Skip to content

Threat Model & Security Boundaries

This document outlines the security properties, threat model, and operational limitations of the PlyQR dual-channel steganographic system.


  • The private payload is encrypted with ChaCha20, an authenticated stream cipher operating with a 256-bit key.
  • Without the secret key, recovering the private payload is computationally infeasible ($2^{256}$ security level).
  • Sealed using Poly1305 message authentication code (128-bit MAC).
  • Protects against bit-flipping, codeword injection, and optical manipulation. Any modification to private codewords causes immediate decryption failure.
  • Associated Data Binding: The Poly1305 tag incorporates the 22-byte header and the raw public payload bytes as Additional Authenticated Data (AAD).
  • Cross-Channel Tamper Invalidation: If an attacker modifies the public text (e.g., swapping a genuine brand URL for a malicious link), the AAD calculation fails, and the private data is discarded as invalid.

PlyQR is designed as a functional dual-channel system, not an undetectable military subliminal channel:

  1. Terminator Inspection: Standard QR decoders ignore bytes after the terminator. However, a specialized forensic parser inspecting raw bitstreams can observe that padding bytes do not follow the standard alternating 0xEC/0x11 pattern.
  2. Entropy Analysis: Encrypted payload bytes exhibit high pseudo-random entropy compared to constant padding codewords.
  3. Explicit Design Goal: PlyQR prioritizes universal compatibility with consumer phone cameras and cryptographic verification, rather than evading specialized lab forensic bitstream analysis.

  • Reed-Solomon Parity Budget: The system relies on the inequality hidden_per_block + noise_reserve <= floor(r / 2). Setting noise_reserve too low increases susceptibility to physical dirt, scratches, and poor camera focus.
  • Minimum Resolution: For mobile camera scanning, printed symbols should have module sizes of at least 0.5 mm to ensure accurate pixel binarization.