Paper 2025/2180

Weight of Polynomial Products Mod $(X^n+1)$-Application to the HQC Cryptosystem-

Laila El Aimani, Cadi Ayyad University
Abstract

We consider the problem of computing the variance and tail probability bounds for the weight of the product $z = x \cdot y$ of two random polynomials $x, y \in \F_2[X]/(X^n+1)$, where the weight of a binary polynomial is defined as the number of its nonzero coefficients. We investigate two probabilistic models for $x$ and $y$: the \emph{uniform slice} model, where the weights are fixed to $w_x$ and $w_y$, and the \emph{binomial} model, where the coefficients are independent Bernoulli variables with parameters $p_x$ and $p_y$. Our analysis is directly motivated by the need for accurate security analysis of the error vector of the HQC code-based encryption scheme. Prior work has progressed from heuristic arguments backed by extensive simulations to exact computations of the probability mass function (PMF) of the weight of the error vector; however, these computations were largely restricted to the uniform slice setting. We adopt a different approach, leveraging the full covariance structure of the product vector $z$ (i.e., the pairwise covariances of its coefficients) to derive tight, rigorously proven bounds on the tail probabilities of its weight for both the uniform and binomial models. These results confirm HQC's security guarantees and, moreover, reveal additional symmetry properties of the HQC error vector that are desirable for cryptographic design.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
Hamming weightproduct of polynomialscovariance analysistail probabilitydecryption failureHQC
Contact author(s)
laila elaimani @ gmail com
History
2026-06-25: revised
2025-12-01: received
See all versions
Short URL
https://ia.cr/2025/2180
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2180,
      author = {Laila El Aimani},
      title = {Weight of Polynomial Products Mod $(X^n+1)$-Application to the {HQC} Cryptosystem-},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2180},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2180}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.