{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:31:29Z","timestamp":1785421889296,"version":"3.56.0"},"reference-count":13,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T00:00:00Z","timestamp":1720483200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>We analyze Layered ROLLO-I, a code-based cryptosystem published in IEEE Communications Letters and submitted to the Korean post-quantum cryptography competition. Four versions of Layered ROLLO-I have been proposed in the competition. We show that the first two versions do not provide the claimed security against rank decoding attacks and give reductions to small instances of the original ROLLO-I scheme, which was a candidate in the NIST competition and eliminated there due to rank decoding attacks. As a second contribution, we provide two efficient message recovery attacks, affecting every security level of the first three versions of Layered ROLLO-I and security levels 128 and 192 of the fourth version.<\/jats:p>","DOI":"10.62056\/a6qgy11zn4","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T11:13:33Z","timestamp":1728299613000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Analysis of Layered ROLLO-I:  A BII-LRPC code-based KEM"],"prefix":"10.62056","author":[{"given":"Seongtaek","family":"Chee","sequence":"first","affiliation":[{"name":"The Affiliated Institute of ETRI","place":["Daejeon, 34044, Republic of Korea"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kyung","family":"Jeong","sequence":"additional","affiliation":[{"name":"The Affiliated Institute of ETRI","place":["Daejeon, 34044, Republic of Korea"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tanja","family":"Lange","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02c2kyt77","id-type":"ROR","asserted-by":"publisher"}],"name":"Eindhoven University of Technology","place":["The Netherlands"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nari","family":"Lee","sequence":"additional","affiliation":[{"name":"The Affiliated Institute of ETRI","place":["Daejeon, 34044, Republic of Korea"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1976-9269","authenticated-orcid":false,"given":"Alex","family":"Pellegrini","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02c2kyt77","id-type":"ROR","asserted-by":"publisher"}],"name":"Eindhoven University of Technology","place":["The Netherlands"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hansol","family":"Ryu","sequence":"additional","affiliation":[{"name":"The Affiliated Institute of ETRI","place":["Daejeon, 34044, Republic of Korea"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"ref1:1994\/Shor","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1109\/SFCS.1994.365700","article-title":"Algorithms for Quantum Computation: Discrete Logarithms and\n  Factoring","author":"Peter W. Shor","year":"1994"},{"key":"ref2:2009\/bernstein","isbn-type":"print","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-540-88702-7","volume-title":"Post-Quantum Cryptography","author":"Daniel\u00a0J. Bernstein","year":"2009","ISBN":"https:\/\/id.crossref.org\/isbn\/9783540887027"},{"key":"ref3:2022\/weger","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2201.07119","article-title":"A Survey on Code-Based Cryptography","author":"Violetta Weger","year":"2022","journal-title":"CoRR"},{"key":"ref4:1978\/rjmceliece","volume-title":"A Public-Key Cryptosystem Based on Algebraic Coding Theory","author":"Robert J. McEliece","year":"1978"},{"key":"ref5:1970\/goppa","first-page":"24","article-title":"A new class of linear error correcting codes","volume":"60","author":"Valery\u00a0D. Goppa","year":"1970","journal-title":"Problemy Peredachi Informatsii"},{"key":"ref6:EC:GabParTre91","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"482","DOI":"10.1007\/3-540-46416-6_41","article-title":"Ideals over a Non-Commutative Ring and thier Applications in\n  Cryptology","volume":"547","author":"Ernst M. Gabidulin","year":"1991"},{"key":"ref7:JC:Overbeck08","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/s00145-007-9003-9","article-title":"Structural Attacks for Public Key Cryptosystems based on\n  Gabidulin Codes","volume":"21","author":"R. Overbeck","year":"2008","journal-title":"Journal of Cryptology"},{"key":"ref8:EC:BBBGNRT20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-45727-3_3","article-title":"An Algebraic Attack on Rank Metric Code-Based\n  Cryptosystems","volume":"12107","author":"Magali Bardet","year":"2020"},{"key":"ref9:AC:BBCGPSTV20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1007\/978-3-030-64837-4_17","article-title":"Improvements of Algebraic Attacks for Solving the Rank\n  Decoding and MinRank Problems","volume":"12491","author":"Magali Bardet","year":"2020"},{"key":"ref10:2023\/kim","doi-asserted-by":"publisher","first-page":"1277","DOI":"10.1109\/lcomm.2023.3257136","article-title":"New Design of Blockwise Interleaved Ideal Low-Rank\n  Parity-Check Codes for Fast Post-Quantum Cryptography","volume":"27","author":"Chanki Kim","year":"2023","journal-title":"IEEE Communications Letters","ISSN":"https:\/\/id.crossref.org\/issn\/2373-7891","issn-type":"electronic"},{"key":"ref11:2023\/bardet","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10623-023-01265-x","article-title":"Revisiting algebraic attacks on MinRank and on the rank\n  decoding problem","author":"Magali Bardet","year":"2023","journal-title":"Designs, Codes and Cryptography"},{"key":"ref12:2024\/redog","isbn-type":"print","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-981-97-1238-0_15","volume-title":"Information Security and Cryptology \u2013 ICISC 2023","author":"Tanja Lange","year":"2024","ISBN":"https:\/\/id.crossref.org\/isbn\/9789819712380","ISSN":"https:\/\/id.crossref.org\/issn\/1611-3349","issn-type":"electronic"},{"key":"ref13:1962\/prange","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TIT.1962.1057777","article-title":"The use of information sets in decoding cyclic codes","volume":"8","author":"Eugene Prange","year":"1962","journal-title":"IRE Transactions on Information Theory"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:28:46Z","timestamp":1733848126000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/45"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,7]]},"references-count":13,"URL":"https:\/\/doi.org\/10.62056\/a6qgy11zn4","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-120"}}