OAEP Reconsidered

OAEP Reconsidered
复制标题

DOI:
10.1007/s00145-002-0133-9
复制
发表时间:
2002-09
影响因子:
3
通讯作者:
V. Shoup
V. Shoup
中科院分区:
计算机科学4区
文献类型:
--
作者:
V. Shoup

文献摘要

被引文献

相似文献

OAEP加密方案是由Bellare和Rogaway在94年欧洲密码会议上提出的。它将任何陷门置换方案转换为公钥加密方案。人们普遍认为,OAEP能够抵抗自适应选择密文攻击。假设潜在的陷门置换方案是单向的,则这一信念的主要理由是假设随机预言模型中的安全性的一个假设证明。首先,它观察到,在OAEP的安全证明中似乎存在一个不小的漏洞。其次,它证明了这一空白是无法填补的,因为不可能有标准的OAEP“黑箱”安全削减。给出了一个新的方案OAEP+,并在随机预言机模型下给出了一个完全的安全性证明。应该强调的是,这些结果并不意味着OAEP的特定实例化(如RSA-OAEP)是不安全的。它们只会破坏其安全的最初理由。事实上,事实证明RSA-OAEP在随机预言模型中是安全的--本质上是偶然的,而不是故意的;然而,这一事实依赖于RSA函数的特殊代数性质,而不是一般OAEP方案的安全性。
The OAEP encryption scheme was introduced by Bellare and Rogaway at Eurocrypt '94. It converts any trapdoor permutation scheme into a public key encryption scheme. OAEP is widely believed to provide resistance against adaptive chosen ciphertext attack. The main justification for this belief is a supposed proof of security in the random oracle model, assuming the underlying trapdoor permutation scheme is one way.This paper shows conclusively that this justification is invalid. First, it observes that there appears to be a non-trivial gap in the OAEP security proof. Second, it proves that this gap cannot be filled, in the sense that there can be no standard ``black box'' security reduction for OAEP. This is done by proving that there exists an oracle relative to which the general OAEP scheme is insecure.The paper also presents a new scheme OAEP+, along with a complete proof of security in the random oracle model. OAEP+is essentially just as efficient as OAEP.It should be stressed that these results do not imply that a particular instantiation of OAEP, such as RSA-OAEP, is insecure. They simply undermine the original justification for its security. In fact, it turns out—essentially by accident, rather than by design—that RSA-OAEP is secure in the random oracle model; however, this fact relies on special algebraic properties of the RSA function, and not on the security of the general OAEP scheme.