Paper 2026/1984

Improving GIJS Key Recovery for Classic McEliece

Stephen A. Weis, Anthropic
Abstract

Classic McEliece is a post-quantum encryption scheme. Its public key is a generator matrix of a secret binary Goppa code. Its security levels are set by generic decoding attacks, which cost $2^{151}$ to $2^{287}$ bit operations for the five parameter sets. Ghoshal, Ishai, Jain and Sun (GIJS26) recently gave the first test that tells a public key from a random matrix at a lower cost, an estimated $2^{114}$ to $2^{124}$ bit operations. They have since extended it to recover the secret key. The test is one large sparse linear-algebra computation, which we call a run. We improve this attack in two ways. First, we lower the cost of a run to $2^{89}$ to $2^{98}$ bit operations. If every operation is charged for the memory that it addresses, at square-root cost, a run costs $2^{107}$ to $2^{117}$. This is our best estimate, and it is below the cost of generic decoding with free memory. The Classic McEliece security guide charges every operation for the whole memory. Under that rule a run costs $2^{117}$ to $2^{128}$, against $2^{159}$ to $2^{316}$ for generic decoding. Second, we give two ways to recover the secret key. One rests on a theorem that we prove and needs $100$ to $1400$ runs. The other builds on the key recovery of GIJS26 and needs a single run. None of this is close to practical, and a run at full size cannot be tested. The costs rest on four heuristic assumptions, which we state and test on small keys. There the first attack recovered the secret key with polynomials of degree $5$, and the second with degrees $5$, $6$ and $7$. Degree $7$ is the degree of the attack on Classic McEliece. Small keys deviated from the assumptions in a few ways. We identify the cause of each deviation and argue that it does not occur at full size. As a demonstration we recovered the secret key of instance~253 of the TII McEliece key-recovery challenges ($m=8$, $t=9$, $n=214$), a toy-sized code that had not been solved.

Note: Currently on version 0.5. See the revision history in Appendix H for changes.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
McEliece
Contact author(s)
sweis @ anthropic com
History
2026-10-06: last of 5 revisions
2026-09-11: received
See all versions
Short URL
https://ia.cr/2026/1984
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1984,
      author = {Stephen A. Weis},
      title = {Improving {GIJS} Key Recovery for Classic {McEliece}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1984},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1984}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.