Введение
Схема, часто используемая с шифрованием RSA
In cryptography, Optimal Asymmetric Encryption Padding (OAEP) is a padding scheme often used together with RSA encryption. OAEP was introduced by Bellare and Rogaway, and subsequently standardized in PKCS#1 v2 and RFC 2437. The OAEP algorithm is a form of Feistel network which uses a pair of random oracles G and H to process the plaintext prior to asymmetric encryption. When combined with any secure trapdoor one way permutation , this processing is proved in the random oracle model to result in a combined scheme which is semantically secure under chosen plaintext attack (IND CPA). When implemented with certain trapdoor permutations (e. g., RSA), OAEP is also proven to be secure against chosen ciphertext attack. OAEP can be used to build an all or nothing transform. OAEP satisfies the following two goals:
Add an element of randomness which can be used to convert a deterministic encryption scheme (e. g., traditional RSA) into a probabilistic scheme. Prevent partial decryption of ciphertexts (or other information leakage) by ensuring that an adversary cannot recover any portion of the plaintext without being able to invert the trapdoor one way permutation
The original version of OAEP (Bellare/Rogaway, 1994) showed a form of "plaintext awareness" (which they claimed implies security against chosen ciphertext attack) in the random oracle model when OAEP is used with any trapdoor permutation. Subsequent results contradicted this claim, showing that OAEP was only IND CCA1 secure. However, the original scheme was proved in the random oracle model to be IND CCA2 secure when OAEP is used with the RSA permutation using standard encryption exponents, as in the case of RSA OAEP. An improved scheme (called OAEP+) that works with any trapdoor one way permutation was offered by Victor Shoup to solve this problem. More recent work has shown that in the standard model (that is, when hash functions are not modeled as random oracles) it is impossible to prove the IND CCA2 security of RSA OAEP under the assumed hardness of the RSA problem.
В криптографии оптимальное асимметричное заполнение (OAEP) — это схема заполнения, часто используемая совместно с шифрованием RSA. OAEP была предложена Белларе и Рогавеем и впоследствии стандартизирована в PKCS#1 v2 и RFC 2437. Алгоритм OAEP представляет собой форму сети Фейстеля, использующую пару случайных оракулов G и H для обработки открытого текста перед асимметричным шифрованием. В сочетании с любой безопасной односторонней функцией с секретным ключом эта обработка, доказано в модели случайного оракула, приводит к комбинированной схеме, семантически устойчивой к атаке с выбранным открытым текстом (IND CPA). При реализации с определенными односторонними функциями с секретным ключом (например, RSA), OAEP также доказано устойчива к атаке с выбранным шифротекстом. OAEP может быть использована для построения преобразования «все или ничего». OAEP удовлетворяет следующим двум целям:
In cryptography, Optimal Asymmetric Encryption Padding (OAEP) is a padding scheme often used together with RSA encryption. OAEP was introduced by Bellare and Rogaway, and subsequently standardized in PKCS#1 v2 and RFC 2437. The OAEP algorithm is a form of Feistel network which uses a pair of random oracles G and H to process the plaintext prior to asymmetric encryption. When combined with any secure trapdoor one way permutation , this processing is proved in the random oracle model to result in a combined scheme which is semantically secure under chosen plaintext attack (IND CPA). When implemented with certain trapdoor permutations (e. g., RSA), OAEP is also proven to be secure against chosen ciphertext attack. OAEP can be used to build an all or nothing transform. OAEP satisfies the following two goals:
Add an element of randomness which can be used to convert a deterministic encryption scheme (e. g., traditional RSA) into a probabilistic scheme. Prevent partial decryption of ciphertexts (or other information leakage) by ensuring that an adversary cannot recover any portion of the plaintext without being able to invert the trapdoor one way permutation
The original version of OAEP (Bellare/Rogaway, 1994) showed a form of "plaintext awareness" (which they claimed implies security against chosen ciphertext attack) in the random oracle model when OAEP is used with any trapdoor permutation. Subsequent results contradicted this claim, showing that OAEP was only IND CCA1 secure. However, the original scheme was proved in the random oracle model to be IND CCA2 secure when OAEP is used with the RSA permutation using standard encryption exponents, as in the case of RSA OAEP. An improved scheme (called OAEP+) that works with any trapdoor one way permutation was offered by Victor Shoup to solve this problem. More recent work has shown that in the standard model (that is, when hash functions are not modeled as random oracles) it is impossible to prove the IND CCA2 security of RSA OAEP under the assumed hardness of the RSA problem.
Добавить элемент случайности, который можно использовать для преобразования детерминированной схемы шифрования (например, традиционной RSA) в вероятностную схему. Предотвратить частичное расшифрование шифротекстов (или утечку другой информации), гарантируя, что противник не сможет восстановить какую-либо часть открытого текста, не сумев обратить одностороннюю функцию с секретным ключом.
In cryptography, Optimal Asymmetric Encryption Padding (OAEP) is a padding scheme often used together with RSA encryption. OAEP was introduced by Bellare and Rogaway, and subsequently standardized in PKCS#1 v2 and RFC 2437. The OAEP algorithm is a form of Feistel network which uses a pair of random oracles G and H to process the plaintext prior to asymmetric encryption. When combined with any secure trapdoor one way permutation , this processing is proved in the random oracle model to result in a combined scheme which is semantically secure under chosen plaintext attack (IND CPA). When implemented with certain trapdoor permutations (e. g., RSA), OAEP is also proven to be secure against chosen ciphertext attack. OAEP can be used to build an all or nothing transform. OAEP satisfies the following two goals:
Add an element of randomness which can be used to convert a deterministic encryption scheme (e. g., traditional RSA) into a probabilistic scheme. Prevent partial decryption of ciphertexts (or other information leakage) by ensuring that an adversary cannot recover any portion of the plaintext without being able to invert the trapdoor one way permutation
The original version of OAEP (Bellare/Rogaway, 1994) showed a form of "plaintext awareness" (which they claimed implies security against chosen ciphertext attack) in the random oracle model when OAEP is used with any trapdoor permutation. Subsequent results contradicted this claim, showing that OAEP was only IND CCA1 secure. However, the original scheme was proved in the random oracle model to be IND CCA2 secure when OAEP is used with the RSA permutation using standard encryption exponents, as in the case of RSA OAEP. An improved scheme (called OAEP+) that works with any trapdoor one way permutation was offered by Victor Shoup to solve this problem. More recent work has shown that in the standard model (that is, when hash functions are not modeled as random oracles) it is impossible to prove the IND CCA2 security of RSA OAEP under the assumed hardness of the RSA problem.
Оригинальная версия OAEP (Белларе/Рогавей, 1994) продемонстрировала форму «осведомленности об открытом тексте» (которая, по их утверждению, подразумевает устойчивость к атаке с выбранным шифротекстом) в модели случайного оракула при использовании OAEP с любой односторонней функцией с секретным ключом. Последующие результаты опровергли это утверждение, показав, что OAEP обеспечивает только устойчивость IND CCA1. Однако оригинальная схема была доказана в модели случайного оракула как устойчивая IND CCA2 при использовании OAEP с пермутацией RSA и стандартными степенями шифрования, как в случае RSA OAEP. Для решения этой проблемы Виктор Шоуп предложил улучшенную схему (называемую OAEP+), которая работает с любой односторонней функцией с секретным ключом. Более поздние исследования показали, что в стандартной модели (то есть, когда хеш-функции не моделируются как случайные оракулы) невозможно доказать устойчивость RSA OAEP IND CCA2, исходя из предполагаемой сложности задачи RSA.
In cryptography, Optimal Asymmetric Encryption Padding (OAEP) is a padding scheme often used together with RSA encryption. OAEP was introduced by Bellare and Rogaway, and subsequently standardized in PKCS#1 v2 and RFC 2437. The OAEP algorithm is a form of Feistel network which uses a pair of random oracles G and H to process the plaintext prior to asymmetric encryption. When combined with any secure trapdoor one way permutation , this processing is proved in the random oracle model to result in a combined scheme which is semantically secure under chosen plaintext attack (IND CPA). When implemented with certain trapdoor permutations (e. g., RSA), OAEP is also proven to be secure against chosen ciphertext attack. OAEP can be used to build an all or nothing transform. OAEP satisfies the following two goals:
Add an element of randomness which can be used to convert a deterministic encryption scheme (e. g., traditional RSA) into a probabilistic scheme. Prevent partial decryption of ciphertexts (or other information leakage) by ensuring that an adversary cannot recover any portion of the plaintext without being able to invert the trapdoor one way permutation
The original version of OAEP (Bellare/Rogaway, 1994) showed a form of "plaintext awareness" (which they claimed implies security against chosen ciphertext attack) in the random oracle model when OAEP is used with any trapdoor permutation. Subsequent results contradicted this claim, showing that OAEP was only IND CCA1 secure. However, the original scheme was proved in the random oracle model to be IND CCA2 secure when OAEP is used with the RSA permutation using standard encryption exponents, as in the case of RSA OAEP. An improved scheme (called OAEP+) that works with any trapdoor one way permutation was offered by Victor Shoup to solve this problem. More recent work has shown that in the standard model (that is, when hash functions are not modeled as random oracles) it is impossible to prove the IND CCA2 security of RSA OAEP under the assumed hardness of the RSA problem.
Реализация
В стандарте PKCS#1 случайные оракулы тождественны. Стандарт PKCS#1 дополнительно требует, чтобы случайные оракулы представляли собой MGF1 с подходящей хеш-функцией.