---
title: Twisted Gabidulin Codes Overview
url: https://www.emergentmind.com/topics/twisted-gabidulin-codes
type: topic
---

# Twisted Gabidulin Codes Overview

Twisted Gabidulin codes are maximum rank distance (MRD) codes in the rank metric obtained by modifying Gabidulin evaluation codes through the insertion of one or more constrained high-degree linearized monomials. In Sheekey’s 2015 construction, the added term ties the coefficient of the highest monomial to a low-degree coefficient, producing codes with the same parameters as Gabidulin codes but, for nonzero twist, typically inequivalent to them [1504.01581]. Later work broadened this idea to generalized twists indexed by $s$ and $h$, to multi-twist constructions based on linear functionals, and to several distinct twist families with explicit MRD and non-MRD criteria [1507.07855] [1703.08093] [2509.12693]. Across these formulations, twisted Gabidulin codes preserve the optimal distance $d_R=n-k+1$ under explicit algebraic conditions while altering nuclei, automorphism groups, $q$-sum growth, and decoding behaviour in ways that sharply distinguish them from classical Gabidulin codes.

## 1. Rank-metric setting and Gabidulin antecedents

Let $q$ be a prime power, let $\F_{q^m}$ be a degree-$m$ extension of $\F_q$, and view $\F_{q^m}$ as an $m$-dimensional vector space over $\F_q$. For vectors in $\F_{q^m}^n$, the rank metric is obtained by expanding each coordinate in an $\F_q$-basis and taking the $\F_q$-rank of the resulting $m\times n$ matrix. A linear $[n,k]$ code over $\F_{q^m}$ has minimum rank distance at most $n-k+1$, and codes meeting this bound are MRD [1703.08093].

Gabidulin codes are evaluation codes of linearized polynomials. In a standard formulation, one fixes $\F_q$-linearly independent evaluation points $\alpha_1,\dots,\alpha_n\in \F_{q^m}$ and considers
\[
f(x)=\sum_{i=0}^{k-1} f_i x^{[i]},
\qquad [i]=q^i,
\]
or, more generally, $q^{si}$-powers with $\gcd(s,n)=1$. Evaluating these polynomials on the $\alpha_j$ yields a code of dimension $k$ over $\F_{q^m}$ and minimum rank distance $n-k+1$, so Gabidulin codes are MRD [1806.10055] [1611.04447].

The classical Gabidulin family supplies the structural template for all twisted variants: the same evaluation paradigm is retained, but the polynomial space is deformed by one or more extra monomials whose coefficients are not free. The resulting codes remain close enough to the Gabidulin framework to inherit strong distance properties, yet sufficiently different to alter equivalence type and cryptographic profile.

## 2. Sheekey’s twist and later generalizations

The original twist introduced by Sheekey adds one extra monomial of $q$-degree $k$, with coefficient determined by a low-degree coefficient. One common formulation is
\[
H_k(\eta,h)
=
\Bigl\{
f(x)=a_0x+a_1x^q+\cdots+a_{k-1}x^{q^{k-1}}+\eta\,a_0^{q^h}x^{q^k}
: a_i\in\F_{q^n}
\Bigr\},
\]
with $1\le k\le n-1$, $0\le h<n$, and $\eta\in\F_{q^n}^*$ satisfying a nondegeneracy condition on the norm [1504.01581]. A generalized version replaces the Frobenius step $i\mapsto i$ by $i\mapsto si$ modulo $n$, producing the family $H_{k,s}(\eta,h)$ [1507.07855].

The literature then splits into several structurally related extensions. One direction keeps a single “hook” coefficient but allows several twist exponents; another allows several hooks; a third replaces the selected coefficient by an arbitrary linear functional of the low-degree coefficients.

| Family | Defining polynomial space | Remark |
|---|---|---|
| Sheekey single twist | $\sum_{i=0}^{k-1}a_i x^{q^i}+\eta a_0^{q^h}x^{q^k}$ | Original twisted Gabidulin code |
| Generalized twist | $\sum_{i=0}^{k-1}a_i x^{q^{si}}+\eta a_0 x^{q^{sh}}$ or $\eta a_0^{q^h}x^{q^{sk}}$ | Step size $s$ with $\gcd(s,n)=1$ |
| Multi-twist by functionals | $\sum_{i=0}^{k-1}f_i x^{\sigma^i}+\sum_{\kappa=1}^{\ell}\eta_\kappa \lambda_\kappa(f_0,\dots,f_{k-1})x^{\sigma^{k-1+t_\kappa}}$ | Further generalization |
| Common-hook $\ell$-twist | $\sum_{i=0}^{k-1}f_i x^{[i]}+f_h\sum_{j=1}^{\ell}\eta_j x^{[k+t_j]}$ | Studied with determinant criteria |

In the 2017 multi-twist construction, one fixes $1\le k<n\le m$, integers $0<t_1<\cdots<t_\ell<n-k$, scalars $\eta_1,\dots,\eta_\ell\in \F_{q^m}^*$, and $\F_{q^m}$-linear functionals $\lambda_\kappa:\F_{q^m}^k\to \F_{q^m}$, and defines
\[
V=\Bigl\{
\sum_{i=0}^{k-1}f_i x^{\sigma^i}
+
\sum_{\kappa=1}^{\ell}
\eta_\kappa \lambda_\kappa(f_0,\dots,f_{k-1})x^{\sigma^{k-1+t_\kappa}}
\Bigr\}.
\]
Evaluation at $\F_q$-independent points gives an $[n,k]_{q^m}$ code. When $\ell=1$ and $\lambda_1$ selects $f_0$, Sheekey’s original twist is recovered; when $\ell=1$ and $\lambda_1(f_0,\dots,f_{k-1})=f_h$, one recovers the Lunardon–Trombetti–Zhou generalization [1703.08093].

A complementary viewpoint comes from skew-polynomial theory. In the one-block specialization of twisted linearized Reed–Solomon codes over $\F_{q^m}[x;\sigma]/(x^n-1)$, the rank-metric case reproduces Sheekey’s twisted Gabidulin family exactly, placing twisted Gabidulin codes inside a broader sum-rank framework [2105.10451].

## 3. MRD property and explicit existence criteria

The defining feature of twisted Gabidulin codes is that, despite the deformation of the polynomial space, the minimum rank distance remains $n-k+1$ under explicit algebraic constraints. In Sheekey’s original construction this is enforced by the norm condition
\[
N_{\F_{q^n}/\F_q}(\eta)\neq (-1)^{nk}.
\]
The usual proof observes that every codeword has $q$-degree at most $k$, so its rank is at least $n-k$; if rank were exactly $n-k$, a determinant-norm identity would force the forbidden equality on $N(\eta)$, which is excluded [1504.01581]. Equivalent MRD proofs are also phrased by bounding the number of $\F_q$-independent roots of a nonzero twisted linearized polynomial [1507.07855].

For generalized twisted Gabidulin codes in rectangular form $m\le n$, the same phenomenon persists: evaluating $H_{k,s}(n,h)$ on any $\F_q$-independent set $S=\{\alpha_1,\dots,\alpha_m\}\subset \F_{q^n}$ yields an $\F_q$-linear MRD code with
\[
d(\C)=n-k+1
\]
and cardinality $q^{nk}$ [1611.04447].

The 2017 multi-twist paper gives a linear-algebraic characterization of the MRD property. For a $k$-dimensional $\F_q$-subspace $S$ inside the span of the evaluation points, let $\Ann_S(x)=\sum_{i=0}^k a_i x^{\sigma^i}$ be the annihilator polynomial. Then the evaluated code fails to be MRD if and only if there exists such an $S$ for which a certain linear system in unknowns $g_0,\dots,g_{t_\ell-1}$ admits a nonzero solution. Equivalently, nonexistence of nontrivial solutions for all $S$ is equivalent to distance $n-k+1$ [1703.08093].

That same paper also supplies a sufficient subfield-chain condition. If
\[
\F_q=F_0\subsetneq F_1\subsetneq \cdots \subsetneq F_\ell=\F_{q^m},
\]
with $\eta_\kappa\in F_\kappa\setminus F_{\kappa-1}$, $\lambda_{\kappa,j}\in F_0$, $n\le |F_0|$, and the evaluation points $\alpha_i$ chosen in $F_0$, then the corresponding $\ell$-twisted Gabidulin code is MRD [1703.08093].

A later determinant-based treatment studies three twist families $C_1,C_2,C_3$ in which one coefficient $f_h$ controls one, two, or $\ell$ extra monomials. For $C_1$, $C_1$ is MRD if and only if
\[
\eta\neq -\,|V M_k^{(h,k+t)}(\alpha)^\top|\,/\,|V M_k(\alpha)^\top|
\quad\text{for all }V\in V_q(k,n).
\]
For $C_2$ and $C_3$, analogous determinant conditions involve
\[
\eta_1|V M_k^{(h,k+t_1)}|+\eta_2|V M_k^{(h,k+t_2)}|
\]
or
\[
|V M_k|+\sum_{j=1}^{\ell}\eta_j |V M_k^{(h,k+t_j)}|.
\]
The same work gives explicit non-MRD criteria and new MRD constructions via subfield conditions, field chains, common-twist ratios, and a 1-sum-product-free condition [2509.12693].

## 4. Equivalence, duality, nuclei, and automorphisms

A central theme in the subject is that twisted Gabidulin codes are often MRD without being equivalent to Gabidulin codes. In the semilinear rank-metric setting, equivalence means that two $\F_{q^m}$-linear codes $C,C'\subset \F_{q^m}^n$ satisfy
\[
C'=\tau(\lambda C)A
\]
for some $\lambda\in \F_{q^m}^*$, some $A\in \GL_n(q)$, and some $\tau\in \mathrm{Gal}(\F_{q^m}/\F_q)$ [1703.08093]. Sheekey’s original family already contains codes inequivalent to classical Gabidulin codes whenever the twist is nontrivial and the norm condition holds [1504.01581].

For generalized twisted Gabidulin codes $H_{k,s}(\eta,h)$, the equivalence problem is completely determined in the square case. The decisive constraints are that the step sizes must agree up to sign modulo $n$, the twist positions must agree up to sign modulo $n$, and the parameters $\eta,\theta$ must satisfy a precise relation induced by conjugation and field automorphisms. In this sense, the tuples $(s,h,\eta)$ function as genuine invariants up to a narrow family of transformations [1507.07855].

Duality behaves unusually well. The Delsarte dual of a twisted Gabidulin code is again a generalized twisted Gabidulin code up to equivalence:
\[
H_{k,s}(\eta,h)^\perp \sim H_{n-k,s}(\eta^{-1},n-h),
\]
and the adjoint code is likewise twisted with modified parameters [1507.07855]. This closure under duals and adjoints is one reason the family is structurally robust.

Nuclei provide a finer invariant. For an $\F_q$-linear rank-metric code $\C\subseteq \F_q^{m\times n}$, the middle nucleus and right nucleus are
\[
N_m(\C)=\{Z\in \F_q^{m\times m}: ZC\in \C\ \forall C\in \C\},
\qquad
N_r(\C)=\{Y\in \F_q^{n\times n}: CY\in \C\ \forall C\in \C\}.
\]
Under mild hypotheses on $(m,k)$ and the twist parameter $h$, these nuclei are explicitly computed for punctured generalized twisted Gabidulin codes $T_S(H_{k,s}(n,h))$, and they become finite fields that distinguish twisted families from ordinary generalized Gabidulin codes and from one another [1611.04447].

Automorphism groups are correspondingly rigid. In both the square and rectangular cases, automorphisms are forced to come from monomial actions on the domain and image together with field automorphisms, subject to a single compatibility condition preserving the twist term. The explicit description shows that, apart from these semilinear monomial symmetries, there are no additional hidden automorphisms [1611.04447].

## 5. Decoding theory

The decoding theory of twisted Gabidulin codes is less uniform than that of classical Gabidulin codes. For a code of minimum distance $d=n-k+1$, the usual unique-decoding radius is
\[
t\le \Bigl\lfloor \frac{d-1}{2}\Bigr\rfloor
=
\Bigl\lfloor \frac{n-k}{2}\Bigr\rfloor.
\]
A 2017 decoding algorithm adapts the Koetter–Kschischang interpolation-and-division method to twisted and generalized twisted Gabidulin codes that are $\F_q$-linear but not $\F_{q^n}$-linear [1705.07668]. The method solves interpolation equations
\[
P_1(\alpha_i)=P_2(r_i),\qquad i=1,\dots,n,
\]
for linearized polynomials $P_1,P_2$, and then proceeds either by direct linearized division or by a twist-extraction step. In the second case, comparing two interpolation solutions yields a quadratic equation in the unknown leading message coefficient $f_0$ when the congruence
\[
r\equiv t+k \pmod n
\]
holds. The reported complexity is $O(n^3)$ over $\F_q$, with the observation that fast interpolation may reduce this to $O(n^2)$ [1705.07668].

The scope of efficient decoding remained limited. A GPT-oriented survey from 2018 explicitly listed as a drawback that no generic fast decoding algorithm is known for the full twisted family, although progress was said to be underway [1806.10055]. This statement remains important because it separates special algorithmic regimes from the family in full generality.

A different line of work, published in 2021, studies a restricted communication model in which the error vector interpolates through a linearized error polynomial satisfying additional public constraints. Under that model, an interpolation-based decoder for Gabidulin codes can be extended to generalized twisted Gabidulin codes and additive generalized twisted Gabidulin codes, and the decoding radius increases by one beyond the usual half-distance bound:
\[
t_{\max}
=
\Bigl\lfloor\frac{n-k}{2}\Bigr\rfloor+1
=
\Bigl\lfloor\frac{d-1}{2}\Bigr\rfloor+1.
\]
The complexity remains quadratic in $n$ for the main steps, including Moore-matrix inversion, Berlekamp–Massey-type recovery, quadratic solving, and recurrence evaluation [2109.02069]. The additional radius is conditional on the prescribed interpolation model, so it does not constitute an unrestricted unique decoder for arbitrary twisted Gabidulin channels.

## 6. Additional metric properties

Later work studies twisted Gabidulin codes simultaneously in the rank and Hamming metrics. Because $d_R(x,y)\le d_H(x,y)$, an $[n,k]$ rank-metric MRD code with $n\le m$ is automatically Hamming-MDS. For the three twist families $C_1,C_2,C_3$, precise necessary and sufficient criteria are given for the code to be MDS, AMDS, or NMDS in the Hamming metric, expressed through forbidden values of the twist parameters relative to minors of modified Moore matrices [2509.12693].

For the one-twist family $C_1$, the Hamming-MDS criterion is
\[
\eta^{-1}\notin \Omega_1,
\]
where $\Omega_1$ is the set of $-g_h^{(t)}(I)$ over all $k$-subsets $I$. If $\eta^{-1}\in \Omega_1$, then $C_1$ is AMDS precisely when every $(k+1)$-subset contains a $k$-subset avoiding the forbidden equality; if additionally $h\in\{0,k-1\}$, the same condition yields NMDS [2509.12693]. Analogous statements are proved for $C_2$ and $C_3$ with
\[
1+\eta_1 g_h^{(t_1)}(I)+\eta_2 g_h^{(t_2)}(I)=0
\]
or
\[
1+\sum_{j=1}^{\ell}\eta_j g_h^{(t_j)}(I)=0
\]
as the obstruction.

The same paper addresses covering radii and deep holes in the rank metric. For the one-twist family with $t=0$, the covering radius is exactly
\[
\rho_R(C_1)=n-k.
\]
For the two-twist and $\ell$-twist families, the bounds
\[
n-k-1\le \rho_R(C_2)\le n-k,
\qquad
n-k-\ell+1\le \rho_R(C_3)\le n-k
\]
are obtained [2509.12693]. Deep holes are characterized by MRD extensions: if $u\notin C_1$ and the augmented matrix $[G_1;u]$ generates an $[n,k+1]$ MRD code, then $u$ is a deep hole. In particular, vectors obtained by evaluating polynomials of the form $g x^{[k]}+h(x)$ or $g x^{[h]}+h(x)$ with $h\in P_1$ are deep holes [2509.12693].

## 7. Cryptographic use and cryptanalysis

Twisted Gabidulin codes were proposed as building blocks for GPT-style public-key cryptosystems because their $q$-sum profile can differ substantially from that of classical Gabidulin codes. For a suitable subfamily defined by
\[
\Delta=\frac{n-k-\ell}{\ell+1}\in \mathbb{N},
\qquad
t_j=(j+1)(\Delta+1),
\qquad
|h_{j+1}-h_j|>1,
\]
the $q$-sum dimensions satisfy
\[
\dim \Lambda_i(C_{\rm twist})
=
\min\{\,k-1+(i+1)(\ell+1),\,n\}.
\]
Thus the dimension jumps by $\ell+1$ at each step rather than by $1$, and there is no $i<\Delta$ with $\dim \Lambda_i(C)=n-1$; this prevents the classical form of Overbeck’s attack, whose distinguisher and recovery require a $q$-sum of dimension exactly $n-1$ [1806.10055].

Within the GPT construction, one publishes
\[
G_{\rm pub}=S[\,X\mid G_{\rm twist}\,]P,
\]
where $G_{\rm twist}$ is a twisted Gabidulin generator, $S\in \mathrm{GL}_k(\F_{q^m})$, $X\in \F_{q^m}^{k\times \lambda}$ has rank $s\le \lambda$, and $P\in \mathrm{GL}_{n+\lambda}(\F_q)$. The public-key size is
\[
k(n+\lambda)m\log_2 q
\]
bits, and the 2018 comparison reports that twisted-GPT keys are “2–4 $\times$ smaller than McEliece-Goppa and comparable to Loidreau’s.” One example at 128-bit security is
\[
k\approx 21,\quad n\approx 33,\quad m\approx 132,\quad \ell=2
\]
with public key $\approx 6.9\,\mathrm{KB}$ and private key $\approx 0.6\,\mathrm{KB}$ [1806.10055].

This cryptographic optimism was later reversed. A 2023 extension of Overbeck’s attack uses a stabilizer algebra of a low $q$-sum rather than the original $n-1$ dimensional criterion. In the twisted-GPT setting, the attack isolates an idempotent that removes the distortion block and recovers a decodable supercode from the first $q$-sum. The paper concludes that, even though twisted codes were designed to foil the classical Overbeck trade-off, the extension breaks them already for $i=1$, and “twisted Gabidulin codes, though MRD and not Gabidulin-equivalent, remain breakable in polynomial time by an extended Overbeck attack” in GPT-style schemes [2305.01287].

The cryptographic record is therefore mixed but technically coherent. Twisted Gabidulin codes remain important MRD constructions and rich objects of algebraic study, yet their use in GPT-like public-key hiding mechanisms has been substantially weakened by structural cryptanalysis.

Source: https://www.emergentmind.com/topics/twisted-gabidulin-codes