Paper 2025/1838
Fault to Forge: Fault Assisted Forging Attacks on LESS Signature Scheme
Abstract
LESS is a digital signature scheme that is currently in the second round of the National Institute of Standards and Technology’s (NIST’s) ongoing call for standardization of additional post-quantum signature schemes. Recently, the ZKfault attack by Mondal et al. (Asiacrypt 2024) showed several attack surfaces on the first version of LESS (LESS-v1) that can be exploited using different fault attacks. However, the designers of LESS have updated the scheme in the second round to improve efficiency and signature size. The fault attacks in ZKfault are not directly applicable to this new version of LESS (LESS-v2). The physical security of LESS-v2 is still unexplored. In this work, we analyze the new structure of the LESS-v2 signature scheme and propose a method for universal forgery. One crucial observation is that, for LESS-v2, an adversary does not require the full signing key, but some other secret-related information, namely, a permutation of secret monomial matrices. We assume an adversary can use execution interruption techniques, such as fault attacks, to recover this extra information. We have analyzed multiple such attack surfaces in the design of LESS-v2, and using fault injection, we can recover secret-related information. We showed the average number of required faults for two particular fault models to recover the secret equivalent component and observed that, for most parameters, we need only 1 faulted signature, and at most 1088. Our attacks rely on simple and standard fault models. We demonstrated these using both simulation and a simple experimental setup.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Post-quantum cryptographyDigital signatureCode-basedZero-knowledge basedFault attacksLESS-v2Chip-whisperer
- Contact author(s)
-
pujamondal @ cse iitk ac in
suparna kundu @ esat kuleuven be
nishiyama hikaru na1 @ is naist jp
adhikarys @ cse iitk ac in
fujimoto @ is naist jp
yu-ichi @ is naist jp
angshuman @ cse iitk ac in - History
- 2026-03-07: revised
- 2025-10-05: received
- See all versions
- Short URL
- https://ia.cr/2025/1838
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1838,
author = {Puja Mondal and Suparna Kundu and Hikaru Nishiyama and Supriya Adhikary and Daisuke Fujimoto and Yuichi Hayashi and Angshuman Karmakar},
title = {Fault to Forge: Fault Assisted Forging Attacks on {LESS} Signature Scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1838},
year = {2025},
url = {https://eprint.iacr.org/2025/1838}
}