Full BPR security of 2-Feistel OEKE

Establish full Bellare–Pointcheval–Rogaway security for 2-Feistel-based OEKE in the post-quantum setting, including man-in-the-middle attacks and fully concurrent executions.

Background

The paper proves stand-alone game-based security for OEKE instantiated with 2-Feistel encryption in the QROM. It explicitly notes that the stronger BPR notion, which models man-in-the-middle attackers and fully concurrent executions, remains to be addressed.

References

We leave the full BPR security of (2-Feistel-based) OEKE as an important direction for future work.

— Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT  (2609.39844 - Bartusek et al., 30 Sep 2026) in Section 2.6, Future work, Post-quantum BPR security