Paper 2025/2029

Forging Dilithium and Falcon Signatures by Single Fault Injection

Sven Bauer, Siemens (Germany), Foundational Technologies
Fabrizio De Santis, Siemens (Germany), Foundational Technologies
Abstract

Embedded devices commonly rely on digital signatures to ensure both integrity and authentication. For example, digital signatures are typically verified during the boot process or firmware updates to verify the integrity of a system. They are also used to ensure authenticity of a communication party in secure protocols. Fault injection can be used to tamper with a device in order to cause malfunctioning during cryptographic computations. For example, fault injections can be used to disturb digital signing operations. With the right type of fault an attacker can compute private keys from faulted signatures. However, fault injections can also be used during verification to get maliciously crafted digital signatures accepted during signature verification with catastrophic consequences for the security of an embedded device. In this paper, we introduce new non-obvious fault injection attacks on the verification routines of Dilithium and Falcon signature schemes, which allow an attacker to get signatures for arbitrary messages accepted by fault injection. We demonstrate the feasibility of our attacks by simulations using an ARM Cortex-M4 and the pqm4 library as a target of evaluation and pinpoint vulnerable instructions. Finally, we propose and discuss possible countermeasures against these attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. FDTC 2023
Keywords
Fault injectionDilithium ML-DSAFalcon
Contact author(s)
svenbauer @ siemens com
fabrizio desantis @ siemens com
History
2025-11-03: approved
2025-11-01: received
See all versions
Short URL
https://ia.cr/2025/2029
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2029,
      author = {Sven Bauer and Fabrizio De Santis},
      title = {Forging Dilithium and Falcon Signatures by Single Fault Injection},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2029},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2029}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.