RSA-OAEP Is Secure under the RSA Assumption

RSA-OAEP Is Secure under the RSA Assumption
复制标题

DOI:
10.1007/s00145-002-0204-y
复制
发表时间:
2001-08
影响因子:
3
通讯作者:
E. Fujisaki;T. Okamoto;D. Pointcheval;J. Stern
E. Fujisaki;T. Okamoto;D. Pointcheval;J. Stern
中科院分区:
计算机科学4区
文献类型:
--
作者:
E. Fujisaki;T. Okamoto;D. Pointcheval;J. Stern

文献摘要

被引文献

相似文献

最近维克托Shoup指出,有一个差距,在广泛认为的安全结果OAEP对自适应选择密文攻击。此外,他还指出,据推测,OAEP无法从底层陷阱排列的单向性中证明是安全的。本文建立了OAEP安全性的另一个结果。证明了在随机预言机模型下,在部分域单向置换的情况下,OAEP提供了抵抗自适应选择密文攻击的语义安全性。因此,这使用了形式上更强的假设。然而,由于RSA函数的部分域单向性等同于其(全域)单向性,因此可以得出结论,RSA-OAEP的安全性实际上可以在唯一的RSA假设下得到证明,尽管简化并不严格。
Recently Victor Shoup noted that there is a gap in the widely believed security result of OAEP against adaptive chosen-ciphertext attacks. Moreover, he showed that, presumably, OAEP cannot be proven secure from the one-wayness of the underlying trapdoor permutation. This paper establishes another result on the security of OAEP. It proves that OAEP offers semantic security against adaptive chosen-ciphertext attacks, in the random oracle model, under the partial-domain one-wayness of the underlying permutation. Therefore, this uses a formally stronger assumption. Nevertheless, since partial-domain one-wayness of the RSA function is equivalent to its (full-domain) onewayness, it follows that the security of RSA-OAEP can actually be proven under the sole RSA assumption, although the reduction is not tight.