Eurocrypt 2026
Key Attack on the ACDGV Matrix Encryption Scheme
Anmoal Porwal
Technical University of Munich, Munich, Germany
Antonia Wachter-Zeh
Technical University of Munich, Munich, Germany
Pierre Loidreau
DGA and University of Rennes, Rennes, France; CNRS, Rennes, France; IRMAR – UMR 6625, Rennes, France
Keywords: rank metric, matrix codes, McEliece scheme, public-key encryption, structural attack
Abstract
We present an exponential-time key recovery attack on the public-key encryption scheme using matrix codes proposed by Aragon et al. at Asiacrypt 2024. The secret key is a Gabidulin code expanded using an F_q-basis of F_q^m to obtain a matrix code, which is then hidden by appending random rows and columns and by left- and right-multiplication with invertible matrices. Our attack does not rely on the Gabidulin structure and hence applies to most F_q^m-linear codes hidden by their transform. Its complexity is better than the previously best-known distinguisher and significantly better than the naive key recovery algorithm. Our attack breaks some of their proposed parameters. For example, a parameter set targeting 192-bit security is reduced to about 161 bits, and a 256-bit set to about 223 bits.
Publication
EUROCRYPT 2026, LNCS 16544
PaperArtifact
Artifact number
eurocrypt/2026/a14
Artifact published
July 25, 2026
Badge
🏆 IACR EUROCRYPT Results Reproduced
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Anmoal Porwal, Antonia Wachter-Zeh, and Pierre Loidreau. (2026). Key Attack on the ACDGV Matrix Encryption Scheme. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16544, pp. 420–448, Springer. https://doi.org/10.1007/978-3-032-25327-9_15. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a14.