We prove in the random oracle model that OAEP++, which was proposed by us at the rump session of Asiacrypt 2000, can generate IND-CCA2 ciphers using deterministic OW-CPA cryptographic primitives. Note that OAEP++ differs from OAEP proposed by Jonsson in [4]. While OAEP requires a non-malleable block cipher, OAEP++ does not require such additional functions. The security reduction of OAEP++ is a...