Constant-time decoding of Gabidulin codes and their generalizations with application to RQC
This work addresses a critical gap in rank-metric cryptography: the absence of constant-time decoding implementations for Gabidulin codes, which renders schemes like RQC vulnerable to side-channel attacks. The paper presents the first constant-time decoding algorithm for augmented Gabidulin (AG) codes, achieving quadratic time complexity by introducing zero-column-extended Gabidulin codes and a constant-time q-polynomial left division technique. This approach is integrated into a new variant, RQC-Block-MS-AG, which maintains ciphertext and key sizes approximately one-quarter those of HQC while outperforming the original RQC in efficiency. Although roughly four times slower than HQC, the proposed scheme significantly improves the trade-off between security and practicality, thereby filling a key void in secure implementations of rank-metric cryptosystems.