Paper 2026/228

SCA-MAYO: Demystifying Side-channel Security of MAYO Signature Scheme

N.K. Vishwaajith, Indian Institute of Technology Bombay
Anindya Ganguly, Indian Institute of Technology Kanpur
Trevor Yap, Nanyang Technological University
Debranjan Pal, LNM Institute of Information Technology
Puja Mondal, Indian Institute of Technology Kanpur
Suparna Kundu, KU Leuven
Sayandeep Saha, Indian Institute of Technology Bombay
Shivam Bhasin, Nanyang Technological University
Ingrid Verbauwhede, KU Leuven
Angshuman Karmakar, Indian Institute of Technology Kanpur
Abstract

Multivariate quadratic (MQ)-based digital signature schemes are promising candidates for the ongoing post-quantum (PQ) standardization procedure due to their compact signatures and fast verification. However, the side-channel security of their recent optimized and protected implementations remains underexplored. This work presents novel side-channel attacks on the MQ-based signature scheme MAYO, targeting both unprotected and masked implementations. We develop the first non-profiled single-trace correlation power attack against the recent nibble-sliced implementation of MAYO. Next, we evaluate two masking approaches proposed for MQ-based signatures. Our findings indicate that masking sensitive variables alone leaves the implementation vulnerable to single-trace attacks, and that masking only public variables also fails to provide the intended protection. To assess the second case, we consider both profiled and blind adversaries. The blind setting adopts a recent deep-learning-based blind side-channel analysis framework and demonstrates secret-key recovery without access to the masked public values or a cloned device. We validate our attacks on an STM32F3 Cortex-M4 platform and demonstrate that recently proposed countermeasures do not provide adequate protection against realistic single-trace adversaries. Finally, we discuss how the underlying attack methodology extends to other MQ-based signature schemes and present a strengthened masking and refreshing countermeasure that mitigates the proposed attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Side-channel analysisPost-quantum CryptographyMultivariate cryptographySingle-traceNon-profilingMayo
Contact author(s)
23b1038 @ cse iitb ac in
anindyag @ cse iitk ac in
trevor yap @ ntu edu sg
debranjan crl @ gmail com
pujamondal @ cse iitk ac in
suparna kundu @ esat kuleuven be
sayandeepsaha @ cse iitb ac in
sbhasin @ ntu edu sg
ingrid verbauwhede @ esat kuleuven be
angshuman @ cse iitk ac in
History
2026-09-07: revised
2026-02-11: received
See all versions
Short URL
https://ia.cr/2026/228
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/228,
      author = {N.K. Vishwaajith and Anindya Ganguly and Trevor Yap and Debranjan Pal and Puja Mondal and Suparna Kundu and Sayandeep Saha and Shivam Bhasin and Ingrid Verbauwhede and Angshuman Karmakar},
      title = {{SCA}-{MAYO}: Demystifying Side-channel Security of {MAYO} Signature Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/228},
      year = {2026},
      url = {https://eprint.iacr.org/2026/228}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.