Paper 2025/1895

Differential Fault Attacks on MQOM, Breaking the Heart of Multivariate Evaluation

Vladimir Sarde, Versailles Saint-Quentin-en-Yvelines University, Cryptography & Security Group, IDEMIA Secure Transactions, Pessac, France
Nicolas Debande, Cryptography & Security Group, IDEMIA Secure Transactions, Pessac, France
Abstract

MQOM is one of the fourteen remaining candidates in the second round of the NIST post-quantum signature standardization process. Introduced in 2023, MQOM instantiates the Multi-Party Computation in the Head (MPCitH) paradigm over the well-established hard problem of solving Multivariate Quadratic (MQ) equations. In this paper, we present the first fault attacks on MQOM targeting the MQ evaluation phase, which is a central component of the algorithm. We introduce four differential fault attacks and demonstrate their effectiveness against both unprotected and masked implementations. The first two target the secret key using a random fault model, making them particularly realistic and practical. With as little as one or two injected faults, depending on the variant, the entire secret key can be recovered through linear algebra. The other two attacks exploit faults on the coefficients of the MQ system directly. Our results highlight that the MQ evaluation, despite not being identified as a sensitive component until now, can be exploited using just a few fault injections.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. CASCADE
Keywords
MQOMMPC-in-the-HeadPost-Quantum SignatureMultivariate CryptographyPIOPFault Attack
Contact author(s)
vladimir sarde @ idemia com
nicolas debande @ idemia com
History
2025-10-12: approved
2025-10-10: received
See all versions
Short URL
https://ia.cr/2025/1895
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2025/1895,
      author = {Vladimir Sarde and Nicolas Debande},
      title = {Differential Fault Attacks on {MQOM}, Breaking the Heart of Multivariate Evaluation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1895},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1895}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.