Paper 2026/1232

A Heuristic Subexponential Attack on the McEliece Cryptosystem

Pierre Briaud, XLIM, Centre National de la Recherche Scientifique
Axel Lemoine, French Institute for Research in Computer Science and Automation, Direction Générale de l'Armement
Hugues Randriambololona, ANSSI, Télécom ParisTech
Jean-Pierre Tillich, French Institute for Research in Computer Science and Automation
Abstract

We provide a new way of performing an algebraic attack on the McEliece cryptosystem based on binary Goppa codes. It also applies in general to the case where the field over which the Goppa code is defined is of even characteristic. It is based on a new algebraic modeling for finding matrices of rank $2$ in the code of quadratic relations related to the Goppa code that is attacked. Such matrices are then used to recover the secret algebraic structure of the code, from which an equivalent secret key can be efficiently derived, leading to a full key-recovery attack. A byproduct of our approach is a new distinguisher for Goppa codes in even characteristic which is as the syzygy distinguisher of \cite{R25}subexponential in the security level of the scheme. We demonstrate the effectiveness of our attack on McEliece TII challenges, some of which having been studied in \cite{BLT26}, and aimed at having 83,89,119,166, 210 and even 248 bit security respectively and CFS keys with parameters $r=9$ and $m=16$, corresponding to a security of $74.9$ bits according to \cite{LS12}. This CFS key was not attacked in practice in \cite{BLT26} and took us 14 hours of computation and 24GB of RAM. We make the conjecture that this attack has a complexity which is of the same nature as the distinguisher, namely subexponential in the security level. It should be noted that this attack is at best of complexity of order $2^{454}$ for NIST level 1 Classic McEliece parameters.

Note: Long version with appendices.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
McEliece schemeAlgebraic cryptanalysisBinary Goppa codes
Contact author(s)
pierre briaud @ xlim fr
axel lemoine @ inria fr
hugues randriam @ telecom-paris fr
jean-pierre tillich @ inria fr
History
2026-09-17: last of 5 revisions
2026-06-10: received
See all versions
Short URL
https://ia.cr/2026/1232
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1232,
      author = {Pierre Briaud and Axel Lemoine and Hugues Randriambololona and Jean-Pierre Tillich},
      title = {A Heuristic Subexponential Attack on the {McEliece} Cryptosystem},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1232},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1232}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.