# OAEP Reconsidered

@article{Shoup2002OAEPR, title={OAEP Reconsidered }, author={Victor Shoup}, journal={Journal of Cryptology}, year={2002}, volume={15}, pages={223-249} }

Abstract. The OAEP encryption scheme was introduced by Bellare and Rogaway at Eurocrypt '94. It converts any trapdoor permutation scheme into a public key encryption scheme. OAEP is widely believed to provide resistance against adaptive chosen ciphertext attack. The main justification for this belief is a supposed proof of security in the random oracle model, assuming the underlying trapdoor permutation scheme is one way. This paper shows conclusively that this justification is invalid. First…

