Twisted Gabidulin Codes Overview
- Twisted Gabidulin codes are MRD rank-metric codes derived from Gabidulin codes by inserting extra high-degree linearized monomials that modify structural invariants.
- The construction preserves the optimal distance while altering nuclei, automorphism groups, and decoding behavior, leading to significant cryptographic and algorithmic implications.
- Generalizations include multi-twist versions indexed by parameters s and h, with explicit MRD and non-MRD criteria that ensure inequivalence to classical Gabidulin codes.
Twisted Gabidulin codes are maximum rank distance (MRD) codes in the rank metric obtained by modifying Gabidulin evaluation codes through the insertion of one or more constrained high-degree linearized monomials. In Sheekey’s 2015 construction, the added term ties the coefficient of the highest monomial to a low-degree coefficient, producing codes with the same parameters as Gabidulin codes but, for nonzero twist, typically inequivalent to them (Sheekey, 2015). Later work broadened this idea to generalized twists indexed by and , to multi-twist constructions based on linear functionals, and to several distinct twist families with explicit MRD and non-MRD criteria (Lunardon et al., 2015, Puchinger et al., 2017, Li et al., 16 Sep 2025). Across these formulations, twisted Gabidulin codes preserve the optimal distance under explicit algebraic conditions while altering nuclei, automorphism groups, -sum growth, and decoding behaviour in ways that sharply distinguish them from classical Gabidulin codes.
1. Rank-metric setting and Gabidulin antecedents
Let be a prime power, let $\F_{q^m}$ be a degree- extension of $\F_q$, and view $\F_{q^m}$ as an -dimensional vector space over 0. For vectors in 1, the rank metric is obtained by expanding each coordinate in an 2-basis and taking the 3-rank of the resulting 4 matrix. A linear 5 code over 6 has minimum rank distance at most 7, and codes meeting this bound are MRD (Puchinger et al., 2017).
Gabidulin codes are evaluation codes of linearized polynomials. In a standard formulation, one fixes 8-linearly independent evaluation points 9 and considers
0
or, more generally, 1-powers with 2. Evaluating these polynomials on the 3 yields a code of dimension 4 over 5 and minimum rank distance 6, so Gabidulin codes are MRD (Puchinger et al., 2018, Trombetti et al., 2016).
The classical Gabidulin family supplies the structural template for all twisted variants: the same evaluation paradigm is retained, but the polynomial space is deformed by one or more extra monomials whose coefficients are not free. The resulting codes remain close enough to the Gabidulin framework to inherit strong distance properties, yet sufficiently different to alter equivalence type and cryptographic profile.
2. Sheekey’s twist and later generalizations
The original twist introduced by Sheekey adds one extra monomial of 7-degree 8, with coefficient determined by a low-degree coefficient. One common formulation is
9
with 0, 1, and 2 satisfying a nondegeneracy condition on the norm (Sheekey, 2015). A generalized version replaces the Frobenius step 3 by 4 modulo 5, producing the family 6 (Lunardon et al., 2015).
The literature then splits into several structurally related extensions. One direction keeps a single “hook” coefficient but allows several twist exponents; another allows several hooks; a third replaces the selected coefficient by an arbitrary linear functional of the low-degree coefficients.
| Family | Defining polynomial space | Remark |
|---|---|---|
| Sheekey single twist | 7 | Original twisted Gabidulin code |
| Generalized twist | 8 or 9 | Step size 0 with 1 |
| Multi-twist by functionals | 2 | Further generalization |
| Common-hook 3-twist | 4 | Studied with determinant criteria |
In the 2017 multi-twist construction, one fixes 5, integers 6, scalars 7, and 8-linear functionals 9, and defines
$\F_{q^m}$0
Evaluation at $\F_{q^m}$1-independent points gives an $\F_{q^m}$2 code. When $\F_{q^m}$3 and $\F_{q^m}$4 selects $\F_{q^m}$5, Sheekey’s original twist is recovered; when $\F_{q^m}$6 and $\F_{q^m}$7, one recovers the Lunardon–Trombetti–Zhou generalization (Puchinger et al., 2017).
A complementary viewpoint comes from skew-polynomial theory. In the one-block specialization of twisted linearized Reed–Solomon codes over $\F_{q^m}$8, the rank-metric case reproduces Sheekey’s twisted Gabidulin family exactly, placing twisted Gabidulin codes inside a broader sum-rank framework (Neri, 2021).
3. MRD property and explicit existence criteria
The defining feature of twisted Gabidulin codes is that, despite the deformation of the polynomial space, the minimum rank distance remains $\F_{q^m}$9 under explicit algebraic constraints. In Sheekey’s original construction this is enforced by the norm condition
0
The usual proof observes that every codeword has 1-degree at most 2, so its rank is at least 3; if rank were exactly 4, a determinant-norm identity would force the forbidden equality on 5, which is excluded (Sheekey, 2015). Equivalent MRD proofs are also phrased by bounding the number of 6-independent roots of a nonzero twisted linearized polynomial (Lunardon et al., 2015).
For generalized twisted Gabidulin codes in rectangular form 7, the same phenomenon persists: evaluating 8 on any 9-independent set $\F_q$0 yields an $\F_q$1-linear MRD code with
$\F_q$2
and cardinality $\F_q$3 (Trombetti et al., 2016).
The 2017 multi-twist paper gives a linear-algebraic characterization of the MRD property. For a $\F_q$4-dimensional $\F_q$5-subspace $\F_q$6 inside the span of the evaluation points, let $\F_q$7 be the annihilator polynomial. Then the evaluated code fails to be MRD if and only if there exists such an $\F_q$8 for which a certain linear system in unknowns $\F_q$9 admits a nonzero solution. Equivalently, nonexistence of nontrivial solutions for all $\F_{q^m}$0 is equivalent to distance $\F_{q^m}$1 (Puchinger et al., 2017).
That same paper also supplies a sufficient subfield-chain condition. If
$\F_{q^m}$2
with $\F_{q^m}$3, $\F_{q^m}$4, $\F_{q^m}$5, and the evaluation points $\F_{q^m}$6 chosen in $\F_{q^m}$7, then the corresponding $\F_{q^m}$8-twisted Gabidulin code is MRD (Puchinger et al., 2017).
A later determinant-based treatment studies three twist families $\F_{q^m}$9 in which one coefficient 0 controls one, two, or 1 extra monomials. For 2, 3 is MRD if and only if
4
For 5 and 6, analogous determinant conditions involve
7
or
8
The same work gives explicit non-MRD criteria and new MRD constructions via subfield conditions, field chains, common-twist ratios, and a 1-sum-product-free condition (Li et al., 16 Sep 2025).
4. Equivalence, duality, nuclei, and automorphisms
A central theme in the subject is that twisted Gabidulin codes are often MRD without being equivalent to Gabidulin codes. In the semilinear rank-metric setting, equivalence means that two 9-linear codes 00 satisfy
01
for some 02, some 03, and some 04 (Puchinger et al., 2017). Sheekey’s original family already contains codes inequivalent to classical Gabidulin codes whenever the twist is nontrivial and the norm condition holds (Sheekey, 2015).
For generalized twisted Gabidulin codes 05, the equivalence problem is completely determined in the square case. The decisive constraints are that the step sizes must agree up to sign modulo 06, the twist positions must agree up to sign modulo 07, and the parameters 08 must satisfy a precise relation induced by conjugation and field automorphisms. In this sense, the tuples 09 function as genuine invariants up to a narrow family of transformations (Lunardon et al., 2015).
Duality behaves unusually well. The Delsarte dual of a twisted Gabidulin code is again a generalized twisted Gabidulin code up to equivalence: 10 and the adjoint code is likewise twisted with modified parameters (Lunardon et al., 2015). This closure under duals and adjoints is one reason the family is structurally robust.
Nuclei provide a finer invariant. For an 11-linear rank-metric code 12, the middle nucleus and right nucleus are
13
Under mild hypotheses on 14 and the twist parameter 15, these nuclei are explicitly computed for punctured generalized twisted Gabidulin codes 16, and they become finite fields that distinguish twisted families from ordinary generalized Gabidulin codes and from one another (Trombetti et al., 2016).
Automorphism groups are correspondingly rigid. In both the square and rectangular cases, automorphisms are forced to come from monomial actions on the domain and image together with field automorphisms, subject to a single compatibility condition preserving the twist term. The explicit description shows that, apart from these semilinear monomial symmetries, there are no additional hidden automorphisms (Trombetti et al., 2016).
5. Decoding theory
The decoding theory of twisted Gabidulin codes is less uniform than that of classical Gabidulin codes. For a code of minimum distance 17, the usual unique-decoding radius is
18
A 2017 decoding algorithm adapts the Koetter–Kschischang interpolation-and-division method to twisted and generalized twisted Gabidulin codes that are 19-linear but not 20-linear (Randrianarisoa et al., 2017). The method solves interpolation equations
21
for linearized polynomials 22, and then proceeds either by direct linearized division or by a twist-extraction step. In the second case, comparing two interpolation solutions yields a quadratic equation in the unknown leading message coefficient 23 when the congruence
24
holds. The reported complexity is 25 over 26, with the observation that fast interpolation may reduce this to 27 (Randrianarisoa et al., 2017).
The scope of efficient decoding remained limited. A GPT-oriented survey from 2018 explicitly listed as a drawback that no generic fast decoding algorithm is known for the full twisted family, although progress was said to be underway (Puchinger et al., 2018). This statement remains important because it separates special algorithmic regimes from the family in full generality.
A different line of work, published in 2021, studies a restricted communication model in which the error vector interpolates through a linearized error polynomial satisfying additional public constraints. Under that model, an interpolation-based decoder for Gabidulin codes can be extended to generalized twisted Gabidulin codes and additive generalized twisted Gabidulin codes, and the decoding radius increases by one beyond the usual half-distance bound: 28 The complexity remains quadratic in 29 for the main steps, including Moore-matrix inversion, Berlekamp–Massey-type recovery, quadratic solving, and recurrence evaluation (Kadir, 2021). The additional radius is conditional on the prescribed interpolation model, so it does not constitute an unrestricted unique decoder for arbitrary twisted Gabidulin channels.
6. Additional metric properties
Later work studies twisted Gabidulin codes simultaneously in the rank and Hamming metrics. Because 30, an 31 rank-metric MRD code with 32 is automatically Hamming-MDS. For the three twist families 33, precise necessary and sufficient criteria are given for the code to be MDS, AMDS, or NMDS in the Hamming metric, expressed through forbidden values of the twist parameters relative to minors of modified Moore matrices (Li et al., 16 Sep 2025).
For the one-twist family 34, the Hamming-MDS criterion is
35
where 36 is the set of 37 over all 38-subsets 39. If 40, then 41 is AMDS precisely when every 42-subset contains a 43-subset avoiding the forbidden equality; if additionally 44, the same condition yields NMDS (Li et al., 16 Sep 2025). Analogous statements are proved for 45 and 46 with
47
or
48
as the obstruction.
The same paper addresses covering radii and deep holes in the rank metric. For the one-twist family with 49, the covering radius is exactly
50
For the two-twist and 51-twist families, the bounds
52
are obtained (Li et al., 16 Sep 2025). Deep holes are characterized by MRD extensions: if 53 and the augmented matrix 54 generates an 55 MRD code, then 56 is a deep hole. In particular, vectors obtained by evaluating polynomials of the form 57 or 58 with 59 are deep holes (Li et al., 16 Sep 2025).
7. Cryptographic use and cryptanalysis
Twisted Gabidulin codes were proposed as building blocks for GPT-style public-key cryptosystems because their 60-sum profile can differ substantially from that of classical Gabidulin codes. For a suitable subfamily defined by
61
the 62-sum dimensions satisfy
63
Thus the dimension jumps by 64 at each step rather than by 65, and there is no 66 with 67; this prevents the classical form of Overbeck’s attack, whose distinguisher and recovery require a 68-sum of dimension exactly 69 (Puchinger et al., 2018).
Within the GPT construction, one publishes
70
where 71 is a twisted Gabidulin generator, 72, 73 has rank 74, and 75. The public-key size is
76
bits, and the 2018 comparison reports that twisted-GPT keys are “2–4 77 smaller than McEliece-Goppa and comparable to Loidreau’s.” One example at 128-bit security is
78
with public key 79 and private key 80 (Puchinger et al., 2018).
This cryptographic optimism was later reversed. A 2023 extension of Overbeck’s attack uses a stabilizer algebra of a low 81-sum rather than the original 82 dimensional criterion. In the twisted-GPT setting, the attack isolates an idempotent that removes the distortion block and recovers a decodable supercode from the first 83-sum. The paper concludes that, even though twisted codes were designed to foil the classical Overbeck trade-off, the extension breaks them already for 84, and “twisted Gabidulin codes, though MRD and not Gabidulin-equivalent, remain breakable in polynomial time by an extended Overbeck attack” in GPT-style schemes (Couvreur et al., 2023).
The cryptographic record is therefore mixed but technically coherent. Twisted Gabidulin codes remain important MRD constructions and rich objects of algebraic study, yet their use in GPT-like public-key hiding mechanisms has been substantially weakened by structural cryptanalysis.