---
title: Permutation Code Equivalence in Coding Theory
url: https://www.emergentmind.com/topics/permutation-code-equivalence-pce
type: topic
---

# Permutation Code Equivalence in Coding Theory

Permutation Code Equivalence (PCE) is the problem of deciding, for two linear codes \(C,D \subseteq \mathbb{F}_q^n\), whether one is obtained from the other by a permutation of coordinates. In generator-matrix form, with full-rank \(G_1,G_2 \in \mathbb{F}_q^{k \times n}\), PCE asks whether there exist \(U \in GL_k(\mathbb{F}_q)\) and a permutation matrix \(\Pi\) such that \(G_2 = U G_1 \Pi\). Within the modern literature, PCE appears both as an autonomous equivalence problem and as the permutation-only core of broader monomial or linear code equivalence problems; it is also studied through quotient actions on Grassmannians, reductions to Graph Isomorphism and lattice isomorphism, and family-specific descriptions for cyclic, self-dual, and extended perfect codes [2603.09869] [1905.00073] [2502.07916] [1111.4382].

## 1. Formal problem and equivalent formulations

In the standard linear-code setting, a linear \([n,k]\) code over \(\mathbb{F}_q\) is a \(k\)-dimensional subspace of \(\mathbb{F}_q^n\). A permutation \(\pi \in S_n\) acts on coordinates via its permutation matrix \(P_\pi\), and the permuted code is \(C^\pi = \{cP_\pi : c \in C\}\). Two codes are permutation equivalent when \(D=C^\pi\) for some \(\pi\). If \(G\) generates \(C\) and \(G'\) generates \(D\), then \(D=C^\pi\) is equivalent to the existence of \(S \in GL_k(\mathbb{F}_q)\) with \(G' = SG P_\pi\); once \(P_\pi\) is known, \(S\) is recovered by linear algebra. The associated automorphism group is
\[
Aut(C)=\{P_\pi \in S_n : \exists\, S \in GL_k(\mathbb{F}_q)\ \text{with}\ G=SGP_\pi\},
\]
so PCE is naturally both a search problem for a witness permutation and a decision problem about orbit membership under \(S_n\) [1111.4382].

PCE is distinct from Linear Code Equivalence (LCE) and Signed Permutation Code Equivalence (SPCE). LCE allows an arbitrary monomial matrix \(M=D\Pi\), where \(D\) is diagonal with nonzero entries and \(\Pi\) is a permutation matrix, so the defining relation is \(G_2 = U G_1 D\Pi\). SPCE restricts the diagonal part to signs \(\{\pm 1\}\). These variants satisfy \(\Pi_n \subseteq S_n \subseteq Monomial_n \subseteq GL_n\), and recent reductions show that PCE admits polynomial-time Karp reductions to both LCE and SPCE; over prime fields, composition with a reduction from SPCE to the Lattice Isomorphism Problem yields a reduction from PCE to lattice isomorphism [2502.07916].

A second formulation, important for cryptographic work on LCE, passes from generator matrices to the Grassmannian \(G(k,n)\) of \(k\)-dimensional subspaces of \(\mathbb{F}_q^n\). Writing \(\Delta=(\mathbb{F}^\times)^n\) for the diagonal group acting by coordinatewise scalings, one studies the quotient \(G(k,n)/\Delta\). In that quotient, the monomial ambiguity is factored into a diagonal part and a permutation part, and PCE becomes: given representatives \([V]_\Delta\) and \([V']_\Delta\), find \(P \in S_n\) such that \([P \star V]_\Delta = [V']_\Delta\). The paper on Plücker coordinates makes explicit that recovering a monomial \(Q=DP\) reduces to recovering only its permutation part \(P\), with diagonal scalings disappearing in the quotient formulation [2603.09869].

## 2. Grassmannians, Plücker coordinates, and invariant-theoretic models

The algebraic-geometric treatment of PCE begins with the Plücker embedding of the Grassmannian. If \(W \in G(k,n)\) has generator matrix \(M \in \mathbb{F}^{k \times n}\), then for each \(k\)-subset \(I \subseteq [n]\), the Plücker coordinate is \(p_I=\det(M_I)\), where \(M_I\) is the \(k \times k\) submatrix on columns indexed by \(I\). These coordinates define a point in \(\mathbb{P}^{\binom{n}{k}-1}\) satisfying the quadratic Plücker relations. Monomial actions separate cleanly in these coordinates: if \(Q=DP\) with \(D=\operatorname{diag}(d_1,\dots,d_n)\), then diagonal scaling sends \(p_I\) to \((\prod_{i \in I} d_i)p_I\), while permutations relabel indices by \(p_I \mapsto p_{P(I)}\) [2603.09869].

This separation permits an invariant-field construction for the diagonal action. Let \(K(G(k,n))\) be the field of rational functions on the Grassmannian, and let \(K(G(k,n))^\Delta\) be the subfield fixed by \(\Delta\). The key combinatorial device is the incidence matrix \(W_{k,n} \in \mathbb{Z}^{\binom{n}{k} \times n}\), whose \(I\)-th row is the indicator vector of \(I\). For \(v \in \mathbb{Z}^{\binom{n}{k}}\), the rational monomial
\[
f_v=\prod_I p_I^{v_I}
\]
is \(\Delta\)-invariant exactly when \(v\) lies in the left kernel of \(W_{k,n}\). Since \(\operatorname{rank}(W_{k,n})=n\) for \(1 \le k \le n-1\), the kernel has rank \(\binom{n}{k}-n\). The paper then uses a Jacobian/Kähler-differentials criterion to select algebraically independent generators, with
\[
\operatorname{trdeg} K(G(k,n))^\Delta = k(n-k)-(n-1),
\]
matching the geometric fact that diagonal scaling removes \(n-1\) generic degrees of freedom. A practically computable family of low-degree invariants is
\[
f_{I_1,J_1;I_2,J_2}=\frac{p_{I_1}p_{J_1}}{p_{I_2}p_{J_2}},
\]
whenever \(I_1 \uplus J_1 = I_2 \uplus J_2\) as multisets, so the diagonal weights cancel [2603.09869].

Given two equivalent codes generated by \(G_1\) and \(G_2\), every \(\Delta\)-invariant rational function \(\mu=g/f\) yields a polynomial constraint in an unknown matrix \(X=(x_{ij})\):
\[
h(X)=g(G_1X)-f(G_1X)\mu(G_2).
\]
By construction, the true permutation matrix \(P\) satisfies \(h(P)=0\). Because each Plücker coordinate \(p_I(G_1X)\) is a determinant of degree \(k\) in the entries of \(X\), the resulting polynomial has degree \(2k\). These equations can be combined with the standard permutation constraints \(x_{ij}^2-x_{ij}=0\), row sums equal to \(1\), and column sums equal to \(1\). A second family of equations,
\[
h'(X)=g(G_2X^T)-f(G_2X^T)\mu(G_1),
\]
uses \(P^{-1}=P^T\) to add constraints without introducing new variables [2603.09869].

The framework is theoretically precise but computationally prohibitive at cryptographic parameters. Determinants expand into \(k!\) monomials, products of determinants amplify this growth, and the number of Plücker coordinates is \(\binom{n}{k}\), which is exponentially large in the worst regime. For parameters relevant to LESS, such as \(k \approx 126\), the degree becomes \(2k \approx 252\). The paper therefore concludes that the polynomials are not practical for cryptographic parameter sets, even though the method constitutes the first application of Grassmannians, Plücker coordinates, and diagonal-invariant rational functions to LCE/PCE cryptanalysis. In the worked example \(G(2,4)\), the invariant field has transcendence degree \(1\); the invariants
\[
\mu_1=\frac{p_{12}p_{34}}{p_{14}p_{23}}, \qquad
\mu_2=\frac{p_{13}p_{24}}{p_{14}p_{23}}
\]
satisfy \(\mu_2=\mu_1+1\) via the Plücker relation, and the resulting polynomial \(h(X)\) has degree \(4\) [2603.09869].

## 3. Cyclic and constacyclic families

For cyclic codes, PCE can often be described explicitly in group-theoretic terms. If \(C\) is cyclic of length \(n=p^m\), then the full cycle \(T=(1,2,\dots,n)\) lies in \(Aut(C)\), and the relevant equivalence permutations are controlled by the \(p\)-Sylow subgroup \(P\) of \(Aut(C)\) containing \(T\). The core criterion is
\[
H(P)=\{\sigma \in S_{p^m} : \sigma^{-1}T\sigma \in P\},
\]
with the statement that two cyclic objects on \(p^m\) points are equivalent if and only if they are equivalent via an element of \(H(P)\). When \(|P|=p^m\), one has \(P=\langle T\rangle\) and \(H(P)=AG(p^m)\), so equivalence reduces to affine permutations \(x \mapsto ax+b \bmod p^m\); when \(m<s\le p+m-1\) and \(|P|=p^s\), one has \(P=Q_{s-m}^1\) and equivalence lies in \(Q_{s-m+1}\), a family of polynomial permutations
\[
f(x)=a_0+a_1x+p^{m-1}(a_2x^2+\cdots+a_{s-m+1}x^{s-m+1}) \bmod p^m
\]
with \(a_1 \in \mathbb{Z}_{p^m}^\times\). The operational procedure determines the relevant \(p\)-Sylow size by testing specific permutations \(f_i\), using at most \(\lfloor \log_2(p-1)\rfloor+1\) checks, and then restricts the search accordingly [1207.3132].

A closely related treatment for cyclic and quasi-cyclic codes describes the normalizer \(N_{S_n}(\langle T\rangle)=AGL(1,n)\), generalized multipliers, and the polynomial \(p\)-groups \(Q^n\) and \(Q_1^n\). For cyclic codes of length \(p^r\), it proves that equivalence testing can be restricted to \(H(P)\), with \(H(P)=AG(p^r)\) when the Sylow size is minimal and \(H(P)=Q^{s-1}\) when \(s>r\) in the range covered by the theorem. For quasi-cyclic codes, the analogous set \(H'(P)=\{\sigma \in S_n : \sigma^{-1}T_\ell \sigma \in P\}\) contains the normalizer of the \(\ell\)-shift and, in particular, \(AG(n)\) [1002.2456].

For cyclic codes over general finite fields, defining sets give a second explicit language for PCE. If \(T_1,T_2\) are defining sets of cyclic codes of length \(n\), then a multiplier \(\mu_s: i \mapsto si \bmod n\) with \(\mu_s(T_1)=T_2\) yields permutation equivalence. If \(\gcd(n,\varphi(n))=1\), this multiplier description is complete for cyclic codes: two cyclic codes are permutation equivalent if and only if their defining sets are related by a multiplier. The 2022 work also isolates a necessary-and-sufficient criterion for monomial equivalence through a shift \(\phi_b: i \mapsto i+b \bmod n\): one must have \(\phi_b(T_1)=T_2\) and \(n \mid |T_1|(q-1)b\). Beyond multipliers and shifts, it introduces specific transformations \(P_\sigma D\), \(P_\gamma\), and \(P_\chi\) that produce additional monomial or permutation equivalences in the cases \(n \equiv 0 \pmod 8\) or \(q=4\) with \(n\) divisible by \(27\). For \(\omega\)-constacyclic codes over \(\mathbb{F}_4\), if \(\gcd(3n,\varphi(3n))=1\), then all permutation equivalent constacyclic codes of length \(n\) are given by the action of multipliers with \(e \equiv 1 \pmod 3\) [2211.00897].

## 4. Tractable subclasses, complete invariants, and the role of hulls

A major tractable class is formed by codes with trivial hull. Fixing a nondegenerate symmetric bilinear form on \(F^n\), the hull is \(Hull(C)=C \cap C^\perp\). When \(Hull(C)=\{0\}\), one has \(F^n=C \oplus C^\perp\), and for any generator matrix \(G_C\) the Gram matrix \(G_CG_C^T\) is invertible. The reduction to weighted Graph Isomorphism constructs the symmetric idempotent projection
\[
\Sigma_C = G_C^T (G_CG_C^T)^{-1} G_C.
\]
If \(D=C\Pi\), then \(\Sigma_D=\Pi^T \Sigma_C \Pi\), and conversely this conjugacy implies \(D=C\Pi\). PCE on trivial-hull codes therefore reduces deterministically in polynomial time to weighted undirected graph isomorphism, with graph construction cost \(O(n^\omega)\). The experiments reported for random binary codes with trivial hull show that permutation equivalence can be decided “in a few minutes” for lengths up to \(50{,}000\), with the \(\Sigma\)-construction dominating the runtime [1905.00073].

Self-dual binary codes illustrate a different phenomenon: large hull does not, by itself, force hard instances. A self-dual code \(C=C^\perp\) has hull dimension \(n/2\), but every such code admits a canonical decomposition
\[
P(C)=C_0 \oplus Z^r,
\]
where \(Z=\{(0,0)^T,(1,1)^T\}\), \(C_0\) is reduced with minimum distance at least \(4\), and the reduced length \(R_0(C)=\operatorname{len}(C_0)\) is an invariant. The \(Z^r\) summand is found in polynomial time by enumerating weight-2 codewords and puncturing their supports. Search PCE on self-dual binary codes then runs in
\[
2^{R_0(C)+o(R_0(C))} + poly(n)
\]
time by reducing the problem to the reduced part. If \(R_0(C)=O(\log n)\), the algorithm becomes polynomial-time. The same paper defines a “large shadow” regime through the minimum weight \(s(C)\) of a characteristic vector and proves a polynomial-time consequence when \(s(C)\ge (n-8K)/2\) and \(N_c(K)=O(\log n)\); in particular, \(K=3\) yields a polynomial-time regime unconditionally because \(N_c(3)\le N_L(3)\le 8{,}388{,}630\). This directly contradicts the common intuition that large hull should systematically make PCE difficult [2606.18662].

For certain extended perfect propelinear codes \(S_T\), the Steiner quadruple system \(SQS(S_T)\) of weight-4 supports is a complete invariant for permutation equivalence. The construction decomposes the design as \(Q_0 \cup Q_1 \cup Q_T\), where \(Q_0\) and \(Q_1\) are affine blocks internal to each half and \(Q_T\) is the cross-part determined by a permutation \(T\) of \(\mathbb{F}_2^r\) fixing \(0\). In this family, \(Aut(SQS(S_T)) \cong PAut(S_T)\), and \(S_T\) and \(S_{T'}\) are permutation equivalent if and only if \(SQS(S_T)\) and \(SQS(S_{T'})\) are isomorphic. The isomorphism condition is explicit: \(T'\) must equal either \(B \circ T \circ A^{-1}\) or \(B \circ T^{-1} \circ A^{-1}\) with \(A,B \in GL(r,2)\). Point transitivity is controlled by the criterion \(T^{-1} \in GL(r,2)\, T\, GL(r,2)\). This produces a design-theoretic route to PCE in a highly structured class [2009.08191].

## 5. Reductions, complexity-theoretic placement, and quantum formulations

Several reductions place PCE among isomorphism-type problems. On the one hand, PCE with trivial hulls is not harder than weighted Graph Isomorphism, by the projection-matrix reduction just described [1905.00073]. On the other hand, the 2025 reduction paper states that Graph Isomorphism reduces to PCE, cites Petrank–Roth for that direction, and notes that PCE is not NP-complete unless the polynomial hierarchy collapses; it also cites Babai’s quasi-polynomial-time algorithm as evidence that GI, and hence PCE, is likely outside the usual NP-complete paradigm. The same paper gives deterministic polynomial-time Karp reductions \(PCE \le_K LCE\) and \(PCE \le_K SPCE\) by an explicit block construction \(A \mapsto A'\), and then obtains \(PCE(\mathbb{F}_p)\le_K LIP\) through the Bennett–Win reduction from SPCE to the Lattice Isomorphism Problem [2502.07916].

PCE also admits a nonabelian Hidden Subgroup Problem formulation over \(S_n\). If \(G\) generates a code \(C\), one considers a canonicalization map and defines \(f(\pi)=Canon(GP_\pi)\). When \(G'\) generates an equivalent code, the hidden subgroup is \(Aut(C)\), and the unknown coset encodes the desired permutation. This makes PCE formally parallel to the HSP formulation of Graph Isomorphism. However, the 2011 paper proves an HSP-hardness criterion: if a \(q\)-ary \([n,k]\) code \(M\) satisfies \(q^{k^2}\le n^{0.2n}\), \(|Aut(M)|\le e^{o(n)}\), and the minimal degree of \(Aut(M)\) is \(\Omega(n)\), then any single-coset-state measurement, including strong Fourier sampling, reveals negligible information about the hidden permutation. Reed–Muller codes \(RM(r,m)\) with \(r \le 0.1m\) satisfy this condition for large \(m\), because \(Aut(RM(r,m))=AGL(m,2)\) has size \(2^{O((\log n)^2)}\) and minimal degree \(n/2\). The paper states that Goppa codes fall in the same broad regime. This places Fourier-sampling quantum attacks out of reach for those instances, at least within current HSP methods [1111.4382].

The same work emphasizes that quantum difficulty does not imply classical resistance in the known-code model. Sendrier’s Support Splitting Algorithm (SSA) canonically labels coordinates using invariants derived from punctured hulls and succeeds on many structured families, including Goppa codes, thereby breaking known-private-code McEliece instances classically. Reed–Muller codes behave differently: SSA fails or becomes impractical because the codes are self-dual and the relevant hull weight enumerators are exponentially large, but low-rate instances of the Sidelnikov system are still attacked classically by the quasipolynomial-time algorithm of Minder and Shokrollahi [1111.4382].

## 6. Cryptographic role, limitations, and open directions

The cryptographic importance of PCE is clearest through LCE. The assumed hardness of LCE lies at the core of the security of the LESS signature scheme and other signature schemes with advanced functionalities, and the Plücker-coordinate framework is explicitly motivated by isolating the permutation component inside the quotient action of \(S_n\) on \(G(k,n)/\Delta\). The same paper also notes that, although LCE is treated as a one-way group action in the single-sample setting, the multi-sample assumptions needed for advanced functionalities are subtle: the textbook action on generator matrices is not multiple one-way, and similar caveats apply to the canonical action on \(G(k,n)\). This suggests that the exact form of the action—generator matrices, canonical forms, or quotient orbits—matters materially for security arguments [2603.09869].

The main practical limitation of the invariant-theoretic approach is combinatorial blow-up. In the Plücker model, degree-\(2k\) equations are already large for moderate \(k\), and the number of Plücker coordinates is \(\binom{n}{k}\). Even one invariant may yield a massive polynomial, and evaluating many invariants exacerbates the monomial explosion. In structured families, explicit group-theoretic descriptions can be much sharper: cyclic and constacyclic codes admit multiplier, affine, or polynomial-permutation descriptions; self-dual binary codes may collapse to reduced instances of size \(R_0(C)\); and some extended perfect codes are completely classified by their Steiner quadruple systems [2603.09869] [1207.3132] [2606.18662] [2009.08191].

Several open directions recur across the literature. The algebraic-geometric work explicitly asks for lower-degree or sparser invariant constraints, structured parameter regimes where the Plücker machinery becomes feasible, and a better understanding of whether the quotient action \(S_n \star (G(k,n)/\Delta)\) has the multiple one-wayness, weak pseudorandomness, or unpredictability properties needed by advanced cryptographic constructions [2603.09869]. The self-dual-code work asks whether the decomposition and shadow bounds extend beyond binary self-dual codes, whether there is a threshold in the shadow parameter separating easy from hard instances, and whether \(N_c(K)\) can be controlled uniformly through Elkies-type finiteness results [2606.18662]. The reduction paper leaves open whether SPCE-to-lattice-isomorphism techniques can be extended beyond prime fields and whether any converse reduction from general LIP to code-equivalence variants exists [2502.07916]. For cyclic and constacyclic codes, the natural unresolved question is a fuller classification of non-multiplier equivalences beyond the special transformations already identified [2211.00897].

Across these directions, PCE appears less as a single uniform problem than as a family of orbit problems whose behavior depends sharply on algebraic structure. In some settings it reduces cleanly to graph isomorphism, to small reduced cores, or to explicit permutation groups; in others it is embedded in monomial equivalence and admits only high-degree algebraic encodings. The current literature therefore supports a differentiated view: PCE is simultaneously a foundational equivalence notion in coding theory, a cryptographic hardness assumption, and a testbed for invariant theory, group actions, and isomorphism algorithms.

Source: https://www.emergentmind.com/topics/permutation-code-equivalence-pce