{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:14:01Z","timestamp":1771611241415,"version":"3.50.1"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Inform. Theory"],"published-print":{"date-parts":[[2012,10]]},"DOI":"10.1109\/tit.2012.2203582","type":"journal-article","created":{"date-parts":[[2012,6,7]],"date-time":"2012-06-07T14:02:10Z","timestamp":1339077730000},"page":"6672-6680","source":"Crossref","is-referenced-by-count":23,"title":["A CCA2 Secure Variant of the McEliece Cryptosystem"],"prefix":"10.1109","volume":"58","author":[{"given":"Nico","family":"Dottling","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rafael","family":"Dowsley","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J\u00f6rn","family":"Muller-Quade","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anderson C. A.","family":"Nascimento","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref38","first-page":"216","article-title":"Side channels in the McEliece PKC","author":"strenzke","year":"2008","journal-title":"Proc Int Workshop Post-Quantum"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1137\/100782929"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/1060590.1060603"},{"key":"ref31","first-page":"433","article-title":"Non-interactive zero-knowledge proof of knowledge and chosen ciphertext attack","author":"rackoff","year":"1991","journal-title":"Proc Crypto"},{"key":"ref30","author":"persichetti","year":"0","journal-title":"Personal communication"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0019850"},{"key":"ref36","author":"sendrier","year":"2010","journal-title":"Advances in Coding Theory and Cryptography 3"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/18.850662"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SFFCS.1999.814628"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795291562"},{"key":"ref11","first-page":"240","article-title":"A CCA2 secure public key encryption scheme based on the McEliece assumptions in the standard model","author":"dowsley","year":"2009","journal-title":"Proc RSA Conf Topics Cryptol"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ITW.2011.6089437"},{"key":"ref13","first-page":"279","article-title":"Algebraic cryptanalysis of McEliece variants with compact keys","author":"faugre","year":"2010","journal-title":"Proc EUROCRYPT"},{"key":"ref14","first-page":"88","article-title":"Security bounds for the design of code-based cryptosystems","author":"finiasz","year":"2009","journal-title":"Proc ASIACRYPT"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(84)90070-9"},{"key":"ref16","author":"goldwasser","year":"2008","journal-title":"Correlation-secure Trapdoor Functions from Lattices"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74143-5_31"},{"key":"ref18","first-page":"73","article-title":"Parallel and concurrent security of the HB and HB+ protocols","author":"katz","year":"2006","journal-title":"Proc EUROCRYPT"},{"key":"ref19","volume":"1992","author":"kobara","year":"2001","journal-title":"Semantically Secure McEliece Public-Key Cryptosystems Conversions for McEliece PKC"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-008-9175-9"},{"key":"ref4","first-page":"743","article-title":"Smaller decoding exponents: Ball-collision decoding","author":"bernstein","year":"2011","journal-title":"Proc Crypto"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/73007.73011"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1007\/978-3-540-88403-3_3","article-title":"Attacking and defending the McEliece cryptosystem","author":"bernstein","year":"2008","journal-title":"Proc Int Workshop Post-Quantum Cryptography"},{"key":"ref6","first-page":"207","article-title":"Chosen-Ciphertext security from identity-based encryption","author":"canetti","year":"2004","journal-title":"Proc EUROCRYPT"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374406"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88403-3_4"},{"key":"ref8","first-page":"157","article-title":"How to achieve a McEliece digital signature scheme","author":"courtois","year":"2001","journal-title":"Proc ASIACRYPT"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/18.651067"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1978.1055873"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0055717"},{"key":"ref1","first-page":"520","article-title":"Decoding random binary linear codes in <formula formulatype=\"inline\"> <tex Notation=\"TeX\">$2^{n\/20}$<\/tex><\/formula>: How <formula formulatype=\"inline\"> <tex Notation=\"TeX\">$1 + 1 = 0$<\/tex><\/formula> improves information set decoding","author":"becker","year":"2012","journal-title":"Proc EUROCRYPT"},{"key":"ref20","author":"lamport","year":"1979","journal-title":"Constructing digital signatures from a one-way function"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/18.21270"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45961-8_25"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/18.915687"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39200-9_15"},{"key":"ref26","first-page":"107","article-title":"Decoding random linear codes in <formula formulatype=\"inline\"><tex Notation=\"TeX\">${\\tilde {\\cal O}}(2^{0.054n})$<\/tex> <\/formula>","author":"may","year":"2011","journal-title":"Proc ASIACRYPT"},{"key":"ref25","author":"mceliece","year":"1978","journal-title":"A public-key cryptosystem based on algebraic coding theory"}],"container-title":["IEEE Transactions on Information Theory"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/18\/6299030\/06213552.pdf?arnumber=6213552","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,1,23]],"date-time":"2018-01-23T18:44:51Z","timestamp":1516733091000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6213552\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,10]]},"references-count":38,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/tit.2012.2203582","relation":{},"ISSN":["0018-9448","1557-9654"],"issn-type":[{"value":"0018-9448","type":"print"},{"value":"1557-9654","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,10]]}}}