Papers
Topics
Authors
Recent
Search
2000 character limit reached

Noise-Enhanced High-Memory Codes

Updated 9 December 2025
  • The paper introduces a novel construction of high-memory convolutional codes enhanced by deliberate noise and dense masking to secure public-key cryptography against classical and quantum attacks.
  • It employs directed-graph decryption, high constraint-length coding, and polynomial division to achieve exponential adversarial complexity while ensuring efficient decryption for legitimate users.
  • The scheme scales linearly with plaintext length and resists advanced attacks like Information-Set Decoding, making it a promising candidate for post-quantum cryptographic applications.

Noise-Enhanced High-Memory Convolutional Codes (NE-HMCC) constitute a cryptographic construction employing directed-graph decryption of convolutional codes with substantially increased memory and deliberate noise injection. This approach produces public keys with generator matrices statistically indistinguishable from random linear codes, ensuring robust resistance to both classical and quantum cryptanalytic attacks. NE-HMCC integrates high constraint-length coding, dense masking, and polynomial division to facilitate efficient decryption for legitimate users while imposing exponential complexity on adversaries, making it a compelling scheme for scalable, quantum-resistant public-key cryptography (Ariel, 2 Dec 2025).

1. Code Structure and Masked Generator Construction

The NE-HMCC scheme begins with a base convolutional code (CC) of rate k/nk/n (typically k=1k=1 for exposition, but the construction allows arbitrary rates). The memory parameters are pp (original CC memory) and qq (high-memory extension), yielding an overall constraint length m=p+qm = p + q and trellis size up to 2p+q2^{p+q} states. The base generator polynomials are

Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]

with pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}, and the high-memory "masking" polynomials are

GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]

with qi(x)=∑j=0qbj(i)xjq_i(x)=\sum_{j=0}^q b_{j}^{(i)}x^j, chosen so k=1k=10 and k=1k=11.

The high-memory generator is constructed as

k=1k=12

which in block form is a k=1k=13 matrix of full rank k=1k=14, with k=1k=15. This structure inherently includes periodicity and algebraic structure that must be obscured for security.

To achieve a dense and random-like public matrix, a masking operation is applied. A small mask space k=1k=16 of rank k=1k=17 is selected, and a dense mask k=1k=18 (the set of all k=1k=19 linear combinations of rows from pp0) is drawn. The masked generator is

pp1

which is then obfuscated through two further transformations: pp2, where pp3 is a random nonsingular pp4 matrix and pp5 a random pp6 permutation. The public key is pp7 where pp8 is the encryption bit-flip probability and pp9 a CRC polynomial; the private key is the tuple qq0.

2. Noise-Enhancement and Ambiguity Mechanisms

Noise enhancement is central to the NE-HMCC security and decryption strategy. Encryption proceeds by computing qq1 and applying independent bit-flips with probability qq2, yielding ciphertext qq3, qq4.

Decryption intensifies the noise through polynomial division at each block. In block qq5, the operation is: qq6 where qq7 is the inverse-permuted ciphertext and qq8 is each mask candidate. The resulting quotient accumulates not only input bit-flip errors, but also additional "division noise." The total noise affecting the legitimate decoder is qq9 where m=p+qm = p + q0 is the total increase in error weight from division.

By carefully selecting mask polynomials (e.g., m=p+qm = p + q1) with widely spaced taps, both the trellis capacity and resistance to structural cryptanalysis are enhanced.

3. Decryption Workflow and Polynomial Ambiguity

Decryption proceeds through the following steps:

  1. Inverse Permutation: Apply m=p+qm = p + q2 to the ciphertext to recover m=p+qm = p + q3.
  2. Mask Ambiguity: For all m=p+qm = p + q4 possible mask vectors m=p+qm = p + q5, form m=p+qm = p + q6.
  3. Blockwise Division: De-interleave m=p+qm = p + q7 into m=p+qm = p + q8 blocks, divide each by m=p+qm = p + q9, and collect quotients.
  4. Re-interleaving and Decoding: Each mask candidate yields a separate candidate 2p+q2^{p+q}0, providing 2p+q2^{p+q}1 length-2p+q2^{p+q}2 vectors, each decoded via Viterbi in parallel (complexity 2p+q2^{p+q}3).
  5. Plaintext Recovery: The candidate with minimal decoding distance (close to 2p+q2^{p+q}4) is selected. CRC validation ensures correctness; if unsuccessful, the process iterates or requests retransmission.

The mask ambiguity is tractable for legitimate users (with typical 2p+q2^{p+q}5) but yields a combinatorial barrier for attackers. Incorrect mask choices inflate the Hamming distance of decoded candidates, efficiently distinguishing the correct plaintext in high probability.

4. Security Margins and Cryptanalytic Resistance

NE-HMCC achieves indistinguishability of 2p+q2^{p+q}6 from random linear codes, with full rank and row/column weights close to 2p+q2^{p+q}7 making all linear and parity structure tests ineffective. Dual-codewords can occur only with vanishing probability 2p+q2^{p+q}8, while mask entropy provides 2p+q2^{p+q}9 possible combinations, making mask-space enumeration infeasible given ciphertext noise.

Information-Set Decoding (ISD) is the main generic attack vector. With effective error weight Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]0: Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]1 and, for quantum ISD: Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]2

Compared to Classic McEliece (e.g., Goppa Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]3), NE-HMCC with parameters Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]4, Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]5, Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]6, Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]7, Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]8 yields Gp(x)=[ p0(x), p1(x), …, pn−1(x) ]G_p(x) = [\,p_0(x),\,p_1(x),\,\ldots,\,p_{n-1}(x)\,]9, and pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}0, exceeding McEliece security margins by over pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}1 in exponent (a pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}2 margin).

Resistance to "known-CC" attacks—where attackers have pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}3 but not pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}4—is guaranteed by the impractically large permutation/mask search space and the exponential complexity of all plausible decoding strategies.

5. Decryption Complexity and Scalability

Legitimate decryption requires pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}5 add-compare-select (ACS) operations. For fixed (pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}6), this complexity is pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}7, supporting linear-time scaling with plaintext length and uniform per-bit cost. Parallel hardware implementations, such as arrays of directed-graph decoders, are feasible, with ACS modules mapped efficiently to ASIC, FPGA, or closely coupled RISC-V cores. For pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}8, pi(x)=∑j=0paj(i)xjp_i(x)=\sum_{j=0}^{p} a_{j}^{(i)} x^{j}9, GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]0 ACS/bit operations are well within capabilities of contemporary mobile or embedded hardware, delivering Mbps throughput.

6. Analytical Formulas and Bounds

Key analytical results that support the security and performance claims include:

  • Error-Propagation Bound:

GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]1

  • Gilbert Bound for Incorrect-Candidate Distance:

GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]2

where GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]3.

  • ISD Complexity Estimates:

GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]4

  • Decoding Ambiguity: With GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]5-bit mask uncertainty, GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]6 decoding candidates are separated by decoding distances such that only the correct candidate achieves minimal (close to GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]7) Hamming distance with high probability.

7. Significance in Post-Quantum Cryptography

NE-HMCC harmonizes high constraint-length convolutional codes, dense masking, random transformation, and controlled noise injection to yield a public code statistically indistinguishable from random. This supports polynomial-time decryption for legitimate users and exponential-cost attacks (ISD or otherwise) for adversaries. The resulting scheme provides security margins surpassing Classic McEliece by GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]8 classically and GQ(x)=[ q0(x), q1(x), …, qn−1(x) ]G_Q(x) = [\,q_0(x),\,q_1(x),\,\ldots,\,q_{n-1}(x)\,]9 quantumly, offers hardware-friendly, scalable decryption, and admits arbitrary plaintext lengths with uniform per-bit cost (Ariel, 2 Dec 2025). The architectural properties and cryptanalytic barriers position NE-HMCC as a strong candidate for scalable, robust, and high-security public-key systems in the post-quantum era.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Noise-Enhanced High-Memory Convolutional Codes.