Papers
Topics
Authors
Recent
Search
2000 character limit reached

Twisted Gabidulin Codes Overview

Updated 11 July 2026
  • Twisted Gabidulin codes are MRD rank-metric codes derived from Gabidulin codes by inserting extra high-degree linearized monomials that modify structural invariants.
  • The construction preserves the optimal distance while altering nuclei, automorphism groups, and decoding behavior, leading to significant cryptographic and algorithmic implications.
  • Generalizations include multi-twist versions indexed by parameters s and h, with explicit MRD and non-MRD criteria that ensure inequivalence to classical Gabidulin codes.

Twisted Gabidulin codes are maximum rank distance (MRD) codes in the rank metric obtained by modifying Gabidulin evaluation codes through the insertion of one or more constrained high-degree linearized monomials. In Sheekey’s 2015 construction, the added term ties the coefficient of the highest monomial to a low-degree coefficient, producing codes with the same parameters as Gabidulin codes but, for nonzero twist, typically inequivalent to them (Sheekey, 2015). Later work broadened this idea to generalized twists indexed by ss and hh, to multi-twist constructions based on linear functionals, and to several distinct twist families with explicit MRD and non-MRD criteria (Lunardon et al., 2015, Puchinger et al., 2017, Li et al., 16 Sep 2025). Across these formulations, twisted Gabidulin codes preserve the optimal distance dR=nk+1d_R=n-k+1 under explicit algebraic conditions while altering nuclei, automorphism groups, qq-sum growth, and decoding behaviour in ways that sharply distinguish them from classical Gabidulin codes.

1. Rank-metric setting and Gabidulin antecedents

Let qq be a prime power, let $\F_{q^m}$ be a degree-mm extension of $\F_q$, and view $\F_{q^m}$ as an mm-dimensional vector space over hh0. For vectors in hh1, the rank metric is obtained by expanding each coordinate in an hh2-basis and taking the hh3-rank of the resulting hh4 matrix. A linear hh5 code over hh6 has minimum rank distance at most hh7, and codes meeting this bound are MRD (Puchinger et al., 2017).

Gabidulin codes are evaluation codes of linearized polynomials. In a standard formulation, one fixes hh8-linearly independent evaluation points hh9 and considers

dR=nk+1d_R=n-k+10

or, more generally, dR=nk+1d_R=n-k+11-powers with dR=nk+1d_R=n-k+12. Evaluating these polynomials on the dR=nk+1d_R=n-k+13 yields a code of dimension dR=nk+1d_R=n-k+14 over dR=nk+1d_R=n-k+15 and minimum rank distance dR=nk+1d_R=n-k+16, so Gabidulin codes are MRD (Puchinger et al., 2018, Trombetti et al., 2016).

The classical Gabidulin family supplies the structural template for all twisted variants: the same evaluation paradigm is retained, but the polynomial space is deformed by one or more extra monomials whose coefficients are not free. The resulting codes remain close enough to the Gabidulin framework to inherit strong distance properties, yet sufficiently different to alter equivalence type and cryptographic profile.

2. Sheekey’s twist and later generalizations

The original twist introduced by Sheekey adds one extra monomial of dR=nk+1d_R=n-k+17-degree dR=nk+1d_R=n-k+18, with coefficient determined by a low-degree coefficient. One common formulation is

dR=nk+1d_R=n-k+19

with qq0, qq1, and qq2 satisfying a nondegeneracy condition on the norm (Sheekey, 2015). A generalized version replaces the Frobenius step qq3 by qq4 modulo qq5, producing the family qq6 (Lunardon et al., 2015).

The literature then splits into several structurally related extensions. One direction keeps a single “hook” coefficient but allows several twist exponents; another allows several hooks; a third replaces the selected coefficient by an arbitrary linear functional of the low-degree coefficients.

Family Defining polynomial space Remark
Sheekey single twist qq7 Original twisted Gabidulin code
Generalized twist qq8 or qq9 Step size qq0 with qq1
Multi-twist by functionals qq2 Further generalization
Common-hook qq3-twist qq4 Studied with determinant criteria

In the 2017 multi-twist construction, one fixes qq5, integers qq6, scalars qq7, and qq8-linear functionals qq9, and defines

$\F_{q^m}$0

Evaluation at $\F_{q^m}$1-independent points gives an $\F_{q^m}$2 code. When $\F_{q^m}$3 and $\F_{q^m}$4 selects $\F_{q^m}$5, Sheekey’s original twist is recovered; when $\F_{q^m}$6 and $\F_{q^m}$7, one recovers the Lunardon–Trombetti–Zhou generalization (Puchinger et al., 2017).

A complementary viewpoint comes from skew-polynomial theory. In the one-block specialization of twisted linearized Reed–Solomon codes over $\F_{q^m}$8, the rank-metric case reproduces Sheekey’s twisted Gabidulin family exactly, placing twisted Gabidulin codes inside a broader sum-rank framework (Neri, 2021).

3. MRD property and explicit existence criteria

The defining feature of twisted Gabidulin codes is that, despite the deformation of the polynomial space, the minimum rank distance remains $\F_{q^m}$9 under explicit algebraic constraints. In Sheekey’s original construction this is enforced by the norm condition

mm0

The usual proof observes that every codeword has mm1-degree at most mm2, so its rank is at least mm3; if rank were exactly mm4, a determinant-norm identity would force the forbidden equality on mm5, which is excluded (Sheekey, 2015). Equivalent MRD proofs are also phrased by bounding the number of mm6-independent roots of a nonzero twisted linearized polynomial (Lunardon et al., 2015).

For generalized twisted Gabidulin codes in rectangular form mm7, the same phenomenon persists: evaluating mm8 on any mm9-independent set $\F_q$0 yields an $\F_q$1-linear MRD code with

$\F_q$2

and cardinality $\F_q$3 (Trombetti et al., 2016).

The 2017 multi-twist paper gives a linear-algebraic characterization of the MRD property. For a $\F_q$4-dimensional $\F_q$5-subspace $\F_q$6 inside the span of the evaluation points, let $\F_q$7 be the annihilator polynomial. Then the evaluated code fails to be MRD if and only if there exists such an $\F_q$8 for which a certain linear system in unknowns $\F_q$9 admits a nonzero solution. Equivalently, nonexistence of nontrivial solutions for all $\F_{q^m}$0 is equivalent to distance $\F_{q^m}$1 (Puchinger et al., 2017).

That same paper also supplies a sufficient subfield-chain condition. If

$\F_{q^m}$2

with $\F_{q^m}$3, $\F_{q^m}$4, $\F_{q^m}$5, and the evaluation points $\F_{q^m}$6 chosen in $\F_{q^m}$7, then the corresponding $\F_{q^m}$8-twisted Gabidulin code is MRD (Puchinger et al., 2017).

A later determinant-based treatment studies three twist families $\F_{q^m}$9 in which one coefficient mm0 controls one, two, or mm1 extra monomials. For mm2, mm3 is MRD if and only if

mm4

For mm5 and mm6, analogous determinant conditions involve

mm7

or

mm8

The same work gives explicit non-MRD criteria and new MRD constructions via subfield conditions, field chains, common-twist ratios, and a 1-sum-product-free condition (Li et al., 16 Sep 2025).

4. Equivalence, duality, nuclei, and automorphisms

A central theme in the subject is that twisted Gabidulin codes are often MRD without being equivalent to Gabidulin codes. In the semilinear rank-metric setting, equivalence means that two mm9-linear codes hh00 satisfy

hh01

for some hh02, some hh03, and some hh04 (Puchinger et al., 2017). Sheekey’s original family already contains codes inequivalent to classical Gabidulin codes whenever the twist is nontrivial and the norm condition holds (Sheekey, 2015).

For generalized twisted Gabidulin codes hh05, the equivalence problem is completely determined in the square case. The decisive constraints are that the step sizes must agree up to sign modulo hh06, the twist positions must agree up to sign modulo hh07, and the parameters hh08 must satisfy a precise relation induced by conjugation and field automorphisms. In this sense, the tuples hh09 function as genuine invariants up to a narrow family of transformations (Lunardon et al., 2015).

Duality behaves unusually well. The Delsarte dual of a twisted Gabidulin code is again a generalized twisted Gabidulin code up to equivalence: hh10 and the adjoint code is likewise twisted with modified parameters (Lunardon et al., 2015). This closure under duals and adjoints is one reason the family is structurally robust.

Nuclei provide a finer invariant. For an hh11-linear rank-metric code hh12, the middle nucleus and right nucleus are

hh13

Under mild hypotheses on hh14 and the twist parameter hh15, these nuclei are explicitly computed for punctured generalized twisted Gabidulin codes hh16, and they become finite fields that distinguish twisted families from ordinary generalized Gabidulin codes and from one another (Trombetti et al., 2016).

Automorphism groups are correspondingly rigid. In both the square and rectangular cases, automorphisms are forced to come from monomial actions on the domain and image together with field automorphisms, subject to a single compatibility condition preserving the twist term. The explicit description shows that, apart from these semilinear monomial symmetries, there are no additional hidden automorphisms (Trombetti et al., 2016).

5. Decoding theory

The decoding theory of twisted Gabidulin codes is less uniform than that of classical Gabidulin codes. For a code of minimum distance hh17, the usual unique-decoding radius is

hh18

A 2017 decoding algorithm adapts the Koetter–Kschischang interpolation-and-division method to twisted and generalized twisted Gabidulin codes that are hh19-linear but not hh20-linear (Randrianarisoa et al., 2017). The method solves interpolation equations

hh21

for linearized polynomials hh22, and then proceeds either by direct linearized division or by a twist-extraction step. In the second case, comparing two interpolation solutions yields a quadratic equation in the unknown leading message coefficient hh23 when the congruence

hh24

holds. The reported complexity is hh25 over hh26, with the observation that fast interpolation may reduce this to hh27 (Randrianarisoa et al., 2017).

The scope of efficient decoding remained limited. A GPT-oriented survey from 2018 explicitly listed as a drawback that no generic fast decoding algorithm is known for the full twisted family, although progress was said to be underway (Puchinger et al., 2018). This statement remains important because it separates special algorithmic regimes from the family in full generality.

A different line of work, published in 2021, studies a restricted communication model in which the error vector interpolates through a linearized error polynomial satisfying additional public constraints. Under that model, an interpolation-based decoder for Gabidulin codes can be extended to generalized twisted Gabidulin codes and additive generalized twisted Gabidulin codes, and the decoding radius increases by one beyond the usual half-distance bound: hh28 The complexity remains quadratic in hh29 for the main steps, including Moore-matrix inversion, Berlekamp–Massey-type recovery, quadratic solving, and recurrence evaluation (Kadir, 2021). The additional radius is conditional on the prescribed interpolation model, so it does not constitute an unrestricted unique decoder for arbitrary twisted Gabidulin channels.

6. Additional metric properties

Later work studies twisted Gabidulin codes simultaneously in the rank and Hamming metrics. Because hh30, an hh31 rank-metric MRD code with hh32 is automatically Hamming-MDS. For the three twist families hh33, precise necessary and sufficient criteria are given for the code to be MDS, AMDS, or NMDS in the Hamming metric, expressed through forbidden values of the twist parameters relative to minors of modified Moore matrices (Li et al., 16 Sep 2025).

For the one-twist family hh34, the Hamming-MDS criterion is

hh35

where hh36 is the set of hh37 over all hh38-subsets hh39. If hh40, then hh41 is AMDS precisely when every hh42-subset contains a hh43-subset avoiding the forbidden equality; if additionally hh44, the same condition yields NMDS (Li et al., 16 Sep 2025). Analogous statements are proved for hh45 and hh46 with

hh47

or

hh48

as the obstruction.

The same paper addresses covering radii and deep holes in the rank metric. For the one-twist family with hh49, the covering radius is exactly

hh50

For the two-twist and hh51-twist families, the bounds

hh52

are obtained (Li et al., 16 Sep 2025). Deep holes are characterized by MRD extensions: if hh53 and the augmented matrix hh54 generates an hh55 MRD code, then hh56 is a deep hole. In particular, vectors obtained by evaluating polynomials of the form hh57 or hh58 with hh59 are deep holes (Li et al., 16 Sep 2025).

7. Cryptographic use and cryptanalysis

Twisted Gabidulin codes were proposed as building blocks for GPT-style public-key cryptosystems because their hh60-sum profile can differ substantially from that of classical Gabidulin codes. For a suitable subfamily defined by

hh61

the hh62-sum dimensions satisfy

hh63

Thus the dimension jumps by hh64 at each step rather than by hh65, and there is no hh66 with hh67; this prevents the classical form of Overbeck’s attack, whose distinguisher and recovery require a hh68-sum of dimension exactly hh69 (Puchinger et al., 2018).

Within the GPT construction, one publishes

hh70

where hh71 is a twisted Gabidulin generator, hh72, hh73 has rank hh74, and hh75. The public-key size is

hh76

bits, and the 2018 comparison reports that twisted-GPT keys are “2–4 hh77 smaller than McEliece-Goppa and comparable to Loidreau’s.” One example at 128-bit security is

hh78

with public key hh79 and private key hh80 (Puchinger et al., 2018).

This cryptographic optimism was later reversed. A 2023 extension of Overbeck’s attack uses a stabilizer algebra of a low hh81-sum rather than the original hh82 dimensional criterion. In the twisted-GPT setting, the attack isolates an idempotent that removes the distortion block and recovers a decodable supercode from the first hh83-sum. The paper concludes that, even though twisted codes were designed to foil the classical Overbeck trade-off, the extension breaks them already for hh84, and “twisted Gabidulin codes, though MRD and not Gabidulin-equivalent, remain breakable in polynomial time by an extended Overbeck attack” in GPT-style schemes (Couvreur et al., 2023).

The cryptographic record is therefore mixed but technically coherent. Twisted Gabidulin codes remain important MRD constructions and rich objects of algebraic study, yet their use in GPT-like public-key hiding mechanisms has been substantially weakened by structural cryptanalysis.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Twisted Gabidulin Codes.