Decoding supercodes of Gabidulin codes and applications to cryptanalysis

Maxime Bombar and Alain Couvreur

Abstract: This article discusses the decoding of Gabidulin codes and shows how to extend the usual decoder to any supercode of a Gabidulin code at the cost of a significant decrease of the decoding radius. Using this decoder, we provide polynomial time attacks on the rank–metric encryption schemes Ramesses and Liga.

Category / Keywords: public-key cryptography / Code–based cryptography, Gabidulin codes, decoding, rank–metric, cryptanalysis

Date: received 16 Mar 2021

Contact author: maxime bombar at inria fr

Note: The Sage code is available on Github:

Version: 20210317:154915 (All versions of this report)

