Exploring Decryption Failures of BIKE: New Class of Weak Keys and Key Recovery Attacks
Tianrui Wang, Anyu Wang, Xiaoyun Wang
Abstract
Code-based cryptography has received a lot of attention recently because it is considered secure under quantum computing. Among them, the QC-MDPC based scheme is one of the most promising due to its excellent performance. QC-MDPC based scheme is usually subject to a small rate of decryption failure, which can leak information about the secret key. This raises two crucial problems: how to accurately estimate the decryption failure rate and how to use the failure information to recover the secret key. However, the two problems are challenging due to the difficulty of geometrically characterizing the bit-flipping decoder employed in QC-MDPC, such as using decoding radius.
In this work, we introduce the gathering property and show that it is strongly connected with the decryption failure rate of QC-MDPC. Based on the gathering property, we present two results for QC-MDPC based schemes. The first is a new construction of weak keys obtained by extending the keys that have gathering property via ring isomorphism. For the set of weak keys, we present a rigorous analysis of the probability, as well as experimental simulation of the decryption failure rates. Considering BIKE's parameter set targeting -bit security, our result eventually indicates that the average decryption failure rate is lower bounded by . The second is a key recovery attack against CCA secure QC-MDPC schemes using decryption failures in a multi-target setting. By decrypting ciphertexts with errors satisfying the gathering property, we show that a single decryption failure can be used to identify whether a target's secret key satisfies the gathering property. Then using the gathering property as extra information, we present a modified information set decoding algorithm that efficiently retrieves the target's secret key. For BIKE's parameter set targeting -bit security, a key recovery attack with complexity can be expected by using extrapolated decryption failure rates.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b74c4748-869f-4bab-a21b-0eacadc5b364Cited by top-tier papers3
- Error Floor Prediction with Markov Models for QC-MDPC CodesSarah Arpin, Jun Bo Lau, Antoine Mesnard, Ray A. Perlner et al.CRYPTO 2025 · 5 citations
- Efficient QC-MDPC Cryptosystems with Bounded Decoding Failure RateAlessandro Annechini, Alessandro Barenghi, Gerardo Pelosi, Simone PerrielloCRYPTO 2026
- Formally Verified Correctness Bounds for Lattice-Based CryptographyManuel Barbosa, Matthias J. Kannwischer, Thing-Han Lim, Peter Schwabe et al.CCS 2025
Related papers
- Partial Key Exposure Attacks on BIKE, Rainbow and NTRUAndre Esser, Alexander May, Javier A. Verbel, Weiqiang WenCRYPTO 2022 · 22 citations
- McEliece Needs a Break - Solving McEliece-1284 and Quasi-Cyclic-2918 with Modern ISDAndre Esser, Alexander May, Floyd ZweydingerEUROCRYPT 2022 · 32 citations
- Cryptanalysis of LEDAcryptDaniel Apon, Ray A. Perlner, Angela Robinson, Paolo SantiniCRYPTO 2020 · 16 citations
- (One) Failure Is Not an Option: Bootstrapping the Search for Failures in Lattice-Based Encryption SchemesJan-Pieter D'Anvers, Mélissa Rossi, Fernando VirdiaEUROCRYPT 2020 · 2 citations
- HQC Beyond the Standard: Ciphertext Compression and Refined DFR AnalysisSebastian Bitzer, Jean-Christophe Deneuville, Emma Munisamy, Bharath Purtipli et al.EUROCRYPT 2026
