Universal Padding Schemes for RSA with Optimal Bandwidth of Message Recovery

Wenbo Mao and John Malone-Lee

Abstract: We prove that three OAEP-inspired randomised padding schemes (i.e., OAEP, OAEP+ and SAEP), when used with the RSA function in the trapdoor direction, form provably secure signature schemes with message recovery. Two of our three reductionist proofs are tight and hence provide exact security. Because of the exact security and OAEP's optimally high bandwidth for message recovery, our results form a desirable improvement from a previous universal RSA padding scheme good for both encryption and signature.

Date: received 11 Feb 2003, withdrawn 12 Mar 2003

Contact author: wenbo mao at hp com

Version: 20030312:131553 (All versions of this report)

