Paper 2025/2101

Fault Attacks against UOV-based Signatures

Sven Bauer, Siemens AG, Foundational Technologies
Fabrizio De Santis, Siemens AG, Foundational Technologies
Kristjane Koleci, Siemens AG, Foundational Technologies
Abstract

The Unbalanced Oil and Vinegar (UOV) construction is the foundation of several post-quantum digital signature algorithms currently under consideration in NIST's standardization process for additional post-quantum digital signature schemes. This paper introduces new single fault injection attacks against the signing procedure of deterministic variants of signature schemes based on the UOV construction. We show how these attacks can be applied to attack MAYO and PROV, two signature schemes submitted to the NIST call for additional post-quantum signature schemes. The attacks are demonstrated with reference implementations that run on an ARM Cortex-M4 processor. Our attacks do not require precise triggering or precise fault injection capabilities. Any type of fault in large portions of the code has the potential to result in successful key recovery. We demonstrate our attacks with very cheap equipment and simple clock glitching techniques, enabling the recovery of the secret key with either two faulty signatures or one correct signature and one faulty signature in the case of MAYO and one correct signature and two faulty signatures in case of PROV. The fact that our attacks do not require precise fault injection capabilities and can be successful with only a few signatures makes them particularly powerful, hence harmful for the implementation security of post-quantum digital signature schemes.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. FDTC 2025
Keywords
Multivariate CryptographyPost-Quantum CryptographyUOVMayoPROVFault Attacks
Contact author(s)
svenbauer @ siemens com
fabrizio desantis @ siemens com
History
2025-11-17: approved
2025-11-15: received
See all versions
Short URL
https://ia.cr/2025/2101
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2101,
      author = {Sven Bauer and Fabrizio De Santis and Kristjane Koleci},
      title = {Fault Attacks against {UOV}-based Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2101},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2101}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.