Paper 2026/2280
Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT
Abstract
Encrypted key exchange (EKE), introduced by Bellovin and Merritt (IEEE S\&P 1992), and Masny-Rindal OT, introduced by Masny and Rindal (ACM CCS 2019), are highly-efficient methods for compiling essentially any KEM into advanced cryptographic protocols, namely password-authenticated key exchange (PAKE) and oblivious transfer (OT), by relying only on idealized symmetric-key primitives. They have become leading candidates for practically-implementable PAKE and OT due to (1) their simplicity, (2) their plug-and-play nature, allowing for flexibility in the choice of KEM, and (3) existing proofs of UC-security (in the classical adversarial model). Due to point (2) above, these compilers yield attractive candidates for efficient \emph{post-quantum} PAKE and OT, especially given the recent post-quantum KEM standardization efforts. This motivates the question of whether the (UC-)security of these compilers translates to the quantum adversarial model. In this work, we show that it does not. In particular, we prove that a general family of (O)EKE protocols, as well as Masny-Rindal OT, are \emph{not} UC-secure against quantum polynomial-time adversaries, even when instantiated with a post-quantum KEM. To establish UC-insecurity, we devise an adversarial strategy that provably thwarts any attempt by the simulator to extract its input (the password in the case of PAKE, and the receiver's choice bit in the case of OT). To complement these negative results, we establish that both compilers yield certain notions of \emph{game-based} security. In the PAKE setting, we consider OEKE instantiated with the ``2-Feistel'' cipher, and prove its stand-alone game-based security in the quantum random oracle model. We view these results as a proof of concept that security of (O)EKE and Masny-Rindal OT can yet be redeemed in the quantum setting, though we caution that the situation will be more subtle than in the classical setting due to the breakdown of simulation-based security. Along the way, we establish a novel ``advantage-tight'' one-way to hiding lemma that may be of independent interest.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Oblivious TransferPAKEPost-Quantum
- Contact author(s)
-
bartusek james @ gmail com
jj3544 @ columbia edu - History
- 2026-10-03: approved
- 2026-09-30: received
- See all versions
- Short URL
- https://ia.cr/2026/2280
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/2280,
author = {James Bartusek and Jake Januzelli},
title = {Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O){EKE} and Masny-Rindal {OT}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2280},
year = {2026},
url = {https://eprint.iacr.org/2026/2280}
}