The syzygy Distinguisher
Hugues Randriambololona
Abstract
We present a new distinguisher for alternant and Goppa codes, whose complexity is subexponential in the error-correcting capability, hence better than that of generic decoding algorithms. Moreover it does not suffer from the strong regime limitations of the previous distinguishers or structure recovery algorithms: in particular, it applies to the codes used in the Classic McEliece candidate for postquantum cryptography standardization. The invariants that allow us to distinguish are graded Betti numbers of the homogeneous coordinate ring of a shortening of the dual code. Since its introduction in 1978, this is the first time an analysis (in the CPA model) of the McEliece cryptosystem breaks the exponential barrier.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8ff34874-0b53-426a-82fb-be01437f6fbbRelated papers
- Distinguishing Goppa Codes Using Higher-Order VanishingTobias Hemmert, Andreas WiemersCRYPTO 2026 · 2 citations
- An Attack on the CFS Scheme and on TII McEliece ChallengesMagali Bardet, Axel Lemoine, Jean-Pierre TillichCRYPTO 2026 · 1 citation
- Cryptanalysis of LEDAcryptDaniel Apon, Ray A. Perlner, Angela Robinson, Paolo SantiniCRYPTO 2020 · 16 citations
- Mckeycutter: A High-throughput Key Generator of Classic McEliece on HardwareYihong Zhu, Wenping Zhu, Chen Chen, Min Zhu et al.DAC 2023 · 9 citations
- Message-Recovery Laser Fault Injection Attack on the Classic McEliece CryptosystemPierre-Louis Cayrel, Brice Colombier, Vlad-Florin Dragoi, Alexandre Menu et al.EUROCRYPT 2021 · 28 citations
