Paper 2026/430

An attack on the CFS scheme and on TII McEliece challenges

Magali Bardet, Université de Rouen
Axel Lemoine, French Institute for Research in Computer Science and Automation
Jean-Pierre Tillich, French Institute for Research in Computer Science and Automation
Abstract

It has been a very long standing open question whether the CFS signature scheme whose security is basically that of a McEliece scheme based on very high rate binary Goppa codes could be attacked or not. There was a first cryptanalytic result by Faugère et al in 2011 consisting in finding a distinguisher for the binary Goppa codes used in this scheme showing that these codes can be distinguished in polynomial time from a random binary linear code. However despite numerous cryptanalytic attempts and even if the original distinguisher has been significantly improved, no attack on the McEliece scheme based on binary Goppa codes has been found so far except for very peculiar Goppa codes of degree $2$. We show here that the Pfaffian modeling used in the distinguishing attack of Couvreur, Mora and Tillich of Asiacrypt 2023 can actually be used together with a shortening trick and looking for squares in the corresponding ideal to find a polynomial attack on the CFS scheme based on very high rate binary Goppa codes.This breaks this 25 years old signature scheme. We demonstrate the effectiveness of this approach by recovering the key of TII McEliece challenges with a claimed key security of up to 210 bits.

Metadata
Available format(s)
PDF
Publication info
Preprint.
Contact author(s)
magali bardet @ univ-rouen fr
axel lemoine @ inria fr
jean-pierre tillich @ inria fr
History
2026-03-05: approved
2026-03-03: received
See all versions
Short URL
https://ia.cr/2026/430
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/430,
      author = {Magali Bardet and Axel Lemoine and Jean-Pierre Tillich},
      title = {An attack on the {CFS} scheme and on {TII} {McEliece} challenges},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/430},
      year = {2026},
      url = {https://eprint.iacr.org/2026/430}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.