Re: What's this called?

From: Henrick Hellström (henrick.hellstrm_at_telia.com)
Date: 05/16/04


Date: Sat, 15 May 2004 23:16:56 GMT

Tom St Denis wrote:

> Just thought of something odd. What's to stop someone from applying
> OAEP padding? OAEP padding is specific enough as to make random
> decryption of the wrong root infeasible.

Ahh! I see what you mean (I think).

- If you use the original Rabin Scheme for public key encryption (as
opposed to signing) the recipient will have to choose between four
roots, and making that choice would be impossible if OAEP padding had
been applied.
- If you use RW for public key encryption the sender would have to force
the cipher text to be congruent to 12 modulo 16.



Relevant Pages

  • Re: Whats this called?
    ... > Tom St Denis wrote: ... OAEP padding is specific enough as to make random ... >> decryption of the wrong root infeasible. ... decrypt to a valid OAEP packet. ...
    (sci.crypt)
  • RSACryptoServiceProvider
    ... am getting "Direct Encryption and decryption using RSA ... OAEP padding are not available on this platform" message. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Whats this called?
    ... Tom St Denis wrote: ... OAEP padding is specific enough as to make random ... > decryption of the wrong root infeasible. ... In IEEE P1363 the same signature/encryption encodings are used with both ...
    (sci.crypt)