Question: RSA - OAEP Consider RSA with padding ( OAEP ) used as a block cipher with block size 2 0 4 8 bits in ECB

RSA-OAEP
Consider RSA with padding (OAEP) used as a block cipher with block size 2048
bits in ECB mode. For the purposes of this question we do not need the details of
how OAEP works, we just need to know:
OAEP is an algorithm that takes an m-bit block and mixes it with a k-bit
random string to return an (m+k)-bit padded block. To be concrete, here
we have m=2048, and we will take k=1536.
OAEP is invertible: given the padded block (and the details of the OAEP
algorithm), it is possible to recover the original unpadded block without
any additional information.
(a) Should the padding be done to the plaintext block before encryption, or to the
ciphertext block after encryption, or does it not matter? Why?
(b) How does padding (properly done) affect the nominal unicity point?
(It might be helpful to think about how the padding affects the entropy.)
RSA - OAEP Consider RSA with padding ( OAEP )

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Accounting Questions!