Merkle–Damgård Construction - MD-compliant Padding
... As mentioned in the introduction, the padding scheme used in the Merkle–Damgård construction must be chosen carefully to ensure the security of the scheme ... Mihir Bellare gives sufficient conditions for a padding scheme to possess to ensure that the MD construction is secure the scheme must be "MD-compliant" (the original length-padding scheme ...
Key Encapsulation - Example Using RSA Encryption
... by using an agreed-upon reversible protocol known as a padding scheme, such as OAEP ... the following computation Given, she recovers the original message M by reversing the padding scheme ... The KEM eliminates the complexity of the padding scheme and the proofs needed to show the padding is secure ...

