{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,17]],"date-time":"2026-01-17T00:42:27Z","timestamp":1768610547419,"version":"3.49.0"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"1","license":[{"start":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T00:00:00Z","timestamp":1768521600000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["TCHES"],"abstract":"<jats:p>Ongoing efforts to transition to post-quantum public-key cryptosystems have created the need for algorithms with a variety of performance characteristics and security assumptions. Among the candidates in NIST\u2019s post-quantum standardisation process for additional digital signatures are FAEST and SDitH, two Vector Oblivious Linear Evaluation in-the-Head (VOLEitH)-based schemes. The security of FAEST is based on the Advanced Encryption Standard (AES), while SDitH relies on the regular syndrome decoding problem. The VOLEitH paradigm enables competitive performance and signature sizes under conservative security assumptions. However, since it was introduced relatively recently, in 2023, its resistance to physical attacks has not yet been analysed. In this paper, we present the first security analysis of VOLEitH-based signature schemes in the context of fault injection attacks. We demonstrate two practical attacks on the reference implementations of the secondround variants of FAEST and SDitH in ARM Cortex-M4 capable of recovering the secret key from a single signature. These attacks exploit vulnerabilities of components specific to VOLEitH schemes, namely the batch all-but-one vector commitments and the VOLE generation. We also propose countermeasures to mitigate these attacks and enhance the physical security of VOLEitH-based digital signature schemes.<\/jats:p>","DOI":"10.46586\/tches.v2026.i1.225-249","type":"journal-article","created":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T15:13:15Z","timestamp":1768576395000},"page":"225-249","source":"Crossref","is-referenced-by-count":0,"title":["Fault Attacks on VOLEitH Signature Schemes"],"prefix":"10.46586","volume":"2026","author":[{"given":"S\u00f6nke","family":"Jendral","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"25480","published-online":{"date-parts":[[2026,1,16]]},"container-title":["IACR Transactions on Cryptographic Hardware and Embedded Systems"],"original-title":[],"link":[{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/download\/12675\/12363","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/download\/12675\/12363","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T15:13:16Z","timestamp":1768576396000},"score":1,"resource":{"primary":{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/12675"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,16]]},"references-count":0,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,1,16]]}},"URL":"https:\/\/doi.org\/10.46586\/tches.v2026.i1.225-249","relation":{},"ISSN":["2569-2925"],"issn-type":[{"value":"2569-2925","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,16]]}}}