RSA ⇒ IND-CCA PKE (RSA-OAEP)
Statement
In the random oracle model, OAEP over a trapdoor permutation is IND-CCA-secure if is partial-domain one-way; by RSA’s self-reducibility, partial-domain one-wayness of the RSA function is equivalent to its one-wayness, so RSAES-OAEP is IND-CCA-secure under the RSA assumption — FOPS01.