RSA-OAEP Is Secure under the RSA Assumption

被引:0
|
作者
Eiichiro Fujisaki
Tatsuaki Okamoto
David Pointcheval
Jacques Stern
机构
[1] NTT Labs,
[2] 1-1 Hikarino-oka,undefined
[3] Yokosuka-shi 239-0847,undefined
[4] Département d’Informatique,undefined
[5] ENS – CNRS,undefined
[6] 45 rue d’Ulm,undefined
[7] 75230 Paris Cedex 05,undefined
来源
Journal of Cryptology | 2004年 / 17卷
关键词
Public-key encryption; Provable security; RSA; OAEP;
D O I
暂无
中图分类号
学科分类号
摘要
Recently Victor Shoup noted that there is a gap in the widely believed security result of OAEP against adaptive chosen-ciphertext attacks. Moreover, he showed that, presumably, OAEP cannot be proven secure from the one-wayness of the underlying trapdoor permutation. This paper establishes another result on the security of OAEP. It proves that OAEP offers semantic security against adaptive chosen-ciphertext attacks, in the random oracle model, under the partial-domain one-wayness of the underlying permutation. Therefore, this uses a formally stronger assumption. Nevertheless, since partial-domain one-wayness of the RSA function is equivalent to its (full-domain) onewayness, it follows that the security of RSA-OAEP can actually be proven under the sole RSA assumption, although the reduction is not tight.
引用
收藏
页码:81 / 104
页数:23
相关论文
共 50 条
  • [1] RSA-OAEP is secure under the RSA assumption
    Fujisaki, E
    Okamoto, T
    Pointcheval, D
    Stern, J
    JOURNAL OF CRYPTOLOGY, 2004, 17 (02) : 81 - 104
  • [2] RSA-OAEP is RKA Secure
    Jia, Dingding
    Li, Bao
    Lu, Xianhui
    Liu, Yamin
    INFORMATION SECURITY AND CRYPTOLOGY, INSCRYPT 2013, 2014, 8567 : 270 - 281
  • [3] Strengthening Security of RSA-OAEP
    Boldyreva, Alexandra
    TOPICS IN CRYPTOLOGY - CT-RSA 2009, PROCEEDINGS, 2009, 5473 : 399 - 413
  • [4] How to Strengthen the Security of RSA-OAEP
    Boldyreva, Alexandra
    Imai, Hideki
    Kobara, Kazukuni
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2010, 56 (11) : 5876 - 5886
  • [5] Instantiability of RSA-OAEP under Chosen-Plaintext Attack
    Kiltz, Eike
    O'Neill, Adam
    Smith, Adam
    ADVANCES IN CRYPTOLOGY - CRYPTO 2010, 2010, 6223 : 295 - +
  • [6] Instantiability of RSA-OAEP Under Chosen-Plaintext Attack
    Eike Kiltz
    Adam O’Neill
    Adam Smith
    Journal of Cryptology, 2017, 30 : 889 - 919
  • [7] Instantiability of RSA-OAEP Under Chosen-Plaintext Attack
    Kiltz, Eike
    O'Neill, Adam
    Smith, Adam
    JOURNAL OF CRYPTOLOGY, 2017, 30 (03) : 889 - 919
  • [8] A novel key exchange protocol based on RSA-OAEP
    Liu, Jie
    Li, Jianhua
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 1641 - 1643
  • [9] A Rational Secret-Sharing Scheme Based on RSA-OAEP
    Isshiki, Toshiyuki
    Wada, Koichiro
    Tanaka, Keisuke
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2010, E93A (01) : 42 - 49
  • [10] On the Robustness of RSA-OAEP Encryption and RSA-PSS Signatures Against (Malicious) Randomness Failures
    Schuldt, Jacob C. N.
    Shinagawa, Kazumasa
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 241 - 252