McEliece Needs a Break - Solving McEliece-1284 and Quasi-Cyclic-2918 with Modern ISD
Andre Esser, Alexander May, Floyd Zweydinger
Abstract
With the recent shift to post-quantum algorithms it becomes increasingly important to provide precise bit-security estimates for code-based cryptography such as McEliece and quasi-cyclic schemes like BIKE and HQC. While there has been significant progress on information set decoding (ISD) algorithms within the last decade, it is still unclear to which extent this affects current cryptographic security estimates.
We provide the first concrete implementations for representation-based ISD, such as May-Meurer-Thomae (MMT) or Becker-Joux-May-Meurer (BJMM), that are parameter-optimized for the McEliece and quasi-cyclic setting. Although MMT and BJMM consume more memory than naive ISD algorithms like Prange, we demonstrate that these algorithms lead to significant speedups for practical cryptanalysis on medium-sized instances (around 60 bit). More concretely, we provide data for the record computations of McEliece-1223 and McEliece-1284 (old record: 1161), and for the quasi-cyclic setting up to code length 2918 (before: 1938).
Based on our record computations we extrapolate to the bit-security level of the proposed BIKE, HQC and McEliece parameters in NIST's standardization process. For BIKE/HQC, we also show how to transfer the Decoding-One-Out-of-Many (DOOM) technique to MMT/BJMM. Although we achieve significant DOOM speedups, our estimates confirm the bit-security levels of BIKE and HQC.
For the proposed McEliece round-3 parameter sets of 192 and 256 bit, however, our extrapolation indicates a security level overestimate by roughly 20 and 10 bits, respectively, i.e., the high-security McEliece instantiations may be a bit less secure than desired.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 782dfd93-bbe9-4cb4-b875-d36dd8c34af5Cited by top-tier papers1
Ask how each one uses itRelated papers
- New Time-Memory Trade-Offs for Subset Sum - Improving ISD in Theory and PracticeAndre Esser, Floyd ZweydingerEUROCRYPT 2023 · 11 citations
- Efficient QC-MDPC Cryptosystems with Bounded Decoding Failure RateAlessandro Annechini, Alessandro Barenghi, Gerardo Pelosi, Simone PerrielloCRYPTO 2026
- CryptAttackTester: high-assurance attack analysisDaniel J. Bernstein, Tung ChouCRYPTO 2024 · 8 citations
- The Cost to Break SIKE: A Comparative Hardware-Based Analysis with AES and SHA-3Patrick Longa, Wen Wang, Jakub SzeferCRYPTO 2021 · 13 citations
- PQ-Hammer: End-to-End Key Recovery Attacks on Post-Quantum Cryptography Using RowhammerSamy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang et al.S&P 2025
