SearcharxivSearch

arXiv subjects

Violetta Weger

Publications and source records attributed to Violetta Weger.

At least 19 recordsLinked to original sources

A Survey on Code Equivalence: The State-of-the-Art and Open Questions

In this work, we provide a comprehensive survey of the code equivalence problem and its variants. We explain the existing results, highlighting the relationships between different problem formulations, algorithmic techniques, and hardness assumptions. In addition, we systematically review known attacks, identify the parameter regimes in which they are effective, and discuss their limitations. Lastly, we outline several open problems and research directions, with the aim of clarifying the current landscape and guiding future work toward a deeper understanding of the hardness of code equivalence.

cs.IT

The Power of Power Codes: New Classes of Easy Instances for the Linear Equivalence Problem

Given two linear codes, the Linear Equivalence Problem (LEP) asks to find (if it exists) a linear isometry between them; as a special case, we have the Permutation Equivalence Problem (PEP), in which isometries must be permutations. LEP and PEP have recently gained renewed interest as the security foundations for several post-quantum schemes, including LESS. A recent paper has introduced the use of the Schur product to solve PEP, identifying many new easy-to-solve instances. In this paper, we extend this result to LEP. In particular, we generalize the approach and rely on the more general notion of power codes. Combining it with Frobenius automorphisms and Hermitian hulls, we identify many classes of easy LEP instances. To the best of our knowledge, this is the first work exploiting algebraic weaknesses for LEP. Finally we show an improved reduction to PEP whenever the coefficients of the monomial matrix are in a subgroup of the multiplicative group of the finite field.

cs.CR

On Optimal Homogeneous-Metric Codes

The homogeneous metric can be viewed as a natural extension of the Hamming metric to finite chain rings. It distinguishes between three types of elements: zero, non-zero elements in the socle, and elements outside the socle. Since the Singleton bound is one of the most fundamental and widely studied bounds in classical coding theory, we investigate its analogue for codes over finite chain rings equipped with the homogeneous metric. We provide a complete characterization of Maximum Homogeneous Distance (MHD) codes, showing that MHD codes coincide with lifted MDS codes and are contained within the socle at low rank. Exceptions arise from exceptional MDS codes or single-parity-check codes. We then shift our focus to the Plotkin-type bound in the homogeneous metric and close an existing gap in the theory of constant homogeneous-weight codes by identifying those of minimal length.

cs.IT

Cryptanalysis of a PIR Scheme based on Linear Codes over Rings

In this paper we present an attack on a recently proposed code-based Private Information Retrieval (PIR) scheme. Indeed, the server can retrieve the index of the desired file with high probability in polynomial time. The attack relies on the fact that random codes over finite rings are free with high probability and that the dimension of the rowspan of the query matrix decreases when the rows corresponding to the desired index are removed.

cs.CR

Coarsest Fourier-reflexive Partitions for the Lee, Homogeneous and Subfield Metric

MacWilliams identities relate the weight enumerators of a code with those of its dual and are classically formulated with respect to the Hamming weight. For other metrics, however, these identities often fail when considering the weight partition of the ambient space. It is known that MacWilliams identities hold for enumerators associated with Fourier-reflexive partitions, and that orbits of subgroups of the linear isometry group always yield such partitions. This raises the question whether, for metrics beyond the Hamming metric, there exist meaningful partitions that lie strictly between the weight partition and the orbit partition: finer than the latter, yet still coarse enough to retain useful MacWilliams-type identities. In this work, we study this question for finite chain rings endowed with additive metrics. For the Lee metric, we show that the partition induced by the action of the full group of linear isometries is already the coarsest Fourier-reflexive partition refining the weight partition. In particular, no intermediate partition exists that is both finer than the Lee weight partition and Fourier-reflexive. We refer to this partition as the Lee partition and show that it allows the recovery of all additive weight enumerators over the ring. In contrast, for the homogeneous metric and for the subfield metric, we identify new, significantly coarser symmetrized partitions that remain Fourier-reflexive and still allow the recovery of the corresponding weight enumerators. We prove that these partitions are the coarsest such symmetrized partitions for which MacWilliams-type identities hold. As an application, we derive linear programming bounds based on the resulting MacWilliams identities.

math.AC

TCitH- and VOLEitH-based Signatures from Restricted Decoding

Threshold-Computation-in-the-Head (TCitH) and VOLE-in-the-Head (VOLEitH), two recent developments of the MPC-in-the-Head (MPCitH) paradigm, have significantly improved the performance of digital signature schemes. This work embeds the restricted decoding problem within these frameworks: we propose a structurally simple modeling that achieves competitive signature sizes. Specifically, by instantiating the restricted decoding problem with the same hardness assumption underlying CROSS, we reduce sizes by more than a factor of two compared to the NIST submission. Moreover, we observe that ternary full-weight decoding, closely related to the hardness assumption underlying WAVE, is a restricted decoding problem. Using ternary full-weight decoding, we obtain signature sizes comparable to the smallest MPCitH-based candidates in the NIST competition.

cs.CR

Weighted-Hamming Metric: Bounds and Codes

The weighted-Hamming metric generalizes the Hamming metric by assigning different weights to blocks of coordinates. It is well-suited for applications such as coding over independent parallel channels, each of which has a different level of importance or noise. From a coding-theoretic perspective, the actual error-correction capability of a code under this metric can exceed half its minimum distance. In this work, we establish direct bounds on this capability, tightening those obtained via minimum-distance arguments. We also propose a flexible code construction based on generalized concatenation and show that these codes can be efficiently decoded up to a lower bound on the error-correction capability.

cs.IT

Weak Composition Lattices and Ring-Linear Anticodes

Lattices and partially ordered sets have played an increasingly important role in coding theory, providing combinatorial frameworks for studying structural and algebraic properties of error-correcting codes. Motivated by recent works connecting lattice theory, anticodes, and coding-theoretic invariants, we investigate ring-linear codes endowed with the Lee metric. We introduce and characterize optimal Lee-metric anticodes over the ring $\mathbb{Z}/p^s\mathbb{Z}$. We show that the family of such anticodes admits a natural partition into subtypes and forms a lattice under inclusion. We establish a bijection between this lattice and a lattice of weak compositions ordered by dominance. As an application, we use this correspondence to introduce new invariants for Lee-metric codes via an anticode approach.

cs.IT

A Survey on Code-Based Cryptography

The improvements on quantum technology are threatening our daily cybersecurity, as a capable quantum computer can break all currently employed asymmetric cryptosystems. In preparation for the quantum-era the National Institute of Standards and Technology (NIST) has initiated in 2016 a standardization process for public-key encryption (PKE) schemes, key-encapsulation mechanisms (KEM) and digital signature schemes. In 2023, NIST made an additional call for post-quantum signatures. With this chapter we aim at providing a survey on code-based cryptography, focusing on PKEs and signature schemes. We cover the main frameworks introduced in code-based cryptography and analyze their security assumptions. We provide the mathematical background in a lecture notes style, with the intention of reaching a wider audience.

cs.CR

The Subfield Metric and its Application to Quantum Error Correction

We introduce a new weight and corresponding metric over finite extension fields for asymmetric error correction. The weight distinguishes between elements from the base field and the ones outside of it, which is motivated by asymmetric quantum codes. We set up the theoretic framework for this weight and metric, including upper and lower bounds, asymptotic behavior of random codes, and we show the existence of an optimal family of codes achieving the Singleton-type upper bound.

cs.IT

Weighted-Hamming Metric for Parallel Channels

Independent parallel q-ary symmetric channels are a suitable transmission model for several applications. The proposed weighted-Hamming metric is tailored to this setting and enables optimal decoding performance. We show that some weighted-Hamming-metric codes exhibit the unusual property that all errors beyond half the minimum distance can be corrected. Nevertheless, a tight relation between the error-correction capability of a code and its minimum distance can be established. Generalizing their Hamming-metric counterparts, upper and lower bounds on the cardinality of a code with a given weighted-Hamming distance are obtained. Finally, we propose a simple code construction with optimal minimum distance for specific parameters.

cs.IT

Better bounds on the minimal Lee distance

This paper provides new and improved Singleton-like bounds for Lee metric codes over integer residue rings. We derive the bounds using various novel definitions of generalized Lee weights based on different notions of a support of a linear code. In this regard, we introduce three main different support types for codes in the Lee metric and analyze their utility to derive bounds on the minimum Lee distance. Eventually, we propose a new point of view to generalized weights and give an improved bound on the minimum distance of codes in the Lee metric for which we discuss the density of maximum Lee distance codes with respect to this novel Singleton-like bound.

cs.IT

Generic Decoding of Restricted Errors

Several recently proposed code-based cryptosystems base their security on a slightly generalized version of the classical (syndrome) decoding problem. Namely, in the so-called restricted (syndrome) decoding problem, the error values stem from a restricted set. In this paper, we propose new generic decoders, that are inspired by subset sum solvers and tailored to the new setting. The introduced algorithms take the restricted structure of the error set into account in order to utilize the representation technique efficiently. This leads to a considerable decrease in the security levels of recently published code-based cryptosystems.

cs.CR

On the Number of $t$-Lee-Error-Correcting Codes

We consider $t$-Lee-error-correcting codes of length $n$ over the residue ring $\mathbb{Z}_m := \mathbb{Z}/m\mathbb{Z}$ and determine upper and lower bounds on the number of $t$-Lee-error-correcting codes. We use two different methods, namely estimating isolated nodes on bipartite graphs and the graph container method. The former gives density results for codes of fixed size and the latter for any size. This confirms some recent density results for linear Lee metric codes and provides new density results for nonlinear codes. To apply a variant of the graph container algorithm we also investigate some geometrical properties of the balls in the Lee metric.

cs.IT

On the Density of Codes over Finite Chain Rings

We determine the asymptotic proportion of free modules over finite chain rings with good distance properties and treat the asymptotics in the code length n and the residue field size q separately. We then specialize and apply our technique to rank metric codes and to Hamming metric codes.

cs.IT

Interleaved Prange: A New Generic Decoder for Interleaved Codes

Due to the recent challenges in post-quantum cryptography, several new approaches for code-based cryptography have been proposed. For example, a variant of the McEliece cryptosystem based on interleaved codes was proposed. In order to deem such new settings secure, we first need to understand and analyze the complexity of the underlying problem, in this case the problem of decoding a random interleaved code. A simple approach to decode such codes, would be to randomly choose a vector in the row span of the received matrix and run a classical information set decoding algorithm on this erroneous codeword. In this paper, we propose a new generic decoder for interleaved codes, which is an adaption of the classical idea of information set decoding by Prange and perfectly fits the interleaved setting. We then analyze the cost of the new algorithm and a comparison to the simple approach described above shows the superiority of Interleaved Prange.

cs.IT

Generic Decoding in the Cover Metric

In this paper, we study the hardness of decoding a random code endowed with the cover metric. As the cover metric lies in between the Hamming and rank metric, it presents itself as a promising candidate for code-based cryptography. We give a polynomial-time reduction from the classical Hamming-metric decoding problem, which proves the NP-hardness of the decoding problem in the cover metric. We then provide a generic decoder, following the information set decoding idea from Prange's algorithm in the Hamming metric. A study of its cost then shows that the complexity is exponential in the number of rows and columns, which is in contrast to the behaviour in the Hamming metric, where the complexity grows exponentially in the number of code symbols.

cs.IT

Information Set Decoding for Lee-Metric Codes using Restricted Balls

The Lee metric syndrome decoding problem is an NP-hard problem and several generic decoders have been proposed. The observation that such decoders come with a larger cost than their Hamming metric counterparts make the Lee metric a promising alternative for classical code-based cryptography. Unlike in the Hamming metric, an error vector that is chosen uniform at random of a given Lee weight is expected to have only few entries with large Lee weight. Using this expected distribution of entries, we are able to drastically decrease the cost of generic decoders in the Lee metric, by reducing the original problem to a smaller instance, whose solution lives in restricted balls.

cs.IT