---
title: Goppa-Like Elliptic Codes
url: https://www.emergentmind.com/topics/goppa-like-elliptic-codes
type: topic
---

# Goppa-Like Elliptic Codes

Goppa-like elliptic codes are algebraic-geometry codes attached to elliptic curves, hence to smooth projective curves of genus \(g=1\). In the literature, the expression is used in two closely related ways: as the genus-\(1\) specialization of classical geometric Goppa evaluation codes, and, in a more specific cryptographic usage, as subfield subcodes of dual AG codes on elliptic curves whose finite divisors mimic the classical \(G_0-P_\infty\) pattern. Both viewpoints are governed by the same elliptic function-field data—Riemann–Roch spaces, evaluation at rational places, the Weierstrass semigroup at the point at infinity, and explicit rational bases for elliptic divisors [1204.1559] [2508.04340] [2303.08687].

## 1. Terminological scope and relation to classical Goppa codes

The broad AG viewpoint starts from a smooth projective curve \(X\) over a finite field, a divisor \(G\), and an evaluation divisor \(D=P_1+\cdots+P_n\) supported on rational points disjoint from \(\operatorname{Supp}(G)\). In that setting, the code is the image of the evaluation map on the Riemann–Roch space \(\mathcal L(G)\). When \(X\) is elliptic, this becomes the elliptic specialization of geometric Goppa coding theory. The dissertation literature on elementary methods makes this specialization explicit by identifying “Goppa-like elliptic codes” with genus-\(1\) AG Goppa codes and with evaluation codes derived from the van Lint–Pellikaan–Høhold order/semigroup formalism [1204.1559].

A narrower definition appears in work on subfield-subcode constructions. There, one fixes a curve \(X\) over \(F_{q^m}\), an effective divisor \(D\), and a rational function \(g\notin L(D)\), forms the AG code
\[
C=C_L(X,P,D+(g)),
\]
and defines the associated Goppa-like AG code by
\[
\Gamma(P,D,g):=C^\perp|_{F_q}.
\]
For \(X=\mathbb P^1\), this recovers classical Goppa codes exactly; for \(X\) elliptic, it yields the elliptic instance of the same construction [2303.08687]. Recent elliptic work further specializes this pattern to divisors of the form \(G_0-P_\infty\) or, more generally, \(G'+\operatorname{div}(g)\), defining elliptic Goppa-like codes as
\[
\Gamma(D,G_0-P_\infty)=\mathcal C_{\mathcal L}(D,G_0-P_\infty)^\perp\cap\mathbb F_q^n
\]
and
\[
\Gamma(D,G',g)=\left.\mathcal C^\perp\right|_{\mathbb F_q},
\quad
\mathcal C=\mathcal C_{\mathcal L}(D,G'+\operatorname{div}(g))
\]
[2508.04340].

This terminological variation is substantive rather than contradictory. The first usage emphasizes the genus-\(1\) specialization of AG code theory; the second emphasizes the classical-Goppa-like placement of elliptic subfield subcodes inside code-based cryptography. A plausible implication is that “Goppa-like elliptic code” is best treated as an umbrella term whose precise meaning depends on whether the context is function-field coding theory or cryptographic code design.

## 2. Elliptic specialization of the classical AG construction

Let \(F/\mathbb F_q\) be a function field of genus \(g\), \(D=P_1+\dots+P_n\) a sum of pairwise distinct rational places, and \(G\) a divisor with \(\operatorname{supp}(G)\cap\operatorname{supp}(D)=\varnothing\). The associated geometric Goppa code is
\[
C(D,G)=\{(f(P_1),\dots,f(P_n)):f\in\mathcal L(G)\}\subseteq\mathbb F_q^n.
\]
Its parameters satisfy
\[
k=\ell(G)-\ell(G-D),\qquad d\ge n-\deg G.
\]
If \(2g-2<\deg G<n\), then \(\ell(G-D)=0\) and Riemann–Roch gives
\[
k=\deg G+1-g,\qquad d\ge n-\deg G.
\]
The dual code is the differential code \(C_\Omega(D,G)\), with
\[
C_\Omega(D,G)=C(D,G)^\perp
\]
and, in the same degree range,
\[
\dim C_\Omega(D,G)=n+g-1-\deg G,\qquad d_\Omega\ge \deg G-2g+2
\]
[1204.1559].

For an elliptic curve \(E/\mathbb F_q\) with distinguished rational point \(O\), one takes \(g=1\), chooses distinct rational points \(P_1,\dots,P_n\in E(\mathbb F_q)\setminus\{O\}\), sets \(D=P_1+\cdots+P_n\), and lets \(G=mO\) with \(1\le m<n\). Because \(g=1\), Riemann–Roch simplifies to
\[
\ell(mO)=m
\]
for all \(m\ge 1\), while \(\ell(mO-D)=0\) because \(\deg(mO-D)=m-n<0\). Hence
\[
C_L(D,mO)=\{(f(P_1),\dots,f(P_n)):f\in\mathcal L(mO)\}
\]
has parameters
\[
[n,k,d]\quad\text{with}\quad k=m,\qquad d\ge n-m.
\]
Its dual \(C_\Omega(D,mO)\) has
\[
\dim C_\Omega(D,mO)=n-m,\qquad d_\Omega\ge m
\]
[1204.1559].

This places elliptic AG codes between Reed–Solomon codes and higher-genus AG codes. Reed–Solomon codes, arising from genus \(0\), meet the MDS equality \(k+d=n+1\); elliptic AG codes satisfy \(k+d\ge n\), so the genus-\(1\) loss is exactly one unit in the Singleton-type relation. That “almost MDS” behavior is one reason elliptic constructions recur in both classical AG coding and code-based cryptography [1204.1559].

## 3. Semigroup and order-domain formulation

The elementary approach replaces much of the divisor formalism by a weight function \(\rho\) on an \(\mathbb F_q\)-algebra \(R\), satisfying the order axioms and, in the multiplicative case, the weight identity \(\rho(fg)=\rho(f)+\rho(g)\). The set
\[
\Lambda=\{\rho(f):0\neq f\in R\}\subset\mathbb N_0
\]
is then a numerical semigroup. In this framework, the finite number of gaps of \(\Lambda\) plays the role of the genus, and the conductor \(c\) satisfies
\[
c\le 2g,\qquad c=2g\ \text{iff the semigroup is symmetric}
\]
[1204.1559].

For elliptic curves, the relevant semigroup is the Weierstrass semigroup at the point at infinity \(O\):
\[
H_O=\{-v_O(f):f\in F^\times,\ v_O(f)\le 0\}.
\]
In genus \(1\), there is exactly one gap, namely \(1\), and
\[
H_O=\{0,2,3,4,5,\dots\}.
\]
Equivalently, the semigroup is generated by \(2\) and \(3\), is symmetric, and has conductor \(2\). The standard coordinate functions on a Weierstrass model realize this numerically:
\[
f_1=1,\qquad f_2\sim x,\qquad f_3\sim y,\qquad f_4\sim x^2,\dots
\]
with pole orders \(0,2,3,4,\dots\) at \(O\) [1204.1559].

Let \(\varphi:R\to\mathbb F_q^n\) be evaluation at rational points, and let \(L_\ell\) be the span of the first \(\ell\) basis elements ordered by increasing \(\rho\)-value. The resulting evaluation code \(E_\ell=\varphi(L_\ell)\) satisfies
\[
\dim E_\ell=\ell,\qquad d(E_\ell)\ge n-\rho_\ell
\]
whenever \(\rho_\ell<n\). In the elliptic case, taking \(\rho(f)=-v_O(f)\) and identifying \(\rho_\ell=m\), one recovers exactly the classical space \(\mathcal L(mO)\) and therefore the elliptic AG code \(C_L(D,mO)\). The semigroup inequality \(\rho_\ell\le \ell+g-1\) becomes \(\rho_\ell\le \ell\) when \(g=1\), reproducing the AG bound \(d\ge n-m\) by purely semigroup-theoretic means [1204.1559].

The importance of this reformulation is conceptual and algorithmic. It shows that genus-\(1\) AG behavior can be derived from linear algebra and numerical semigroups alone, and it embeds elliptic Goppa-like codes into the broader order-domain tradition.

## 4. Explicit Riemann–Roch bases and divisor models on elliptic curves

A major recent development is the explicit computation of bases of \(\mathcal L(G)\) for arbitrary elliptic divisors. For a non-infinite point \(P=(\alpha,\beta)\) and \(G=kP\), a basis of \(\mathcal L(G)\) is
\[
\mathscr L_b=\{1,f_2,\dots,f_k\},
\qquad
f_s(X,Y)=\frac{Y+A_s(X)}{(X-\alpha)^s},
\quad 2\le s\le k,
\]
where the polynomial \(A_s(X)\) is chosen so that \(Y+A_s(X)\) cancels the unwanted pole at the conjugate point \(-P\). The coefficients of \(A_s\) are obtained by Taylor expansion around \(-P\), using implicit differentiation of the elliptic Weierstrass equation; Algorithm 1 in the paper formalizes this in characteristic \(2\) and in characteristic \(>3\) [2508.04340].

For a general effective divisor
\[
G=\sum_{i=1}^z k_iP_i,
\]
the basis becomes
\[
\mathscr L_b=\{1\}\cup\{f_{i,s}:1\le i\le z,\ 2\le s\le k_i\}\cup\{g_i:1\le i\le z-1\},
\]
where the \(f_{i,s}\) are the single-point functions above and the \(g_i\) are “double-point functions” with simple poles at consecutive points \(P_i,P_{i+1}\). The count is exact:
\[
|\mathscr L_b|=\sum_{i=1}^z k_i=\deg(G)=\dim\mathcal L(G).
\]
This gives an explicit, implementable basis for any effective elliptic divisor, not merely one-point divisors at \(P_\infty\) [2508.04340].

Within this basis-theoretic framework, the elliptic Goppa-like construction takes two principal forms. The one-point form uses a function \(g\in\mathcal L((s+1)P_\infty)\setminus\mathcal L(sP_\infty)\), its zero divisor \(G_0=(g)_0\), and the finite divisor
\[
G=G_0-P_\infty,
\]
yielding
\[
\Gamma(D,sP_\infty,g)
=\mathcal C_{\mathcal L}(D,G_0-P_\infty)^\perp\cap\mathbb F_q^n.
\]
The more general form replaces \(sP_\infty\) by an arbitrary effective divisor \(G'\) and defines
\[
\Gamma(D,G',g)
=
\left.\mathcal C_{\mathcal L}(D,G'+\operatorname{div}(g))^\perp\right|_{\mathbb F_q}.
\]
The explicit basis of \(\mathcal L(G')\) transfers directly to \(\mathcal L(G'+\operatorname{div}(g))\) by dividing basis elements by \(g\), so generator and parity-check matrices become fully constructive [2508.04340].

This explicit-basis viewpoint eliminates the historical restriction to monomial bases at infinity. It also clarifies that finite divisors of the form \(G_0-P_\infty\) are not merely analogies to classical Goppa divisors on \(\mathbb P^1\), but genuine elliptic divisor classes with computable rational-function realizations.

## 5. Duality, self-duality, and symmetric elliptic families

Self-duality on elliptic function fields admits a precise divisor-theoretic criterion. Over a field \(K=\mathbb F_q\) of characteristic different from \(2\), let
\[
F=K(x,y),\qquad y^2=f(x),\qquad \deg f=3,
\]
so that \(F/K\) is elliptic. Choose an even integer \(n>4\), rational places \(R_1,\dots,R_{n/2}\) of \(K(x)\) that split in \(F/K(x)\), and define the evaluation divisor
\[
D=\sum_{i=1}^{n/2}(S_{i,1}+S_{i,2}).
\]
Let \(g(x)\in K[x]\) satisfy \((g(x))_0=D\), and define
\[
\eta=\frac{g'(x)\,dx}{g(x)}.
\]
Then \(v_P(\eta)=-1\) and \(\operatorname{res}_P(\eta)=1\) for all \(P\in\operatorname{supp}(D)\), and the dual divisor becomes
\[
D+(\eta)=(g'(x))+(n-3)Q_\infty+Q_1+\dots+Q_r.
\]
If \(G\) is a divisor of degree \(n/2\), the code \(C_{\mathcal L}(D,G)\) is self-dual if and only if
\[
(g'(x))
=
2G-(u)-(n-3)Q_\infty-Q_1-\dots-Q_r
\]
for some \(u\in F^\times\) such that \(u(P)=1\) for every \(P\in\operatorname{supp}(D)\). Under these hypotheses, the resulting self-dual elliptic code has length \(n\), dimension \(n/2\), and minimum distance at least \(n/2\) [1903.07376].

The same elliptic setting also supports quasi-cyclic constructions. If \(\sigma\in\mathrm{Aut}(\mathcal E/\mathbb F_q)\) has order \(\ell\), and both \(D\) and \(G\) are built from \(\sigma\)-orbits, then \(\mathcal C_{\mathcal L}(D,G)\) is \(\ell\)-quasi-cyclic. The corresponding quasi-cyclic Goppa-like elliptic codes arise when \(G'+\operatorname{div}(g)\) is likewise \(\sigma\)-invariant, in which case
\[
\Gamma(D,G',g)=\left.\mathcal C_{\mathcal L}(D,G'+\operatorname{div}(g))^\perp\right|_{\mathbb F_q}
\]
inherits the quasi-cyclic symmetry [2508.04340].

These symmetric families serve two distinct agendas. In pure coding-theoretic terms, they provide compact structural descriptions and explicit orbit-adapted bases. In cryptographic terms, they create public-key compression opportunities. The associated risk is not uniform: recent elliptic work states that no efficient structural attack is currently known against the quasi-cyclic subfield subcodes of dual elliptic codes, but also concludes that one-point Goppa-like elliptic codes with simple \(g\) are structurally risky because Schur-square distinguishers likely apply [2508.04340].

## 6. Cryptographic use, Schur-square distinguishers, and the Goppa morphism

The cryptographic analysis of Goppa-like elliptic codes proceeds along two complementary lines. The first is combinatorial-algebraic and studies the square of the dual. The second is geometric and studies the image of elliptic level structures inside a Grassmannian.

For Goppa-like AG codes \(\Gamma(P,D,g)\), the relevant object is
\[
(\Gamma(P,D,g)^\perp)^{\star 2},
\]
equivalently the square of the trace code attached to the ambient AG code. On \(C_{a,b}\) curves, and therefore in particular on elliptic \(C_{2,3}\) models, the dimension of this square admits explicit upper bounds substantially below the random expectation \(\binom{mk+1}{2}\). In the one-point setting, Theorem 4.7 gives
\[
\dim_{F_q} (\Gamma(P,sP_\infty,g)^{\perp})^{\star 2}
\le
\binom{mk+1}{2}
-\frac{m}{2}\Big(k^2(2e^*+1)+k-2s'(q^{e^*}-q^{e^*-1}+1)\Big),
\]
under the stated degree condition on \(s\) and \(s'\). For elliptic examples over \(F_{3^6}\) built from
\[
y^2+y=x^3+x+2,
\]
the paper reports equality between the measured value of \(\dim (C_g^\perp)^{\star 2}\) and this theoretical upper bound for \(s=4,\dots,10\), indicating sharpness in random-looking elliptic instances [2303.08687].

The same paper identifies the high-rate regime in which elliptic Goppa-like codes are distinguishable by this Schur-square method. Reported examples include rate \(0.963\) for \(q=2,m=12,n=4218,s=14\), rate \(0.962\) for \(q=3,m=7,n=2186,s=15\), and rate \(0.979\) for \(q=7,m=5,n=8192,s=37\). Its conclusion is that, for elliptic curves, only very high rate codes are distinguishable by this method, whereas higher-genus Hermitian families can evade the same distinguisher entirely [2303.08687].

The geometric line of analysis packages elliptic Goppa-like codes as level structures
\[
(E,p_1,\dots,p_n,L,\gamma_1,\dots,\gamma_n)
\]
with \(\deg L=d\), and maps them to \(\mathrm{Gr}(d,n)\) via the Goppa morphism. For genus \(1\), the moduli stack of elliptic level structures has dimension \(2n\), and the extended Goppa morphism is an immersion for \(n>d>1\). The corresponding dimension gap is
\[
\Xi(d)=-d^2+nd-2n.
\]
The “dangerous” degrees are those in
\[
\left(
\frac{n-\sqrt{n^2-8n}}{2},
\frac{n+\sqrt{n^2-8n}}{2}
\right),
\]
and for large \(n\) this is approximately \((2,n-2)\). The paper’s explicit conclusion is that, from a cryptographic point of view, Goppa codes produced by level structures in that interval are distinguishable from random linear codes and should be avoided [2411.19088].

Taken together, these results sharply qualify the cryptographic status of Goppa-like elliptic codes. They remain mathematically natural, explicitly constructible, and close to MDS in classical parameter terms, but their algebraic regularity is visible to both Schur-product methods and moduli-theoretic dimension arguments. A plausible implication is that elliptic constructions are best regarded as highly structured AG families rather than as random-like code ensembles; this aligns them with the broader experience on symmetric alternant and Goppa cryptosystems, where structural compression has repeatedly created attack surfaces [1405.5101].

Source: https://www.emergentmind.com/topics/goppa-like-elliptic-codes