SearcharxivSearch

arXiv · 2609.17732

A Polynomial-Time Attack on the McEliece Cryptosystem on Elliptic Codes with Arbitrary Divisors

Abstract

The McEliece cryptosystem based on algebraic geometry codes has been proposed as a way to reduce the key size of code-based cryptography, but several structural attacks have demonstrated the vulnerability of particular families of algebraic geometry codes. Despite this, until recently, there remained schemes and parameter sets that were not vulnerable to any known attack. We propose a new structural attack with ``hints'' that applies to elliptic codes with arbitrary effective divisors. In particular, we prove that, given the elliptic curve, the public generator matrix, and three points from the evaluation divisor, the entire divisor can be recovered in polynomial time, independently of the number of errors used in the cryptosystem. The attack requires $\mathcal{O}(k^2n^2+|\mathcal{E}(\mathbb{F}_q)|+n)$ operations in $\mathbb{F}_q$ and succeeds with overwhelming probability, after which the second divisor is recovered in $\mathcal{O}\!\left(k^2n^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations. We further propose an optimized version of the attack that requires no additional information at all. Exploiting the action of the automorphisms of the curve, the three known points are replaced by the enumeration of a single pair of field elements, which yields an equivalent key on the given public curve in $\mathcal{O}\!\left(k^2n^2 + q^2 + (|\mathcal{E}(\mathbb{F}_q)|-n)n^2\right)$ operations on average.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Artyom Kuninets, Ekaterina Malygina, Evgeniy Melnichuk. 2026-09-15. A Polynomial-Time Attack on the McEliece Cryptosystem on Elliptic Codes with Arbitrary Divisors. https://arxiv.org/abs/2609.17732

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Bistatic Target Detection by Exploiting Both Deterministic Pilots and Unknown Random Data Payloads

Integrated sensing and communication (ISAC) plays a crucial role in 6G, to enable innovative applications such as drone surveillance, urban air mobility, and low-altitude logistics. However, the hybrid ISAC signal, which comprises deterministic pilot and random data payload components, poses challenges for target detection due to two reasons: 1) these two components cause coupled shifts in both the mean and variance of the received signal, and 2) the random data payloads are typically unknown to the sensing receiver in the bistatic setting. Unfortunately, these challenges could not be tackled by existing target detection algorithms. In this paper, a generalized likelihood ratio test (GLRT)-based detector is derived, by leveraging the known deterministic pilots and the statistical characteristics of the unknown random data payloads. Due to the analytical intractability of exact performance characterization, we perform an asymptotic analysis for the false alarm probability and detection probability of the proposed detector. The results highlight a critical trade-off: both deterministic and random components improve detection reliability, but the latter also brings statistical uncertainty that hinders detection performance. Simulations validate the theoretical findings and demonstrate the effectiveness of the proposed detector, which highlights the necessity of designing a dedicated detector to fully exploited the signaling resources assigned to random data payloads.

cs.IT

On Unbiased Parameter Estimation and Signal Reconstruction

In this paper, we extend the theory of depth-unbiased source localization to unbiased parameter estimation and signal reconstruction for an arbitrary number of non-zero parameters. The topic touches on exact reconstructibility, most commonly studied in compressed sensing and multisource estimation across various imaging problems. The theoretical results derive upper bounds on the number of recoverable parameters in the noiseless case, and define a probability measure to assess the likelihood of recovering all non-zero parameters with correct magnitude order. The work provides a mathematical explanation of the open question regarding the noise robustness of standardized and unbiased methods. The paper also reveals a trade-off between the number of sensors and the signal-to-noise ratio. Numerical experiments demonstrate the theoretical findings.

cs.IT

Minimum enclosing Bregman balls made easy

In this work, we revisit the problem of computing minimum enclosing Bregman balls (Bregman MEBs) of finite sets of parameters. First, we show that Bregman MEBs are equivalent to MEBs of corresponding weighted point sets with respect to the power distance. We then report an efficient Frank--Wolfe $(1+ε)$-approximation algorithm for computing power MEBs, for any $ε>0$. This power MEB approximation algorithm coincides with the Bregman MEB approximation algorithm of Nock and Nielsen (2005) when expressed in the dual gradient space. Finally, we show that the Bregman potential lifting transforms used to construct Bregman Voronoi diagrams can be reinterpreted as the classical paraboloid lifting transform applied to corresponding weighted point sets. In particular, Bregman MEB circumcenters lie on the farthest Bregman Voronoi diagrams or equivalently on the corresponding farthest power diagrams.

cs.IT