Preprint
Article

This version is not peer-reviewed.

Post-Quantum Cryptocode Constructions on Elliptic and Hyperelliptic Curves

Submitted:

23 July 2026

Posted:

27 July 2026

You are already at the latest version

Abstract
The advent of quantum computing threatens the long-term security of classical public-key cryptosystems: RSA and standard elliptic curve cryptography are vulnerable to Shor's algorithm, making quantum-resistant alternatives a priority for modern cryptography. Code-based constructions are among the strongest candidates in post-quantum cryptography. The McEliece and Niederreiter cryptosystems remain competitive after decades of study but suffer from large public keys and reliance on high-order Galois fields, imposing heavy overhead on resource-constrained platforms such as mobile and embedded devices. The symmetric Rao-Nam (RN) construction offers a more compact alternative by operating over smaller fields. This article develops a family of post-quantum cryptographic code constructions (CCC) combining asymmetric McEliece and Niederreiter cryptography with the symmetric Rao-Nam scheme, based on algebraic-geometric codes derived from elliptic curves. It examines systems synthesizing crypto-code constructions with flawed codes to reduce energy costs to GF(2²) while preserving cryptographic strength, alongside an alternative approach using hyperelliptic curves, and CCC built for mobile protocols using LDPC codes. These code families differ structurally: shortened codes tighten parameter control and reduce key material, extended codes raise the minimum distance and robustness, and higher-genus hyperelliptic curves provide richer algebraic structure and stronger security for comparable parameter sizes.
Keywords: 
;  ;  ;  ;  ;  ;  

1. Introduction

The development of the modern theory of post-quantum cryptography is based on the use of a synthesis of classical approaches to constructing cryptosystems of symmetric and asymmetric cryptography with the mechanisms of the theory of noise-resistant coding, which is based on the Galois mathematical apparatus. This is confirmed by the results of the competition for post-quantum algorithms, which determined the winners of the US NIST competition in 2021 to be cryptosystems based on lattices [1,2,3]. At the same time, NIST specialists proposed security levels in the post-quantum cryptoperiod (the emergence of a full-scale quantum computer capable of obfuscating modern symmetric cryptosystems based on the Grover algorithm, and asymmetric cryptosystems based on the Shor algorithm, including algorithms based on elliptic cryptography) [2]. In addition, the determined winners cannot be used in smart technologies and technologies with limited computing resources. Since most of the approved algorithms are based on mathematical problems with lattices, NIST is conducting additional selection to diversify cryptographic approaches for digital signatures [4]. A promising direction of post-quantum cryptography is an alternative approach – the construction of post-quantum cryptosystems based on crypto-code constructions, which are based on the use of noise-resistant coding mechanisms and form integrated cryptosystems that are capable of providing the speed of cryptographic transformation at the level of modern symmetric cryptosystems with the ability to simultaneously correct errors [5,6,7,8,9].
Asymmetric cryptographic code cryptosystems of McEliece and Niederreiter, built on the basis of Goppa codes or abbreviated algebrogeometric codes (AGC), have long been considered one of the most promising post-quantum cryptographic mechanisms due to their high resistance to known quantum cryptanalysis algorithms [5,6,7,8,9]. At the same time, their wide practical application is limited by significant requirements for the amount of memory for storing public keys and generator matrices, as well as increased computational costs for performing encryption, syndrome formation, and decoding procedures.
A promising direction for improving such cryptographic constructions is the use of algebrogeometric codes built on the basis of hyperelliptic curves of higher genera over finite fields, as well as synthesis by mechanisms of lossy cryptography (the use of flawed codes). The use of hyperelliptic geometry makes it possible to provide an equivalent level of cryptographic stability with a lower power of the base field, which contributes to reducing the size of key structures, increasing performance and reducing the computational costs of cryptographic transformations [10]. The basis of the mathematical apparatus of such systems is the group of classes of divisors of zero degree (Jacobian) of the hyperelliptic curve. With an increase in the genus of the curve, the dimension of the Jacobian increases significantly, which leads to an exponential increase in the complexity of solving the discrete logarithm problem. This creates the possibility of implementing cryptographic schemes with shorter keys without reducing the level of cryptographic stability, which is one of the key requirements for modern post-quantum cryptographic systems [10,11].
Despite the expressed theoretical potential, the integration of multidimensional algebraic structures into real crypto-code systems encounters objective algorithmic obstacles. Direct adaptation of existing mechanisms for constructing linear codes is complicated by the need to perform resource-intensive operations on finite points in projective coordinates. As the previous analysis shows, the problem of fast and deterministic calculation of the number of rational points for curves of arbitrary genus over Galois fields remains critical. Exponential growth of computational complexity of calculating the order of the Jacobian blocks the possibility of operational construction of the evaluation matrix based on a given set of monomials. Existing software implementations of asymmetric and symmetric channel coding approaches (in particular, Rao-Nam schemes) reveal vulnerabilities in issues of scalability and energy efficiency. The lack of unified row selection algorithms for forming verification matrices hinders the creation of cryptographic code systems capable of functioning on hardware platforms with strict resource constraints [5,6,7,8,9].
Thus, in the theory of algebrogeometric coding, there are currently no comprehensive algorithmic solutions for designing systems based on hyperelliptic geometry. Overcoming this problem will eliminate the contradiction between the requirements of post-quantum security and the hardware limitations of telecommunication networks. The creation of optimized mechanisms for generating parameters of curves and verification matrices will reduce energy consumption during data processing [4]. Therefore, the construction of alternative post-quantum algorithms based on crypto-code constructions is a promising direction in post-quantum cryptography.

2. Analysis of Literary Data and Problem Statement

The rapid development of post-quantum cryptography makes the study of new algebraic constructions that can provide a high level of cryptographic stability at acceptable computational costs relevant. One of the most promising directions is the use of hyperelliptic curves, the fundamental aspects of which are presented in cryptographic systems in [10]. The results obtained show that the use of hyperelliptic geometry allows to provide a level of security comparable to traditional schemes on elliptic curves, while simultaneously reducing the length of cryptographic keys due to the larger dimension of the group of classes of the zeroth degree divisors.
Despite significant progress in this direction, the problem of effectively determining the number of rational points and the order of the Jacobian of hyperelliptic curves of arbitrary genus over finite fields remains open. The main reason is the high computational complexity of the corresponding algorithms, which grows rapidly with increasing genus of the curve and size of the field. Direct calculation of the order of the Jacobian requires the solution of large-scale systems of nonlinear algebraic equations, which significantly limits the practical application of universal methods for wide classes of hyperelliptic curves [11,12].
One approach to reducing computational complexity is to study specialized classes of hyperelliptic curves for which efficient algorithms for calculating the Jacobian order can be constructed. In particular, in [13] an algorithm is proposed for curves given by fifth-degree polynomials over large simple Galois fields. However, the proposed approach does not extend to finite fields of small characteristic, since it uses mathematical properties characteristic only of simple fields of large power.
At the same time, binary Galois fields are the most attractive for hardware implementation of post-quantum cryptographic algorithms due to the efficient execution of arithmetic operations in digital devices. The lack of universal algorithms for fast determination of the Jacobian order for hyperelliptic curves over fields of small characteristic significantly limits the possibility of their use in high-performance cryptographic primitives and determines the relevance of further research in this direction.
Of considerable interest are studies devoted to the application of deformation methods and cohomological approaches to the calculation of zeta functions of algebraic manifolds [14]. The proposed mathematical apparatus demonstrates the possibility of a significant reduction in the computational complexity of algorithms for determining the number of rational points over fields of small characteristic. In particular, the use of specialized cohomological methods allows reducing the asymptotic requirements for RAM from cubic to quadratic dependence on the dimensionality of the problem. Despite significant theoretical progress, the results of these studies are mainly limited to problems of computational algebraic geometry and practically do not consider the issue of their integration with methods for constructing algebraic-geometric codes and cryptocode constructions.
A promising direction for further research is the transition from abstract cohomology models to the construction of efficient algorithms for arithmetic of Jacobians of hyperelliptic curves. This approach was implemented in [11], where an arithmetic apparatus for sextic hyperelliptic curves (HEC) of genus two in projective coordinates was developed in order to optimize calculations in isogenic cryptography. At the same time, the proposed methods are primarily focused on performing group operations in the Jacobian space and do not solve the problem of constructing code structures with a fixed length of information blocks, a guaranteed minimum code distance and given parameters of parity check matrices, which are necessary for the practical implementation of cryptographic systems.
A separate direction of modern research is associated with the statistical analysis of the properties of Jacobians of hyperelliptic curves over finite extensions of Galois fields [15]. The results obtained show that with increasing curve genus and field strength, the distribution of the number of rational points asymptotically approaches the normal law. Such regularities are important for the theoretical analysis of random families of curves and the evaluation of their statistical characteristics. However, the results presented describe mainly the asymptotic behavior of the corresponding quantities and do not provide constructive methods for determining the parameters of specific algebraic-geometric codes or for synthesizing generator polynomials and parity-check matrices.
In order to improve the accuracy of local estimates, in [16] an analysis of sums of quadratic characters for hyperelliptic curves of fixed genus with variable Galois field strength was proposed. The proposed approach allowed to establish limiting laws of distribution of the number of rational points and to expand theoretical ideas about statistical properties of families of hyperelliptic curves. At the same time, statistical models do not provide direct synthesis of cryptographically stable code structures and require combination with deterministic algorithms for searching for code parameters or heuristic methods of combinatorial optimization, which significantly limits their practical use in the design of post-quantum crypto-code systems.
Further development of theoretical research is connected with analysis of traces of Frobenius classes in moduli spaces of hyperelliptic curves of high genus [17]. The proposed approach, based on integration over ensembles of random matrices, allows to obtain highly accurate estimates of the mathematical expectation of the number of rational points in finite extensions of Galois fields with asymptotic growth of the genus of the curve. However, such results are mainly asymptotic in nature and cannot be directly used for estimation of parameters of hyperelliptic curves of low genus, which are most often used in practical cryptographic systems with limited hardware resources.
One way to overcome this limitation is to use the methods of Diophantine geometry to construct rigorous estimates of the number of rational points. In particular, in works [18,19] analytical limits for curves of low rank were obtained and properties of torsion Jacobians were investigated. Despite the fundamental importance of these results, they are mainly focused on the problems of arithmetic geometry and practically do not consider the issue of using the found rational points in the construction of algebraic-geometric codes and cryptographic structures with given characteristics of immunity.
An important aspect of the study of the security of hyperelliptic cryptosystems is the analysis of rational covers between hyperelliptic and elliptic curves [12]. It is shown that under certain algebraic conditions the problem of discrete logarithmization on certain classes of hyperelliptic curves can be reduced to the corresponding problem on elliptic curves, for which there are effective algorithms of the type Schoof–Elkies–Atkin. This indicates the need to take into account potential isogenic transformations when designing post-quantum cryptographic schemes based on hyperelliptic curves.
One possible way to improve cryptographic robustness is to integrate hyperelliptic constructs into hybrid post-quantum architectures. A similar approach was explored in [20], where a comparative analysis of the performance of standardized post-quantum algorithms in heterogeneous computing environments was performed. However, the main attention was paid to lattice cryptographic schemes, while the possibilities of using algebraic-geometric codes based on hyperelliptic curves remained outside the scope of the study.
A separate area of modern research is devoted to the use of low-density parity check codes (LDPC codes) in crypto-code systems [21]. Due to the sparse structure of the verification matrices, such codes provide high-performance iterative decoding and efficient operation in communication channels with a high level of noise. However, the use of LDPC codes in post-quantum asymmetric cryptosystems is accompanied by a number of problems related to the protection of the public key from modern attacks on the information set. The main reason is the difficulty of hiding the topology of the Tanner graph without significantly increasing the computational cost, which largely negates the advantage of fast decoding.
In [21], the use of quasi-cyclic moderate-density parity-check codes (QC-MDPC) was proposed, which allow a significant reduction in the size of the public key due to the compact representation of the parity-check matrix. Further development of this direction is presented in the studies [22,23], which analyzes implementations of the McEliece cryptosystem based on QC-MDPC codes, aimed at use in embedded computing devices. Particular attention is paid to the comparative analysis of decoding algorithms and their optimization taking into account limited computational and energy resources.
The obtained results confirm the promising use of QC-MDPC codes to reduce the volume of key data without significant deterioration of cryptographic stability. At the same time, the search for alternative code structures capable of further reducing the size of keys while maintaining the required level of post-quantum security remains relevant. In this context, QC-MDPC codes are considered one of the most promising areas for improving modern cryptographic code systems.
In [24], the prospects for using quasi-cyclic LDPC codes (QC-LDPC, Quasi-Cyclic Low-Density Parity-Check) in the McAleese cryptosystem were analyzed. The results obtained indicate that some families of QC-LDPC codes, built on the basis of cyclic permutation matrices, do not provide the required level of cryptographic stability due to the presence of structural vulnerabilities. At the same time, it is shown that constructions formed using the “difference families” approach demonstrate higher resistance to modern cryptanalytic attacks and can be considered as a promising basis for building post-quantum cryptographic code systems.
The generalization of the results of the performed research [25] allowed to conclude that the classical implementations of the McEliece cryptosystem based on LDPC codes do not provide the optimal combination of public key compactness and cryptographic stability. This stimulates the search for alternative code structures that can eliminate the mentioned limitations without a significant increase in computational complexity.
One such direction is the use of moderate-density parity-check codes (MDPC) and their quasicyclic modifications (QC-MDPC), which are proposed in [26]. Unlike classical LDPC codes, MDPC codes are characterized by a higher density of the parity-check matrix, which, although somewhat reduces their error-correcting ability, is quite acceptable for cryptographic applications. In code cryptography, the critical factor is not the maximum correcting ability of the code, but ensuring the required level of computational complexity of the decoding problem, which determines the cryptographic stability of the system.
The advantage of the proposed approach is that, under reasonable assumptions, the problem of recovering the secret key in the McEliece cryptosystem based on MDPC codes reduces to the classical problem of decoding random linear codes. A similar reduction is characteristic of most known attacks on ciphertext, due to which the level of security of such cryptographic constructions is directly based on the well-studied computationally difficult problem of coding theory. This makes MDPC and QC-MDPC codes one of the most promising candidates for building compact and cryptographically stable post-quantum cryptosystems.
One of the promising directions for overcoming these limitations is the use of algebraic-geometric codes with a more structured algebraic nature. In particular, in [1] a modified asymmetric crypto-code system based on truncated elliptic codes was proposed, which allowed to reduce the size of the public key while maintaining the required level of cryptographic stability. However, the use of only curves of the first kind limits the possibility of further increasing the information density and code distance, which makes it advisable to study hyperelliptic curves of higher kinds as a basis for building new post-quantum crypto-code structures.
In [5,6] it is shown that the use of crypto-code constructions allows to achieve a balanced ratio between the level of cryptographic stability and the size of the ciphertext, which is important for the practical application of post-quantum cryptosystems. At the same time, the problem of reducing the computational complexity of the procedures for forming ciphertext and generating keys for resource-limited devices remains relevant. The main limiting factor is the significant computational costs associated with performing operations on dense matrices of high dimension, which limits the effectiveness of classical code-theoretic cryptosystems in environments with strict requirements for energy consumption and performance.
One of the directions for increasing the efficiency of such systems is the use of the concept of flawed (damaged) codes, which involves controlled modification of generating matrices in order to reduce the complexity of cryptographic transformations. The main principles of this approach are proposed in [5], where the properties of hybrid crypto-code constructions are investigated. Further development of the idea consists in the synthesis of crypto-code constructions based on modified elliptic codes (MEC) with a damage mechanism (MV2 algorithm), which provides a significant reduction in computing resources and allows use in systems based on smart technologies and the Internet of Things. However, the proposed solutions do not provide the necessary scalability for devices with limited computing resources. In addition, [21] investigated the use of damaged codes in the construction of complex information protection systems, but the potential of multidimensional algebraic structures to increase the efficiency of crypto-code constructions is not actually considered. The analysis of the above studies shows that the possibilities of using algebraic-geometric codes based on hyperelliptic curves remain insufficiently explored.
A promising direction for solving these problems is the use of algebrogeometric codes based on hyperelliptic curves, which potentially provide higher information density with a shorter length of code constructions. However, the analysis of modern research shows that methods for constructing parity check matrices directly based on jacobians of hyperelliptic curves have not yet received sufficient theoretical justification and practical implementation. This determines the relevance of further research aimed at developing methods for synthesizing algebrogeometric codes based on hyperelliptic curves over finite Galois fields for constructing effective post-quantum cryptocode systems.

3. Purpose and Objectives of the Study

The aim of the research is to analyze and mathematically substantiate the parameters of algebrogeometric crypto-code constructions based on elliptic (EC) and hyperelliptic curves (HEC). This will make it possible to increase the cryptographic stability and operational efficiency of post-quantum information protection systems.
To achieve the goal, the following tasks were set:
  • to analyze mathematical models of algebrogeometric codes based on elliptic curves and hyperelliptic curves of arbitrary genus over a finite Galois field of characteristic 2, formalizing operations on rational points in projective coordinates and Jacobian elements;
  • to analyze the implementation of two promising approaches to building stable cryptographic systems: iterative decoding of LDPC codes (Low-Density Parity-Check) and algebraic decoding of codes on elliptic curves (Elliptic Curve Algebraic-Geometric Codes) within the framework of the McEliece cryptosystem;
  • to conduct a comparative analysis of the construction of McEliece (asymmetric cryptosystem) and Rao-Nam (symmetric cryptosystem) crypto-code structures with EC and HEC.

4. Materials and Methods

The object of research is the algebraic processes of data formation, encoding, and syndromic decoding in crypto-code constructions built on the basis of elliptic, hyperelliptic curves of higher genera over finite Galois fields.
The hypothesis of the study is based on the assertion that the algorithmic transition to calculations exclusively in projective coordinates during the formation of the evaluation matrix will allow synthesizing verification matrices of linear algebraic-geometric codes with optimized Hamming weight. This will ensure a nonlinear reduction in energy and hardware costs at the decoding stage in symmetric and asymmetric cryptosystems while fully preserving the guaranteed level of resistance to structural cryptanalysis.
To construct an algebrogeometric code on elliptic curves, we will use the following statements.
Х – smooth projective algebraic curve in projective space Pn, that is, the set of solutions of a homogeneous irreducible algebraic equation of degree degX with coefficients from GF(q). The geometric interpretation of the elliptic curve is shown in Figure 1.
Algebrogeometric code along a curve Х over GF (q)linear code of length n ≤ N, code words C (с1, с2, ..., сn) of which are given by the equality:
i = 0 k 1 i j F j ( P i ) = c i ,
where Pi(Xi, Yi, Zi) – projective points of a curve Х, that is (Xi, Yi, Zi) – solutions of a homogeneous algebraic equation that define a curve Х, i = 1 , n ¯ ; F j ( P i ) – values of generating functions at points on the curve.
This definition is equivalent to the matrix representation of the algebraic-geometric code [5,6]:
G ( i 0 , i 1 , ... , i k 1 ) Т = ( c 0 , c 1 , ... , c n 1 ) ,
where G – generating matrix of dimension k×n, k = α – g+1, α=degX⋅degF of kind
G = F 0 ( P 0 ) F 0 ( P 1 ) ... F 0 ( P n 1 ) F 1 ( P 0 ) F 1 ( P 1 ) ... F 1 ( P n 1 ) ... ... ... ... F k 1 ( P 0 ) F k 1 ( P 1 ) ... F k 1 ( P n 1 ) = F j P i n , k .
Elliptic curve (EC) in affine space А2 over the field GF (q) is called a smooth curve given by the equation:
y2 + a1xy + a3y = x3 + a2x2 + a4x + a6,
or in Р2 given by a homogeneous equation:
y2z + a1xyz + a3yz2 = x3 + a2x2z + a4xz + a6z3,
aiGF(q), type of curve g = 1.
To ensure the reduction of key data, it is proposed to use the coefficients of the equation, which define a smooth curve.
Algebrogeometric (n, k, d) code along an elliptic curve (elliptic code) over GF(q) built through view mapping ϕ: EC → Pk-1 related to characteristics k + d ≥ n, moreover: n 2 q + q + 1 , k ≥ α, d ≥ n – α, α = 3 ⋅ degF.
If С – class of divisors on the EC of power α > 0, then C defines a mapping ϕ: X → Pk-1, where k ≥ α. Set yi = ϕ(xi) specifies the code. Number of points in the intersection ϕ(EC) with hyperplane equals α, that is n – d ≤ α.
The fundamental basis of synthesized crypto-code constructions is the mathematical apparatus of algebraic geometry [12]. Finite Galois field GF(2m) is strictly given by an irreducible polynomial f(x) and a canonical basis of elements 1, x, x2, …, xm-1. To perform bit vector serialization procedures in the system, integer encoding of the form is used:
v = i = 0 m 1 v i 2 i .
Hyperelliptic curve C of genus g over a field GF(2m) is given by the equation in the general form:
C: y2 + h(x)y = f(x),
where h(x) ∈ GF(2m)[x] is a polynomial with degree deg(h) ≤ g, and f(x) ∈ GF(2m)[x] is a normalized polynomial of degree deg(f) = 2g+1 or deg(f) = 2g+2. A critical requirement for cryptographic applications is the absence of singular points, which means that solutions cannot exist (x, y) ∈ G F 2 m ¯ × G F 2 m ¯ , which would simultaneously satisfy the basic equation C and the system of its partial derivatives [18,19].
For a visual understanding of the topology of hyperelliptic spaces, it is useful to consider their geometric interpretation over continuous fields. Although the cryptographic transformations are performed over discrete finite Galois fields, the overall structural symmetry of the mathematical model is preserved, as shown in Figure 2.
The visualization above demonstrates the characteristic geometric structure of a hyperelliptic curve of the genus g = 2 , which is characterized by the presence of several components of connectivity, which distinguishes it from classical elliptic curves [15]. The points of intersection of the curve with the abscissa axis correspond to the roots of the polynomial f ( x ) and determine the branching points of the two-sheet covering, which form the algebraic basis for constructing divisors. The absence of singularities at all finite points ensures the smoothness of the curve, which is a necessary condition for the existence of a correctly defined Jacobian and the further use of the arithmetic of divisor classes in cryptographic applications [10,15]. For further analysis of the properties of hyperelliptic curves, it is advisable to consider the spatial arrangement of the branching points and their influence on the structure of divisors over a continuous field. Figure 3 shows the topological structure and branching points of a hyperelliptic curve.
The spatial configuration shown in Figure 3 reflects the topological structure of the hyperelliptic curve and the mechanism for the formation of its connectivity components. The points of intersection with the abscissa axis, which correspond to the roots of the normalized polynomial f(x), determine the branching points of the bilayer covering and set the boundaries of local connected regions. The absence of singularities ensures the smoothness of the algebraic variety, excluding the occurrence of self-intersection points, in particular nodes and cusps. Under such conditions, for each non-special rational point there is a unique hyperelliptic involution, which ensures the correctness of group operations in the Jacobian of the curve and is a necessary condition for the application of divisor arithmetic when forming the evaluation matrix.
The set of all finite rational points P=(x,y), which satisfy the equation of the curve, together with a single point at infinity P , forms the complete space of rational points of a hyperelliptic curve [11]. The point P is defined in the projective closure of the curve as the only element of an infinitely distant straight line that satisfies the homogeneous equation of the curve. Such a projective addition ensures the compactness of the algebraic manifold and the correct definition of the group structure of the Jacobian, which is used during the construction of cryptographic primitives.
For each finite point, an involution is determined - its opposite point:
P ¯ = x , y h x .
A point at infinity is its own opposite ( P ¯ = P ). Points for which P = P ¯ , classified as special [12,17].
When using HEC, mathematical problems with divisors are used.
If K – the field of algebraic numbers, and A∩K – the ring of its algebraic integers. The symbol will denote some embedding of the field K into the field of complex numbers. Thus, there exists n ={К : Q], infinite places, and the symbol ∑ – will mean summing over all such infinite places.
Consider a smooth and complete algebraic curve X, defined over the field K. Through Х∞ we denote the Riemann surface associated with the complex curve X∞øC. Let V – an arbitrary smooth and complete model of the curve X over the ring A.
A finite divisor on V will be called a divisor in the usual sense of the term:
D f i n = k i c i ,
where ki – integers, and Ci∩V – irreducible closed sets of co-dimension 1.
Curves Х∞ – are layers of morphism f: V→SpecA at infinitely distant points of the field K. We will call them infinitely distant components; by definition, the divisor can include these components with real coefficients:
D = k i c i + λ χ = D f i n + λ χ ,
where ki€Z, λ€R. Such divisors form a group, which we denote by Div (V). Can be also considered a group Div (C) – this will be a group of divisors of the form
d = p m p p + λ ,
where p – simple field ideals K, Mp€Z, λ€R.
The prime divisors in this group, by definition, will be divisors of the form:
p υ p α p + log α ,
where а€С, and | а*, | = | ∞ (а) |.
The power of the divisor d is a real number:
deg d = m p log N p + λ ,
the degree of the prime divisor is equal to:
log α p + log α .
By definition, the prime divisor
f = f c o m + υ f χ ,
where (f)com – common divisor of a rational function on a two-dimensional diagram V.
If Р^ (V) – the group of prime divisors, which we will define
C I K = D i v V ÷ P V .
The same group can be organized for the Spec K:
C I K = D i v K ÷ P K .
We have homomorphisms:
C I K P I C ,
in the group of divisor classes in the usual sense. Both of these homomorphisms are subjective and have the same kernel, which we will denote by G. The group G is the quotient group of the space under the image of the unit group of the field K under the logarithmic mapping. Of course, it would be natural to identify the complex-connected embeddings of the field K and consider the connected metrics dμ∞, but, probably, such a need will arise upon deeper study, and so far, nothing forces us to do so. Therefore, the group G turned out to be a little larger than one would expect. Finally, we note the homomorphism of the inverse image:
f ÷ C I K C I V .
Thus, group G comes from below.
Systems based on hyperelliptic curves seem to provide a higher level of information protection. An effective algorithm for cracking such systems is also unknown. At this time, information transformation in this case is required more than in the case of elliptic curves. It follows that the problem of increasing computational efficiency is very relevant, since its solution can significantly expand the scope of application of cryptosystems on hyperelliptic curves and transfer them from the category of theoretical research to the plane of practical application. The basis of the structure of such systems are the so-called rational Jacobians of these curves, which are finite Abelian groups. Single messages are marked by Jacobian points. The encryption and decryption function, as in the case of elliptic curves, is the multiplication of a Jacobian point by an integer. Analysis of existing attacks identifies a class of “appropriate” hyperelliptic curves: the number of Jacobian points must be divisible by a large prime number l ~ 1040, l should not divide qk – 1 for small k (1 ≤ k ≤ 2000/log2q), where q – number of elements of a finite field of constants, genus of the curve g should not exceed 4.

5. The Results of Research on the Construction of Crypto-Code Structures on Elliptic and Hyperelliptic Curves

5.1. Analysis of Mathematical Models of Algebrogeometric Codes Based on Elliptic Curves and Hyperelliptic Curves of Arbitrary Genus over a Finite Galois Field of Characteristic 2

The construction of noise-resistant code structures based on hyperelliptic curves involves performing an isomorphic transition to the projective coordinate system [5,6,11]. This approach eliminates the need for computationally expensive operations of finding the multiplicative inverse element in the field GF (2m), which contributes to increasing the efficiency of algorithm implementation [10]. Within this approach, a set of rational projective points is determined Prat, which consists of elements
Pi = (Xi : Yi : Zi).
To form the structure of the evaluation matrix EL a set of algebraic monomials Lj is generated in projective space [21]
L j = X e x , j Y e y , j Z e z , j .
According to the adopted restrictions, a rigidly fixed list of exponent vectors is used (ex, ey, ez) for total powers from two to four, which together form 31 unique monomials. Evaluation matrix EL is formed by calculating the values of each monomial Lj at each point found Pi ∈ Prat [6]:
E L = L 1 P 1 L 1 P 2 L 1 P N L 31 P 1 L 31 P 2 L 31 P N .
The constructed matrix forms a redundant space of candidate vectors for linear code synthesis. The verification matrix is formed by selecting a subset of rows with the index set IH of the power n k . As a result, the verification matrix of the hyperelliptic code H is determined by the corresponding submatrix of the original design [5].
H = E L I H , :
To experimentally assess the effectiveness of the formed matrices, comparative hardware simulation was performed. The constructed verification matrix H and the corresponding generating matrix G were used during the implementation of two crypto-code constructions: the asymmetric McEliece cryptosystem and the symmetric Rao-Nam scheme [4,5].
In the process of architecture synthesis, a mathematical model of an algebraic-geometric code based on a hyperelliptic curve was developed. Formally, the model is presented as a tuple of parameters:
M=(GF(2m), C, Prat, EL, H, G),
where C defines the equation of a hyperelliptic curve, Prat the set of its rational projective points (4), and the matrices EL, H and G specify the structural characteristics of the code space. The proposed mathematical formalization provides the integration of geometric properties of hyperelliptic manifolds into the discrete representation of code structures, which creates the basis for constructing effective algebraic-geometric codes with given parameters [4,5].
The simulation results showed that the choice of a finite field GF(2m) is an important factor in increasing the computational efficiency of implementing code structures. Performing arithmetic operations modulo an irreducible polynomial allows adding field elements as a parallel bitwise exclusive OR (XOR) operation, which significantly simplifies hardware implementation. This approach eliminates the need to use end-to-end bit transfer schemes typical of arithmetic over large-characteristic fields, thereby reducing hardware costs, processing delays, and power consumption of cryptographic modules [4,5].
Figure 4 shows McEliece crypto-code constructions for EC (Figure 4a), MEC ((MEC shortened (Figure 4.b), MEC extended (Figure 4.c).
Masking matrices are used as the private key: G – the generating matrix of a linear (n, k, d) code over GF (q) with polynomial decoding complexity, X is a non-degenerate k × k matrix over GF (q), D is a diagonal matrix with non-zero elements on the diagonal, P is a permutation matrix of size n × n. The generating matrix GХ = X × G × P × D, obtained by multiplying the generating matrix of a linear (n, k, d) code over GF (q) by the masking matrix (X, P, D), is used as the public key.
The use of MEC (shortened and extended) provides a reduction in computational complexity to the field GF (26– 28), and initialization vectors IV1 – defines the set of symbols for the abbreviation of the codeword of the modified code on the EC, IV2 – after using the initialization vector IV1 – defines a set of plaintext symbols that are appended to the codeword. These vectors provide additional key data and provide a fixed level of cryptographic strength while reducing computational complexity and energy consumption.
The closed information (codogram) is a vector of length n and is calculated according to the rule:
с X * = i × G X + e ,
where the vector сХ = i × GХ belongs to (n, k, d) code with a generating matrix GX; ik-bit information vector; vector e – secret weight error vector ≤ t (session secret key).
The Niederreiter crypto-code construction is formed as follows. H is the verification matrix of a linear (n, k, d) code over GF(q) with polynomial decoding complexity. Let Х – nondegenerate r × r-matrix over GF(q), D is a diagonal matrix with nonzero elements on the diagonal, P is a permutation matrix of size n × n. The public key in the Niederreiter CCC is the matrix НХ = X × Н × P × D, the private key is the masking matrices – X, P, D. The private information (codogram) SX is a syndrome – a vector of length r = nk, which is calculated according to the rule:
S X = e × H X T ,
where the vector e – vector of length n and weight ≤ t, which carries confidential information.
To construct the error vector, the mathematical apparatus of equiaxed coding is used, which provides the transformation of the plaintext vector into the error vector. The authorized recipient of the confidential information (who has the private key) finds one of the qk solutions for expression S X = с X * × H X T .
Solution found – codeword with errors с X * = i × G X + e . Next, as in the McEliece scheme, the authorized user constructs a vector с ¯ * = с X * × D 1 P 1 and decodes the received word. However, instead of recovering the information word i’, it calculates the codeword c ' = i ' G , and then the error vector e ' = с ¯ * c ' . The last step is to calculate the vector e = e’× P × D, which carries confidential information.
Figure 5 shows the Niederreiter crypto-code constructions on the corresponding algebrogeometric codes, on EC (Figure 5a), MEC ((MEC shortened (Figure 5.b), MEC extended (Figure 5.c).
The use of initialization vectors, as in the McEliece CCC, provides an appropriate level of stability and reduces the energy consumption and computational complexity of the implementation.
Figure 6 shows the symmetric Rao-Nam CCC.
In the classical Rao–Nam cryptographic scheme, hiding the structure of the algebraic code is achieved by using the generating matrix G and a random error vector, which can perform the function of a session key. The cryptogram is formed by constructing a codeword of a block (n,k,d)-code with the subsequent addition of the error vector. If the algebraic block code is determined by the generating matrix G, then the encryption process is described by the relation [27,28]:
c=IGT+e ,
where I ={I1, I2,…, Ik} – information vector (plaintext block), e ={e1, e2,…, en} – random error vector, weights w(e)≤ t, where t – correcting ability of the noise-tolerant code.
In the modified Rao–Nam cryptographic scheme, a masking matrix Z is additionally used, which provides hiding of the codeword structure. In this case, the cryptogram is formed by multiplying the information vector by the generating matrix, adding a random error vector, and then transforming it using an n×n permutation matrix Z, in which each row and each column contain only one non-zero element [19]:
c = (IGT + e)×Z.
Despite the simplicity of implementation and high speed, Rao–Nam cryptosystems have a number of limitations. The main ones include a significant amount of key data, a potential decrease in cryptographic stability in the context of the emergence of scalable quantum computing, as well as vulnerability to structural attacks, in particular the Sidelnikov attack aimed at restoring the elements of the generating matrix. The use of an orthogonal connection between the generating and verification matrices creates the prerequisites for applying such attacks to both McEliece cryptocode schemes and Niederreiter schemes built on flawed codes [29,30].
One of the promising directions for increasing cryptographic stability is the use of algebraic-geometric codes built on the basis of elliptic curves. Such codes combine the geometric properties of the set of rational points of an elliptic curve with algebraic methods of noise-resistant coding, which ensures the formation of generating and checking matrices with additional structural properties. In addition to the coordinates of the curve points, the coefficients of the elliptic curve equation can be used as an additional initialization parameter. They determine the parameters for constructing the generating and/or checking matrices and can be used as an additional key sequence during the implementation of cryptographic transformations [5,6,11].
To further reduce the capacity and computational complexity of the implementation, hybrid CCCs (HCCCs) are used. HCCCs are based on the synthesis of CCCs on MEC and lossy codes. Figure 7 shows an example of synthesis based on the Rao-Nam HCCC (Figure 7a) and the modified Rao-Nam HMCCC (Figure 7b).
This approach provides the formation of multi-channel cryptography, increases the level of resistance to attacks based on a full-scale quantum computer. The basis of lossy codes is the MV2 algorithm, which provides the conversion of information into a lossy text based on a loss - pseudo-random sequence. In this case, the amount of information expressing this order will be equal to the reduction in the entropy of the text compared to the maximum possible value of entropy, i.e., the equally likely appearance of any letter after any previous letter. The methods of calculating information proposed in [5] allow us to find the ratio of the amount of predicted (i.e., formed according to certain rules) information and the amount of unexpected information that cannot be predicted in advance. The redundancy of the text is determined by the expression:
B ( M ) = B A L 0 = log N H ( M ) L 0 × L 0 ,
where M – original text; B – redundancy of language ( B = R r ; R – redundancy of language ( R = log N ; N – power of the alphabet; r – language entropy per character, r = H ( M ) / L ; L – message length M in language characters)); H(M) – entropy (uncertainty) of the message; L0 message length M characters of the language with content; BА redundancy of language.
HCCC are created in two stages. At the first stage, MEC (HEC) are used, at the second stage, the second variant of using loss codes is used.
Figure 8 shows a block diagram of one step of the universal mechanism for causing damage.
The information core of a text is understood as a damaged text CFT, obtained as a result of the cyclic transformation of the universal mechanism of causing damage Cm.
Universal damage mechanism Cm can be described as [5]:
С F Т / C H F T = E 1 M , K U E C , C H D / C H D = E 2 M , K U E C , M = E 1 , 2 1 ( С F Т / C H F T , C H D / C H D , K U E C ) ,
where С F Т / C H F T = С F Т / C H F T i , ... , С F Т / C H F T m , K U E C = φ ( K D i , ... , K D m , K U 1 E C , ... , K U m E C , C H D / C H D = C H D / C H D i , ... , C H D / C H D m .
Thus, as a result we have two ciphertexts (damage (СHD) and damaged text (FТC)), each of which makes no sense in either the plaintext alphabet or the ciphertext alphabet. In fact, the ciphertext of the original message (M) is presented as a set of two lossy ciphertexts, each of which individually cannot recover the original text.
To restore the original sequence, it is not necessary to know the intermediate damage sequences. It is necessary to know only the last damage sequence (the last damaged text after all cycles) and all damages with the rules for applying them.
Thus, HCCC provide an increase in the level of security of information resources and simplifies the adaptation of cryptographic mechanisms to the requirements of international and national regulatory documents in the field of information security. This is achieved through parametric adaptation and modification of the McEliece and Niederreiter, Rao-Nam cryptographic code systems integrated with multi-channel cryptographic mechanisms based on flawed codes.

5.2. Analysis of the Implementation of Promising Approaches to Building Stable Cryptographic Systems: Iterative Decoding of LDPC Codes (Low-Density Parity-Check) and Algebraic Decoding of Codes on Elliptic Curves (Elliptic Curve Algebraic-Geometric Codes) Within the Framework of the McEliece Cryptosystem

For the research, two approaches to constructing stable post-quantum cryptosystems that can be practically implemented in information and communication systems and mobile technology systems were implemented. The use of LDPC codes (Low-Density Parity-Check) in mobile technologies determined their application in crypto-code constructions that will provide the main security services in systems based on mobile technologies. First of all, this concerns confidentiality, and secondly, the integrity service. This allows creating a modern transition from WPA technologies to the use of post-quantum algorithms based on crypto-code constructions.
The comparative analysis was carried out based on the implementation of two promising approaches to building stable cryptographic systems: iterative decoding of LDPC codes (Low-Density Parity-Check) and algebraic decoding of codes on elliptic curves (Elliptic Curve Algebraic-Geometric Codes) within the framework of the McEliece cryptosystem.
Approach 1. Iterative graph decoding of LDPC codes
The main error correction mechanism for LDPC codes is the Belief Propagation algorithm, also known as the Sum-Product Algorithm. The software implementation uses LLR (Log-Likelihood Ratios) to achieve maximum throughput close to the Shannon limit.
Implementation of the Sum-Product Algorithm
The fragment below demonstrates the basic structure of updating Check Nodes with value clipping to ensure numerical stability of the algorithm.
Preprints 224711 i001Preprints 224711 i002
This algorithm demonstrates high efficiency in channels with additive white Gaussian noise (AWGN), but has significant memory requirements due to the sparse nature of the H matrix.
Approach 2. McEliece cryptosystem based on elliptic codes (EC)
In contrast to classical Reed-Solomon or BCH codes, algebraic geometric codes (AGCs) built on elliptic curves offer higher resistance to structural cryptanalysis. The number of points N on the curve X over the field G F ( q ) is limited by the Hasse-Weyl theorem:
N 2 q g + q + 1 ,
where g = 1 for an elliptic curve.
In order to protect intellectual property and prevent unauthorized copying of the patented approach, the software implementation of the elliptic cryptosystem below is deliberately simplified (some critical algebraic transformations are hidden).
Software Architecture (Schematic Implementation)
Preprints 224711 i003Preprints 224711 i004Preprints 224711 i005
Thus, graph decoding (LDPC) demonstrates optimal results for classical problems of noise-resistant coding, which allows their use in mobile systems and technologies.
At the same time, the use of algebraic geometric codes (EC, MEC) allows to significantly increase the cryptoresistance of McEliece systems due to the hidden geometric structure (divisors on elliptic curves), which complicates the use of standard attacks on the search for low-weight codewords. The implementation of AGC requires a specific approach to calculating the verification matrix H in projective coordinates, the mechanism of which is a key factor in the security of the developed system.

5.3. Comparative Analysis of the Construction of McEliece (Asymmetric Cryptosystem) and Rao-Nam (Symmetric Cryptosystem) Crypto-Code Constructions with EC and HEC Codes

In [4], the mathematical correctness and qualitative energy advantage of crypto-code constructions based on hyperelliptic curves (HEC) over GF(4) were proven. The key result was a 20–60% reduction in processor time for the symmetric Rao–Nam scheme compared to the asymmetric McEliece scheme, obtained on the basis of complexity analysis for parameters (n = 7, genus 2).
The mathematical analysis of the asymptotic complexity of these processes and the dynamics of the growth of computational costs when scaling the code dimension are graphically displayed in Figure 9.
The results shown in Figure 9 illustrate the scalability features of the studied cryptographic schemes with increasing dimensionality of code structures. For the McEliece cryptosystem, an increase in computational costs is observed, which is due to the need to perform operations on matrices and use syndrome tables during decryption. According to the analysis, the computational complexity of this stage is determined by the dependence (O(k2)), which leads to an increase in time and hardware costs with increasing code parameters.
The Rao–Nam scheme is characterized by linear dependence (O(n)), which is achieved by using a sparse check matrix (H) and the absence of matrix inversion operations during decryption. This organization of the computational process provides lower costs of processor resources compared to the asymmetric scheme.
The shaded area between the curves characterizes the difference in computational costs between the studied approaches and reflects the potential gain in the use of processor time and energy resources when the codeword length increases.
The obtained results show that the application of the proposed algebraic-geometric code in the symmetrical Rao–Nam scheme allows to reduce the computational complexity of the decryption process and increase the energy efficiency of the implementation. This makes the proposed approach promising for use in resource-limited devices and embedded cryptographic systems.
This result has two limitations that prevent it from being used as a quantitative practical guideline:
Lack of absolute CPB (cycles per byte) measurement. The 20–60% figure is relative and intrinsic to HEC. It does not put HEC designs on the same scale as the established baseline on elliptic curves (EC), where Niederreiter achieves 10,916 CPB and McEliece achieves 104,030 CPB at n = 10 using Callgrind methodology (2 GHz, 5% OS load).
Only one code family was investigated. In [4], only HEC codes were analyzed. There was no direct comparison between EC and HEC designs using the same metric in the group’s publications.
For further research, we overcome both limitations by running a 2×2 controlled experiment – by scheme type (McEliece vs. Rao–Nam) and curve family (EC vs. HEC) – with code lengths n∈ {10,100, 1000} bytes of plaintext per run. To conduct the research, we define the metric and measurement parameters:
CPB (cycles per byte) – number of processor cycles spent per byte of plaintext. A hardware-independent metric when normalized to a reference platform.
\text{CPB} = \frac{f \cdot \eta \cdot t_{\text{exec}}}{n_{\text{bytes}}}
С Р В = f × η × t e x e c η b y t e s ,
where f=2×109 Hz (reference processor), η=0,05 (5% background OS load), texec measured execution time in seconds.
Profiling parameters:
Reference processor – 2 GHz, single core;
OS load – 5%;
Number of tests per point – 100 (average ± σ);
Thrown away for warm-up – 10 tests;
Error weight – te =1;
Scaling EC codes: n=10, FG(22), EC(7, 4), 1 byte/block; n=100, FG(23),
EC(13, 10), 3,75 byte/block; n=1000, FG(26), EC(55, 52), 39,0 byte/block. HEC always uses GF(4), k = 4 → 1,0 byte/block for all n.
CPB per block – the number of clock cycles to encode and decode one codeword (one round of encryption + decryption), regardless of the number of information bytes in the block. This metric eliminates the asymmetry of depreciation: as n increases, an EC block carries more bytes, while an HEC block always contains 1 byte.
\text{CPB}{\text{block}} = \text{CPB}{\text{byte}} \times \frac{n_{\text{bytes}}}{n_{\text{blocks}}}
С Р В b l o c k = С Р В b y t e η b y t e s η b l o c k ,
The following limitations were identified during the research:
  • Measurements based on astronomical time. Absolute CPB values are approximated against Callgrind references from the CCC thesis. Relative comparisons between cells are valid because all four cells are measured using identical methodology.
  • HEC is fixed at n = 7. A genus 2 curve over GF(4) has exactly 7 rational points. Multiblock coding correctly models real deployment (the same scheme encrypts large payloads in blocks), but does not allow for the observation of HEC scaling with the intrinsic code length.
  • Toy parameters. At k = 4, the difference in complexity between the O(k2) schemes is negligible. The theoretical advantage of Ra-Nam over McEliece is fully realized at larger k, which corresponds to the scale of practical deployment.
  • EC Rao–Nam for large n. At n = 1000, solving the linear system in GF(64) becomes the dominant cost in the Rao–Nam decoding, partially neutralizing the advantage of the scheme over McEliece in large fields.
Table 1 and Figure 10 show the results of studies evaluating CPB for one codeword (four cells).
Thus, the analysis of Table 1 and Figure 10 showed that at n = 10 (both families use GF(4) – the same algebraic setup): EC is ~10–16% cheaper per block. The advantage of projective coordinates of HEC does not yet outweigh the larger number of monomials of the computation matrix. At n = 100 (EC switches to GF(8)): HEC becomes 20–21% cheaper per block. The arithmetic of the GF(8) field, in particular the inversion by the extended Euclidean algorithm, adds cost.
At n = 1000 (EC switches to GF(64)): HEC is 7.4–8.5 times cheaper per block. Affine inversion in GF(64) dominates the EC block cost; HEC remains on cheap projective arithmetic GF(4) for all n.
The n* intersection point (Figure 9): Between n = 10 and n = 100. Interpolation on a logarithmic scale gives n* ≈ 20–50 – the advantage of HEC is realized when the overhead of the EC field arithmetic starts to exceed the overhead of the HEC computation matrix.
Table 2 and Figure 11 show the results of the evaluation of the acceleration of the symmetric Rao–Nam CCC against the asymmetric McEliece crypto-code construction (the ratio of CPB per block McEliece / Rao–Nam).
Analysis of Table 2 and Figure 11 showed that the Rao–Nam CCC is consistently 21–25% cheaper than McEliece in both families of curves for all n. For HEC, the advantage remains unchanged regardless of n – which is consistent with the theoretical prediction of eliminating the S-1 operation and the syndrome table search.
For EC at n = 1000 (GF(64)), the ratio decreases to ×1.09, as the solution of the linear system becomes the dominant cost in both schemes at large fields.
Table 3 and Figure 12 show the results of comparing the HEC/EC ratio according to computational complexity (cheapness), with > 1 meaning that HEC is cheaper.
Thus, the analysis of Table 3 and Figure 12 shows that at n = 1000 the advantage of HEC per block over EC is 7.4 times for McEliece and 8.5 times for Rao-Nam – due solely to the difference in cost between affine arithmetic GF(64) (EC) and projective arithmetic GF(4) (HEC). The intersection point is stable for both types of schemes and lies between n = 10 and n = 100.
At the same time, the analysis showed that the Rao-Nam CCC is consistently 21-25% cheaper than the McEliece CCC per codeword in both the EC and HEC families at all tested code lengths. The advantage is at the scheme level and independent of the family - it comes from the elimination of the S−1¹ operation and the syndrome table lookup during decryption. HEC becomes cheaper than EC per block for n ≥ n* ≈ 20-50. For n = 1000, HEC requires 7-9 times fewer clock cycles per codeword than EC. The reason is architectural: HEC uses projective arithmetic GF(4) (without inversion) for all n, while EC switches to affine arithmetic GF(8)/GF(64) (with inversion according to the extended Euclidean algorithm) to achieve equivalent code lengths. HEC Rao–Nam is the design with the minimum CPB per block for n ≥ 100. For n = 1000: HEC Rao–Nam achieves 20,230 cycles/block versus 171,615 for EC Rao–Nam and 186,382 for EC McEliece – an 8.5x advantage over the next best alternative. The CPB per byte metric favors EC for all n due to the depreciation effect (EC blocks carry more bytes for larger n).
Estimation of the asymptotic complexity of the basic stages of cryptosystem operation.
Analysis of the asymptotic computational complexity of the main stages of the proposed cryptosystem’s operation showed that the construction of the evaluation matrix (EL), as well as the generating (G) and verification (H) matrices is characterized by polynomial complexity. Similarly, the encryption procedure for one information block, which includes vector-matrix multiplication and addition of the error vector, is performed in polynomial time. At the same time, for the classical McEliece cryptosystem, the greatest computational costs are associated with the formation of a syndrome table, the memory capacity of which grows exponentially with increasing code parameters. The decryption procedure involves searching for the corresponding syndrome in the table and further solving a system of linear equations over a finite field.
For quantitative assessment of energy consumption, the assumption was used that, at a constant average power consumption, the number of processor cycles or the execution time of the algorithm is proportional to energy consumption. Profiling of computational resources was performed using specialized tools for analyzing program code performance (in particular, Valgrind/Callgrind), which provided an assessment of the processor load at the level of individual algorithmic operations.
For the McEliece cryptographic code system implemented over the field (GF(4)), the characteristics of three basic algorithmic primitives were determined:
  • symbol reading (operations of reading and writing elements (GF(4)) in vectors) – an average of 27 processor cycles;
  • comparing rows when searching for a syndrome in a table – 54 processor cycles;
  • concatenation of strings when forming a buffer or resulting data structure – 297 processor cycles.
The conversion into time indicators was performed under the condition of a fixed processor clock frequency of 2 GHz and a controlled background load of the operating system at the level of 5%. The obtained results of instrumental measurement of energy consumption for the asymmetric scheme are summarized in Table 4 [4,5].
The results given in Table 4 show that the main part of the computational costs in the McEliece cryptosystem is accounted for by operations related to the processing of syndrome tables and memory access. To assess the optimization possibilities, the symmetric Rao–Nam scheme was considered, in which the error vector is formed using a shared secret key, and the decryption procedure is based on syndrome decoding without the use of linear systems solution procedures. A comparison of the architectural features of both schemes is given in Table 5 [4,5].
The analysis of experimental results showed that for codes with small values of parameters ((n=7), (t_e=1)) the measured execution time significantly depends on the overhead of the software environment. The simulation was performed using Python 3.13 and the SageMath computer algebra system, the use of which ensured the reproducibility of calculations and the correct execution of operations on finite fields. Under such conditions, the difference in performance between the studied schemes was 20–60% in favor of the symmetric design.
With increasing code design parameters, the influence of software environment overhead gradually decreases, and the algorithmic complexity of the decryption procedure becomes the determining factor. In the Rao–Nam scheme, the absence of a stage for solving systems of linear equations provides lower computational costs compared to the McEliece cryptosystem. To confirm the asymptotic estimates, simulations were conducted for large-length codes ((n>1000)). The obtained results demonstrate the approximation of the time complexity of the symmetric scheme to a linear dependence, which confirms its better scalability and higher computational efficiency when using high-dimensional codes.

6. Discussion of the Crypto-Code Constructions Research Results

The development of systems and technologies requires reliable security in the post-quantum period. At the same time, minimization and strict limitations on computing resources are introduced, the struggle to preserve the energy efficiency of systems based on smart and mobile technologies is being fought. The emergence of a full-scale quantum computer can lead to the collapse of security systems based on modern symmetric and asymmetric cryptosystems. Therefore, the use of innovative transition to security systems of the post-quantum period requires the use of fundamentally new mechanisms.
The conducted studies confirm the practical significance and possibility of using crypto-code constructions, both the symmetric Rao-Nam scheme and the asymmetric McEliece and Niederreiter cryptosystems. At the same time, the use of various algebrogeometric codes – codes that are based on the use of parameters of a geometric figure and the mathematical apparatus of noise-resistant coding allows them to be used practically in all systems of the information space. At the same time, such an approach – changing noise-resistant codes – provides the possibility of providing cryptographic protection of any information for any period. The conducted studies of the properties of EC and HEC codes confirm the possibility of their use in limited computational and energy-intensive indicators.
The study of the computational costs of encoding/decoding, which are given in Table 1, Table 2, Table 3, Table 4 and Table 5, Figure 10, Figure 11 and Figure 12, guarantees the choice of not only the crypto-code construction – symmetric or asymmetric, but also the choice of a noise-resistant code in accordance with the requirements for time and flow of information resources. A promising direction for further research is the use of crypto-code constructions in digital signature and authentication protocols, as well as multi-factor authentication procedures.

7. Conclusions

The conducted studies of post-quantum algorithms based on crypto-code constructions confirm their practical implementation on algebro-geometric and lossy codes for use in information and communication systems and networks. For use in systems with limited computational and energy-intensive indicators, it is proposed to use hybrid crypto-code constructions based on the synthesis of modified (shortened/extended elliptic codes) with lossy codes of multi-channel cryptography. To ensure security services - confidentiality and integrity in mobile technology systems, it is proposed to use the Rao-Nam symmetric crypto-system on EC/MEC, and/or McEliece and Niederreiter on LDPC codes.
The results of the analysis show that LDPC codes are appropriate for implementing noise-resistant coding mechanisms in modern telecommunication systems, while algebraic-geometric codes based on elliptic curves are a promising basis for constructing post-quantum cryptosystems. The use of the projective representation of the verification matrix H allows hiding the internal structure of the code construction, which increases the resistance of the McEliece cryptosystem to known structural cryptanalysis attacks and contributes to strengthening its cryptographic security.
The conducted study confirmed that the symmetric Rao–Nam scheme provides a stable reduction in computational costs compared to the McEliece cryptosystem (by approximately 21–25% per codeword) regardless of the code design used, which is achieved by eliminating the operations of inverting the S−1¹ matrix and searching in the syndrome table. At the same time, the use of hyperelliptic algebraic-geometric codes (HEC) provides an additional increase in computational efficiency with increasing code length. Starting from the region n ≥ n* ≈ 20–50, HEC designs outperform elliptic curve codes (EC), and for n=1000 they demonstrate a reduction in the number of processor cycles per codeword by a factor of 7–9. The best results were obtained for the Rao–Nam HEC scheme, which is characterized by the minimum cost of processor resources among all the studied options. The results obtained confirm that the use of the CPB metric per codeword is a more correct criterion for comparing the algorithmic efficiency of cryptographic structures, since it eliminates the influence of the depreciation effect and objectively reflects the real computational costs.

Author Contributions

Conceptualization, Serhii Yevseiev, Stanislav Milevskyi; methodology, Serhii Yevseiev, Stanislav Milevskyi; software, Serhii Pohasii, Vladyslav Sokol; validation, Serhii Yevseiev, Stanislav Milevskyi, Olena Akhiiezer; formal analysis, Serhii Yevseiev, Stanislav Milevskyi, Olena Akhiiezer; investigation, Serhii Yevseiev, Serhii Pohasii; resources, Serhii Yevseiev, Vladyslav Sokol; data curation, Serhii Pohasii, Olena Akhiiezer; writing—original draft preparation, Serhii Yevseiev; writing—review and editing, Stanislav Milevskyi, Serhii Pohasii, Olena Akhiiezer; visualization, Vladyslav Sokol; supervision, Serhii Yevseiev; project administration, Serhii Yevseiev. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

Data are contained within the article.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process. Available online: https://www.nist.gov/publications/status-report-fourth-round-nist-post-quantum-cryptography-standardization-process.
  2. Post-Quantum Cryptography. Available online: https://csrc.nist.gov/projects/post-quantum-cryptography.
  3. Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process. Available online: https://www.nist.gov/publications/status-report-fourth-round-nist-post-quantum-cryptography-standardization-process.
  4. Akhiiezer, O.; Kushnerov, O.; Nelasa, H.; Korol, O.; Yamkovyi, K.; Voitko, O.; Sokol, V.; Voloshchuk, O.; Novoseletskyi, O.; Nelasyi, O. Development of crypto-code constructions on hyperelliptic curves. East.-Eur. J. Enterp. Technol. 2026, 2(9 (140), 6–18. [Google Scholar] [CrossRef]
  5. Yevseiev; other. Synergy of Building Cybersecurity Systems (May 24, 2021). РС ТЕСHNOLOGY СЕNTЕR; Kharkiv, 2021; 188. Available online: https://ssrn.com/abstract=3918825. [CrossRef]
  6. Yevseiev; other. MODELING OF SECURITY SYSTEMS FOR CRITICAL INFRASTRUCTURE FACILITIES; TECHNOLOGY CENTER PC: Kharkiv, 2022. [Google Scholar] [CrossRef]
  7. Milevskyi, S.; Korol, O.; Mykytyn, G.; Lozova, I.; Solnyshkova, S.; Husarova, I.; Hrebeniuk, A.; Vlasov, A.; Sukhoteplyi, V.; Balagura, D. Development of the sociocyberphysical systems` multi-contour security methodology. East.-Eur. J. Enterp. Technol. 2024, 1(9 (127), 34–51. [Google Scholar] [CrossRef]
  8. Yevseiev, S.; Milevskyi, S.; Melnyk, M.; Opirskyy, I.; Stakhiv, M.; Stakhiv, R. Entropy Method for Assessing the Strength of Encryption Algorithms. 2024 International Congress on Human-Computer Interaction, Optimization and Robotic Applications (HORA), Istanbul, Turkiye; 2024, pp. 1–9. [CrossRef]
  9. Yevseiev, S.; Havrylova, A.; Milevskyi, S.; Sinitsyn, I.; Chalapko, V.; Dukin, H.; Hrebeniuk, V.; Diedov, M.; Bekirova, L.; Shpak, O. Development of an improved SSL/TLS protocol using post-quantum algorithms. East.-Eur. J. Enterp. Technol. 2023, 3(9 (123), 33–48. [Google Scholar] [CrossRef]
  10. Alimoradi, R. A Study of Hyperelliptic Curves in Cryptography. IJCNIS 2016, 8(8), 67–72. [Google Scholar] [CrossRef]
  11. Sato, K.; Onuki, H.; Takagi, T. Explicit addition formulae on hyperelliptic curves of genus 2 for isogeny-based cryptography. JSIAM Lett. 2024, 16, 65–68. [Google Scholar] [CrossRef]
  12. Fan, J.; Fan, X.; Song, N.; Wang, L. Hyperelliptic Covers of Different Degree for Elliptic Curves. Math. Probl. Eng. 2022, 2022(1), 9833393. [Google Scholar] [CrossRef]
  13. Furukawa, E.; Kawazoe, M.; Takahashi, T. Counting Points for Hyperelliptic Curves of Type y2=x5+ax over Finite Prime Fields. In Selected Areas in Cryptography; 2004; pp. 26–41. [Google Scholar] [CrossRef]
  14. Hubrechts, H. MEMORY EFFICIENT HYPERELLIPTIC CURVE POINT COUNTING. Int. J. Number Theory 2011, 07(01), 203–214. [Google Scholar] [CrossRef]
  15. Xiong, M.; Zaharescu, A. Statistics of the Jacobians of hyperelliptic curves over finite fields. Math. Res. Lett. 2012, 19(2), 255–272. [Google Scholar] [CrossRef]
  16. Kurlberg, P.; Rudnick, Z. The fluctuations in the number of points on a hyperelliptic curve over a finite field. J. Number Theory 2009, 129(3), 580–587. [Google Scholar] [CrossRef]
  17. Chinis, I. J. Traces of high powers of the Frobenius class in the moduli space of hyperelliptic curves. Res. Number Theory 2016, 2(1), 13. [Google Scholar] [CrossRef]
  18. Conceição, R. ON INTEGRAL POINTS ON ISOTRIVIAL ELLIPTIC CURVES OVER FUNCTION FIELDS. Bull. Aust. Math. Soc. 2020, 102(2), 177–185. [Google Scholar] [CrossRef]
  19. Katz, E.; Rabinoff, J.; Zureick-Brown, D. Uniform bounds for the number of rational points on curves of small Mordell–Weil rank. Duke Math. J. 2016, 165(16). [Google Scholar] [CrossRef]
  20. Abbasi, M.; Cardoso, F.; Váz, P.; Silva, J.; Martins, P. A Practical Performance Benchmark of Post-Quantum Cryptography Across Heterogeneous Computing Environments. Cryptography 2025, 9(2). [Google Scholar] [CrossRef]
  21. Misoczki, R.; Tillich, J.-P.; Sendrier, N.; Barreto, P. S. L. M. 2012. MDPC-McEliece: New McEliece Variants from Moderate Density Parity-Check Codes. Cryptology ePrint Archive, Report 2012/409. Available online: http://eprint.iacr.org/.
  22. Baldi, M.; Bodrato, M.; Chiaraluce. F.: A New Analysis of the McEliece Cryptosystem Based on QC-LDPC Codes. In SCN 2008. LNCS; Ostrovsky, R., Prisco, R.D., Visconti, I., Eds.; Springer: Heidelberg, 2008; vol. 5229, pp. 246–262. [Google Scholar]
  23. Chang, K.; M., I.B. Researchers Inch Toward Quantum Computer. In New York Times; 2012; Available online: http://www.nytimes.com/2012/02/28/technology/ibm-inch-closer-on-quantum-computer.html?_r=1&hpw.
  24. Baldi, M.; Chiaraluce, F.; Garello, R.; Mininni, F. Quasi-Cyclic Low-Density Parity-Check Codes in the McEliece Cryptosystem. Communications, 2007. ICC ’07. IEEE International Conference on, 2007; pp. pages 951–956. [Google Scholar]
  25. Monico, C.; Rosenthal, J.; Shokrollahi, A. Using Low Density Parity Check Codes in the McEliece Cryptosystem. Information Theory, 2000. Proceedings. IEEE International Symposium on, 2000; p. 215. [Google Scholar]
  26. Otmani, J.-P.; Tillich; Dallot, L. Cryptanalysis of Two McEliece Cryptosystems Based on Quasi-Cyclic Codes. Math. Comput. Sci. 2010, 3(2), 129–140. [Google Scholar] [CrossRef]
  27. Struik, R.; Van Tilburg, J. “The Rao-Nam Scheme is insecure against a chosen-plaintext attack”, A Rump Session paper, CRYPTO’ 87. A revised version appears in this issue.; 1987. [Google Scholar]
  28. Cheng, Yi Chang; Lu, Erl Huei; Wu, Shaw Woei. A modified version of the Rao-Nam algebraic-code encryption scheme. 1998. Available online: https://www.sciencedirect.com/science/article/pii/S0020019098001562#aep-bibliography-id5.
  29. Sidelnikov, V. M. A public-key cryptosystem based on binary Reed-Muller codes. Discret. Math. Appl. 1994, vol. 4(no. 3), 191–208. [Google Scholar]
  30. Minder, L.; Shokrollahi, A. Cryptanalysis of the Sidelnikov cryptosystem. In Advances in Cryptology - EUROCRYPT 2007; Springer, 2007; pp. 347–360. [Google Scholar]
Figure 1. Geometric interpretation of an elliptic curve.
Figure 1. Geometric interpretation of an elliptic curve.
Preprints 224711 g001
Figure 2. Geometric interpretation of a hyperelliptic curve of the second kind.
Figure 2. Geometric interpretation of a hyperelliptic curve of the second kind.
Preprints 224711 g002
Figure 3. Topological structure and branch points of a hyperelliptic curve.
Figure 3. Topological structure and branch points of a hyperelliptic curve.
Preprints 224711 g003
Figure 4. McEliece crypto-code construction.
Figure 4. McEliece crypto-code construction.
Preprints 224711 g004
Figure 5. Niedereiter crypto code construction.
Figure 5. Niedereiter crypto code construction.
Preprints 224711 g005
Figure 6. Rao-Nam crypto code construction.
Figure 6. Rao-Nam crypto code construction.
Preprints 224711 g006
Figure 7. Rao-Nam hybrid crypto-code construction.
Figure 7. Rao-Nam hybrid crypto-code construction.
Preprints 224711 g007
Figure 8. Block diagram of one step of the universal damage mechanism.
Figure 8. Block diagram of one step of the universal damage mechanism.
Preprints 224711 g008
Figure 9. Dynamics of decoding computational complexity growth when scaling code parameters.
Figure 9. Dynamics of decoding computational complexity growth when scaling code parameters.
Preprints 224711 g009
Figure 10. Results of studies evaluating CPB per codeword.
Figure 10. Results of studies evaluating CPB per codeword.
Preprints 224711 g010
Figure 11. CPB ratio on McEliece / Rao–Nam block.
Figure 11. CPB ratio on McEliece / Rao–Nam block.
Preprints 224711 g011
Figure 12. Comparison of CPB on EC block / CPB on HEC block.
Figure 12. Comparison of CPB on EC block / CPB on HEC block.
Preprints 224711 g012
Table 1. CPB score per codeword.
Table 1. CPB score per codeword.
Construction Field n = 10 n = 100 n = 1000
[A] Rao–Nam / EC GF(4) → GF(8) → GF(64) 20 108 26 442 171 615
[B] McEliece / EC GF(4) → GF(8) → GF(64) 25 222 32 532 186 382
[C] Rao–Nam / HEC GF(4) constant 23 237 20 987 20 230
[D] McEliece / HEC GF(4) constant 28 043 25 889 25 107
Table 2. CPB Ratio for McEliece/Rao–Nam Block.
Table 2. CPB Ratio for McEliece/Rao–Nam Block.
Family n = 10 n = 100 n = 1000
HEC (Cells C/D) ×1,21 ×1,23 ×1,24
EC (Cells A/B) ×1,25 ×1,23 ×1,09
Table 3. CPB Ratio for McEliece/Rao–Nam Block.
Table 3. CPB Ratio for McEliece/Rao–Nam Block.
Scheme n = 10 n = 100 n = 1000
ССС McEliece 0,90 (EC is cheaper) 1,26 (HEC is cheaper) 7,42 (HEC is cheaper)
ССС Rao–Nam 0,87 (EC is cheaper) 1,26 (HEC is cheaper) 8,48 (HEC is cheaper)
Table 4. Results of energy consumption evaluation of the McEliece crypto-code system on the GF(4) EC.
Table 4. Results of energy consumption evaluation of the McEliece crypto-code system on the GF(4) EC.
Code sequence length McEliece GF(4)
Length of information vector 10 100 1000
Number of function calls implementing elementary operations Reading a character 30 492 615 70 813 373 13 374 171
String comparison 8 706 738 26 190 840 4 401 031
String concatenation 4 446 793 13 279 110 2 443 144
Sum 43 646 146 110 283 323 20 218 346
Function execution time in processor cycles Reading a character 760 162 1 870 396 406 161
String comparison 469 732 1 251 694 216 051
String concatenation 1 338 255 3 518 200 752 933
Sum 2 568 149 6 640 290 1 375 145
Execution time in 10-6 s 0.54 1.54 3.8
Table 5. Comparative analysis of the McEliece and Rao-Nam crypto-code systems over the field GF(4).
Table 5. Comparative analysis of the McEliece and Rao-Nam crypto-code systems over the field GF(4).
Indicator GF(4) McEliece GF(4) Rao-Nam
Architecture type Asymmetric (public-key) Symmetric (symmetric / secure channel coding)
Dominant calculations Syndrome calculation + lookup + solution of linear system of equations Code decoding + streaming PRNG generation
Decoding scalability Missing for syndrome table (exponential memory growth) Depends on the code (can approach linear time complexity)
Estimated cost difference per 1 block (time / cycles / energy) Baseline benchmark (100% of costs) 20% – 60% less (40% – 80% of McEliece base costs)
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.