Paper 2026/1984
Improving GIJS Key Recovery for Classic McEliece
Abstract
Classic McEliece is a post-quantum encryption scheme. Its public key is a generator matrix of a secret binary Goppa code. Its security levels are set by generic decoding attacks, which cost $2^{151}$ to $2^{287}$ bit operations for the five parameter sets. Ghoshal, Ishai, Jain and Sun (GIJS26) recently gave the first test that tells a public key from a random matrix at a lower cost, an estimated $2^{114}$ to $2^{124}$ bit operations. They have since extended it to recover the secret key. The test is one large sparse linear-algebra computation, which we call a run. We improve this attack in two ways. First, we lower the cost of a run to $2^{89}$ to $2^{98}$ bit operations. If every operation is charged for the memory that it addresses, at square-root cost, a run costs $2^{107}$ to $2^{117}$. This is our best estimate, and it is below the cost of generic decoding with free memory. The Classic McEliece security guide charges every operation for the whole memory. Under that rule a run costs $2^{117}$ to $2^{128}$, against $2^{159}$ to $2^{316}$ for generic decoding. Second, we give two ways to recover the secret key. One rests on a theorem that we prove and needs $100$ to $1400$ runs. The other builds on the key recovery of GIJS26 and needs a single run. None of this is close to practical, and a run at full size cannot be tested. The costs rest on four heuristic assumptions, which we state and test on small keys. There the first attack recovered the secret key with polynomials of degree $5$, and the second with degrees $5$, $6$ and $7$. Degree $7$ is the degree of the attack on Classic McEliece. Small keys deviated from the assumptions in a few ways. We identify the cause of each deviation and argue that it does not occur at full size. As a demonstration we recovered the secret key of instance~253 of the TII McEliece key-recovery challenges ($m=8$, $t=9$, $n=214$), a toy-sized code that had not been solved.
Note: Currently on version 0.5. See the revision history in Appendix H for changes.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- McEliece
- Contact author(s)
- sweis @ anthropic com
- History
- 2026-10-06: last of 5 revisions
- 2026-09-11: received
- See all versions
- Short URL
- https://ia.cr/2026/1984
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1984,
author = {Stephen A. Weis},
title = {Improving {GIJS} Key Recovery for Classic {McEliece}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1984},
year = {2026},
url = {https://eprint.iacr.org/2026/1984}
}