Efficient QC-MDPC Cryptosystems with Bounded Decoding Failure Rate
Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi, Simone Perriello
Abstract
Niederreiter-style post quantum cryptosystems based on QC-MDPC codes, such as BIKE, have shown promising efficiency figures and enjoy a straightforward reduction to conjectured-hard problems in coding theory. The longstanding issue in their design is having a closed form Decoding Failure Rate (DFR) analysis of the iterative decoder employed by their decryption primitive, as decoding failures leak information on the private key. State of the art models either provide loose bounds, or do not consider the decoding algorithm employed in practice, using the behavior of a simpler one as a proxy. In this work, we provide a closedform estimate of the DFR for the practically employed three-iterations parallel decoder, applied to QC-MDPC codes. This result constitutes the first closed form DFR model targeting both the same code family and the same decoder employed in the cryptosystem. Leveraging our estimation technique, we design the parameters for a QC-MDPC based Niederreiter encryption scheme, obtaining a 2× improvement in public key and ciphertext size w.r.t. the previous best cryptosystem design with DFR closed-form bounds, LEDAcrypt-KEM. Furthermore, we show that our new parameters yield up to 30% smaller public key size and 2.2× to 4.4× smaller ciphertexts w.r.t. HQC, the code based key encapsulation method selected by the US NIST for standardization, and achieve up to 3× speedup with respect to BIKE in ephemeral and long-term key usage.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- Cryptanalysis of LEDAcryptDaniel Apon, Ray A. Perlner, Angela Robinson, Paolo SantiniCRYPTO 2020 · 16 citations
- Exploring Decryption Failures of BIKE: New Class of Weak Keys and Key Recovery AttacksTianrui Wang, Anyu Wang, Xiaoyun WangCRYPTO 2023 · 9 citations
- CryptAttackTester: high-assurance attack analysisDaniel J. Bernstein, Tung ChouCRYPTO 2024 · 8 citations
- Error Floor Prediction with Markov Models for QC-MDPC CodesSarah Arpin, Jun Bo Lau, Antoine Mesnard, Ray A. Perlner et al.CRYPTO 2025 · 5 citations
- Ideal Pseudorandom CodesOmar Alrabiah, Prabhanjan Ananth, Miranda Christ, Yevgeniy Dodis et al.STOC 2025 · 2 citations
Related papers
- HQC Beyond the Standard: Ciphertext Compression and Refined DFR AnalysisSebastian Bitzer, Jean-Christophe Deneuville, Emma Munisamy, Bharath Purtipli et al.EUROCRYPT 2026
- McEliece Needs a Break - Solving McEliece-1284 and Quasi-Cyclic-2918 with Modern ISDAndre Esser, Alexander May, Floyd ZweydingerEUROCRYPT 2022 · 32 citations
- Message-Recovery Laser Fault Injection Attack on the Classic McEliece CryptosystemPierre-Louis Cayrel, Brice Colombier, Vlad-Florin Dragoi, Alexandre Menu et al.EUROCRYPT 2021 · 28 citations
- PQ-Hammer: End-to-End Key Recovery Attacks on Post-Quantum Cryptography Using RowhammerSamy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang et al.S&P 2025
- The Cost to Break SIKE: A Comparative Hardware-Based Analysis with AES and SHA-3Patrick Longa, Wen Wang, Jakub SzeferCRYPTO 2021 · 13 citations
