Paper 2026/2050

A Polynomial-Time Attack on the McEliece Cryptosystem on Elliptic Codes with Arbitrary Divisors

Artyom Kuninets, QApp
Ekaterina Malygina, QApp
Evgeniy Melnichuk, QApp
Abstract

The McEliece cryptosystem based on algebraic geometry codes has been proposed as a way to reduce the key size of code-based cryptography, but several structural attacks have demonstrated the vulnerability of particular families of algebraic geometry codes. Despite this, until recently, there remained schemes and parameter sets that were not vulnerable to any known attack. We propose a new structural attack with ``hints'' that applies to elliptic codes with arbitrary effective divisors. In particular, we prove that, given the elliptic curve, the public generator matrix, and three points from the evaluation divisor, the entire divisor can be recovered in polynomial time, independently of the number of errors used in the cryptosystem. The attack requires $\mathcal{O}(k^2n^2+|\mathcal{E}(\mathbb{F}_q)|+n)$ operations in $\mathbb{F}_q$ and succeeds with overwhelming probability, after which the second divisor is recovered in $\mathcal{O}\!\left(k^2n^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations. We further propose an optimized version of the attack that requires no additional information at all. Exploiting the action of the automorphisms of the curve, the three known points are replaced by the enumeration of a single pair of field elements, which yields an equivalent key on the given public curve in $\mathcal{O}\!\left(k^2n^2 + q^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations on average.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Algebraic geometry codesMcEliece cryptosystemcryptanalysis
Contact author(s)
artkuninets @ yandex ru
emalygina @ qapp tech
emelnichuk @ qapp tech
History
2026-09-17: approved
2026-09-15: received
See all versions
Short URL
https://ia.cr/2026/2050
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2050,
      author = {Artyom Kuninets and Ekaterina Malygina and Evgeniy Melnichuk},
      title = {A Polynomial-Time Attack on the {McEliece} Cryptosystem on Elliptic Codes with Arbitrary Divisors},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2050},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2050}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.