Paper 2025/1838

Fault to Forge: Fault Assisted Forging Attacks on LESS Signature Scheme

Puja Mondal, Indian Institute of Technology Kanpur
Suparna Kundu, KU Leuven
Hikaru Nishiyama, Nara Institute of Science and Technology
Supriya Adhikary, Indian Institute of Technology Kanpur
Daisuke Fujimoto, Nara Institute of Science and Technology
Yuichi Hayashi, Nara Institute of Science and Technology
Angshuman Karmakar, Indian Institute of Technology Kanpur
Abstract

LESS is a digital signature scheme that is currently in the second round of the National Institute of Standards and Technology’s (NIST’s) ongoing call for standardization of additional post-quantum signature schemes. Recently, the ZKfault attack by Mondal et al. (Asiacrypt 2024) showed several attack surfaces on the first version of LESS (LESS-v1) that can be exploited using different fault attacks. However, the designers of LESS have updated the scheme in the second round to improve efficiency and signature size. The fault attacks in ZKfault are not directly applicable to this new version of LESS (LESS-v2). The physical security of LESS-v2 is still unexplored. In this work, we analyze the new structure of the LESS-v2 signature scheme and propose a method for universal forgery. One crucial observation is that, for LESS-v2, an adversary does not require the full signing key, but some other secret-related information, namely, a permutation of secret monomial matrices. We assume an adversary can use execution interruption techniques, such as fault attacks, to recover this extra information. We have analyzed multiple such attack surfaces in the design of LESS-v2, and using fault injection, we can recover secret-related information. We showed the average number of required faults for two particular fault models to recover the secret equivalent component and observed that, for most parameters, we need only 1 faulted signature, and at most 1088. Our attacks rely on simple and standard fault models. We demonstrated these using both simulation and a simple experimental setup.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Post-quantum cryptographyDigital signatureCode-basedZero-knowledge basedFault attacksLESS-v2Chip-whisperer
Contact author(s)
pujamondal @ cse iitk ac in
suparna kundu @ esat kuleuven be
nishiyama hikaru na1 @ is naist jp
adhikarys @ cse iitk ac in
fujimoto @ is naist jp
yu-ichi @ is naist jp
angshuman @ cse iitk ac in
History
2026-03-07: revised
2025-10-05: received
See all versions
Short URL
https://ia.cr/2025/1838
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1838,
      author = {Puja Mondal and Suparna Kundu and Hikaru Nishiyama and Supriya Adhikary and Daisuke Fujimoto and Yuichi Hayashi and Angshuman Karmakar},
      title = {Fault to Forge: Fault Assisted Forging Attacks on {LESS} Signature Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1838},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1838}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.