padding scheme often used together with RSA encryption; a form of Feistel network which uses a pair of random oracles to process the plaintext prior to asymmetric encryption; introduced by Bellare and Rogaway; standardized in PKCS#1 v2 and RFC 2437
Discovered by embedding cosine similarity (sentence-transformers MiniLM, 384-dim).