism successfully passes the collision resistance test. Additionally, the proposed scheme is mathematically proven secure against existential forgery under a chosen message attack.

Keywords: Deoxyribonucleic acid cryptography, Low computational, Authentication, Omega deoxyribonucleic acid cryptography key-based authentication, Dieharder statistical test

Subject terms: Applied mathematics, Computational science, Computer science, Information technology

Introduction

The technologies of resource-constrained computing devices have gained significant prominence in recent years13,21. For example, sensor networks, smart cards, and the Internet of Things (IoT) are included in this category11,37. The data generated by these devices needs to be protected in terms of confidentiality,and the origin of the transmitted data needs to be authenticated24. These resource-constrained computing devices have limited capabilities in terms of processing power, memory, storage, and energy consumption. Lightweight cryptography provides a low-complexity solution to enhance security for these devices. One type of lightweight cryptography, known as deoxyribonucleic acid (DNA) cryptography, offers faster computing speeds while requiring minimal storage and low power consumption8,15.

DNA cryptography represents the merging of cryptography and molecular biology, driven by advances in biotechnology and DNA computing. This integration has led to the emergence of DNA cryptography and information science, a domain pioneered by Adleman’s groundbreaking work in DNA computing26. Although this nascent field has rapidly attracted global interest, with numerous research projects underway, it remains in the early stages of development within cryptography, with most investigations focusing on foundational concepts16.

DNA cryptography utilizes biological principles to pioneer new computing paradigms. The concept of a DNA computer envisions matching the processing capabilities of traditional systems while addressing problems currently considered intractable. It exploits DNA’s unique attributes: exceptional parallel processing capacity, which can perform over one billion operations per second and energy efficiency10. These features position DNA-based computing as a transformative frontier in secure information processing.

DNA cryptography explores the use of four types of nitrogenous bases in DNA. The nitrogenous bases are adenine (A), guanine (G), cytosine (C), and thymine (T)20. The researchers form a pseudorandom cryptographically keys based on the nitrogenous bases. These keys are used for encoding, storing, and transmitting information securely. To date literature shown that the DNA cryptography is designed mainly to ensure data confidentiality while transmitting over insecure network. These design only can protect the data from being read by unauthorized parties but does not authenticate the sender. For example, encryption scheme using DNA technology9, DNA-based cryptographic framework34, DNA security algorithm using DNA codons30, DNA with Pi-based key generating encryption algorithm36, DNA-Based S-Box1, DNA-based Vernam Cipher35 and Omega network pseudorandom key generation based on DNA cryptography (ONDNA)29.

Authentication is a cryptographic security mechanism used to verify the identity of a message14,27. This process ensures both the integrity and the source of messages during transmission. There are examples of hybrid cryptographic systems that integrate DNA cryptography and hash functions for authenticating messages during transmission. For instance, DNA-BRNG key and a novel hash algorithm32, as well as DNA-LCG key and a novel hash algorithm33. Both designs propose their own pseudorandom number generators based on the nitrogenous bases in DNA. The output of the pseudorandom number generator is known as a pseudorandom cryptographic key. The message authentication code is generated by applying the novel hash algorithm to the message and the pseudorandom cryptographic key. A drawback is that these studies fail to propose a complete authentication process based on DNA cryptography.

Hence, this design addresses a significant gap in the existing literature, as prior research has not extensively explored DNA cryptography for key-based authentication. By filling this gap, this research introduces an encrypt-then-authenticate process that ensures both the confidentiality and authenticity of data17. The process involves two main steps: encryption followed by authentication. The encryption process is rooted in the Omega network pseudorandom key generation (ONDNA), which produces ciphertext of the same length as the input message. The ciphertext is then authenticated, generating a fixed 256 bits tag. We designate this complete process as ODNAMAC.

It is important to highlight that the existing ONDNA is fundamentally based on DNA cryptography principles, tailored specifically to maximize memory efficiency. This design choice allows for rapid processing speeds and scalability, making it suitable for large-scale applications involving extensive data encryption and decryption tasks29. Consequently, the tags generated by the ODNAMAC process inherit these advantageous properties, ensuring that they are not only produced quickly but also support scalable operations, thereby facilitating efficient and secure data authentication in cryptographic environments.

The key advantage of our proposed encrypt-then-authenticate2 ODNAMAC approach lies in its verification optimization: when tag matching fails during verification, decryption becomes unnecessary because message integrity cannot be guaranteed. This approach minimizes the computational steps involved in decryption, optimizes the authentication process, and enhances overall efficiency by conserving computational resources12.

We present a literature review in Sect. “Literature review”. Section “Deoxyribonucleic acid” generally introduces deoxyribonucleic acid (DNA). Section "Omega network pseudorandom key generation based on DNA cryptography" discusses Omega network pseudorandom key generation based on DNA cryptography. Section "Message authentication Code" introduces the theoretical definition of message authentication codes. Section “Research Design” shows the research design. Section "The proposed ODNAMAC scheme" presents our proposed ODNAMAC scheme. Section "ODNAMAC analysis and discussion" provides the ODNAMAC analysis and discussion, including tag generation, statistical tests, formal security analysis, brute-force attacks, and collision attacks. Section “Conclusion” concludes the paper.”

Literature review

The DNA-based encryption scheme is a cryptographic approach that combines biological DNA operations with computational methods to improve data security. It encodes plaintext into DNA nucleotides bases A, C, T, and G using binary mapping rules, utilizing eight pattern types (CTAG, CATG, GTAC, GATC, TCGA, TGCA, ACGT, AGCT) that are topologically equivalent and follow the complementary pairing rules of nucleotides9. The authors utilize Watson-Crick complementarity for diffusion and produce pseudorandom keys via DNA oligonucleotide synthesis. Their encryption method combines DNA substitution and permutation techniques inspired by polymerase chain reactions (PCR) to enhance diffusion and confusion. Even though the encryption and decryption processes are effective, the authors do not provide formal proofs or statistical analyses to substantiate the scheme’s security, leaving its robustness uncertain.

Sukumaran and Misbahuddin introduce a DNA-based cryptographic framework designed to improve cloud data security by encoding sensitive information into synthetic DNA sequences34. This approach involves converting plaintext into binary, then mapping it to nucleotide bases through a deterministic algorithm, and utilizing PCR along with Watson-Crick complementarity to diffuse the data. Encryption keys are derived from unique synthetic DNA nucleotide sequences to ensure resistance against brute-force attacks. The scheme also incorporates error-correcting codes to mitigate the synthesis errors commonly associated with DNA storage. Their security analysis focuses primarily on two key aspects: integrity and confidentiality, while authentication was not addressed.

Patnala and Kumar present a hierarchical DNA encryption algorithm that utilizes codon-level encoding to improve data security30. The process begins by converting plaintext into ASCII codes, which are then transformed into binary. These binary sequences are mapped to DNA nucleotides using a triplet codon scheme, such as assigning 3 bits to each codon which facilitating multi-layered diffusion. The algorithm incorporates three tiers of security: base substitution through codon shuffling, position permutation, and stochastic noise injection, providing scalable protection suitable for DNA-based storage and biomedical communication. However, the authors only report the encryption time and do not include a security analysis.

The paper introduces a hybrid cryptographic approach that integrates DNA-based encoding with pi-derived key generation to improve security and randomness36. Initially, the plaintext is transformed into a binary stream, which is then mapped to DNA nucleotides via a pi-based mapping scheme that prevents repetitive patterns. For key creation, the algorithm derives pseudorandom sequences from pi values and processes them using DNA diffusion synthesis rules to produce biologically inspired cryptographic keys with increased entropy. The encryption process utilizes substitution-permutation networks (SPNs) to achieve diffusion and confusion. However, as noted in6, this method is vulnerable to man-in-the-middle attacks. The authors suggest addressing this security flaw by implementing a key exchange protocol6.

The DNA-based S-Box technique is an example of a DNA cryptography cipher. The S-Box includes the SPN that manipulates the nitrogenous bases A, C, T, and G. The SPN is essential to enhance the pseudorandomness and complexity of the S-Box output. Hence, satisfies key cryptographic properties, such as nonlinearity, uniformity in differential analysis, and resistance to linear attacks1.

The DNA-based Vernam Cipher is another example of a symmetric DNA cryptography cipher which integrates the security of the traditional Vernam Cipher with the complexity and pseudorandomness of DNA sequences35. The goal is to develop a highly secure encryption technique that utilizes the uniqueness characteristics of DNA. The process includes DNA encoding, key generation, encryption and decryption. The DNA encoding process, the plaintext message is converted into a predefined mapping binary format. Next, the key generation, a random DNA sequence is generated to serve as the one-time pad key. This key length is same length as the plaintext DNA sequence. As for encryption process, the DNA-based Vernam Cipher performs a XOR operation between the plaintext DNA sequence and the key DNA sequence. While, the decryption process is the reverse process of encryption, by performing the XOR operation between the ciphertext DNA sequence with the corresponding key DNA sequence35.

The Omega network pseudorandom key generation based on DNA cryptography is characterized as a low-complexity cipher for generating pseudorandom keys29. The Omega Network is used to create a complex and nonlinear transformation of input data. This transformation is essential for generating pseudorandom sequences as secret keys for encryption and decryption. The network’s routing capabilities ensure that the output is highly dependent on the input, making it difficult for adversaries to predict the key.

Sodhi and Gaba introduced a MAC scheme that utilizes a DNA-based random number generator (DNA-BRNG) key to derive unique DNA sequences, generating highly unpredictable private keys and enhancing protection against key-guessing attacks32. For authentication purposes, they employ a conventional hash function in conjunction with this private key to improve efficiency and collision resistance, thereby ensuring reliable message authentication. By integrating DNA-generated randomness with a tailored hash function, their scheme attains robust security alongside practical computational performance. Sodhi et al. further extended their research by combining the DNA-based linear congruential generator (DNA-LCG) with a novel hash algorithm for message authentication33. This method utilizes unique DNA sequences to generate highly unpredictable cryptographic keys, while the LCG further strengthens randomness. A new hash algorithm is introduced to improve collision resistance and efficiency in MAC computation. By integrating biological data with traditional pseudorandom number generation, the scheme aims to resist brute-force and key-guessing attacks. Shaw, et. al. proposes an integration genomic data together with traditional hash function as keyed-hash message authentication code (HMAC) protocol31. The approach involves extracting genomic features, processing them into secure keys, and integrating them with traditional HMAC mechanisms. By utilizing the inherent variability and complexity of DNA sequences, the protocol aims to improve resistance against brute-force and forgery attacks. A drawback is that these studies fail to propose a complete authentication process based on DNA cryptography.

Deoxyribonucleic acid

Deoxyribonucleic Acid (DNA) functions as the molecular blueprint of life, controlling organism development and biological activities. This remarkable macromolecule contains all genetic information within an organism and is located in the nucleus of each cell, earning its status as a fundamental component of life25. As the universal genetic material in all cellular life forms, DNA orchestrates cellular processes such as growth, reproduction, and programmed cell death through its complex chemical structure.

The well-known double-helix structure of DNA, initially described by Watson and Crick, consists of two antiparallel strands that twist into a ladder-like formation (28; see Fig. 1). This long polymer is made up of millions of nucleotides arranged in specific sequences, with genetic information encoded by different combinations of four nitrogenous bases3. According in28, the variations in these base sequences generate genetic diversity and underpin DNA’s unique replication process. During semiconservative replication, the double helix unwinds, and each strand serves as a template for synthesizing a complementary strand, resulting in two daughter molecules with each containing one original and one newly formed strand.

Fig. 1.

Fig. 1

DNA double helix structure28.

The structural intricacy of DNA allows for nearly limitless genetic variation. With about one million base pairs in a typical DNA molecule and billions of potential nucleotide arrangements within the double helix, DNA provides the molecular foundation for biological diversity. This sophisticated system of information storage and transfer is fundamental to all known life processes.

Omega network pseudorandom key generation based on DNA cryptography

The Omega network pseudorandom key generation based on DNA cryptography (ONDNA), as shown in Algorithm 1, consists of three rows and four columns, denoted as Inline graphic29. It incorporates four operations or DNA rules: DNA XOR rules (represented by Inline graphic), mRNA mapping rules where the first letter precedes the second (denoted as Inline graphic), mRNA mapping rules where the second letter precedes the first (denoted as Inline graphic), and complementary mapping rules (denoted as Inline graphic). The inputs are two 128 bits of private strings, namely sperm and ovum. The output is 256 bits of cryptographically pseudorandom key. Specifically, the elements Inline graphic, Inline graphic, and Inline graphic are generated using DNA XOR rules. Meanwhile, Inline graphic, Inline graphic, and Inline graphic follow mRNA mapping rules with the first letter leading the second. Inline graphic, Inline graphic, and Inline graphic adhere to mRNA mapping rules where the second letter comes before the first. Lastly, Inline graphic, Inline graphic, and Inline graphic are derived from complementary mapping rules. These operations are randomly arranged to ensure an even distribution across the design, enabling the generation of a cryptographically pseudorandom key-based on DNA. These cryptographically pseudorandom keys are used for encryption and decryption to ensure the confidentiality of data during the transmission over insecure internet.

In one round of the ONDNA key generation, a 128 bits sperm and a 128 bits ovum are used to generate a 256 bits cryptographic pseudorandom key-based DNA. If an application or protocol demands more than 256 bits, the process is repeated. For instance, to obtain 400 bits of pseudorandom key-based DNA, two iterations are needed. The first round, as outlined, produces a 256 bits pseudorandom key-based DNA. The last round, the initial 128 bits (0Inline graphic127) and the subsequent 128 bits (128Inline graphic255) of the first output serve as the sperm and ovum, respectively. The key generation process is repeated (steps 1 through 11). Together, these two rounds yield 512 bits of pseudorandom key-based DNA. Since the application requires only 400 bits, the final 112 bits are discarded.

Algorithm 1.

Algorithm 1

ONDNA29

The DNA XOR rules, as presented in Table 1, consist of combinations involving A, C, G, and T. In this encoding, A corresponds to 10, C to 01, G to 11, and T to 00. There are four rules, and the rule applied depends on the first character of the string. For instance, consider the first string, TCGA, which translates to the binary value 00011110, and the second string, AACT, which translates to the binary value 10100100. Because the first string begins with ‘T’, the output follows the first rule of DNA XOR. As a result, the XOR operation yields CGTT, with a binary value of 01110000.

Table 1.

DNA XOR rules Inline graphic29.

DNA Rule 1 - T(00) Rule 2 - T(01) Rule 3 - T(10) Rule 4- T(11)
XOR A C G T A C G T A C G T A C G T
10 01 11 00 10 01 11 00 10 01 11 00 10 01 11 00
A A G C T G T A C C G T A T A C G
10 10 11 01 00 11 00 10 01 01 11 00 10 00 10 01 11
C G C T A T A C G G T A C A C G T
01 11 01 00 10 00 10 01 11 11 00 10 01 10 01 11 00
G C T A G A C G T T A C G C G T A
11 01 00 10 11 10 01 11 00 00 10 01 11 01 11 00 10
T C T A G C G T A A A C G G T A C
00 01 00 10 11 01 11 00 10 10 10 01 11 11 00 10 1

Table 2 presents the mRNA mapping rules. For instance, take the string CGTT, which encodes the binary value 01110000. The first letter and second letter are C and G, respectively; following the mRNA mapping rules, this yields AT, represented by the binary value 1000. Next, the third and fourth letters are T, producing GA according to the mRNA rules, which corresponds to the binary value 1110. Therefore, the result is ATGA, with a binary representation of 10001110.

Table 2.

mRNA mappring rules Inline graphic29.

Seconnd letter
T (00) C (01) A (10) G (11)
First letter T (00) GA (1110) GT (1100) TA (0010) CC (0101)
C (01) GC (1101) TC (0001) CT (0100) AT (1000)
A (10) TT (0000) AC (1001) GG (1111) AA (1010)
G (11) CA (0110) CG (0111) TG (0011) AG (1011)

Table 3 illustrates the complementary mapping of nucleotide letters in binary format. Four binary values represent the base of each nucleotide letter. For instance, consider the binary sequence 1010, which corresponds to the bases C and T. The complementary result is 1001. In another example, with the input string 10001110, the complementary output is 01111011.

Table 3.

Complementary Mapping Rules29.

Input Binary Base Represented Complement Output Binary
0000 A 0011
0001 C 0010
0010 G 0001
0011 T 0000
0100 U 0000
0101 A T 0101
0110 C G 0110
0111 A C 1000
1000 G T 0111
1001 A G 1010
1010 C T 1001
1011 C G T 1110
1100 A G T 1101
1101 A C T 1100
1110 A C G 1011
1111 A C G T 1111

Definition 1

ONDNA is defined as: Inline graphic

  • sperm is private string, it is chosen from the public space Inline graphic, such that Inline graphic with the length Inline graphic (128 bits) and probability distribution Inline graphic.

  • ovum is private string, it is chosen from the public string space Inline graphic, such that Inline graphic with the length Inline graphic (128 bits) and probability distribution Inline graphic.

  • x is public random string consisting of space Inline graphic, such that Inline graphic, with the length Inline graphic (128 bits) and probability distribution X.

  • y is public random string consisting of space Inline graphic, such that Inline graphic, with the length Inline graphic (128 bits) and probability distribution Y.

  • z is public random string consisting of space Inline graphic, such that Inline graphic, with the length Inline graphic (128 bits) and probability distribution Z.

  • K is a 256 bits pseudorandom cryptographic key.

The output of ONDNA is 256 bits block of pseudorandom cryptographic keys which follows the Definition 2. This algorithm generates cryptographic keys of arbitrary length by producing multiple 256-bit blocks and discarding any excess bits.

Definition 2

A pseudorandom keystream generator is considered secure only if no polynomial time algorithm can distinguish between the pseudorandom string generated by the pseudorandom keystream generator and a truly random string of the same length with a probability significantly greater than Inline graphic19.

Message authentication code

The message authentication code (MAC) is a symmetric key cryptographic algorithm that ensures parties with the shared secret key may communicate securely and identify any unauthorized modifications to the message during transmission19,23. MAC generates a tag that verifies the authenticity of a message. This technique produces fixed-length tags for messages of arbitrary length. Figure 2 shows the general model of MAC. Both the sender and receiver use the same secret key to perform the message authentication process. The receiver generates a tag and compares it with the received tag. If both tags match, the message is regarded as authentic; if not, it is considered to have been tampered with by an unauthorized entity.

Fig. 2.

Fig. 2

Message authentication code general model.

Definition 3

Message authentication code (MAC) over the message Inline graphic is defined as: MAC(Gen, Tag, Ver)19.

  • Gen is a pseudorandom polynomial time algorithm that generates a key, such that Inline graphic.

  • Tag is a pseudorandom polynomial time algorithm that on input key k and message m output a tag, Inline graphic.

  • Ver is a deterministic polynomial time algorithm that on input key k, message m and tag t, output Inline graphic, where Inline graphic represents “accept”, Inline graphic represents “reject”.

  • For all Inline graphic and Inline graphic, Pr[Inline graphic=“accept”] = 1.

The MAC scheme must secure existentially unforgeable under chosen message attacks where an attacker is able to generate at least one valid message and tag pair without possessing the secret key with negligible probability. This property guarantees that the MAC scheme provides strong integrity and authenticity assurances, preventing attackers from forging valid tags without knowledge of the secret key.

Definition 4

A MAC scheme MAC(Gen, Tag, Ver) is said to be existentially unforgeable under chosen message attacks if, for any generated key k, a polynomial time adversary can make tag and verification queries for arbitrary messages using k, to forge a valid tag t for a message m, the following advantage is negligible. Inline graphic Pr[Inline graphic; Inline graphic; Inline graphic: Inline graphic]4.

The MAC must prevent an attacker from finding two distinct messages Inline graphic and Inline graphic, that produce the same tag, Inline graphic is equal with Inline graphic, where Inline graphic. This property is known as collision resistance of the MAC. Ensuring this property prevents collision attacks, where an attacker attempts to find two different messages that produce the same MAC, which could compromise the integrity and authenticity assurances provided by the MAC.

Definition 5

Let a MAC has a tag generation function, Tag(k, m). A collision for Tag as a pair Inline graphic such that Inline graphic. The tag generation function Tag is called collision-resistant, if for any polynomial time adversary, the probability that the adversary output the collision is negligible5.

Research design

Figure 3 illustrates the research design, which consists of four major processes. The first step is to examine the existing literature on DNA cryptography-based authentication. Next, the study proposes an omega DNA cryptography key-based authentication method. This is followed by a phase of conducting tag generation. Finally, the research performs security testing on the proposed method.

Fig. 3.

Fig. 3

Research design.

Firstly, this research provides a comprehensive examination of the literature on DNA cryptography as it applies to authentication. By exploring existing work on authentication protocols, MAC, and security vulnerabilities, this study identifies a critical gap in the field, where the current literature lacks fully developed DNA cryptography-based methods for message authentication.

Next, an omega DNA cryptography-based authentication method is proposed, comprising three algorithms for key generation, signing, and verification. The key generation algorithm, which uses an Omega network pseudorandom key generator, creates a 256 bits tag to ensure the confidentiality of the message.

Third, the proposed omega DNA cryptography-based authentication is implemented in C++ to support the tag generation and security evaluation phases. Four tags are generated: two use long messages that differ by only a single full stop, demonstrating one bit sensitivity, and two use short messages to confirm that the tag is fixed at 256 bits.

The security test includes the Dieharder statistical test, a formal security analysis, a brute force attack, and a collision attack. The Dieharder statistical test confirms the tag’s unpredictability and security against the birthday paradox. The formal security analysis uses mathematical models and logic to prove that the proposed omega DNA cryptography key-based authentication is resilient against existential forgery attacks. A brute force attack systematically checks every possible key combination until it finds the correct one. The proposal generates a 256 bits tag, and the brute force test demonstrates that the key space for this tag is large enough to resist an exhaustive search, confirming its strength against this type of attack. For the collision attack, this research uses the birthday paradox to calculate the complexity of finding two different messages that produce the same 256 bits authentication tag. This experiment demonstrates that such an attack is computationally infeasible, proving the authentication method’s security.

The proposed ODNAMAC scheme

The Omega DNA cryptography key-based authentication (ODNAMAC) is designed to provide message confidentiality and authenticate the message as shown in Algorithm 1 and Fig. 4. If the message fails authentication, the message may be being alter during transmission. For confidentiality, the message is encrypted using the ONDNA process. For authentication, the design consists of three algorithms: a key generation algorithm, a signing algorithm, and a verification algorithm. The key generator for authentication is ONDNA. The signing algorithm uses DNA XOR rules (denoted by the symbol ‘Inline graphic’, refer to Table 1), mRNA mapping rules (denoted by the symbol ‘Inline graphic’, refer to Table 2), and complementary mapping rules (denoted by the symbol ‘Inline graphic’, refer to Table 3). The use of these rules aims to make it computationally infeasible for an attacker to generate a valid tag for a message without knowing the secret key. It should be noted that the message is of arbitrary length, and therefore, the ciphertext is also of arbitrary same length as message. However, the signing algorithm generates a fixed-length tag of 256 bits. The verification algorithm is used to compare the generated tag with the received tag.

Fig. 4.

Fig. 4

ODNAMAC general flowchart.

Algorithm 2.

Algorithm 2

ODNAMAC

Definition 6

A ODNAMAC(Gen,Tag,Ver) is existential forgery under a chosen message attack secure, if no polynomial time adversary can produce a valid forgery message (Inline graphic, Inline graphic) for a new ciphertext Inline graphic, who can win the ODNAMAC oracle game with probability not larger than (Inline graphic).

Assume a 400 bits message needs to be authenticated as shown in Fig. 5. The encryption process is described in Sect. "Omega network pseudorandom key generation based on DNA cryptography", and the output of encryption is the ciphertext (400 bits). Here, we further discuss the authentication process, which includes authentication key generation, tag generation, and tag verification. The authentication key generation process uses ONDNA, which produces a single block of 256 bits pseudorandom key-based DNA. Next, the 400 bits ciphertext is split into two blocks. The first block is 256 bits, while the second block is 144 bits. To align with the block size, the second block is padded with 112 bits of 0.

Fig. 5.

Fig. 5

Flow of the ODNAMAC process for 400 bits ciphertext demonstration.

The first block of message is XORed with the 256 bits pseudorandom key-based DNA using DNA XOR rules (represented by Inline graphic), and the output is stored in register Inline graphic. Register Inline graphic is then processed using complementary mapping rules (represented by Inline graphic), and the output is stored in register Inline graphic. Register Inline graphic is initialized with 256 bits of 0. Register Inline graphic is XORed with the initialized register Inline graphic using DNA XOR rules, and the result is stored in register Inline graphic.

The process is repeated for the second block. The second block is XORed with the same 256 bits symmetric secret key using DNA XOR rules, and the output is stored in register Inline graphic. Register Inline graphic is processed using complementary mapping rules, and the output is stored in register Inline graphic. Next, register Inline graphic is XORed with register Inline graphic using DNA XOR rules. The final result is processed using mRNA rules (represented by Inline graphic) to generate the 256 bits authentication tag.

Note that both the ciphertext and the tag are sent to receiver. In the verification algorithm, the receiver uses the ciphertext to generate the tag Inline graphic together with the same pseudorandom key-based DNA. The receiver then compares the generated tag Inline graphic with the tag t received from the sender. If the two tags are identical, such that Inline graphic, the ciphertext has not been altered by unauthorized parties. If the tag does not match, decryption becomes unnecessary since message integrity cannot be guaranteed. This approach minimizes the computational steps involved in decryption, optimizes the authentication process, and enhances efficiency by conserving computational resources.

ODNAMAC analysis and discussion

The code simulation for this research is developed using the Inline graphic programming language, chosen for its efficiency, flexibility, and widespread use in research simulation. The design of the ODNAMAC is simulated on a personal laptop equipped with an Intel i5-12500H processor running at 3.10 GHz, 12GB of RAM, and a 1TB SSD. The simulation aims to validate the effectiveness and security of the proposed ODNAMAC by testing its performance under various conditions, including different input sizes and collision attack scenarios. The results obtained from this simulation will provide valuable insights into the practical feasibility.

Tag generation

Two example test cases of the ODNAMAC are provided, along with their corresponding outputs. The inputs include a long message with minor changes, such that the first message lacks a full stop, while the second message includes a full stop. These results demonstrate that the proposed ODNAMAC generates distinct tags even when only a single character is changed in the input message.

  • Message one: “Omega DNA Cryptograby key-based authentication”
    • Inline graphic: e3e300d3df5ee5e01b1bcc0b0f61161debebff4b434eb4e83f3f996f6b63f638861dccbdb0 c15c12be52eee2e3a5
    • Ciphertext: ac8e65b4be7ea1ae5a3b8f79761162728c999e293a6edf8d461ffb0e18069218e7 68b8d5d5af287bdd339a8b8ccb
    • Inline graphic: 518ee59edde4777e206002c050039990a5523a033a2644e3e001be7bbe1d663b
    • Tag: db8afefc413cffaf498020fcc2c8528a1798f9afb15b36f04fab7966cf97fb92
  • Message two: “Omega DNA Cryptograby key-based authentication.”
    • Inline graphic: 5557959d5959d5d52229c2c02d2c0252aaae8a0aada8aa3aeee38e7ee0e8eebeb667b6b0 6b6b0666a889a8ac8a8ac8
    • Ciphertext: 1a3af0fa3879919b630981b2545c763dcddceb68d488c15f97c3ec1f938d8 a9ed712c2d80e05720fcbe8dcc5e5e4e6
    • Inline graphic: 73ef3d3e3edfe366c61ae3e1e13a1ecd5434fcf3f3c43f0306b6929b9b26b97b
    • Tag: 2031a07d87f1b51a3f0d3bf8775de8a86bb694cdd0082b01ff9e31187e5bb98d

The second simulation is the ODNAMAC is able to produce a fixed-length tag (256 bits) even when the input message is shorter than 256 bits.

  • Message three: “Cryptography”
    • Inline graphic: 579985d7e9557e9d29cc6209
    • Ciphertext: 14ebfca79d3a19ef48bc0a70
    • Inline graphic: af3ff3f633ee6f364515515211ee25125c8bcbcc18d7c719028f2f22580c 2c5a
    • Tag: bb1cd9eeb2ac9b1784b6d8b044000d40dfbbfbff4b49f946f0bf0f00dbff 0fd3
  • Message four: “Authentication”
    • Inline graphic: 527d9d2da5d77a777ec999e9b75d
    • Ciphertext: 1308e945c0b90e1e1da8ed80d833
    • Inline graphic: 7f93f0dffb309e3eca86ab3aaf6b81615f9449cff749934309a66a299c6a ab6b
    • Tag: 6da41fa0cf7fa85854157f40441afd6d8eaccaeeeccaaeceea06605aae6 00f6f

Dieharder statistical test

The Dieharder statistical testing suite is a collection of statistical tests designed to evaluate the quality and randomness of random number generators7. It is widely used in cryptography and simulations where high-quality randomness is critical18. In this research, the Dieharder statistical testing suite is used to test the tags generated by ODNAMAC. This ensures that even for similar messages, such as those differing by a single character, the tags produced will be differ.

Figure 6 illustrates the process of the Dieharder statistical test. There are five steps: tags generation, tags concatenation, file selection, executing Dieharder, and obtaining the results. This process repeats twice for two experiments. In Experiment One, ten messages with each differing by one character is generated, ensuring slight variations in content. In Experiment Two, ten non-random messages are created, such as “000...000,” “111...111,” up to “999...999.”

Fig. 6.

Fig. 6

Dieharder statistical test process.

Next, each of the ten generated authentication tags is concetenated to form a binary file. Since each tag is 256 bits long, the total length of the concatenated tags is 2,560 bits. Then, one executes Dieharder version 3.31.1, selecting the binary file as input. To start the test, the command “dieharder -a -f filename.bin.” is entered. Once the test completes, the results display, including the p-value and an assessment that indicates the randomness of the input data. The assessment is either PASSED or WEAK. A PASSED result indicates that the data is sufficiently random, while a WEAK result suggests that the input data may contain patterns or biases that attackers could exploit.

Figure 7 displays the outcomes of the Dieharder statistical testing suite applied to 10 messages that differ by only one character, used as input to the proposed ODNAMAC scheme. The test produces a p-value of 0.23583, suggesting a relatively high probability that the generated outputs are uniformly random and free of detectable biases. This p-value indicates a low likelihood of collisions or predictable patterns in the outputs, thereby demonstrating the robustness and reliability of the ODNAMAC scheme in producing statistically sound and secure pseudorandom sequences.

Fig. 7.

Fig. 7

Dieharder test result for concatenated 10 random messages’ authentication tag.

Similarly, Fig. 8 presents the Dieharder statistical testing suite results for 10 non-random messages used as input. The test yields a p-value of 0.11187. A p-value below 1 suggests that the probability of collisions is minimal, which is a critical factor for ensuring the security and reliability of the ODNAMAC scheme.

Fig. 8.

Fig. 8

Dieharder test result for concatenated 10 non-random messages’ authentication tag.

These results demonstrate that the proposed authentication mechanism is highly effective in generating unique authentication tags for distinct inputs. Specifically, the findings show that it is computationally difficult to find two different inputs that produce the same authentication tag. This property is essential for preventing collision attacks, where an attacker attempts to forge a valid tag for a different message. By ensuring that even small changes in the input message result in significantly different tags, the ODNAMAC scheme provides strong guarantees of message integrity and authenticity.

Formal security analysis

This section presents the formal security proof of the ODNAMAC scheme, demonstrating that the scheme (Gen, Tag, Ver) is secure. The proof establishes that ODNAMAC satisfies the required security properties, ensuring its resilience against existential forgery attacks.

Theorem 1

Suppose that ONDNA is an ideal pseudorandom function satisfying Definition 2. If ODNAMAC is constructed using ONDNA, then the ODNAMAC scheme (Gen, Tag, Ver) is secure against existential forgery under a chosen message attack with respect to the private key k with Inline graphic entropy and over the message space Inline graphic.

Proof

To meet the requirements stated in Theorem 1, we must demonstrate

  1. the ONDNA is an Inline graphic)-pseudorandom function.

  2. the ODNAMAC (Gen, Tag, Ver) scheme is secure against existential forgery under a chosen message attack.

To prove (1), we assume that ONDNA is not a Inline graphic)-pseudorandom function. This would mean that there exists a polynomial time adversary Inline graphic capable of distinguishing a string of length n either it is a pseudorandom key-based DNA generated by ONDNA or a truly random string, all within polynomial time Inline graphic. The probability of making the correct guess is greater than of Inline graphic, where Inline graphic is not negligible. This contradicts the assumption that ONDNA is a secure pseudorandom function generator satisfying Definition 2. Hence (1) is true. This implies that the private key k that is used in ODHAMAC can be distinguished with probability not greater than of Inline graphic.

To prove (2) assuming the ODNAMAC(Gen, Tag, Ver) scheme is not secure against existential forgery under a chosen message attack. This means that there exists a polynomial time adversary Inline graphic capable of producing a valid forgery Inline graphic with non-negligible probability. On the basis of adversary Inline graphic we build the adversary Inline graphic to break the pseudorandom security of ODNAMAC. Adversary Inline graphic has access to an oracle Inline graphic, which is either ODNAMAC (k,.) or a truly random function f(.). Adversary Inline graphic simulates the ODNAMAC oracle for Inline graphic using Inline graphic. When adversary Inline graphic queries a message m, adversary Inline graphiccomputes Inline graphic as the tag. If Inline graphic = ODNAMAC(k,.), this perfectly simulates the ODNAMAC scheme. Eventually, adversary Inline graphic output a forgery Inline graphic, where Inline graphic is not being queried before. Adversary Inline graphic checks if Inline graphic= Inline graphic. If so, adversary Inline graphic outputs 1, guessing Inline graphic = ODNAMAC(k,.); otherwise, adversary Inline graphic outputs 0, guessing Inline graphic. Note that if Inline graphic = ODNAMAC(k,.), adversary Inline graphic succeeds in forging with non-negligible probability Inline graphic, so adversary Inline graphic outputs 1 with probability Inline graphic. If Inline graphic, adversary Inline graphic succeeds with probability at most Inline graphic. Thus, adversary Inline graphic distinguishes ODNAMAC(k,.) from f(.) with non-negligible advantage Inline graphic. This contradicts the assumption that ONDNA is a secure pseudorandom function. Hence, by Theorem 1 the ODNAMAC(Gen, Tag, Ver) scheme built from the ONDNA must be secure against existential forgery under a chosen message attack, satisfying Definition 3. Hence (2) is true.

Hence, by Theorem 1 the ODNAMAC that is built from the ONDNA is (Gen, Tag, Ver) is secure against existential forgery under a chosen message attack with respect to the private key k with Inline graphic entropy and over the message space Inline graphic. Inline graphic

Brute force attack

A brute force attack is a straightforward search method that seeks to identify the correct input by systematically trying every possible option within the input space. The input can be message or private key. This approach is typically used when the attacker cannot exploit specific vulnerabilities or weaknesses in the cryptographic scheme. The attacker must carefully test all potential input values until the correct one is found.

Since the proposed ODNAMAC is designed to satisfy Definitions 2 and 3, an adversary who has the tag generated by ODNAMAC could attempt a brute force attack on either the message or the private authentication key. Assume a message m has length of ml. If the length of the message m is shorter than the private authentication key Inline graphic, then discovering the correct message generally requires fewer attempts than uncovering the private authentication key Inline graphic. If the message length exceeds 256 bits, the security complexity of ODNAMAC is at most Inline graphic. Conversely, if the message length is less than 256 bits, the security complexity is Inline graphic.

Collision attack

Assume a message m has length of ml and a tag generation process tag maps m to an output a tag t of length 256 bits. Collision will occur when ml exceeds 256 bits. For the tag generation process tag on a random message m, a message collision occurs when Inline graphic. When the output length is 256 bits, the birthday paradox22 indicates that after calculating tag for approximately Inline graphic distinct messages, there is a 50% chance of a collision. Therefore, one may conclude that the security complexity of ODNAMAC against collision attacks is approximately Inline graphic.

Conclusion

DNA cryptography is widely recognized as a lightweight cryptographic method characterized by its low computational complexity, making it particularly suitable for resource constrained environments such as IoT devices, embedded systems, and mobile applications. This research introduces the Omega DNA cryptography key-based authentication scheme (ODNAMAC), a novel and innovative approach firmly grounded in the principles of DNA cryptography. This mechanism not only preserves the confidentiality of data but also introduces robust message authentication capabilities. The proposed mechanism employs the ONDNA approach to produce a fixed length authentication tag of 256 bits from arbitrary length of input. It passed the Dieharder statistical test. Overall, this paper establishes that the ODNAMAC is proven (Gen, Tag, Ver) secure against existential forgery under a chosen message attack with respect to the private key k with Inline graphic entropy and over the message space Inline graphic. The current work is only able to identify unauthorized modifications without privacy preservation. For future work, one may extend ODNAMAC to include privacy preserving authentication.

Author contributions

All authors contributed to the study conception and design. Jocelyn Tay performed material preparation, data collection, and analysis. The first draft of the manuscript was written by Chuah Chai Wen and Jocelyn Tay, and all authors commented on previous versions of the manuscript. All authors read and approved the final manuscript

Funding

This work was fully supported by Guangdong University of Science & Technology (Grant no. GKY2023BSQD-46).

Data availability

Data authentication generated during this study are included in this published article. Security analysis datasets used and/or analysed for current study available from the corresponding author on reasonable request.

Code availability

Share upon request.

Declarations

Competing interests

The authors declare no competing interests.

Footnotes

Publisher’s note

Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

References

  • 1.Al-Wattar, A. H., Mahmod, R., Zukarnain, Z. A. & Udzir, N. I. A new dna-based s-box. Int. J. Eng. Technol15(4), 1–9 (2015). [Google Scholar]
  • 2.Alomair, B. Authenticated encryption: how reordering can impact performance. Security and Communication Networks9(18), 6173–6188 (2016). [Google Scholar]
  • 3.Atassi, M. Z. Protein Reviews-Purinergic Receptors (Springer, 2019). [Google Scholar]
  • 4.Baritel-Ruet, C., Dupressoir, F., Fouque, P.-A. & Grégoire, B. Formal security proof of cmac and its variants. In 2018 IEEE 31st Computer Security Foundations Symposium (CSF), 91–104 (IEEE, 2018).
  • 5.Bellare, M. New proofs for nmac and hmac: Security without collision resistance. Journal of Cryptology28, 844–878 (2015). [Google Scholar]
  • 6.Bhoi, G., Bhavsar, R., Prajapati, P. & Shah, P. A review of recent trends on dna based cryptography. In 2020 3rd International Conference on Intelligent Sustainable Systems (ICISS), 815–822 (IEEE, 2020).
  • 7.Brown, R. G.: Dieharder: A Random Number Test Suite. Version 3.31.1. https://webhome.phy.duke.edu/rgb/General/dieharder.php. [Online; accessed 11-January-2025].
  • 8.Chu, L., Su, Y., Yao, X., Xu, P. & Liu, W. A review of dna cryptography. Intelligent Computing4, 0106 (2025). [Google Scholar]
  • 9.Cui, G., Qin, L., Wang, Y. & Zhang, X. An encryption scheme using dna technology. In 2008 3rd International Conference on Bio-Inspired Computing: Theories and Applications, 37–42 (IEEE, 2008).
  • 10.Deepa, N. R. & Sivamangai, N.M. A state-of-art model of encrypting medical image using dna cryptography and hybrid chaos map-2d zaslavaski map. In 2022 6th International Conference on Devices, Circuits and Systems (ICDCS), 190–195 (IEEE, 2022).
  • 11.Dhal, S. et al. Internet of things (iot) in digital agriculture: An overview. Agronomy Journal116(3), 1144–1163 (2024). [Google Scholar]
  • 12.Eichlseder, M. Authenticated encryption schemes. Symmetric Cryptography, Volume 1: Design and Security Proofs, 87, (2024).
  • 13.Gamiz, I., Regueiro, C., Lage, O., Jacob, E. & Astorga, J. Challenges and future research directions in secure multi-party computation for resource-constrained devices and large-scale computations. International Journal of Information Security24(1), 1–29 (2025). [Google Scholar]
  • 14.Hasan, M. K., Weichen, Z., Safie, N., Ahmed, F. R. A. & Ghazal, T. M. A survey on key agreement and authentication protocol for internet of things application. (IEEE access, 2024).
  • 15.Iliyasu, M. A., Abisoye, O. A., Bashir, S. A. & Ojeniyi, J. A. A review of dna cryptograhic approaches. In 2020 IEEE 2nd International Conference on Cyberspac (CYBER NIGERIA), 66–72. (IEEE, 2021).
  • 16.Jiang, C., Zhang, Y., Wang, F. & Liu, H. Toward smart information processing with synthetic dna molecules. Macromolecular Rapid Communications42(11), 2100084 (2021). [DOI] [PubMed] [Google Scholar]
  • 17.Jimale, M. A. et al. Authenticated encryption schemes: A systematic review. IEEE Access10, 14739–14766 (2022). [Google Scholar]
  • 18.Jóźwiak, P. P., Jóźwiak, I., Juszczyszyn, K. & Małachowski, T. Randomness testing of the random number generators using dieharder tool. Scientific Papers of Silesian University of Technology-Organization and Management Series, 167, 151 (2022).
  • 19.Katz, J., Lindell, Y.: Introduction to modern cryptography: principles and protocols. (Chapman and hall/CRC, 2014).
  • 20.Khademi, Z. & Nikoofar, K. Applications of catalytic systems containing dna nucleobases (adenine, cytosine, guanine, and thymine) in organic reactions. RSC advances15(5), 3192–3218 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
  • 21.Khalil, K., Idriss, H., Idriss, T. & Bayoumi, M. Security in resource-constrained iot devices. In Lightweight Hardware Security and Physically Unclonable Functions: Improving Security of Constrained IoT Devices, 41–48 (Springer, 2025).
  • 22.Knospe, H. A course in cryptography Vol. 40 (American Mathematical Soc., 2019). [Google Scholar]
  • 23.Krawczyk, H., Bellare, M. & Canetti, R. Rfc2104: Hmac: Keyed-hashing for message authentication, (1997).
  • 24.Kumar, S. et al. A review of lightweight security and privacy for resource-constrained iot devices. Computers, Materials and Continua78(1), 31–63 (2024). [Google Scholar]
  • 25.Namasudra, S. Fast and secure data accessing by using dna computing for the cloud environment. IEEE Transactions on Services Computing15(4), 2289–2300 (2020). [Google Scholar]
  • 26.Pavithran, P., Mathew, S., Namasudra, S. & Lorenz, P. A novel cryptosystem based on dna cryptography and randomly generated mealy machine. Computers & Security104, 102160 (2021). [Google Scholar]
  • 27.Pragathi, B. & Ramu, P. Authentication technique for safeguarding privacy in smart grid settings. In E3S Web of Conferences, 540, 10014 (EDP Sciences, 2024).
  • 28.Pray, L. Discovery of dna structure and function: Watson and crick. Nature Education1(1), 100 (2008). [Google Scholar]
  • 29.Rahman, G. & Wen, C. C. Omega network pseudorandom key generation based on dna cryptography. Applied Sciences12(16), 8141 (2022). [Google Scholar]
  • 30.Satyanarayana, C.H., Rao, K. N., Bush, R. G., Patnala, B. D. & Kumar, R. K. A novel level-based dna security algorithm using dna codons. Computational Intelligence and Big Data Analytics: Applications in Bioinformatics, 1–13 (2019).
  • 31.Shaw, H., Hussein, S. & Helgert, H. Prototype genomics-based keyed-hash message authentication code protocol. In 2010 2nd International Conference on Evolving Internet, 131–136 (IEEE, 2010).
  • 32.Sodhi, G. K. & Gaba, G. S. A competent mac scheme designed using a unique dna-brng key and a novel hash algorithm. Journal of Engineering Science and Technology13(2), 505–514 (2018). [Google Scholar]
  • 33.Sodhi, G. K., Gaba, G. S., Kansal, L., El Bakkali, M. & Tubbal, F. E. Implementation of message authentication code using dna-lcg key and a novel hash algorithm. International Journal of Electrical and Computer Engineering9(1), 352 (2019). [Google Scholar]
  • 34.Sukumaran, S. C. & Misbahuddin, M. Dna cryptography for secure data storage in cloud. Int. J. Netw. Secur.20(3), 447–454 (2018). [Google Scholar]
  • 35.Tornea, O., Borda, M.E., Pileczki, V. & Malutan, R. Dna vernam cipher. In 2011 E-Health and Bioengineering Conference (EHB), 1–4 (IEEE, 2011).
  • 36.Vikas, B., Akshay, A.K., Thanneeru, S. P. M., Raghuram, U.M.V. & Bhargav, K. S. A novel dna-and pi-based key generating encryption algorithm. In Information Systems Design and Intelligent Applications: Proceedings of Fourth International Conference INDIA 2017, 945–954 (Springer, 2018).
  • 37.Yalli, J. S., Hasan, M. H. & Badawi, A. Internet of things (iot): Origin, embedded technologies, smart applications and its growth in the last decade. (IEEE access, 2024).

Associated Data

This section collects any data citations, data availability statements, or supplementary materials included in this article.

Data Availability Statement

Data authentication generated during this study are included in this published article. Security analysis datasets used and/or analysed for current study available from the corresponding author on reasonable request.

Share upon request.


Articles from Scientific Reports are provided here courtesy of Nature Publishing Group

RESOURCES