On the Security of RSA Encryption in TLS

  • Authors:
  • Jakob Jonsson;Burton S. Kaliski, Jr.

  • Affiliations:
  • -;-

  • Venue:
  • CRYPTO '02 Proceedings of the 22nd Annual International Cryptology Conference on Advances in Cryptology
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

We show that the security of the TLS handshake protocol based on RSA can be related to the hardness of inverting RSA given a certain "partial-RSA" decision oracle. The reduction takes place in a security model with reasonable assumptions on the underlying TLS pseudo-random function, thereby addressing concerns about its construction in terms of two hash functions. The result is extended to a wide class of constructions that we denote tagged key-encapsulation mechanisms.