{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T04:21:57Z","timestamp":1775794917317,"version":"3.50.1"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100004359","name":"Vetenskapsr\u00e5det","doi-asserted-by":"publisher","award":["2015-04528"],"award-info":[{"award-number":["2015-04528"]}],"id":[{"id":"10.13039\/501100004359","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100005416","name":"Norges Forskningsr\u00e5d","doi-asserted-by":"publisher","award":["247742\/070"],"award-info":[{"award-number":["247742\/070"]}],"id":[{"id":"10.13039\/501100005416","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Inform. Theory"],"published-print":{"date-parts":[[2019,3]]},"DOI":"10.1109\/tit.2018.2877458","type":"journal-article","created":{"date-parts":[[2018,10,22]],"date-time":"2018-10-22T19:50:30Z","timestamp":1540237830000},"page":"1845-1861","source":"Crossref","is-referenced-by-count":24,"title":["A Key Recovery Reaction Attack on QC-MDPC"],"prefix":"10.1109","volume":"65","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0930-3174","authenticated-orcid":false,"given":"Qian","family":"Guo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Johansson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2002-4240","authenticated-orcid":false,"given":"Paul","family":"Stankovski Wagner","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88702-7_4"},{"key":"ref38","year":"2018","journal-title":"Round 1 Submissions for Post-Quantum Cryptography Standardization"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-29360-8_1"},{"key":"ref32","doi-asserted-by":"crossref","first-page":"266","DOI":"10.1007\/978-3-319-11659-4_16","article-title":"Towards side-channel resistant implementations of QC-MDPC McEliece encryption on constrained devices","author":"von maurich","year":"2014","journal-title":"Post-Quantum Cryptography"},{"key":"ref31","first-page":"38","article-title":"Lightweight code-based cryptography: QC-MDPC McEliece encryption on reconfigurable devices","author":"von maurich","year":"2014","journal-title":"Proc Conf Design Autom Test Eur (DATE)"},{"key":"ref30","volume":"16","author":"macwilliams","year":"1977","journal-title":"The Theory of Error Correcting Codes"},{"key":"ref37","article-title":"Error amplification in code-based cryptography","author":"nilsson","year":"2019","journal-title":"Proc IACR Trans Cryptograph Hardw Embedded Syst (TCHES)"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2013.6620590"},{"key":"ref35","first-page":"114","article-title":"A public-key cryptosystem based on algebraic coding theory","volume":"44","author":"mceliece","year":"1978","journal-title":"Deep Space Network Progress Report"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/2700102"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1972.1054746"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.2478\/tmmp-2014-0025"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2016.7541522"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.8105"},{"key":"ref13","article-title":"QcBits: Constant-time small-key code-based cryptography","author":"chou","year":"2016","journal-title":"Cryptographic Hardware and Embedded Systems"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-79063-3_3","article-title":"QC-MDPC: A Timing Attack and a CCA2 KEM","volume":"10786","author":"eaton","year":"2018","journal-title":"Post Quantum Cryptography"},{"key":"ref15","first-page":"51","article-title":"A reaction attack on the QC-LDPC McEliece cryptosystem","author":"fab\u0161i?","year":"2016","journal-title":"Proc PQCrypto"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511801655"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/18.412683"},{"key":"ref18","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/4347.001.0001","article-title":"Low-density parity-check codes","author":"gallager","year":"1963"},{"key":"ref19","first-page":"24","article-title":"A new class of linear correcting codes","volume":"6","author":"goppa","year":"1970","journal-title":"Problemy Peredachi Informat"},{"key":"ref28","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1007\/3-540-44586-2_2","article-title":"Semantically secure McEliece public-key cryptosystems -conversions for McEliece PKC","author":"kobara","year":"2001","journal-title":"Public Key Cryptography"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2007.161"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2002.802608"},{"key":"ref3","author":"augot","year":"2015","journal-title":"Initial Recommendations of Long-Term Secure Post-Quantum Systems"},{"key":"ref6","first-page":"26","article-title":"Relations among notions of security for public-key encryption schemes","author":"bellare","year":"1998","journal-title":"Adv Cryptology"},{"key":"ref29","doi-asserted-by":"crossref","first-page":"461","DOI":"10.1007\/978-3-642-34129-8_45","article-title":"A new version of McEliece PKC based on convolutional codes","volume":"7618","author":"l\u00f6ndahl","year":"2012","journal-title":"Information and Communications Security"},{"key":"ref5","first-page":"520","article-title":"Decoding random binary linear codes in \n$2^{n\/20}$\n: How 1+1=0 improves information set decoding","author":"becker","year":"2012","journal-title":"Adv Cryptology"},{"key":"ref8","first-page":"213","article-title":"Failure of the McEliece public-key cryptosystem under message-resend and related-message attack","author":"berson","year":"1997","journal-title":"Adv Cryptology"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88702-7"},{"key":"ref2","author":"aragon","year":"2017","journal-title":"BIKE&#x2014;Bit flipping key encapsulation"},{"key":"ref9","first-page":"187","article-title":"Cryptanalysis of the original McEliece cryptosystem","author":"canteaut","year":"1998","journal-title":"Adv Cryptology"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CWIT.2009.5069516"},{"key":"ref20","first-page":"789","article-title":"A key recovery attack on MDPC with CCA security using decoding errors","volume":"10031","author":"guo","year":"2016","journal-title":"Adv Cryptology"},{"key":"ref22","first-page":"273","article-title":"Smaller keys for code-based cryptography: QC-MDPC McEliece implementations on embedded devices","author":"heyse","year":"2013","journal-title":"Cryptographic Hardware and Embedded Systems&#x2014;CHES"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-47942-0_2"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1994.365700"},{"key":"ref24","doi-asserted-by":"crossref","DOI":"10.1007\/BFb0054868","article-title":"NTRU: A ring-based public key cryptosystem","volume":"1423","author":"hoffstein","year":"1998","journal-title":"Algorithmic Number TheoryProc ANTS V"},{"key":"ref41","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1007\/978-3-642-25405-5_4","article-title":"Decoding one out of many","author":"sendrier","year":"2011","journal-title":"Post-Quantum Cryptography"},{"key":"ref23","article-title":"Choosing Parameters for NTRUEncrypt","author":"hoffstein","year":"2015"},{"key":"ref44","author":"yamada","year":"2018","journal-title":"QC-MDPC KEM"},{"key":"ref26","article-title":"NAEP: Provable security in the presence of decryption failures","volume":"172","author":"howgrave-graham","year":"2003"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2018.8437843"},{"key":"ref25","first-page":"226","article-title":"The impact of decryption failures on the security of NTRU encryption","author":"howgrave-graham","year":"2003","journal-title":"Adv Cryptology"}],"container-title":["IEEE Transactions on Information Theory"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/18\/8642547\/08502112.pdf?arnumber=8502112","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T20:52:14Z","timestamp":1657745534000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8502112\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3]]},"references-count":44,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tit.2018.2877458","relation":{},"ISSN":["0018-9448","1557-9654"],"issn-type":[{"value":"0018-9448","type":"print"},{"value":"1557-9654","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,3]]}}}