{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T06:25:47Z","timestamp":1766298347445,"version":"3.41.2"},"reference-count":31,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"DOI":"10.13039\/501100017607","name":"Shenzhen Basic Research Project","doi-asserted-by":"crossref","award":["JCYJ20210324101210027 and JCYJ2022081 8100814033"],"award-info":[{"award-number":["JCYJ20210324101210027 and JCYJ2022081 8100814033"]}],"id":[{"id":"10.13039\/501100017607","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Characteristic Innovation Project of Ordinary Universities in Guangdong Province","award":["2024 KTSCX025"],"award-info":[{"award-number":["2024 KTSCX025"]}]},{"name":"Guangdong Provincial Key Laboratory of Computility Microelectronics","award":["2024B1212010007"],"award-info":[{"award-number":["2024B1212010007"]}]},{"name":"Shenzhen Science and Technology Plan Project","award":["KJZD20230923115105010"],"award-info":[{"award-number":["KJZD20230923115105010"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,7,31]]},"abstract":"<jats:p>\n            In embedded systems, particularly resource-constrained Internet of Things (IoT) devices, the SM2 Digital Signature Algorithm\u00a0(SM2-DSA) standard is widely deployed for cryptographic security. While fault injection attacks can compromise digital signatures and extract private keys without physical damage, traditional approaches require precise temporal or spatial control, resulting in limited success rates and revealing insufficient research into the potential vulnerabilities of SM2-DSA. To address this issue, this article introduces a novel and efficient lattice-based fault attack method targeting SM2-DSA. The method involves injecting faults into the nonce before the fourth step of the signature operation. By leveraging both the correct and erroneous intermediate values of\n            <jats:italic toggle=\"yes\">Q<\/jats:italic>\n            obtained from the signature and verification processes, we can deduce partial bits of the nonce. Following this, we construct a lattice attack to recover the private key. Additionally, we establish the theoretical security boundary for lattice attack against SM2-DSA. Building upon the boundary, we propose an efficient implementation scheme for the attack. Experimental results demonstrate a 100% success rate over 1,000 trials, using 61 signatures with six known bits of nonces for 256-bit SM2-DSA, with each recovery process completed in under three seconds. Finally, we propose countermeasures against this attack. Our proposed attack reveals potential security vulnerabilities in SM2-DSA implementations, providing constructive guidance for enhancing algorithmic security measures and defensive countermeasures.\n          <\/jats:p>","DOI":"10.1145\/3744246","type":"journal-article","created":{"date-parts":[[2025,6,7]],"date-time":"2025-06-07T05:15:06Z","timestamp":1749273306000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["A Novel Lattice-Based Fault Injection Attack Targeting the Nonce in the SM2 Digital Signature Algorithm"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2219-2328","authenticated-orcid":false,"given":"Cuiping","family":"Shao","sequence":"first","affiliation":[{"name":"Shenzhen University of Advanced Technology","place":["Shenzhen, China"]},{"name":"Guangdong Provincial Key Laboratory of Computility Microelectronics","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8236-2831","authenticated-orcid":false,"given":"Wenzhe","family":"Li","sequence":"additional","affiliation":[{"name":"Shenzhen Institutes of Advanced Technology Chinese Academy of Sciences","place":["Shenzhen, China"]},{"name":"University of the Chinese Academy of Sciences","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0157-1393","authenticated-orcid":false,"given":"Huiyun","family":"Li","sequence":"additional","affiliation":[{"name":"Shenzhen University of Advanced Technology","place":["Shenzhen, China"]},{"name":"Guangdong Provincial Key Laboratory of Computility Microelectronics","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5806-9033","authenticated-orcid":false,"given":"Zhimin","family":"Tang","sequence":"additional","affiliation":[{"name":"Shenzhen University of Advanced Technology","place":["Shenzhen, China"]},{"name":"Guangdong Provincial Key Laboratory of Computility Microelectronics","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2725-0013","authenticated-orcid":false,"given":"Jianing","family":"Liang","sequence":"additional","affiliation":[{"name":"Shenzhen Institutes of Advanced Technology Chinese Academy of Sciences","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,7,14]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2967103"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2603974"},{"key":"e_1_3_1_4_2","first-page":"890","volume-title":"Proceedings of the 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","author":"Yang Mei","year":"2022","unstructured":"Mei Yang, Chong Liu, Huiyun Li, and Cuiping Shao. 2022. Efficient SM2 hardware design for digital signature of internet of vehicles. In Proceedings of the 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 890\u2013896."},{"key":"e_1_3_1_5_2","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1007\/978-3-031-31034-8_11","volume-title":"Proceedings of the Hardware Security Training, Hands-on!","author":"Tehranipoor Mark","year":"2023","unstructured":"Mark Tehranipoor, N Nalla Anandakumar, and Farimah Farahmandi. 2023. Clock glitch fault attack on FSM in AES controller. In Proceedings of the Hardware Security Training, Hands-on!Springer, 199\u2013217."},{"key":"e_1_3_1_6_2","first-page":"1","volume-title":"Proceedings of the 2024 39th Conference on Design of Circuits and Integrated Systems (DCIS)","author":"Casado-Gal\u00e1n A.","year":"2024","unstructured":"A. Casado-Gal\u00e1n, F. E. Potestad-Ord\u00f3\u00f1ez, A. J. Acosta, and E. Tena-S\u00e1nchez. 2024. Electromagnetic fault injection attack methodology against AES hardware implementation. In Proceedings of the 2024 39th Conference on Design of Circuits and Integrated Systems (DCIS). 1\u20136."},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2022.3231814"},{"key":"e_1_3_1_8_2","first-page":"169","volume-title":"Proceedings of the Cryptographers\u2019 Track at the RSA Conference","author":"Cao Weiqiong","year":"2022","unstructured":"Weiqiong Cao, Hongsong Shi, Hua Chen, Jiazhe Chen, Limin Fan, and Wenling Wu. 2022. Lattice-based fault attacks on deterministic signature schemes of ECDSA and EdDSA. In Proceedings of the Cryptographers\u2019 Track at the RSA Conference. Springer, 169\u2013195."},{"key":"e_1_3_1_9_2","first-page":"1","volume-title":"Proceedings of the 2019 Asian Hardware Oriented Security and Trust Symposium (AsianHOST)","author":"Qiu Pengfei","year":"2019","unstructured":"Pengfei Qiu, Dongsheng Wang, Yongqiang Lyu, and Gang Qu. 2019. VoltJockey: Breaking SGX by software-controlled voltage-induced hardware faults. In Proceedings of the 2019 Asian Hardware Oriented Security and Trust Symposium (AsianHOST). IEEE, 1\u20136."},{"key":"e_1_3_1_10_2","first-page":"1445","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security 20)","author":"Kenjar Zijo","year":"2020","unstructured":"Zijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz, and Ahmad-Reza Sadeghi. 2020. \\(\\lbrace\\) V0LTpwn \\(\\rbrace\\) : Attacking x86 processor integrity from software. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20). 1445\u20131461."},{"key":"e_1_3_1_11_2","doi-asserted-by":"crossref","first-page":"1466","DOI":"10.1109\/SP40000.2020.00057","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP)","author":"Murdock Kit","year":"2020","unstructured":"Kit Murdock, David Oswald, Flavio D Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based fault injection attacks against Intel SGX. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 1466\u20131482."},{"key":"e_1_3_1_12_2","first-page":"1247402","volume-title":"Proceedings of the 2nd International Symposium on Computer Technology and Information Science (ISCTIS 2022)","volume":"12474","author":"Qian Chuisheng","year":"2022","unstructured":"Chuisheng Qian, Yan Wang, MingHua Wang, and ZiQi Zhao. 2022. Security analysis of SM2 signature algorithm based on fault attack. In Proceedings of the 2nd International Symposium on Computer Technology and Information Science (ISCTIS 2022), Vol. 12474. SPIE, 1247402."},{"key":"e_1_3_1_13_2","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1007\/11889700_4","volume-title":"Proceedings of the Fault Diagnosis and Tolerance in Cryptography","author":"Bl\u00f6mer Johannes","year":"2006","unstructured":"Johannes Bl\u00f6mer, Martin Otto, and Jean-Pierre Seifert. 2006. Sign change fault attacks on elliptic curve cryptosystems. In Proceedings of the Fault Diagnosis and Tolerance in Cryptography, Luca Breveglieri, Israel Koren, David Naccache, and Jean-Pierre Seifert (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 36\u201352."},{"key":"e_1_3_1_14_2","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1109\/FDTC.2009.38","volume-title":"Proceedings of the 2009 Workshop on Fault Diagnosis and Tolerance in Cryptography","author":"Schmidt J\u00f6rn-Marc","year":"2009","unstructured":"J\u00f6rn-Marc Schmidt and Marcel Medwed. 2009. A fault attack on ECDSA. In Proceedings of the 2009 Workshop on Fault Diagnosis and Tolerance in Cryptography. 93\u201399. DOI:10.1109\/FDTC.2009.38"},{"key":"e_1_3_1_15_2","first-page":"62","volume-title":"Proceedings of the Information and Communications Security: 17th International Conference, ICICS 2015, Beijing, China, December 9\u201311, 2015, Revised Selected Papers 17","author":"Cao Weiqiong","year":"2016","unstructured":"Weiqiong Cao, Jingyi Feng, Shaofeng Zhu, Hua Chen, Wenling Wu, Xucang Han, and Xiaoguang Zheng. 2016. Practical lattice-based fault attack and countermeasure on SM2 signature algorithm. In Proceedings of the Information and Communications Security: 17th International Conference, ICICS 2015, Beijing, China, December 9\u201311, 2015, Revised Selected Papers 17. Springer, 62\u201370."},{"key":"e_1_3_1_16_2","first-page":"163","volume-title":"Proceedings of the Applied Cryptography and Network Security: 12th International Conference, ACNS 2014, Lausanne, Switzerland, June 10-13, 2014. Proceedings 12","author":"Kim Taechan","year":"2014","unstructured":"Taechan Kim and Mehdi Tibouchi. 2014. Bit-flip faults on elliptic curve base fields, revisited. In Proceedings of the Applied Cryptography and Network Security: 12th International Conference, ACNS 2014, Lausanne, Switzerland, June 10-13, 2014. Proceedings 12. Springer, 163\u2013180."},{"key":"e_1_3_1_17_2","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1007\/978-3-0348-8295-8_23","volume-title":"Proceedings of the Cryptography and Computational Number Theory","author":"Nguyen Phong Q","year":"2001","unstructured":"Phong Q Nguyen. 2001. The dark side of the hidden number problem: Lattice attacks on DSA. In Proceedings of the Cryptography and Computational Number Theory. Springer, 321\u2013330."},{"key":"e_1_3_1_18_2","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1023\/A:1025436905711","article-title":"The insecurity of the elliptic curve digital signature algorithm with partially known nonces","volume":"30","author":"Nguyen Phong Q","year":"2003","unstructured":"Phong Q Nguyen and Igor E Shparlinski. 2003. The insecurity of the elliptic curve digital signature algorithm with partially known nonces. Designs, Codes and Cryptography 30, 3 (2003), 201\u2013217.","journal-title":"Designs, Codes and Cryptography"},{"key":"e_1_3_1_19_2","doi-asserted-by":"crossref","first-page":"103210","DOI":"10.1016\/j.jisa.2022.103210","article-title":"Timing leakage to break SM2 signature algorithm","volume":"67","author":"Chen Aidong","year":"2022","unstructured":"Aidong Chen, Chen Hong, Xinna Shang, Hongyuan Jing, and Sen Xu. 2022. Timing leakage to break SM2 signature algorithm. Journal of Information Security and Applications 67, 3 (2022), 103210.","journal-title":"Journal of Information Security and Applications"},{"key":"e_1_3_1_20_2","first-page":"248","volume-title":"Proceedings of the 2017 13th International Conference on Computational Intelligence and Security (CIS)","author":"Zhang Kaiyu","year":"2017","unstructured":"Kaiyu Zhang, Sen Xu, Dawu Gu, Haihua Gu, Junrong Liu, Zheng Guo, Ruitong Liu, Liang Liu, and Xiaobo Hu. 2017. Practical partial-nonce-exposure attack on ECC algorithm. In Proceedings of the 2017 13th International Conference on Computational Intelligence and Security (CIS). IEEE, 248\u2013252."},{"key":"e_1_3_1_21_2","volume-title":"Proceedings of the International Conference on Security and Privacy in Communication Systems","author":"Ma Ziqiang","year":"2023","unstructured":"Ziqiang Ma, Shuaigang Li, Jingqiang Lin, Quanwei Cai, Shuqin Fan, Fan Zhang, and Bo Luo. 2023. Another lattice attack against ECDSA withthewNAF torecover more bits persignature. In Proceedings of the International Conference on Security and Privacy in Communication Systems."},{"key":"e_1_3_1_22_2","first-page":"343","volume-title":"Proceedings of the Information Security and Cryptology: 9th International Conference, Inscrypt 2013, Guangzhou, China, November 27-30, 2013, Revised Selected Papers 9","author":"Liu Mingjie","year":"2014","unstructured":"Mingjie Liu, Jiazhe Chen, and Hexin Li. 2014. Partially known nonces and fault injection attacks on SM2 signature algorithm. In Proceedings of the Information Security and Cryptology: 9th International Conference, Inscrypt 2013, Guangzhou, China, November 27-30, 2013, Revised Selected Papers 9. Springer, 343\u2013358."},{"key":"e_1_3_1_23_2","unstructured":"Office of state commercial cryptography administration: Public key cryptographic algorithm SM2 based on elliptic curves (in chinese). Retrieved from http:\/\/www.oscca.gov.cn\/UpFile\/2010122214822692.pdf. ([n. d.])."},{"key":"e_1_3_1_24_2","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1007\/BF01457454","article-title":"Factoring polynomials with rational coefficients","volume":"261","author":"Lenstra Arjen K","year":"1982","unstructured":"Arjen K Lenstra, Hendrik Willem Lenstra, and L\u00e1szl\u00f3 Lov\u00e1sz. 1982. Factoring polynomials with rational coefficients. Mathematische Annalen 261, ARTICLE (1982), 515\u2013534.","journal-title":"Mathematische Annalen"},{"key":"e_1_3_1_25_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/BF01581144","article-title":"Lattice basis reduction: Improved practical algorithms and solving subset sum problems","volume":"66","author":"Schnorr Claus-Peter","year":"1994","unstructured":"Claus-Peter Schnorr and Martin Euchner. 1994. Lattice basis reduction: Improved practical algorithms and solving subset sum problems. Mathematical Programming 66, 2 (1994), 181\u2013199.","journal-title":"Mathematical Programming"},{"key":"e_1_3_1_26_2","article-title":"fpylll: A Python wrapper for the fplll library","author":"Team The fpylll Development","year":"2023","unstructured":"The fpylll Development Team. 2023. fpylll: A Python wrapper for the fplll library. https:\/\/github.com\/fplll\/fpylll. (2023).","journal-title":"https:\/\/github.com\/fplll\/fpylll"},{"key":"e_1_3_1_27_2","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1023\/A:1011214926272","article-title":"Lattice attacks on digital signature schemes","volume":"23","author":"Howgrave-Graham Nick A","year":"2001","unstructured":"Nick A Howgrave-Graham and Nigel P. Smart. 2001. Lattice attacks on digital signature schemes. Designs, Codes and Cryptography 23, 3 (2001), 283\u2013290.","journal-title":"Designs, Codes and Cryptography"},{"key":"e_1_3_1_28_2","first-page":"445","volume-title":"Proceedings of the Cryptographers\u2019 Track at the RSA Conference","author":"Barbu Guillaume","year":"2023","unstructured":"Guillaume Barbu and Christophe Giraud. 2023. All shall FA-LLL: Breaking CT-RSA 2022 and CHES 2022 infective countermeasures with lattice-based fault attacks. In Proceedings of the Cryptographers\u2019 Track at the RSA Conference. Springer, 445\u2013468."},{"key":"e_1_3_1_29_2","article-title":"A Differential Fault Attack against Deterministic Falcon Signatures","author":"Bauer Sven","year":"2023","unstructured":"Sven Bauer and Fabrizio De Santis. 2023. A Differential Fault Attack against Deterministic Falcon Signatures. Cryptology ePrint Archive, Paper 2023\/422. (2023). Retrieved from https:\/\/eprint.iacr.org\/2023\/422https:\/\/eprint.iacr.org\/2023\/422.","journal-title":"Cryptology ePrint Archive, Paper 2023\/422"},{"key":"e_1_3_1_30_2","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1109\/FDTC.2017.12","volume-title":"Proceedings of the 2017 Workshop Fault Diagnosis Tolerance Cryptography","author":"Romailler Yolan","year":"2017","unstructured":"Yolan Romailler and Sylvain Pelissier. 2017. Practical fault attack against the Ed25519 and EdDSA signature schemes. In Proceedings of the 2017 Workshop Fault Diagnosis Tolerance Cryptography. IEEE, 17\u201324."},{"key":"e_1_3_1_31_2","first-page":"391","article-title":"Guessing bits: Improved lattice attacks on (EC) DSA with nonce leakage","author":"Sun Chao","year":"2022","unstructured":"Chao Sun, Thomas Espitau, Mehdi Tibouchi, and Masayuki Abe. 2022. Guessing bits: Improved lattice attacks on (EC) DSA with nonce leakage. IACR Transactions on Cryptographic Hardware and Embedded Systems 2022, 1 (2022), 391\u2013413.","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded Systems"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.11772\/j.issn.1001-9081.2016.12.3328"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3744246","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T12:59:24Z","timestamp":1752497964000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3744246"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,14]]},"references-count":31,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,7,31]]}},"alternative-id":["10.1145\/3744246"],"URL":"https:\/\/doi.org\/10.1145\/3744246","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2025,7,14]]},"assertion":[{"value":"2025-01-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-07-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}