Paper 2026/1986
Two-Anchor Holdout/Hermite: Solving the TII-254 McEliece Key Recovery Challenge
Abstract
We report on the solution to the TII-254 McEliece key recovery challenge -- currently the hardest solved challenge under the original brute-force metric ($2^{254}$). The parameters of TII-254 are $(m,t,n) = (8,12,223)$, defining a binary $[223,127]$ code specified by a full-rank $(96 \times 223)$ parity-check matrix. We state the method as a thirteen-step process, separating heuristic and non-heuristic choices. At a high level, we computed two complete $121$-dimensional relation kernels conditioned at distinct public coordinates, combined them to isolate a certified $80$-dimensional pair core, removed a $64$-dimensional common nuisance space, and identified the remaining $16$ dimensions as an $\mathbb{F}_{2^8}$ projective-line geometry. This yielded all $87$ visible locators, after which a deterministic completion search recovered the full support and polynomial. The two final Krylov sequences alone used $27.2$ GPU-hours on NVIDIA GH200s, excluding GPU reconstruction and CPU processing. We provide a self-contained artifact with compact recovery inputs and code, an independent key verifier, and Lean proofs of the reusable linear-algebraic steps.
Note: A solution and source code artifact is available: https://github.com/mjosaarinen/tii254-artifact
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- McElieceBinary Goppa CodesKey RecoveryHoldout attackBlock Wiedemann
- Contact author(s)
- markku-juhani saarinen @ tuni fi
- History
- 2026-09-14: approved
- 2026-09-11: received
- See all versions
- Short URL
- https://ia.cr/2026/1986
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1986,
author = {Markku-Juhani O. Saarinen},
title = {Two-Anchor Holdout/Hermite: Solving the {TII}-254 {McEliece} Key Recovery Challenge},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1986},
year = {2026},
url = {https://eprint.iacr.org/2026/1986}
}