Search arXivSearch

arXiv · 2609.17732

A Polynomial-Time Attack on the McEliece Cryptosystem on Elliptic Codes with Arbitrary Divisors

Abstract

The McEliece cryptosystem based on algebraic geometry codes has been proposed as a way to reduce the key size of code-based cryptography, but several structural attacks have demonstrated the vulnerability of particular families of algebraic geometry codes. Despite this, until recently, there remained schemes and parameter sets that were not vulnerable to any known attack. We propose a new structural attack with ``hints'' that applies to elliptic codes with arbitrary effective divisors. In particular, we prove that, given the elliptic curve, the public generator matrix, and three points from the evaluation divisor, the entire divisor can be recovered in polynomial time, independently of the number of errors used in the cryptosystem. The attack requires $\mathcal{O}(k^2n^2+|\mathcal{E}(\mathbb{F}_q)|+n)$ operations in $\mathbb{F}_q$ and succeeds with overwhelming probability, after which the second divisor is recovered in $\mathcal{O}\!\left(k^2n^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations. We further propose an optimized version of the attack that requires no additional information at all. Exploiting the action of the automorphisms of the curve, the three known points are replaced by the enumeration of a single pair of field elements, which yields an equivalent key on the given public curve in $\mathcal{O}\!\left(k^2n^2 + q^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations on average.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Artyom Kuninets, Ekaterina Malygina, Evgeniy Melnichuk. 2026-09-15. A Polynomial-Time Attack on the McEliece Cryptosystem on Elliptic Codes with Arbitrary Divisors. https://arxiv.org/abs/2609.17732

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Fundamental Scaling Laws of Covert Communication in the Presence of Block Fading

Covert communication is the undetected transmission of sensitive information over a communication channel. In wireless communication systems, channel impairments such as signal fading present challenges in the effective implementation and analysis of covert communication systems. This paper generalizes early work in the covert communication field by considering asymptotic results for the number of bits that can be covertly transmitted in $n$ channel uses on a block fading channel. Critical to the investigation is characterizing the performance of optimal detectors at the adversary. Matching achievable and converse results are presented.

cs.IT

Sequence Reconstruction over the Deletion Channel

In this paper, we consider the Levenshtein's sequence reconstruction problem in the case where the transmitted codeword is chosen from $\{0,1\}^n$ and the channel can delete up to $t$ symbols from the transmitted codeword. We determine the minimum number of channel outputs (assuming that they are distinct) required to reconstruct a list of size $\ell-1$ of candidate sequences, one of which corresponds to the original transmitted sequence. More specifically, we determine the maximum possible size of the intersection of $\ell \geq 3$ deletion balls of radius $t$ centered at $x_1, x_2, \dots, x_{\ell}$, where $x_i \in \{0,1\}^n$ for all $i \in \{1,2,\dots,\ell\}$ and $x_i \neq x_j$ for $i \neq j$, with $ n \geq t+\ell-1$ and $t \geq 1$.

cs.IT

A generalization of the map $χ$

The mapping $ χ_n:\mathbb{F}_2^n \to \mathbb{F}_2^n$ defined by $y=χ_n(x)$ with $y_i = x_i + x_{i+1}x_{i+2} + x_{i+2}$, where the indices are computed modulo $n$, has been widely studied for its application in lightweight cryptography. In this paper, we generalize this mapping and completely characterize all these shift-invariant permutations of the form $y_i=x_{i+u}+x_{i+v}(x_{i+w}+a_i)$, where $0\le u, v, w<n$ and $a_i\in \mathbb{F}_2$, $1\le i\le n$.

cs.IT