An Attack on High Rate McEliece Cryptosystems Using Generalized Reed Solomon Codes with Weight $2$ Mask

📅 2026-07-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the lack of effective attacks against high-rate McEliece cryptosystems employing masking matrices with row and column weight two. We propose a novel distinguisher based on cubic codes, leveraging algebraic coding theory and structured matrix analysis to achieve, for the first time, an efficient distinction of such variants under high-rate conditions. Building upon this distinguisher, we develop a general framework that transitions from distinguishing to full key recovery, successfully reconstructing the private key. Our approach fills a critical gap in the literature and exposes a fundamental security vulnerability inherent in these constructions.
📝 Abstract
Due to the insecurity of McEliece cryptosystems instantiated with Generalized Reed-Solomon codes, there have been several proposals of McEliece type systems that replace the permutation matrix by a matrix $M$ with larger row and column weight. In many of them, the secret key is still a GRS code. There have been successful attacks on some of those schemes with row and column weight between $1$ and $1 + R$, where $R$ is the rate of the code. The case of weight two and larger has been left open in these works. Subsequently, several authors proposed schemes with weight exactly two and with even higher weight. We provide distinguishers for the public codes appearing in these cryptosystems in the high rate regime. In addition, we give a framework to turn a good enough distinguisher into a key-recovery attack. In the case where the matrix $M$ has row and column weight $2$, we can successfully attack the scheme in the high rate regime using a cube code distinguisher.
Problem

Research questions and friction points this paper is trying to address.

McEliece cryptosystem
Generalized Reed-Solomon codes
weight-2 mask
high rate regime
code-based cryptography
Innovation

Methods, ideas, or system contributions that make the work stand out.

McEliece cryptosystem
Generalized Reed-Solomon codes
weight-2 mask
distinguisher
key-recovery attack
🔎 Similar Papers
2024-07-22IACR Cryptology ePrint ArchiveCitations: 3