An Attack on the CFS Scheme and on TII McEliece Challenges
Magali Bardet, Axel Lemoine, Jean-Pierre Tillich
Abstract
It has been a very long standing open question whether the CFS signature scheme whose security is basically that of a McEliece scheme based on very high rate binary Goppa codes could be attacked or not. There was a first cryptanalytic result by Faugère et al in 2011 consisting in finding a distinguisher for the binary Goppa codes used in this scheme showing that these codes can be distinguished in polynomial time from a random binary linear code. However despite numerous cryptanalytic attempts and even if the original distinguisher has been significantly improved, no attack on the McEliece scheme based on binary Goppa codes has been found so far except for very peculiar Goppa codes of degree . We show here that the Pfaffian modeling used in the distinguishing attack of Couvreur, Mora and Tillich of Asiacrypt 2023 can actually be used together with a shortening trick and looking for squares in the corresponding ideal to find a polynomial attack on the CFS scheme based on very high rate binary Goppa codes.This breaks this 25 years old signature scheme. We demonstrate the effectiveness of this approach by recovering the key of TII McEliece challenges with a claimed key security of up to 210 bits.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a109289c-9a9d-4182-8c5e-df4b3a503c6dRelated papers
- Distinguishing Goppa Codes Using Higher-Order VanishingTobias Hemmert, Andreas WiemersCRYPTO 2026 · 2 citations
- The syzygy DistinguisherHugues RandriambololonaEUROCRYPT 2025 · 10 citations
- Key Attack on the ACDGV Matrix Encryption SchemeAnmoal Porwal, Antonia Wachter-Zeh, Pierre LoidreauEUROCRYPT 2026 · 1 citation
- Analysis of the Security of the PSSI Problem and Cryptanalysis of the Durandal Signature SchemeNicolas Aragon, Victor Dyseryn, Philippe GaboritCRYPTO 2023 · 8 citations
- Message-Recovery Laser Fault Injection Attack on the Classic McEliece CryptosystemPierre-Louis Cayrel, Brice Colombier, Vlad-Florin Dragoi, Alexandre Menu et al.EUROCRYPT 2021 · 28 citations
