English

Fast Gao-like Decoding of Horizontally Interleaved Linearized Reed-Solomon Codes

Information Theory 2023-08-23 v1 math.IT

Abstract

Both horizontal interleaving as well as the sum-rank metric are currently attractive topics in the field of code-based cryptography, as they could mitigate the problem of large key sizes. In contrast to vertical interleaving, where codewords are stacked vertically, each codeword of a horizontally ss-interleaved code is the horizontal concatenation of ss codewords of ss component codes. In the case of horizontally interleaved linearized Reed-Solomon (HILRS) codes, these component codes are chosen to be linearized Reed-Solomon (LRS) codes. We provide a Gao-like decoder for HILRS codes that is inspired by the respective works for non-interleaved Reed-Solomon and Gabidulin codes. By applying techniques from the theory of minimal approximant bases, we achieve a complexity of O~(s2.373n1.635)\tilde{\mathcal{O}}(s^{2.373} n^{1.635}) operations in Fqm\mathbb{F}_{q^m}, where O~()\tilde{\mathcal{O}}(\cdot) neglects logarithmic factors, ss is the interleaving order and nn denotes the length of the component codes. For reasonably small interleaving order sns \ll n, this is subquadratic in the component-code length nn and improves over the only known syndrome-based decoder for HILRS codes with quadratic complexity. Moreover, it closes the performance gap to vertically interleaved LRS codes for which a decoder of complexity O~(s2.373n1.635)\tilde{\mathcal{O}}(s^{2.373} n^{1.635}) is already known. We can decode beyond the unique-decoding radius and handle errors of sum-rank weight up to ss+1(nk)\frac{s}{s + 1} (n - k) for component-code dimension kk. We also give an upper bound on the failure probability in the zero-derivation setting and validate its tightness via Monte Carlo simulations.

Keywords

Cite

@article{arxiv.2308.11328,
  title  = {Fast Gao-like Decoding of Horizontally Interleaved Linearized Reed-Solomon Codes},
  author = {Felicitas Hörmann and Hannes Bartz},
  journal= {arXiv preprint arXiv:2308.11328},
  year   = {2023}
}

Comments

21 pages, 1 figure, published in the proceedings of CBCrypto 2023

R2 v1 2026-06-28T12:01:19.972Z