Sciweavers

CRYPTO
2010
Springer

Instantiability of RSA-OAEP under Chosen-Plaintext Attack

13 years 9 months ago
Instantiability of RSA-OAEP under Chosen-Plaintext Attack
We show that the widely deployed RSA-OAEP encryption scheme of Bellare and Rogaway (Eurocrypt 1994), which combines RSA with two rounds of an underlying Feistel network whose hash (i.e., round) functions are modeled as random oracles, meets indistinguishability under chosen-plaintext attack (IND-CPA) in the standard model based on simple, non-interactive, and noninterdependent assumptions on RSA and the hash functions. To prove this, we first give a result on a more general notion called "padding-based" encryption, saying that such a scheme is IND-CPA if (1) its underlying padding transform satisfies a "fooling" condition against small-range distinguishers on a class of high-entropy input distributions, and (2) its trapdoor permutation is sufficiently lossy as defined by Peikert and Waters (STOC 2008). We then show that the first round of OAEP satifies condition (1) if its hash function is t-wise independent for appopriate t and that RSA satisfies condition (2) und...
Eike Kiltz, Adam O'Neill, Adam Smith
Added 01 Mar 2011
Updated 01 Mar 2011
Type Journal
Year 2010
Where CRYPTO
Authors Eike Kiltz, Adam O'Neill, Adam Smith
Comments (0)