On the security of OAEP

30Citations
Citations of this article
35Readers
Mendeley users who have this article in their library.

Abstract

Currently, the best and only evidence of the security of the OAEP encryption scheme is a proof in the contentious random oracle model. Here we give further arguments in support of the security of OAEP. We first show that partial instantiations, where one of the two random oracles used in OAEP is instantiated by a function family, can be provably secure (still in the random oracle model). For various security statements about OAEP we specify sufficient conditions for the instantiating function families that, in some cases, are realizable through standard cryptographic primitives and, in other cases, may currently not be known to be achievable but appear moderate and plausible. Furthermore, we give the first non-trivial security result about fully instantiated OAEP in the standard model, where both oracles are instantiated simultaneously. Namely, we show that instantiating both random oracles in OAEP by modest functions implies non-malleability under chosen plaintext attacks for random messages. We also discuss the implications, especially of the full instantiation result, to the usage of OAEP for secure hybird encryption (as required in SSL/TLS, for example). © 2006 Springer-Verlag.

References Powered by Scopus

HOW TO GENERATE CRYPTOGRAPHICALLY STRONG SEQUENCES OF PSEUDO-RANDOM BITS.

850Citations
N/AReaders
Get full text

Relations among notions of security for public-key encryption schemes

712Citations
N/AReaders
Get full text

Nonmalleable cryptography

607Citations
N/AReaders
Get full text

Cited by Powered by Scopus

Adaptive one-way functions and applications

74Citations
N/AReaders
Get full text

Instantiability of RSA-OAEP under chosen-plaintext attack

72Citations
N/AReaders
Get full text

Instantiating random oracles via UCEs

64Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Boldyreva, A., & Fischlin, M. (2006). On the security of OAEP. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4284 LNCS, pp. 210–225). https://doi.org/10.1007/11935230_14

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 20

65%

Professor / Associate Prof. 6

19%

Lecturer / Post doc 3

10%

Researcher 2

6%

Readers' Discipline

Tooltip

Computer Science 26

87%

Physics and Astronomy 2

7%

Design 1

3%

Engineering 1

3%

Save time finding and organizing research with Mendeley

Sign up for free