Paper 2026/1747

Extending Distinguishing to Key Recovery for Subfield Subcodes of GRS codes

Kirill Vedenev, CryptoPro, Southern Federal University
Abstract

The McEliece cryptosystem based on binary Goppa codes is the oldest public-key scheme to have resisted both classical and quantum cryptanalysis. Ghoshal, Ishai, Jain, and Sun recently gave a quasipolynomial-time distinguisher for subcodes of Generalized Reed-Solomon codes, including alternant and Goppa codes. We derive two key-recovery attacks from it, both using derivative spaces of the hidden curve. The first attack recovers high-order derivative spaces at a few positions, guesses the partial GRS support at those positions, and tests whether the guessed partial support admits a compatible curve. Once the partial support is found, the attack recovers the remaining support elements point-by-point via linear algebra. The second - a minor-code attack - requires only order-1 derivative spaces. In the non-subfield case, these spaces directly yield an auxiliary minor code that, with high probability, is itself a full GRS code with the original support. In the subfield case, the recovered derivative spaces have an additional Frobenius ambiguity. We handle this by constructing a generalized minor code and extracting a full GRS code from it. In both cases, the standard Sidelnikov-Shestakov attack then recovers the support without enumeration. Both attacks were verified end-to-end over $\mathbb{F}_4$. For binary Goppa codes, derivative flag recovery remains out of computational reach, but the other components have supporting evidence. Conditioned on our assumptions, for Classic McEliece parameters the minor-code attack costs essentially a several runs of the distinguisher (well below the claimed security levels). Concurrently, a later revision of the work of Ghoshal et al. gave an independent key recovery based on different ideas.

Note: The previous revision introduced a second, more efficient attack route and reorganized the presentation. This revision improved the minor-code attack for alternant and Goppa codes by removing Frobenius alignment step.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
McEliece cryptosystemGRS codeskey-recovery attackHasse derivatives
Contact author(s)
vedenevk @ yandex ru
History
2026-09-06: last of 8 revisions
2026-08-20: received
See all versions
Short URL
https://ia.cr/2026/1747
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1747,
      author = {Kirill Vedenev},
      title = {Extending Distinguishing to Key Recovery for Subfield Subcodes of {GRS} codes},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1747},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1747}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.