Paper 2026/097
Secret-Subspace Recovery in MAYO via Linearization of Errors from a Single Fault
Abstract
We present fault injection attacks against MAYO in which a single faulty execution reveals structural information about the secret. We consider two closely related single-block fault models. In the first one, a controlled perturbation affects one oil coordinate of a signature block and induces an error $e \in \mathcal{O}$. In the second one, the perturbation may affect several oil coordinates of the same block. In both cases, we show that the observable verification mismatch can be written as the image of the induced error under a publicly derivable linear operator. This yields two recovery strategies. In the linear route, when the relevant oil part of the error can be identified, recovery reduces to solving a linear system over $\mathbb{F}_q$. In the reduced-quadratic route, the same linear relation is combined with the constraint $P(e)=0$, which leaves, in the generic full-rank case, a reduced system of $m$ quadratic equations in $n-m$ variables. For the MAYO parameter sets, $n-m=o$ is small, and the resulting reduced quadratic systems can be solved over the base field. Recovering $e$ yields a nonzero vector of the secret subspace and provides a starting point for key-recovery techniques against the oil space. We also discuss the practical cost of both approaches and explain why the attack applies to randomized MAYO.
Note: Revised version with additional analysis and experimental validation.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Post-Quantum CryptographyMultivariate CryptographyMayoFault Injection
- Contact author(s)
- amarcos @ arquimea com
- History
- 2026-08-16: revised
- 2026-01-21: received
- See all versions
- Short URL
- https://ia.cr/2026/097
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/097,
author = {Alberto Marcos},
title = {Secret-Subspace Recovery in {MAYO} via Linearization of Errors from a Single Fault},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/097},
year = {2026},
url = {https://eprint.iacr.org/2026/097}
}