arXiv · 2609.30925
How to break the Miranda signature scheme over matrix Gabidulin codes
Abstract
The Miranda signature scheme relies on masking a matrix code which disposes of a masked underlying structure, and the knowledge of which allows for efficient error decoding. We consider a Gabidulin code which is expanded into a matrix code, that is only \Fq-linear. An additional masking is then applied to it. The attack proposed here shares similarities with that of [Le26, https://arxiv.org/abs/2608.03328] on the EGMC encryption scheme, which also follows the paradigm described above. It consists in recovering the Fqm-linear structure of a masked matrix Gabidulin code by reducing to a MinRank instance to be solved over the extension field Fqm, but where the matrices have coefficients in Fq. Such an instance can be efficiently solved. However, unlike the previous attack, it is possible to reduce in polynomial time to such a MinRank instance in the case of the Miranda signature scheme. This results in a particularly efficient key recovery attack against the parameters proposed for Miranda. For example, for the proposed parameter set with m=79, the complexity drops from 146 bits to 46 bits in this attack.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Adrien Vinçotte. 2026-09-25. How to break the Miranda signature scheme over matrix Gabidulin codes. https://arxiv.org/abs/2609.30925
Cite the original work for its findings. Save a collection to share your selection of sources.