Paper 2003/029

Universal Padding Schemes for RSA with Optimal Bandwidth of Message Recovery

Wenbo Mao and John Malone-Lee

Abstract

We prove that three OAEP-inspired randomised padding schemes (i.e., OAEP, OAEP+ and SAEP), when used with the RSA function in the trapdoor direction, form provably secure signature schemes with message recovery. Two of our three reductionist proofs are tight and hence provide exact security. Because of the exact security and OAEP's optimally high bandwidth for message recovery, our results form a desirable improvement from a previous universal RSA padding scheme good for both encryption and signature.

Metadata
Available format(s)
-- withdrawn --
Publication info
Published elsewhere. Unknown where it was published
Contact author(s)
wenbo mao @ hp com
History
2003-03-12: withdrawn
2003-02-11: received
See all versions
Short URL
https://ia.cr/2003/029
License
Creative Commons Attribution
CC BY
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.