Toward RSA-OAEP Without Random Oracles

被引:5
|
作者
Cao, Nairen [1 ]
O'Neill, Adam [2 ]
Zaheri, Mohammad [1 ]
机构
[1] Georgetown Univ, Dept Comp Sci, Washington, DC 20057 USA
[2] Univ Massachusetts Amherst, Coll Informat & Comp Sci, Amherst, MA USA
来源
PUBLIC-KEY CRYPTOGRAPHY - PKC 2020, PT I | 2020年 / 12110卷
关键词
PUBLIC-KEY ENCRYPTION; DIGITAL-SIGNATURES; ZERO-KNOWLEDGE; SECURITY; HASH;
D O I
10.1007/978-3-030-45374-9_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We show new partial and full instantiation results under chosen-ciphertext security for the widely implemented and standardized RSA-OAEP encryption scheme of Bellare and Rogaway (EUROCRYPT 1994) and two variants. Prior work on such instantiations either showed negative results or settled for "passive" security notions like IND-CPA. More precisely, recall that RSA-OAEP adds redundancy and randomness to a message before composing two rounds of an underlying Feistel transform, whose round functions are modeled as random oracles (ROs), with RSA. Our main results are: - Either of the two oracles (while still modeling the other as a RO) can be instantiated in RSA-OAEP under IND-CCA2 using mild standard-model assumptions on the round functions and generalizations of algebraic properties of RSA shown by Barthe, Pointcheval, and B ' aguelin (CCS 2012). The algebraic properties are only shown to hold at practical parameters for small encryption exponent (e = 3), but we argue they have value for larger e as well. - Both oracles can be instantiated simultaneously for two variants of RSA-OAEP, called "t-clear" and "s-clear" RSA-OAEP. For this we use extractability-style assumptions in the sense of Canetti and Dakdouk (TCC 2010) on the round functions, as well as novel yet plausible "XOR-type" assumptions on RSA. While admittedly strong, such assumptions may nevertheless be necessary at this point to make positive progress. In particular, our full instantiations evade impossibility results of Shoup (J. Cryptology 2002), Kiltz and Pietrzak (EUROCRYPT 2009), and Bitansky et al. (STOC 2014). Moreover, our results for s-clear RSA-OAEP yield the most efficient RSA-based encryption scheme proven IND-CCA2 in the standard model (using bold assumptions on cryptographic hashing) to date.
引用
收藏
页码:279 / 308
页数:30
相关论文
共 50 条
  • [1] RSA-OAEP Is Secure under the RSA Assumption
    Eiichiro Fujisaki
    Tatsuaki Okamoto
    David Pointcheval
    Jacques Stern
    Journal of Cryptology, 2004, 17 : 81 - 104
  • [2] RSA-OAEP is secure under the RSA assumption
    Fujisaki, E
    Okamoto, T
    Pointcheval, D
    Stern, J
    JOURNAL OF CRYPTOLOGY, 2004, 17 (02) : 81 - 104
  • [3] Instantiability of RSA-OAEP under Chosen-Plaintext Attack
    Kiltz, Eike
    O'Neill, Adam
    Smith, Adam
    ADVANCES IN CRYPTOLOGY - CRYPTO 2010, 2010, 6223 : 295 - +
  • [4] Analysis of Rabin-P and RSA-OAEP Encryption Scheme on Microprocessor Platform
    Mazlisham, Muhammad Hafiz
    Adnan, Syed Farid Syed
    Isa, Mohd Anuar Mat
    Mahad, Zahari
    Asbullah, Muhammad Asyraf
    IEEE 10TH SYMPOSIUM ON COMPUTER APPLICATIONS AND INDUSTRIAL ELECTRONICS (ISCAIE 2020), 2020, : 292 - 296
  • [5] Efficient digital signatures from RSA without random oracles
    Seo, Jae Hong
    INFORMATION SCIENCES, 2020, 512 (512) : 471 - 480
  • [6] New Constructions of Equality Test Scheme Without Random Oracles
    Zhu, Huijun
    Ahmad, Haseeb
    Xue, Qingji
    Li, Tianfeng
    Liu, Ziyu
    Liu, Ao
    IEEE ACCESS, 2023, 11 (49519-49529) : 49519 - 49529
  • [7] Hidden Credential Retrieval without Random Oracles
    Miyaji, Atsuko
    Rahman, Mohammad Shahriar
    Soshi, Masakazu
    INFORMATION SECURITY APPLICATIONS, 2011, 6513 : 160 - +
  • [8] Certificateless Signature Scheme without Random Oracles
    Yuan, Yumin
    Li, Da
    Tian, Liwen
    Zhu, Haishan
    ADVANCES IN INFORMATION SECURITY AND ASSURANCE, 2009, 5576 : 31 - 40
  • [9] Certificateless Signcryption Scheme Without Random Oracles
    Zhou Caixue
    CHINESE JOURNAL OF ELECTRONICS, 2018, 27 (05) : 1002 - 1008
  • [10] An Efficient Certificate-Based Encryption Scheme Without Random Oracles
    Guo, Lan
    Lu, Yang
    Miao, Qing
    Zu, Guangao
    Wang, Zhongqi
    ARTIFICIAL INTELLIGENCE AND SECURITY, ICAIS 2022, PT III, 2022, 13340 : 97 - 107