Paper 2026/1944

Fault Injection Attacks on Torsion Masking

Valerie Gilchrist, Université Libre de Bruxelles
Yi-Fu Lai, Shanghai Jiao Tong University
Michael Meyer, University of Regensburg
Abstract

In 2022, a string of attacks on SIDH was released that made use of the now infamous Kani's Lemma. Since then, several new and exciting isogeny-based protocols have emerged that both avoid the attacks, while at the same time, leverage the power of Kani's Lemma to improve their efficiency. One common technique to do so has been the inclusion of masked torsion points. This is when a protocol publishes information about how a secret isogeny acts on a large torsion subgroup, but masks the exact image points by multiplying them by some secret scalars. In this work, we present the first analysis of the physical security of the masked torsion point technique. We provide fault injection attacks on the signature scheme PRISM, and the public-key encryption schemes POKÉ and FESTA. Our fault model is standard in the literature, and can be implemented inexpensively. Most notably, three of the five attacks presented only require one or two first-order faults, which is significantly less than what is needed to attack other isogeny-based cryptosystems that do not use torsion masking.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
Fault-injection attackisogenies cryptographypost-quantum cryptographypublic key encryptionssignatures
Contact author(s)
valerie gilchrist @ ulb be
yifu lai @ sjtu edu cn
michael1 meyer @ ur de
History
2026-09-13: approved
2026-09-09: received
See all versions
Short URL
https://ia.cr/2026/1944
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1944,
      author = {Valerie Gilchrist and Yi-Fu Lai and Michael Meyer},
      title = {Fault Injection Attacks on Torsion Masking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1944},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1944}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.