D. Bleichenbacher. Chosen ciphertext attacks against protocols based on the rsa encryption standard pkcs #1. InProceedings of the 18th Annual International Cryptology Conference on Advances in Cryptology
, CRYPTO ’98, pages 1–12, London, UK, UK, 1998. Springer-Verlag.