RSA ⇒ IND-CCA PKE (RSA-OAEP)

Random oracle model · FOPS01

Statement

In the random oracle model, OAEP over a trapdoor permutation is IND-CCA-secure if is partial-domain one-way; by RSA’s self-reducibility, partial-domain one-wayness of the RSA function is equivalent to its one-wayness, so RSAES-OAEP is IND-CCA-secure under the RSA assumption — FOPS01.

Notes

  • The reduction from RSA is not tight — FOPS01.
  • OAEP, the padding behind RSAES-OAEP, is due to Bellare and Rogaway — BR94.
  • The BR94 argument for OAEP has a gap and does not establish IND-CCA security from one-wayness of the trapdoor permutation alone — Sho01a.