In this paper a new structural attack on the McEliece/Niederreiter public key cryptosystem based on subcodes of generalized Reed-Solomon codes proposed by Berger and Loidreau is described. It allows the reconstruction of the private key for almost all practical parameter choices in polynomial time with high probability.


Public key cryptography McEliece encryption Niederreiter encryption error-correcting codes generalized Reed-Solomon codes Sidelnikov-Shestakov attack 


