Paper 2025/913

A Little LESS Secure - Side-Channel Attacks Exploiting Randomness Leakage

Dina Hesse, Ruhr University Bochum
Elisabeth Krahmer, Ruhr University Bochum
Yi-Fu Lai, KU Leuven
Jonas Meers, Ruhr University Bochum
Abstract

Schnorr and (EC)DSA signatures famously become completely insecure once a few bits of the random nonce are revealed to an attacker. In this work, we explore whether the Fiat-Shamir based post-quantum signature scheme LESS is vulnerable to analogous attacks. In particular, we investigate the impact of partial leakage of the commitment randomness – a scenario that falls under the broader class of Hidden Number Problems – on the security of the secret key. We present an efficient attack on LESS that requires knowledge of a single bit of the randomness with less than 1200 signatures to fully recover the secret key. Our attack leverages the observation that knowledge of one bit is sufficient to distinguish secret key entries from random candidates. In addition, we describe a variant of this attack that requires one-bit leakage of multiple randomness values, but succeeds with only two signatures. To demonstrate the practicality of our attacks, we identify and exploit two different side-channels that are present in the reference implementation: One timing-based attack and one exploiting the power side-channel leakage. Both show that the assumptions regarding the required single-bit leakage can be obtained in practice and that our attack poses a realistic threat to the current implementation of LESS. To our knowledge, these are the first practically verified side-channel attacks on LESS.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CRYPTO 2026
Keywords
Hidden Number ProblemFiat-ShamirLESSPost-QuantumSide-Channel Attacks
Contact author(s)
Dina Hesse @ rub de
Elisabeth Krahmer @ rub de
yi-fulai lai @ kuleuven be
jonas meers @ rub de
History
2026-06-03: last of 3 revisions
2025-05-21: received
See all versions
Short URL
https://ia.cr/2025/913
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/913,
      author = {Dina Hesse and Elisabeth Krahmer and Yi-Fu Lai and Jonas Meers},
      title = {A Little {LESS} Secure - Side-Channel Attacks Exploiting Randomness Leakage},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/913},
      year = {2025},
      url = {https://eprint.iacr.org/2025/913}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.