Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study investigates whether the classical UC security of (O)EKE and the Masny-Rindal compiler remains valid in post-quantum settings. Employing the Universal Composability framework under quantum polynomial-time adversaries, the authors utilize cryptographic reduction techniques to reveal inherent extraction barriers. This work proves that these protocols fail to achieve quantum UC security even when instantiated with post-quantum KEMs, presenting adversarial strategies that preclude simulation-based extraction. Concurrently, it establishes their game-based security by introducing a tightly bounded one-way hiding lemma. These results bridge critical theoretical gaps in the post-quantum security analysis of PAKE and oblivious transfer protocols.
📝 Abstract
Encrypted key exchange (EKE), introduced by Bellovin and Merritt (IEEE S\&P 1992), and Masny-Rindal OT, introduced by Masny and Rindal (ACM CCS 2019), are highly-efficient methods for compiling essentially any KEM into advanced cryptographic protocols, namely password-authenticated key exchange (PAKE) and oblivious transfer (OT), by relying only on idealized symmetric-key primitives. They have become leading candidates for practically-implementable PAKE and OT due to (1) their simplicity, (2) their plug-and-play nature, allowing for flexibility in the choice of KEM, and (3) existing proofs of UC-security (in the classical adversarial model). Due to point (2) above, these compilers yield attractive candidates for efficient \emph{post-quantum} PAKE and OT, especially given the recent post-quantum KEM standardization efforts. This motivates the question of whether the (UC-)security of these compilers translates to the quantum adversarial model. In this work, we show that it does not. In particular, we prove that a general family of (O)EKE protocols, as well as Masny-Rindal OT, are \emph{not} UC-secure against quantum polynomial-time adversaries, even when instantiated with a post-quantum KEM. To establish UC-insecurity, we devise an adversarial strategy that provably thwarts any attempt by the simulator to extract its input (the password in the case of PAKE, and the receiver's choice bit in the case of OT). To complement these negative results, we establish that both compilers yield certain notions of \emph{game-based} security. Along the way, we establish a novel ``advantage-tight'' one-way to hiding lemma that may be of independent interest.
Problem

Research questions and friction points this paper is trying to address.

Post-Quantum Security
Encrypted Key Exchange
Oblivious Transfer
Universal Composability
Quantum Adversary
Innovation

Methods, ideas, or system contributions that make the work stand out.

Post-Quantum Security
Universal Composability
Encrypted Key Exchange
Oblivious Transfer
One-Way to Hiding Lemma
James Bartusek
James Bartusek
NYU
Cryptography
J
Jake Januzelli
Columbia University