Paper 2026/2223

Linear Key Recovery in the BAG-Loong Reference Implementation

Zihan Liu, Institute of Software, Chinese Academy of Sciences
Abstract

The BAG-Loong reference implementation samples its secret matrices X and Y from fixed, publicly known subspaces, although the specification calls for secret random supports. This makes the public-key relation S = HX + Y , with public H, amenable to Gaussian elimination. Expanding the relation over F2 and projecting away the support of Y leaves a linear system for X. We prove an exact recovery criterion based on its column rank. All 40 supplied known-answer-test records, covering four parameter sets, satisfy this criterion: two independent solvers recover each X exactly, and the unmodified decapsulation code reproduces the corresponding session keys. For the largest parameter set, the reduced system has 9360 equations in 728 unknowns per column; one elimination solves all 15 columns.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
rank-metric cryptographyBAG-Loongpublic supportslinear algebrakey recoveryimplementation analysis.
Contact author(s)
liuzihan2024 @ iscas ac cn
History
2026-09-27: approved
2026-09-26: received
See all versions
Short URL
https://ia.cr/2026/2223
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2223,
      author = {Zihan Liu},
      title = {Linear Key Recovery in the {BAG}-Loong Reference Implementation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2223},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2223}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.