Paper 2026/2225

Breaking the G\'omez-Torrecillas--Lobillo--Navarro Cryptosystem: LLL Recovers the Secret Key Within Seconds

Abul Kalam, Indian Institute of Technology Madras
Santanu Sarkar, Indian Institute of Technology Madras
Abstract

We present a key-recovery attack on the knapsack McEliece-based public key cryptosystem recently proposed by G\'omez-Torrecillas, Lobillo, and Navarro in DCC 2026. Given the public key alone, the attack recovers the complete private key in time polynomial in the bit-length of the public key, and therefore constitutes a total break. The attack combines two observations based solely on the public key. An integer combination of the public entries whose coefficients sum to zero eliminates the secret mask. If such a combination is also orthogonal to the public key and sufficiently short, then its coordinates are divisible by the corresponding private key integers. The modulus required for correct decryption creates a large norm gap between these short vectors satisfying the hidden private key relations and the remaining vectors in the lattice. LLL reduction exploits this gap to recover the short vectors and hence the corresponding divisibility relations. The private key integers and the remaining secret parameters are then recovered by combining information from multiple overlapping lattices and using greatest common divisors. We implemented the attack in SageMath and recovered the complete private key for all twenty four parameter sets proposed by the authors within 3 seconds, despite claimed security levels ranging from $64$ to $156$ bits. Our analysis further shows that the weakness is structural rather than a consequence of the particular parameter choices.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
public key cryptanalysisknapsack cryptosystemslattice basis reductionLLLorthogonal lattices
Contact author(s)
abulkalam sunny @ gmail com
sarkar santanu bir1 @ gmail com
History
2026-09-27: approved
2026-09-26: received
See all versions
Short URL
https://ia.cr/2026/2225
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2225,
      author = {Abul Kalam and Santanu Sarkar},
      title = {Breaking the G\'omez-Torrecillas--Lobillo--Navarro Cryptosystem: {LLL} Recovers the Secret Key Within Seconds},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2225},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2225}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.