Paper 2003/029
Universal Padding Schemes for RSA with Optimal Bandwidth of Message Recovery
Wenbo Mao and John Malone-Lee
Abstract
We prove that three OAEP-inspired randomised padding schemes (i.e., OAEP, OAEP+ and SAEP), when used with the RSA function in the trapdoor direction, form provably secure signature schemes with message recovery. Two of our three reductionist proofs are tight and hence provide exact security. Because of the exact security and OAEP's optimally high bandwidth for message recovery, our results form a desirable improvement from a previous universal RSA padding scheme good for both encryption and signature.
Metadata
- Available format(s)
- -- withdrawn --
- Publication info
- Published elsewhere. Unknown where it was published
- Contact author(s)
- wenbo mao @ hp com
- History
- 2003-03-12: withdrawn
- 2003-02-11: received
- See all versions
- Short URL
- https://ia.cr/2003/029
- License
-
CC BY