Reduction from Sparse LPN to LPN, Dual Attack 3.0
Kévin Carrier, Thomas Debris-Alazard, Charles Meyer-Hilfiger, Jean-Pierre Tillich
Abstract
The security of code-based cryptography relies primarily on the hardness of decoding generic linear codes. Until very recently, all the best algorithms for solving the decoding problem were information set decoders (ISD). However, recently a new algorithm called RLPN-decoding which relies on a completely different approach was introduced and it has been shown that RLPN outperforms significantly ISD decoders for a rather large range of rates. This RLPN decoder relies on two ingredients, first reducing decoding to some underlying LPN problem, and then computing efficiently many parity-checks of small weight when restricted to some positions. We revisit RLPN-decoding by noticing that, in this algorithm, decoding is in fact reduced to a sparse-LPN problem, namely with a secret whose Hamming weight is small. Our new approach consists this time in making an additional reduction from sparse-LPN to plain-LPN with a coding approach inspired by coded-BKW. It outperforms significantly the ISD's and RLPN for code rates smaller than 0.42. This algorithm can be viewed as the code-based cryptography cousin of recent dual attacks in lattice-based cryptography. We depart completely from the traditional analysis of this kind of algorithm which uses a certain number of independence assumptions that have been strongly questioned recently in the latter domain. We give instead a formula for the LPNs noise relying on duality which allows to analyze the behavior of the algorithm by relying only on the analysis of a certain weight distribution. By using only a minimal assumption whose validity has been verified experimentally we are able to justify the correctness of our algorithm. This key tool, namely the duality formula, can be readily adapted to the lattice setting and is shown to give a simple explanation for some phenomena observed on dual attacks in lattices in [DP23].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9a1bb36b-1e23-46b7-97e9-7c431dd74fa7Cited by top-tier papers2
- Assessing the Impact of a Variant of MATZOV's Dual Attack on KyberKévin Carrier, Charles Meyer-Hilfiger, Yixin Shen, Jean-Pierre TillichCRYPTO 2025 · 3 citations
- Post-quantum Cryptography from Quantum Stabilizer DecodingJonathan Z. Lu, Alexander Poremba, Yihui Quek, Akshar RamkumarCRYPTO 2026
Builds on3
- Syndrome Decoding in the Head: Shorter Signatures from Zero-Knowledge ProofsThibauld Feneuil, Antoine Joux, Matthieu RivainCRYPTO 2022 · 73 citations
- Does the Dual-Sieve Attack on Learning with Errors Even Work?Léo Ducas, Ludo N. PullesCRYPTO 2023 · 32 citations
- Provable Dual Attacks on Learning with ErrorsAmaury Pouly, Yixin ShenEUROCRYPT 2024 · 18 citations
Related papers
- Smoothing Out Binary Linear Codes and Worst-Case Sub-exponential Hardness for LPNYu Yu, Jiang ZhangCRYPTO 2021 · 11 citations
- A New Algebraic Approach to the Regular Syndrome Decoding Problem and Implications for PCG ConstructionsPierre Briaud, Morten ØygardenEUROCRYPT 2023 · 21 citations
- On the Lattice Isomorphism Problem, Quadratic Forms, Remarkable Lattices, and CryptographyLéo Ducas, Wessel P. J. van WoerdenEUROCRYPT 2022 · 67 citations
- Sample Efficient Search to Decision for kLINAndrej Bogdanov, Alon Rosen, Kel Zin TanCRYPTO 2025 · 2 citations
- A Systematic Study of Sparse LWEAayush Jain, Huijia Lin, Sagnik SahaCRYPTO 2024 · 8 citations
