[Resource Topic] 2001/110: RSA hybrid encryption schemes

Welcome to the resource topic for 2001/110

RSA hybrid encryption schemes

Authors: Louis Granboulan


This document compares the two published RSA-based hybrid encryption
schemes having linear reduction in their security proof:
While the performance of RSA-REACT is worse than the performance of
RSA-KEM+DEM1, a complete proof of its security has already been
This is indeed an advantage, because we show that the security result
for RSA-KEM+DEM1 has a small hole.
We provide here a complete proof of the security of
We also propose some changes to RSA-REACT to improve its efficiency
without changing its security, and conclude that this new RSA-REACT is
a generalisation of RSA-KEM+DEM1, with at most the same security,
and with possibly worse performance.

Therefore we show that RSA-KEM+DEM1 should be preferred to RSA-REACT.

ePrint: https://eprint.iacr.org/2001/110

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .