Paper 2026/1327
Fault assisted Man-In-The-Middle Attack on MAYO
Abstract
Multivariate quadratic (MQ) signature schemes such as MAYO are among the leading candidates for post-quantum digital signatures, with security relying on the hardness of solving systems of multivariate quadratic equations. In this paper, we present a fault-assisted man-in-the-middle attack targeting the key-generation procedure of MAYO. Specifically, we target the computation of the public key, which is represented as a system of $m$ quadratic polynomials. Following the MAYO specification, each polynomial is associated with a matrix representation composed of the components $P_i^{(1)}, P_i^{(2)}$, and $P_i^{(3)}$. Our attack injects a single fault during the computation of the $P_i^{(3)}$ component of the public key, causing the resulting public key to satisfy a simplified linear relation involving the secret oil matrix. From the faulty public key, we derive an overdetermined linear system over $F_{16}$ that enables complete recovery of the secret oil matrix. Unlike previous fault attacks that primarily target the signing algorithm, our attack targets the key generation procedure to recover the oil secret and exploit the recovered oil secret to reconstruct the legitimate public key corresponding to the victim's secret key i.e correcting the public key. This allows the adversary to transparently participate in the communication as a man-in-the-middle, producing valid signatures on behalf of the victim. We evaluate the attack on a fault simulated MAYO implementation and demonstrate successful recovery of the oil matrix from a single faulty key-generation execution followed by public key correction.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Man-In-The-Middle AttackFault AttackMAYOPost-quantum Multivariate cryptographyKey recovery
- Contact author(s)
-
siddheshh @ cse iitb ac in
sayandeepsaha @ cse iitb ac in - History
- 2026-06-29: approved
- 2026-06-26: received
- See all versions
- Short URL
- https://ia.cr/2026/1327
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1327,
author = {Siddhesh Shinde and Sayandeep Saha},
title = {Fault assisted Man-In-The-Middle Attack on {MAYO}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1327},
year = {2026},
url = {https://eprint.iacr.org/2026/1327}
}