对著名的明文填充方案三轮OAEP进行了分析,指出当解密机可以输出填充方案中的随机串时,三轮OAEP在适应性选择密文攻击下是不安全的,并给出了相应的攻击实例.对三轮OAEP进行了改进,使其具备明文可意识性,并在随机预言机模型下证明了即使解密机可以输出填充方案中的随机串,改进方案在适应性选择密文攻击下仍然是语义安全的.
OAEP 3-Round is a famous padding scheme. But if the attacker could obtain the random string of the OAEP 3-Round, it would not be indistinguishable against adaptive chosen ciphertext attacks any more. Examples are given to support the argument. The authors improve the OAEP 3-Round padding scheme to be plaintext awareness and prove that the revised version is semantic security against adaptive chosen ciphertext attacks in the random oracle model even in the case that attacker could get the random string of the padding scheme.