Classic McEliece was submitted in 2017 to NIST's Post-Quantum Cryptography Standardization Project. In 2025, NIST delayed McEliece standardization, in particular writing "Concurrent standardization of Classic McEliece by NIST and ISO risks the creation of incompatible standards" and "After the ISO standardization process has been completed, NIST may consider developing a standard for Classic McEliece based on the ISO standard". There is a separate page regarding ISO.
This page is organized in reverse chronological order. All documents listed below are from the Classic McEliece Team. The PDFs say Classic McEliece at the top; the email statements are labeled "on behalf of the Classic McEliece team" or similar. See also the separate list of many more papers from a variety of sources.
Latest postings
- "Notes on a recent claim that a mceliece348864 distinguisher uses only 2529 operations", 2025-04-17
- "Re: Structural analysis of McEliece asymptotically better than generic decoding", 2024-08-16
Round-4 downloads (2022-10-23)
- Submission overview:
mceliece-submission-20221023.pdf
- Cryptosystem specification:
mceliece-spec-20221023.pdf
- Design rationale:
mceliece-rationale-20221023.pdf
- Guide for security reviewers:
mceliece-security-20221023.pdf
- Guide for implementors:
mceliece-impl-20221023.pdf
- Description of modifications from round 3 to round 4:
mceliece-mods3-20221023.pdf
- What plaintext confirmation means:
mceliece-pc-20221023.pdf
- Round-4 submission package. Includes all of the above, and implementations (at submission time).
- KAT files accompanying round-4 submission package.
Postings during round 3
- "Re: Question on Classic McEliece definition of FixedWeight", 2023-02-24
- "ROUND 3 OFFICIAL COMMENT: Classic McEliece", 2022-06-06
- "ROUND 3 OFFICIAL COMMENT: Classic McEliece", 2021-11-19
- "Re: ROUND 3 OFFICIAL COMMENT: Classic McEliece", 2021-06-29
- "Re: Rationale for Benes in Classic McEliece", 2020-12-05
- "Re: ROUND 3 OFFICIAL COMMENT: Classic McEliece", 2020-11-19
Round-3 downloads (2020-10-10)
- "Supporting Documentation" describing the round-3 submission:
mceliece-20201010.pdf
- Description of modifications from round 2 to round 3:
mceliece-20201010-mods2.pdf
- Round-3 submission package.
Includes "Supporting Documentation" (as
doc.pdf
), description of modifications (asmods2.pdf
), and implementations (at submission time). - KAT files accompanying round-3 submission package.
Postings during round 2
- Re: [pqc-forum] A question on the keypair generation of Classic McEliece, 2020-08-03
- Re: ROUND 2 OFFICIAL COMMENT: Classic McEliece, 2020-05-27
Round-2 downloads (2019-03-31)
- "Supporting Documentation" describing the round-2 submission:
mceliece-20190331.pdf
- Description of modifications from round 1 to round 2:
mceliece-20190331-mods.pdf
- Round-2 submission package.
Includes "Supporting Documentation" (as
doc.pdf
), description of modifications (asmods.pdf
), and implementations (at submission time). - KAT files accompanying round-2 submission package.
Round-1 downloads (2017-11-29)
- "Supporting Documentation" describing the round-1 submission:
mceliece-20171129.pdf
- Round-1 submission package.
Includes "Supporting Documentation" (as
doc.pdf
), implementations (at submission time), and KATs.
Version: This is version 2025.04.25 of the "NIST" web page.