---
title: Matrix Subcode Equivalence Problem
url: https://www.emergentmind.com/topics/matrix-subcode-equivalence-problem
type: topic
---

# Matrix Subcode Equivalence Problem

The Matrix Subcode Equivalence Problem concerns rank-metric matrix codes over a finite field and asks whether a given matrix code can be mapped, by a rank isometry, into another code as a subcode. In the formulation introduced for matrix spaces \(C,D \subseteq F^{m\times n}\), with \(\dim(C)=k\) and \(\dim(D)=k'\) for \(k'<k\), one seeks invertible matrices \(A \in \mathrm{GL}_m(q)\) and \(B \in \mathrm{GL}_n(q)\) such that \(D \subseteq A C B\) [2507.15377]. The problem extends the rank-metric equivalence agenda developed for full matrix-code equivalence, but the subcode condition changes the algebraic structure substantially: the hidden mixing on the code side is no longer invertible, several invariants used in full equivalence disappear, and both algebraic and combinatorial attacks degrade sharply [2507.15377].

## 1. Formal definition and ambient equivalence structure

In the rank-metric setting, an \([m\times n,k]\) matrix code \(C\) is an \(F\)-linear subspace \(C \subseteq F^{m\times n}\) of dimension \(k\), with rank weight \(w_R(X)=\operatorname{rank}(X)\) and rank distance \(d(X,Y)=\operatorname{rank}(X-Y)\) [2507.15377]. The Matrix Subcode Equivalence Problem, denoted
\[
\mathrm{MSE}(q,m,n,k,k'),
\]
takes as input a code \(C \subseteq F^{m\times n}\) of dimension \(k\) and a code \(D \subseteq F^{m\times n}\) of dimension \(k'\) with \(k'<k\), and asks whether there exist \(A \in \mathrm{GL}_m(q)\) and \(B \in \mathrm{GL}_n(q)\) such that
\[
D \subseteq A C B
\]
[2507.15377].

The underlying rank-isometry group is the classical one for the rank metric. A linear rank-preserving map on matrices has the form
\[
f(X)=A X B,
\]
with \(A \in \mathrm{GL}_m(F_q)\), \(B \in \mathrm{GL}_n(F_q)\), and when \(m=n\) one may also have transpose-based maps [1304.0501]. More generally, linear matrix-equivalence maps are generated by left multiplication, right multiplication, and, in the square case, transposition; semilinear extensions further incorporate \(\operatorname{Gal}(F_q/F_p)\) entrywise [1304.0501]. The paper introducing MSE focuses on the \(A X B\) case [2507.15377].

A generator-matrix formulation makes the hidden structure explicit. If \(G \in F^{k\times mn}\) and \(G' \in F^{k'\times mn}\) generate \(C\) and \(D\), then
\[
D \subseteq A C B
\]
is equivalent to the existence of a matrix \(T \in F^{k\times k'}\) with \(\operatorname{rank}(T)=k'\) such that
\[
G' = T^\top G (A^\top \otimes B)
\]
[2507.15377]. This is the defining feature of the subcode problem: the map \(T\) is full-rank but non-invertible. If \(H \in F^{(mn-k)\times mn}\) is a parity-check matrix of \(C\), with \(G H^\top=0\), then the same condition yields the dual formulation
\[
G' (A^{-\top}\otimes B^{-1}) H^\top = 0
\]
[2507.15377].

The paper also studies the inhomogeneous Matrix Code Permuted Kernel Problem. Given \(G,G',G''\), it asks whether there exist invertible \(A,B\) and \(T \in F^{k\times k'}\) of rank \(k'\) such that
\[
(T^\top G + G'') (A^\top \otimes B) = G'
\]
[2507.15377]. In dual form, with \(H\) a parity-check matrix of \(G\) and \(Y \in F^{k'\times(mn-k)}\),
\[
G' (A^{-\top} \otimes B^{-1}) H^\top = Y.
\]
For \(Y=0\), this reduces to MSE [2507.15377].

## 2. Relation to matrix code equivalence and earlier equivalence theory

MSE arose in a landscape already shaped by full matrix code equivalence. In the general Matrix Code Equivalence Problem, two \(k\)-dimensional matrix spaces \(\mathcal C,\mathcal D \subset \mathbb F_q^{m\times n}\) are equivalent if there exist invertible \(P \in \mathrm{GL}_m(\mathbb F_q)\) and \(Q \in \mathrm{GL}_n(\mathbb F_q)\) such that
\[
\mathcal D = P \mathcal C Q^{-1}
\]
[2504.01230]. Recent signature schemes such as MEDS and ALTEQ relate their security to the hardness of this problem [2504.01230]. The full-equivalence literature established both the ambient group structure and the distinction between matrix equivalence and rank-metric equivalence: matrix equivalence is strictly more general than rank-metric equivalence, and its linear isometry group is
\[
(\mathrm{GL}_m(F_q)\times \mathrm{GL}_n(F_q))/N
\]
when \(m\neq n\), with an additional \(\mathbb Z_2\)-action by transposition when \(m=n\) [1304.0501].

For given codes, several decision problems in full equivalence admit efficient structure theory. The Matrix Codes Right Equivalence Problem and Hidden Vector Matrix Code Equivalence are in \(\mathcal P\) if \(q=(mn)^{O(1)}\), and in \(\mathcal{ZPP}\) in general; the core tools are conductor spaces, stabilizer algebras, Jacobson radicals, and Wedderburn–Artin decompositions [2011.04611]. That framework applies directly when the subcodes are given explicitly, but not to the existential search inherent in MSE as introduced in the subcode literature. This suggests that MSE should be distinguished from “given-subcode equivalence” problems inherited from conductor-based algorithms [2011.04611].

The introduction of MSE parallels the Hamming-metric notion of subcode equivalence. In the matrix setting, the loss of invertibility on the code-side mixing matrix \(T\) is decisive. The subcode condition does not merely weaken full equivalence; it removes the invertible change-of-basis symmetry on the smaller code and therefore invalidates several transfer principles and invariants that are effective in the full-code case [2507.15377].

## 3. Hardness, reductions, and counting heuristics

The work introducing MSE places it in direct relation with Hamming-metric subcode equivalence. It states that the Matrix Subcode Equivalence problem reduces to the Hamming Subcode Equivalence problem, which is known to be NP-Complete [2507.15377]. In the detailed reduction, Hamming codes are embedded into diagonal matrix codes through the rank isometry
\[
\psi: F^n \to F^{n\times n}, \qquad \psi(x)=\operatorname{Diag}(x_1,\dots,x_n),
\]
for which \(\operatorname{rank}(\psi(x)) = w_H(x)\) [2507.15377]. The corresponding proposition identifies Hamming SEP-equivalence with matrix-subcode inclusion after a rank isometry, and the synthesized conclusion is that MSE is at least as hard as Hamming SEP, hence NP-hard [2507.15377].

The generator description also supports counting heuristics. Under a random-subspace heuristic, the average number of projective isometries mapping \(D\) into \(C\) is approximately
\[
|\mathrm{PGL}_m(q)| \cdot |\mathrm{PGL}_n(q)| \cdot \frac{\binom{k}{k'}_q}{\binom{mn}{k'}_q},
\]
where
\[
|\mathrm{GL}_s(q)|=\prod_{i=0}^{s-1}(q^s-q^i), \qquad |\mathrm{PGL}_s(q)|=\frac{|\mathrm{GL}_s(q)|}{q-1},
\]
and the Gaussian binomial coefficient is
\[
\binom{a}{b}_q = \prod_{i=0}^{b-1}\frac{q^a-q^i}{q^b-q^i} \to q^{b(a-b)} \text{ as } q\to \infty
\]
[2507.15377]. This estimate is used for parameter selection rather than as a proof of average-case complexity.

The same work argues that \(k' \ge 3\) is necessary to avoid large underdetermined systems and proliferation of trivial or invertible solutions. For \(k'=1\) or \(2\), systems such as \(A D_1 = C B\) have at most \(mn\) independent linear equations in \(m^2+n^2\) unknowns, yielding many solutions likely including invertible \(A,B\). For \(k' \ge 3\), the induced systems tend to be overdetermined and uniqueness can be engineered [2507.15377]. This criterion is central in the cryptographic instantiation, where \(k'=3\) is used systematically [2507.15377].

A plausible implication is that MSE occupies an intermediate position between full code equivalence and generic subspace-search problems: it inherits the geometric structure of rank isometries, but its search space is shaped by a non-invertible hidden embedding. The literature repeatedly identifies this non-invertibility of \(T\) as the reason both algebraic and invariant-based attacks become weaker than in the full-equivalence setting [2507.15377].

## 4. Algorithmic approaches and why the subcode case is harder

The existing attack surface for MSE is built by adapting full matrix-code equivalence techniques to the subcode case. The common conclusion is that these adaptations perform much worse than in the code equivalence case, mirroring the Hamming metric [2507.15377].

The simplest reduction guesses a \(k'\)-dimensional subspace of \(C\) and then solves full MCE on that guess. Its complexity is
\[
\binom{k}{k'}_q \cdot C_{\mathrm{MCE}}(q,m,n,k'),
\]
with \(\binom{k}{k'}_q \approx q^{k'(k-k')}\); even for small \(q,k',k\), this is enormous [2507.15377]. The paper gives the example \(q=64,k'=3,k=12\), which leads to \(2^{162}\) possibilities [2507.15377].

The algebraic modelings center on the equation
\[
G' = T^\top G (A^\top \otimes B),
\]
or on its dual quadratic form
\[
G' (A^{-\top} \otimes B^{-1}) H^\top = 0
\]
[2507.15377]. In the naive trilinear model, the unknowns are \(T,A,B\), with \(kk' + m^2 + n^2\) variables and \(k' mn\) affine trilinear equations [2507.15377]. Hybrid variants guess columns of \(A^\top\) or rows of \(T^\top\), producing linear subsystems, but their exponents are substantially worse than for MCE when \(k'\) is small [2507.15377]. The dual quadratic model has only \(k'(mn-k)\) equations in \(m^2+n^2\) unknowns, fewer than in full MCE, and is therefore weaker [2507.15377].

A more elaborate trilinear formalism uses commutation matrices \(K_{p,q}\) and reshaped generators \(G_A,G'_A,G_B,G'_B\). It yields equivalent formulations such as
\[
G'_A = A G_A (B \otimes T), \qquad G'_B = B^\top G_B (T \otimes A^\top),
\]
and bilinear constraints
\[
0 = G_A (B \otimes T) H_A^{\prime\top}, \qquad 0 = G_B (T \otimes A^\top) H_B^{\prime\top}
\]
[2507.15377]. The paper then adds new trilinear equations based on right inverses:
\[
I_m = G_A (B \otimes T) R_{G'_A} \cdot A, \qquad I_n = G_B (T \otimes A^\top) R_{G'_B} \cdot B^\top
\]
[2507.15377]. These improve constraints without introducing \(A^{-1},B^{-1}\) as explicit variables. Yet experimental evidence remains unfavorable: Gröbner basis computations for \(n=3,m=4,k=4,q=64\) took about \(100\) s for \(k'=k\), but more than \(10\) hours for \(k'=k-1\), illustrating the gap between MCE and MSE [2507.15377].

Leon-style combinatorial attacks were also adapted. They search for low-rank codewords in \(C\) and \(D\), construct collision lists, and solve linear systems derived from equal-rank pairs [2507.15377]. If
\[
M_{m,n}(r)=\prod_{i=0}^{r-1}\frac{(q^m-q^i)(q^n-q^i)}{q^r-q^i}
\]
is the number of rank-\(r\) matrices, then the expected number of rank-\(r\) codewords in \(C\) is \(C(r)=M_{m,n}(r)/q^{mn-k}\), and in \(D\) it is \(C'(r)=M_{m,n}(r)/q^{mn-k'}\) [2507.15377]. To obtain collision probability \(c\), it suffices to sample
\[
N_1 \ge -\log(1-c)\cdot q^{k-k'}
\]
elements from \(C\) [2507.15377]. Because \(D\) is smaller, feasible \(r\) is larger than in MCE, so the attack becomes significantly more expensive [2507.15377].

The reduction to Quadratic Sub Map Linear Equivalence provides another algorithmic lens. In QSMLE, one seeks \(S \in \mathrm{GL}_N(q)\) and \(T \in F^{k\times k'}\) of rank \(k'\) such that
\[
P(x)=F(xS)T
\]
for tuples of quadratic polynomials \(F,P\) [2507.15377]. MSE reduces to this problem by associating to code bases bilinear polynomials
\[
p_i(x)=(x_1,\dots,x_m) D^{(i)} (x_{m+1},\dots,x_{m+n})^\top
\]
and similarly for \(f_j(x)\), with isometry
\[
S=\operatorname{diag}(A,B^\top)
\]
[2507.15377]. The inhomogeneous QSMLE solver dominates parameter selection; the lower bound quoted for cubic linearization is
\[
C_{\mathrm{inhQSMLE}} = O\!\left(\left(\binom{v+2}{3}-v_-\right)^\omega\right),
\]
with
\[
v = n^2 + m^2 + kk' - 2k'(m+n)
\]
and an explicit expression for \(v_-\) in terms of \(m,n,k,k'\) [2507.15377]. The stated conclusion is that this attack is substantially worse than MCE due to the non-invertible \(T\) and the reduced number of equations [2507.15377].

Several invariant-based attacks do not transfer at all. The corank walk on bilinear forms requires equal ranks across dimensions, notably \(m=n=k\), and cannot be adapted because \(\operatorname{rank}(C(u,-,-))\) and \(\operatorname{rank}(D(u,-,-))\) are bounded by \(\min(n,k)\) and \(\min(n,k')\), respectively [2507.15377]. Triangle-based invariants from \(3\)-tensor isomorphism also fail: weak-key probabilities fall from about \(1/q\) in MCE to about \(1/q^{k-k'+1}\) in MSE, since one needs \(w \in \operatorname{Im}(T)\) [2507.15377].

| Approach | Core relation | Reported effect in MSE |
|---|---|---|
| Guess subcode, then solve MCE | \(\binom{k}{k'}_q \cdot C_{\mathrm{MCE}}\) | Impractical |
| Algebraic modeling | \(G' = T^\top G (A^\top \otimes B)\) | Equation deficit |
| Dual quadratic modeling | \(G'(A^{-\top}\otimes B^{-1})H^\top=0\) | Weaker than MCE |
| Leon-style collisions | Low-rank collisions in \(C,D\) | Higher feasible \(r\) |
| QSMLE reduction | \(P(x)=F(xS)T\) | Dominant for parameters |
| Corank walks / triangles | Tensor invariants | Do not transfer |

The broader full-equivalence literature helps explain this deterioration. In general MCE, the “Highway to Hull” algorithm reduces equivalence to conjugacy and exploits one-dimensional hulls as conjugacy invariants [2504.01230]. That mechanism relies on exact equivalence of full spaces and on separable characteristic-polynomial collisions. A plausible implication is that no direct hull-based analogue is currently available for the existential subcode setting without substantial additional guessing, because the hidden object is not the whole code but an unknown embedded subspace.

## 5. Matrix Code Permuted Kernel Problem and signature constructions

The main cryptographic application of MSE is the Matrix Code Permuted Kernel Problem, especially in its inhomogeneous form [2507.15377]. Its public relation is the degree-\(2\) polynomial constraint
\[
G' (A^\top \otimes B) H^\top = Y,
\]
where \(H \in F^{(mn-k)\times mn}\) has rank \(mn-k\), \(G' \in F^{k'\times mn}\) has rank \(k'\), and \(Y \in F^{k'\times (mn-k)}\) is stored in row-reduced echelon form [2507.15377]. The secret key is \((A,B)\), while the public key is \((H,G',Y)\) [2507.15377].

Key generation samples \(H,G',A,B\) uniformly with the required ranks and sets
\[
Y := \operatorname{RREF}(G' (A^\top \otimes B) H^\top),
\]
resampling if \(\operatorname{rank}(Y)<k'\) [2507.15377]. The public-key size is approximately
\[
\lambda + k'(mn-k)\log_2(q),
\]
and in the NIST-I set MCPKP-Ib it is about \(255\) Bytes [2507.15377].

The zero-knowledge layer is implemented with MPC-in-the-Head. In the TCitH variant, Shamir sharing of degree \(\ell=1\) is applied to the witness \((A,B)\), and the parties compute
\[
\widetilde G' = G' (A^\top \otimes B) H^\top - Y.
\]
With challenges \(\gamma_j \in F_q\), they form
\[
[\alpha]_i = [v]_i + \sum_j \gamma_j [f_j]_i,
\]
open \(\alpha\), and accept iff \(\alpha=0\) [2507.15377]. One repetition has false-positive probability \(1/q\); after \(\rho\) repetitions it becomes \(1/q^\rho\) [2507.15377]. The signature-size formula is
\[
\mathrm{Size}_{\mathrm{TCIT\_H}} = 4\lambda + \tau\big(|x| + (d-1)\rho \log_2(q) + 2\lambda + \lambda \log_2(N)\big),
\]
where \(|x|=(m^2+n^2)\log_2(q)\) and \(d=2\) [2507.15377].

The VOLE-in-the-Head variant merges \(\tau\) sharings via a morphism \(\phi: F^\tau \to F_{q^\rho}\), reducing soundness to \(d/N^\tau\) [2507.15377]. Its signature-size formula is
\[
\mathrm{Size}_{\mathrm{VOLEitH}} = 4\lambda + (\tau-1)\big(|x| + \rho \log_2(q) + (\rho+B)\log_2(q)\big)
+ (\rho+B)\log_2(q)
+ \tau(\lambda \log_2(N) + 2\lambda)
+ |x| + (d-1)\rho \log_2(q)
\]
with \(B\) chosen so that \(Bq \ge 16\) [2507.15377].

The representative parameter sets reported are:

| Set | \((q,m,n,k,k')\) | Public key | Attack logs |
|---|---|---|---|
| MCPKP-Ia | \((64,12,12,32,3)\) | \(\approx 268\) B | Leon \(\approx 230\), QSMLE \(\approx 156\) |
| MCPKP-Ib | \((128,11,11,30,3)\) | \(\approx 255\) B | Leon \(\approx 237\), QSMLE \(\approx 160\) |
| MCPKP-III | \((64,18,18,50,3)\) | \(\approx 641\) B | Leon \(\approx 340\), QSMLE \(\approx 235\) |
| MCPKP-V | \((64,22,22,67,3)\) | \(\approx 963\) B | Leon \(\approx 413\), QSMLE \(\approx 286\) |

For NIST-I in the “Short” configuration, the reported signature sizes are about \(4{,}788\) B for VOLEitH and \(4{,}975\) B for TCitH on MCPKP-Ib [2507.15377]. The paper contrasts these figures with established schemes and reports that, at NIST-I, the MSE/MKPK-based construction gives a smaller combined size than SPHINCS+, while also producing much smaller public keys than MEDS, LESS, and ALTEQ [2507.15377].

A notable design choice is the use of inhomogeneous MKPK rather than homogeneous MSE. The paper states that using homogeneous MSE with \(Y=0\) would require transmitting \(T\) or verifying \(G'(A^\top \otimes B)=T^\top G\), inflating signatures by about \(1\) kB at level I [2507.15377]. This motivates the inhomogeneous formulation.

## 6. Structural viewpoints, special families, and related classification problems

Although MSE was introduced only recently, it fits into a broader theory of equivalence and classification for matrix codes. Earlier work on matrix equivalence provided invariants such as \(\dim_{F_q}(C)\), minimum rank distance, rank distribution, and weight enumerators; these remain useful as pre-filters in equivalence testing, but in the subcode setting they no longer decide the problem because inclusion does not preserve full distributions [1304.0501]. For self-dual matrix codes, classification can be organized through double cosets of duality-preserving isometries, using
\[
\mathrm{Equiv}_{\mathrm{Vec}}^{SD}(m\times n) \cong (GO_m(F_q)\times GO_n(F_q))/N
\]
or its square-matrix extension with transpose [1505.07363]. This framework is exact for self-dual full codes, but it does not directly solve MSE, since the latter is not formulated as equivalence between equal-dimensional codes and generally lacks transitivity under the ambient group action [1505.07363].

A different strand studies specialized families of low-dimensional MRD codes where subcode equivalence becomes tractable through family-specific invariants. For the \(2\)-dimensional \(F_{q^{2t}}\)-linear MRD family \(C_{h,t,s}\), practical equivalence testing reduces to matching Frobenius support patterns, checking that \(IR(C)\cong F_{q^2}\), computing \(r \equiv l s^{-1} \pmod n\), and verifying the relevant \(\operatorname{Aut}(F_{q^n})\)-orbit relation between \(h\) and \(k\), possibly up to sign and inversion [2208.09701]. This yields a “practical, computable decision procedure” for that family [2208.09701]. The existence of such family-dependent criteria suggests that subcode equivalence may admit efficient solutions on highly structured instances even when the general problem is treated as a cryptographic hardness assumption.

Geometric approaches to Hamming code equivalence supply another perspective. In the projective-geometry formulation, code equivalence is tested by isomorphism of binary incidence matrices \(N(A_k)\) or shortened variants \(N(A_G)\), with automorphism group computations via canonical labeling [2202.02086]. The same synthesis explicitly adapts the matrix form
\[
S G_C M = U G_D
\]
to subcode equivalence, where \(U\) has full row rank, and interprets the problem as orbit-subset containment of projective multisets [2202.02086]. This is a different metric setting, but it clarifies a general phenomenon also present in MSE: subcode equivalence replaces orbit equality by orbit containment, and that shift is algorithmically expensive.

The current literature therefore presents MSE as both a natural rank-metric analogue of Hamming subcode equivalence and a distinct cryptographic primitive. Its defining obstacle is the non-invertible hidden map \(T\), which weakens algebraic constraints, destroys several full-equivalence invariants, and forces parameter choices that differ markedly from those used for matrix code equivalence [2507.15377]. At the same time, the surrounding equivalence theory indicates that structured subclasses, stabilizer algebras, idealizers, and family-specific normal forms remain central tools for understanding when subcode equivalence is tractable and when it is intended to be hard.

Source: https://www.emergentmind.com/topics/matrix-subcode-equivalence-problem