Abstract
Recently Victor Shoup noted that there is a gap in the widely believed security result of OAEP against adaptive chosen-ciphertext attacks. Moreover, he showed that, presumably, OAEP cannot be proven secure from the one-wayness of the underlying trapdoor permutation. This paper establishes another result on the security of OAEP. It proves that OAEP offers semantic security against adaptive chosen-ciphertext attacks, in the random oracle model, under the partial-domain one-wayness of the underlying permutation. Therefore, this uses a formally stronger assumption. Nevertheless, since partial-domain one-wayness of the RSA function is equivalent to its (full-domain) one-wayness, it follows that the security of RSA-OAEP can actually be proven under the sole RSA assumption, although the reduction is not tight.
Author supplied keywords
Cite
CITATION STYLE
Fujisaki, E., Okamoto, T., Pointcheval, D., & Stern, J. (2004). RSA-OAEP is secure under the RSA assumption. Journal of Cryptology, 17(2), 81–104. https://doi.org/10.1007/s00145-002-0204-y
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.