Paper 2026/1616

Flip a Failure into a Success: Improved Bit Flipping Decoding for QC-MDPC Codes

Paolo Santini, Marche Polytechnic University
Davide De Zuane, IMT School for Advanced Studies Lucca, Marche Polytechnic University
Alessio Baldelli, Marche Polytechnic University
Marco Baldi, Marche Polytechnic University
Abstract

Quasi-Cyclic Moderate-Density Parity-Check (QC-MDPC) codes are a family of error correcting codes admitting parity-check matrices composed of sparse circulant blocks. QC-MDPC codes have been used for the design of BIKE, one of the finalists in the NIST competition for the standardization of post-quantum cryptography. Decoding of QC-MDPC codes with cryptographically relevant parameters is intrinsically bound to fail, resulting in a decoding failure rate (DFR) that is nonzero. To achieve INDistinguishability under Adaptively Chosen Ciphertext Attacks (IND-CCA2), the DFR must not exceed $2^{-\lambda}$, with $\lambda$ being the security parameter. QC-MDPC codes are customarily decoded with a Bit Flipping (BF) algorithm. Especially at very low DFR values, error patterns having a large intersection with near-codewords (which are vectors corresponding to columns of the parity-check matrix, up to some shift) are the main cause of decoding failures. In this paper, we show how a BF decoder can be tweaked to exploit the knowledge about near-codewords. Since error vectors that cause decoding failures are likely making the decoder converge to the closest near-codeword (i.e., to the near-codeword with the largest amount of overlapping positions with the error vector), we exploit such a harmful but predictable behavior: we let the decoder recognize, and consequently correct, syndromes of near-codewords. This modification comes with a very mild computational overhead and can be applied to any BF decoder. As a concrete application, we focus on BIKE parameters for NIST security category 1. We show that a recently proposed BF variant called $\textsf{BF}\text{-}\textsf{Max}$ outperforms significantly the two decoders used by BIKE within the NIST competition, achieving a significantly lower DFR with a comparable computational complexity.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
QC-MDPC codesBit FlippingDecoding Failure Rate
Contact author(s)
p santini @ univpm it
davide dezuane @ imtlucca it
a baldelli @ pm univpm it
m baldi @ univpm it
History
2026-08-06: approved
2026-08-05: received
See all versions
Short URL
https://ia.cr/2026/1616
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1616,
      author = {Paolo Santini and Davide De Zuane and Alessio Baldelli and Marco Baldi},
      title = {Flip a Failure into a Success: Improved Bit Flipping Decoding for {QC}-{MDPC} Codes},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1616},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1616}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.