Paper 2026/228

SCA-MQDSA: Side-Channel Analysis of Multivariate Digital Signature Implementations

N.K. Vishwaajith, Indian Institute of Technology Bombay
Anindya Ganguly, Indian Institute of Technology Kanpur
Debranjan Pal, LNM Institute of Information Technology
Trevor Yap, Nanyang Technological University
Puja Mondal, Indian Institute of Technology Kanpur
Suparna Kundu, KU Leuven
Sayandeep Saha, Indian Institute of Technology Bombay
Shivam Bhasin, Nanyang Technological University
Ingrid Verbauwhede, KU Leuven
Angshuman Karmakar, Indian Institute of Technology Kanpur
Abstract

The rapid progress of Internet-of-Things (IoT) systems and network protocols has strengthened the demand for digital signature schemes with compact signatures and low computational overhead. However, standardized post-quantum signature schemes, such as ML-DSA, SLH-DSA, and Falcon, incur relatively large signature sizes, which limit their practicality on resource-constrained devices (RCD). To address this challenge, NIST recalled the post-quantum digital signature standardization process. It reopened the interest in alternative constructions. Signature schemes based on multivariate quadratic equations have emerged as promising candidates due to their comparatively small signature sizes and efficient verification. At the same time, these schemes are often deployed on platforms with limited physical protections, making side-channel security a critical concern. Four multivariate-based signature schemes, such as UOV, MAYO, QR-UOV, and SNOVA, were reached in the second round of the NIST post-quantum signature standardization process for further evaluation. In this work, we analyze implementations of multivariate digital signature algorithms submitted to the NIST process, with a particular focus on the MAYO signature scheme. We present an \textit{inexpensive} side-channel attack targeting nibble-sliced implementations of MAYO. Our attack operates under a minimal threat model: it does not require physical possession of the target device and succeeds using leakage obtained from a single signing execution. We perform our attacks on a ChipWhisperer-Lite platform with a 32-bit STM32F3 ARM Cortex-M4 target mounted on a CW308 UFO board, and we add the corresponding reference code along with target traces.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Side-channel analysisPost-quantum CryptographyMultivariate cryptographySingle-traceNon-profilingMayo
Contact author(s)
23b1038 @ cse iitb ac in
anindyag @ cse iitk ac in
debranjan crl @ gmail com
trevor yap @ ntu edu sg
pujamondal @ cse iitk ac in
suparna kundu @ esat kuleuven be
sayandeepsaha @ cse iitb ac in
sbhasin @ ntu edu sg
ingrid verbauwhede @ esat kuleuven be
angshuman @ cse iitk ac in
History
2026-02-12: approved
2026-02-11: received
See all versions
Short URL
https://ia.cr/2026/228
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/228,
      author = {N.K. Vishwaajith and Anindya Ganguly and Debranjan Pal and Trevor Yap and Puja Mondal and Suparna Kundu and Sayandeep Saha and Shivam Bhasin and Ingrid Verbauwhede and Angshuman Karmakar},
      title = {{SCA}-{MQDSA}: Side-Channel Analysis of Multivariate Digital Signature Implementations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/228},
      year = {2026},
      url = {https://eprint.iacr.org/2026/228}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.