Paper 2026/1344
Public Coefficient Matters: A Practical Differential Fault Attack on ML-DSA and HAETAE
Abstract
With the standardization of post-quantum digital signature schemes and their increasing deployment in security critical applications such as firmware authentication and software distribution, implementations are expected to operate in physically accessible and potentially hostile environments. Consequently, considerable effort has been devoted to protecting these schemes against a variety of attacks, including timing sidechannel attacks. However, evaluating their resilience against fault injection attacks remains equally important. Previous differential fault analysis (DFA) attacks on lattice-based signatures have primarily targeted intermediate values during signing and often relied on assumptions regarding rejection sampling or multiple fault injections. In this work, we demonstrate that the challenge sampling procedure itself constitutes a practical attack surface. Specifically, We present fault attacks against the challenge sampling procedures of deterministic ML-DSA, a NIST-standardized signature scheme, and HAETAE, a KpqC-selected signature scheme, showing that a single faulted signature is sufficient to recover the secret key required for signature forgery. To the best of our knowledge, this is the first fault attack on HAETAE achieving secret-key recovery that enables the generation of valid forged signatures. Our attack model of ML-DSA does not require direct access to faulted challenges. Using only public information, we identify intended fault injections and distinguish them from unintended fault outcomes. We evaluate the method through simulation and practical fault injection, achieving a 100% identification rate for intended faults. We further propose a countermeasure for the identified vulnerability
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Fault Attackclock glitchingML-DSAHAETAE
- Contact author(s)
-
shinryan9 @ korea ac kr
jsh5167 @ korea ac kr
dh_bae @ korea ac kr
lemontrees33 @ korea ac kr
80khs @ korea ac kr - History
- 2026-07-02: approved
- 2026-06-30: received
- See all versions
- Short URL
- https://ia.cr/2026/1344
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1344,
author = {WonGeun Shin and SeungHyeon Jeon and Daehyeon Bae and Sujin Park and HeeSeok Kim},
title = {Public Coefficient Matters: A Practical Differential Fault Attack on {ML}-{DSA} and {HAETAE}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1344},
year = {2026},
url = {https://eprint.iacr.org/2026/1344}
}