Content deleted Content added
m Redirect bypass from All or nothing transform to all-or-nothing transform using popups |
→Diagram of OAEP: italic |
||
Line 41:
# recover the message as ''m''00..0 = ''X'' ⊕ ''G''(''r'')
The "[[All-or-nothing transform|all-or-nothing]]" security is from the fact that to recover ''m'', you must recover the entire ''X'' and the entire ''Y''; ''X'' is required to recover ''r'' from ''Y'', and ''r'' is required to recover ''m'' from ''X''. Since any changed bit of a cryptographic hash completely changes the result, the entire ''X'', and the entire ''Y'' must both be completely recovered.
==See also==
|