Paper 2026/1747

Extending Distinguishing to Key Recovery for Subfield Subcodes of GRS codes

Kirill Vedenev, CryptoPro, Southern Federal University
Abstract

Ghoshal, Ishai, Jain, and Sun recently introduced a novel quasipolynomial-time distinguisher for GRS subcodes (including Goppa codes), leaving key recovery as an open problem. This note presents an approach for turning the distinguisher into a full key-recovery attack. The overall complexity is dominated by a few executions of the distinguisher, and the approach is experimentally validated on Goppa codes over $\mathbb{F}_4$. We conjecture that this recovery route applies to binary Goppa codes as well.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
McEliece cryptosystemGRS codeskey-recovery attackHasse derivatives
Contact author(s)
vedenevk @ yandex ru
History
2026-08-22: approved
2026-08-20: received
See all versions
Short URL
https://ia.cr/2026/1747
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1747,
      author = {Kirill Vedenev},
      title = {Extending Distinguishing to Key Recovery for Subfield Subcodes of {GRS} codes},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1747},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1747}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.