Efficient simulation of ideal ciphers in the quantum setting

Establish whether the ideal-cipher simulation procedures of Grinko–Yoshida and Foxman et al. are efficient, thereby determining whether they can serve as efficient quantum ideal functionalities in the UC framework.

Background

To formulate UC security for protocols using quantum-accessible ideal ciphers, an efficient ideal functionality is needed. The paper states that recent procedures can perfectly simulate a broad class of oracles including ideal ciphers, but that the efficiency of these simulations depends on an unresolved computational transformation.

References

Two other recent works [GY25, FLM+26] define a procedure to perfectly simulate a broad class of oracles that includes ideal ciphers,11 but it is not yet known if this ideal cipher simulation is efficient12.

— Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT  (2609.39844 - Bartusek et al., 30 Sep 2026) in Section 3.4.3, UC security