Quantum-secure compiler from KEM to OT or PAKE

Construct a practically efficient compiler from a key encapsulation mechanism to two-message oblivious transfer or password-authenticated key exchange in the quantum random oracle model that achieves simulation-based security, or establish whether such a compiler exists.

Background

The paper shows that the Masny–Rindal compiler from KEM to two-message OT and the (O)EKE family of KEM-based PAKE compilers fail to achieve simulation-based security against quantum polynomial-time adversaries, despite their classical security proofs. The authors therefore ask whether the query-order extraction paradigm can be replaced by a practical post-quantum technique, and whether any efficient compiler can retain simulation-based security in the QROM.

References

Is there a practically-efficient and truly post-quantum alternative to the “query-order” extraction technique underlying Masny-Rindal OT and (O)EKE? In fact, can we come up with any practically-efficient compiler from KEM to (two-message) OT or PAKE in the quantum random oracle model that achieves simulation-based security?

— Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT  (2609.39844 - Bartusek et al., 30 Sep 2026) in Section 2.6, Future work, Alternative constructions