Paper 2026/097

Secret-Subspace Recovery in MAYO via Linearization of Errors from a Single Fault

Alberto Marcos, Arquimea Research Center
Abstract

We present fault injection attacks against MAYO in which a single faulty execution reveals structural information about the secret. We consider two closely related single-block fault models. In the first one, a controlled perturbation affects one oil coordinate of a signature block and induces an error $e \in \mathcal{O}$. In the second one, the perturbation may affect several oil coordinates of the same block. In both cases, we show that the observable verification mismatch can be written as the image of the induced error under a publicly derivable linear operator. This yields two recovery strategies. In the linear route, when the relevant oil part of the error can be identified, recovery reduces to solving a linear system over $\mathbb{F}_q$. In the reduced-quadratic route, the same linear relation is combined with the constraint $P(e)=0$, which leaves, in the generic full-rank case, a reduced system of $m$ quadratic equations in $n-m$ variables. For the MAYO parameter sets, $n-m=o$ is small, and the resulting reduced quadratic systems can be solved over the base field. Recovering $e$ yields a nonzero vector of the secret subspace and provides a starting point for key-recovery techniques against the oil space. We also discuss the practical cost of both approaches and explain why the attack applies to randomized MAYO.

Note: Revised version with additional analysis and experimental validation.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Post-Quantum CryptographyMultivariate CryptographyMayoFault Injection
Contact author(s)
amarcos @ arquimea com
History
2026-08-16: revised
2026-01-21: received
See all versions
Short URL
https://ia.cr/2026/097
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/097,
      author = {Alberto Marcos},
      title = {Secret-Subspace Recovery in {MAYO} via Linearization of Errors from a Single Fault},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/097},
      year = {2026},
      url = {https://eprint.iacr.org/2026/097}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.