Description
The McEliece scheme is a generic framework allowing to use any error correcting code which disposes of an efficient decoding algorithm to design an encryption scheme by hiding a generator matrix of this code.
In the context of rank metric, we propose a generalization of the McEliece frame to matrix codes. From a vector code, we compute a matrix version of this code, that is hidden in such a way that the code obtained is indistinguishable from a random code. We propose to mask the linearity of the vector code on the extension, which implies a bigger public key (since the code is less structured) but allows to allows to keep a very small size of ciphertext. It results in an encryption scheme whose security relies on a generic instance of the MinRank problem, known to be NP-complete.
Applying it with Gabidulin codes, our approach gives a better trade-off between ciphertexts and public keys sizes than the classic McEliece scheme. For 128 bits of security, we propose parameters with ciphertext of size 65B and public key of size 98kB.
Travail en commun avec Nicolas Aragon, Alain Couvreur, Victor Dyseryn, Philippe Gaborit
Practical infos
Next sessions
-
Dissecting CRAFT, a full-round attack
Speaker : Eran Lambooij - Inria
I will present the first full-round key recovery attack on CRAFT, a block cipher introduced at ToSC 2019. The attack builds on the previous observation (ToSC 2026) that the state of CRAFT can be decomposed into two parts that barely exchange information. We transform this property into a dissection attack on the full-round cipher. This shows that in some cases we can elevate the dissection attack[…]-
Cryptography
-
-
Key Attack on the ACDGV Matrix Encryption Scheme
Speaker : Anmoal Porwal - Technical University of Munich
I will present our key-recovery attack on the ACDGV public-key encryption scheme proposed at ASIACRYPT 2024 by Aragon, Couvreur, Dyseryn, Gaborit, and Vinçotte. The secret key is a Gabidulin code hidden by appending random rows and columns and by left- and right-multiplication with invertible matrices. Our attack exploits the resulting algebraic structure to recover an equivalent secret key. It[…]-
Cryptography
-
Asymmetric primitive
-
-
Module Learning With Errors and Structured Extrapolated Dihedral Cosets
Speaker : Jinwei Zheng - Télécom Paris
The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes. Inspired by the equivalence between LWE and[…]-
Cryptography
-