Paper 2026/2223
Linear Key Recovery in the BAG-Loong Reference Implementation
Abstract
The BAG-Loong reference implementation samples its secret matrices X and Y from fixed, publicly known subspaces, although the specification calls for secret random supports. This makes the public-key relation S = HX + Y , with public H, amenable to Gaussian elimination. Expanding the relation over F2 and projecting away the support of Y leaves a linear system for X. We prove an exact recovery criterion based on its column rank. All 40 supplied known-answer-test records, covering four parameter sets, satisfy this criterion: two independent solvers recover each X exactly, and the unmodified decapsulation code reproduces the corresponding session keys. For the largest parameter set, the reduced system has 9360 equations in 728 unknowns per column; one elimination solves all 15 columns.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- rank-metric cryptographyBAG-Loongpublic supportslinear algebrakey recoveryimplementation analysis.
- Contact author(s)
- liuzihan2024 @ iscas ac cn
- History
- 2026-09-27: approved
- 2026-09-26: received
- See all versions
- Short URL
- https://ia.cr/2026/2223
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2223,
author = {Zihan Liu},
title = {Linear Key Recovery in the {BAG}-Loong Reference Implementation},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2223},
year = {2026},
url = {https://eprint.iacr.org/2026/2223}
}