The syzygy Distinguisher
Hugues Randriambololona
摘要
We present a new distinguisher for alternant and Goppa codes, whose complexity is subexponential in the error-correcting capability, hence better than that of generic decoding algorithms. Moreover it does not suffer from the strong regime limitations of the previous distinguishers or structure recovery algorithms: in particular, it applies to the codes used in the Classic McEliece candidate for postquantum cryptography standardization. The invariants that allow us to distinguish are graded Betti numbers of the homogeneous coordinate ring of a shortening of the dual code. Since its introduction in 1978, this is the first time an analysis (in the CPA model) of the McEliece cryptosystem breaks the exponential barrier.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
相关 Paper
- Distinguishing Goppa Codes Using Higher-Order VanishingTobias Hemmert, Andreas WiemersCRYPTO 2026 · 被引用 2 次
- An Attack on the CFS Scheme and on TII McEliece ChallengesMagali Bardet, Axel Lemoine, Jean-Pierre TillichCRYPTO 2026 · 被引用 1 次
- Cryptanalysis of LEDAcryptDaniel Apon, Ray A. Perlner, Angela Robinson, Paolo SantiniCRYPTO 2020 · 被引用 16 次
- Mckeycutter: A High-throughput Key Generator of Classic McEliece on HardwareYihong Zhu, Wenping Zhu, Chen Chen, Min Zhu 等DAC 2023 · 被引用 9 次
- Message-Recovery Laser Fault Injection Attack on the Classic McEliece CryptosystemPierre-Louis Cayrel, Brice Colombier, Vlad-Florin Dragoi, Alexandre Menu 等EUROCRYPT 2021 · 被引用 28 次
