Cryptanalysis of a system based on twisted Reed-Solomon codes

From MaRDI portal
Publication:780371

DOI10.1007/S10623-020-00747-6zbMATH Open1455.94177arXiv1904.11785OpenAlexW3104110479MaRDI QIDQ780371FDOQ780371


Authors: Julien Lavauzelle, Julian Renner Edit this on Wikidata


Publication date: 15 July 2020

Published in: Designs, Codes and Cryptography (Search for Journal in Brave)

Abstract: Twisted Reed-Solomon (TRS) codes are a family of codes that contains a large number of maximum distance separable codes that are non-equivalent to Reed--Solomon codes. TRS codes were recently proposed as an alternative to Goppa codes for the McEliece code-based cryptosystem, resulting in a potential reduction of key sizes. The use of TRS codes in the McEliece cryptosystem has been motivated by the fact that a large subfamily of TRS codes is resilient to a direct use of known algebraic key-recovery methods. In this paper, an efficient key-recovery attack on the TRS variant that was used in the McEliece cryptosystem is presented. The algorithm exploits a new approach based on recovering the structure of a well-chosen subfield subcode of the public code. It is proved that the attack always succeeds and breaks the system for all practical parameters in O(n4) field operations. A software implementation of the algorithm retrieves a valid private key from the public key within a few minutes, for parameters claiming a security level of 128 bits. The success of the attack also indicates that, contrary to common beliefs, subfield subcodes of the public code need to be precisely analyzed when proposing a McEliece-type code-based cryptosystem. Finally, the paper discusses an attempt to repair the scheme and a modification of the attack aiming at Gabidulin-Paramonov-Tretjakov cryptosystems based on twisted Gabidulin codes.


Full work available at URL: https://arxiv.org/abs/1904.11785




Recommendations




Cites Work


Cited In (13)

Uses Software





This page was built for publication: Cryptanalysis of a system based on twisted Reed-Solomon codes

Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q780371)