Ghoshal, Ishai, Jain, and Sun recently introduced a novel quasipolynomial-time distinguisher for GRS subcodes (including Goppa codes), leaving key recovery as an open problem. This note presents an approach for turning the distinguisher into a full key-recovery attack. The overall complexity is dominated by a few executions of the distinguisher, and the approach is experimentally validated on Goppa codes over . We conjecture that this recovery route applies to binary Goppa codes as well.

Extending Distinguishing to Key Recovery for Subfield Subcodes of GRS codes
Kirill Vedenev

