Paper 2026/1944
Fault Injection Attacks on Torsion Masking
Abstract
In 2022, a string of attacks on SIDH was released that made use of the now infamous Kani's Lemma. Since then, several new and exciting isogeny-based protocols have emerged that both avoid the attacks, while at the same time, leverage the power of Kani's Lemma to improve their efficiency. One common technique to do so has been the inclusion of masked torsion points. This is when a protocol publishes information about how a secret isogeny acts on a large torsion subgroup, but masks the exact image points by multiplying them by some secret scalars. In this work, we present the first analysis of the physical security of the masked torsion point technique. We provide fault injection attacks on the signature scheme PRISM, and the public-key encryption schemes POKÉ and FESTA. Our fault model is standard in the literature, and can be implemented inexpensively. Most notably, three of the five attacks presented only require one or two first-order faults, which is significantly less than what is needed to attack other isogeny-based cryptosystems that do not use torsion masking.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Fault-injection attackisogenies cryptographypost-quantum cryptographypublic key encryptionssignatures
- Contact author(s)
-
valerie gilchrist @ ulb be
yifu lai @ sjtu edu cn
michael1 meyer @ ur de - History
- 2026-09-13: approved
- 2026-09-09: received
- See all versions
- Short URL
- https://ia.cr/2026/1944
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1944,
author = {Valerie Gilchrist and Yi-Fu Lai and Michael Meyer},
title = {Fault Injection Attacks on Torsion Masking},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1944},
year = {2026},
url = {https://eprint.iacr.org/2026/1944}
}