Cryptanalysis of a System Based on Twisted Reed-Solomon Codes

04/26/2019
by   Julien Lavauzelle, et al.
0

It was recently proved that twisted Reed--Solomon codes represent a family of codes which contain a large amount of MDS codes, non-equivalent to Reed--Solomon codes. As a consequence, they were proposed as an alternative to Goppa codes for the McEliece cryptosystem, resulting to a potential reduction of key sizes. In this paper, an efficient key-recovery attack is given on this variant of the McEliece cryptosystem. The algorithm is based on the recovery of the structure of subfield subcodes of twisted Reed--Solomon codes, and it always succeeds. Its correctness is proved, and it is shown that the attack breaks the system for all practical parameters in O(n^4) field operations. A practical implementation is also provided and retrieves a valid private key from the public key within just a few minutes, for parameters claiming a security level of 128 bits. We also discuss a potential repair of the scheme and an application of the attack to GPT cryptosystems using twisted Gabidulin codes.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/26/2018

Twisted Gabidulin Codes in the GPT Cryptosystem

In this paper, we investigate twisted Gabidulin codes in the GPT code-ba...
research
09/09/2018

A Public-Key Cryptosystem from Interleaved Goppa Codes

In this paper, a code-based public-key cryptosystem based on interleaved...
research
01/11/2018

Repairing the Faure-Loidreau Public-Key Cryptosystem

A repair of the Faure-Loidreau (FL) public-key code-based cryptosystem i...
research
05/14/2018

An efficient structural attack on NIST submission DAGS

We present an efficient key recovery attack on code based encryption sch...
research
07/28/2022

Skew differential Goppa codes and their application to McEliece cryptosystem

A class of linear codes that extends classic Goppa codes to a non-commut...
research
05/02/2023

An extension of Overbeck's attack with an application to cryptanalysis of Twisted Gabidulin-based schemes

In the present article, we discuss the decoding of Gabidulin and related...
research
04/01/2020

Estimating The Dimension Of The Subfield Subcodes of Hermitian Codes

In this paper, we study the behavior of the true dimension of the subfie...

Please sign up or login with your details

Forgot password? Click here to reset