Can someone advise if this is a proper paradigm? Payload -> random aes 256 cbc -> rsa public key 2048 encrypted aeskey+iv

And I'm still not sure which of the two I should be signing

