{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T22:35:13Z","timestamp":1775774113547,"version":"3.50.1"},"reference-count":50,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2024,10,4]],"date-time":"2024-10-04T00:00:00Z","timestamp":1728000000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,12,3]]},"abstract":"<jats:p>As the industry prepares for the transition to post-quantum secure public key cryptographic algorithms, vulnerability analysis of their implementations is gaining importance. A theoretically secure cryptographic algorithm should also be able to withstand the challenges of physical attacks in real-world environments. MAYO is a candidate in the ongoing second round of the NIST post-quantum standardization process for selecting additional digital signature schemes. This paper demonstrates three first-order single-execution fault injection attacks on the official MAYO implementation on the ARM Cortex-M4. By using voltage glitching to disrupt the computation of the vinegar seed during the signature generation, we enable the recovery of the secret key directly from the faulty signatures. Our experimental results show that the success rates of the fault attacks in a single execution are 36%, 82%, and 99%, respectively. They emphasize the importance of developing countermeasures against fault attacks prior to the widespread deployment of post-quantum algorithms like MAYO. <\/jats:p>","DOI":"10.62056\/ab0ljbkrz","type":"journal-article","created":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:00:52Z","timestamp":1736787652000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":4,"title":["MAYO Key Recovery by Fixing Vinegar Seeds"],"prefix":"10.62056","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-0070-9595","authenticated-orcid":false,"given":"S\u00f6nke","family":"Jendral","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7382-9408","authenticated-orcid":false,"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref1:FIPS203","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.203","volume-title":"Module-Lattice-Based Key Encapsulation Mechanism\n  Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref2:FIPS204","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.204","volume-title":"Module-Lattice-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref3:FIPS205","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.205","volume-title":"Stateless Hash-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref4:nistdigsig","volume-title":"NIST Announces Additional Digital Signature Candidates for\n  the PQC Standardization Process","author":"National Institute of Standards","year":"2023"},{"key":"ref5:10.1007\/978-3-030-99277-4_17","isbn-type":"print","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1007\/978-3-030-99277-4_17","article-title":"MAYO: Practical Post-quantum Signatures from\n  Oil-and-Vinegar Maps","author":"Ward Beullens","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030992774"},{"key":"ref6:10.1007\/978-3-319-66787-4_25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/978-3-319-66787-4_25","article-title":"Single-Trace Side-Channel Attacks on Masked Lattice-Based\n  Encryption","volume":"10529","author":"Robert Primas","year":"2017"},{"key":"ref7:10.1007\/978-3-030-16350-1_13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1007\/978-3-030-16350-1_13","article-title":"Number \"Not Used\" Once - Practical Fault Attack on pqm4\n  Implementations of NIST Candidates","volume":"11421","author":"Prasanna Ravi","year":"2019"},{"key":"ref8:10.1007\/978-3-030-56880-1_13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56880-1_13","article-title":"A Key-Recovery Timing Attack on Post-quantum Primitives\n  Using the Fujisaki-Okamoto Transformation and Its Application on\n  FrodoKEM","volume":"12171","author":"Qian Guo","year":"2020"},{"key":"ref9:uovspec","volume-title":"UOV: Unbalanced Oil and Vinegar","author":"Ward Beullens","year":"2023"},{"key":"ref10:DBLP:conf\/indocrypt\/BulyginPB10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/978-3-642-17401-8_3","article-title":"Towards Provable Security of the Unbalanced Oil and\n  Vinegar Signature Scheme under Direct Attacks","volume":"6498","author":"Stanislav Bulygin","year":"2010"},{"key":"ref11:mayospec","volume-title":"MAYO","author":"Ward Beullens","year":"2023"},{"key":"ref12:10.1007\/978-3-642-25405-5_1","isbn-type":"print","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-25405-5_1","article-title":"General Fault Attacks on Multivariate Public Key\n  Cryptosystems","author":"Yasufumi Hashimoto","year":"2011","ISBN":"https:\/\/id.crossref.org\/isbn\/9783642254055"},{"key":"ref13:10.1007\/978-3-030-16350-1_11","isbn-type":"print","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/978-3-030-16350-1_11","article-title":"Fault Attacks on UOV and Rainbow","author":"Juliane Kr\u00e4mer","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030163501"},{"key":"ref14:8979393","doi-asserted-by":"publisher","first-page":"2429","DOI":"10.1109\/TIFS.2020.2969555","article-title":"Algebraic Fault Analysis of UOV and Rainbow With the\n  Leakage of Random Vinegar Values","volume":"15","author":"Kyung-Ah Shim","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref15:10.1007\/978-3-031-17433-9_15","isbn-type":"print","doi-asserted-by":"publisher","first-page":"348","DOI":"10.1007\/978-3-031-17433-9_15","article-title":"Recovering Rainbow's Secret Key with a First-Order Fault\n  Attack","author":"Thomas Aulbach","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031174339"},{"key":"ref16:fdtcmayo","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/FDTC64268.2024.00012","article-title":"MAYo or MAY-not: Exploring Implementation Security of the\n  Post-Quantum Signature Scheme MAYO Against Physical Attacks","author":"Thomas Aulbach","year":"2024"},{"key":"ref17:mayonibble","doi-asserted-by":"publisher","first-page":"252","DOI":"10.46586\/TCHES.V2024.I2.252-275","article-title":"Nibbling MAYO: Optimized Implementations for AVX2 and\n  Cortex-M4","volume":"2024","author":"Ward Beullens","year":"2024","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref18:cryptoeprint:2024\/238","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/FDTC64268.2024.00013","article-title":"A Single-Trace Fault Injection Attack on Hedged Module\n  Lattice Digital Signature Algorithm (ML-DSA)","author":"S\u00f6nke Jendral","year":"2024"},{"key":"ref19:10.1145\/3372297.3417272","series-title":"CCS '20","isbn-type":"print","doi-asserted-by":"publisher","first-page":"1071","DOI":"10.1145\/3372297.3417272","article-title":"QuantumHammer: A Practical Hybrid Attack on the LUOV\n  Signature Scheme","author":"Koksal Mus","year":"2020","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450370899"},{"key":"ref20:10.1007\/978-3-031-17234-2_7","isbn-type":"print","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1007\/978-3-031-17234-2_7","article-title":"A New Fault Attack on UOV Multivariate Signature Scheme","author":"Hiroki Furue","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031172342"},{"key":"ref21:10.1007\/978-3-031-57543-3_13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-031-57543-3_13","article-title":"HaMAYO: A Fault-Tolerant Reconfigurable Hardware\n  Implementation of the MAYO Signature Scheme","volume":"14595","author":"Oussama Sayari","year":"2024"},{"key":"ref22:10.1007\/BFb0055733","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/BFB0055733","article-title":"Cryptanalysis of the Oil & Vinegar Signature Scheme","volume":"1462","author":"Aviad Kipnis","year":"1998"},{"key":"ref23:10.1007\/978-3-030-77870-5_13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"348","DOI":"10.1007\/978-3-030-77870-5_13","article-title":"Improved Cryptanalysis of UOV and Rainbow","volume":"12696","author":"Ward Beullens","year":"2021"},{"key":"ref24:uovseparate","doi-asserted-by":"publisher","first-page":"221","DOI":"10.46586\/TCHES.V2023.I3.221-245","article-title":"Separating Oil and Vinegar with a Single Trace Side-Channel\n  Assisted Kipnis-Shamir Attack on UOV","volume":"2023","author":"Thomas Aulbach","year":"2023","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref25:10.1007\/978-3-540-68914-0_15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"242","DOI":"10.1007\/978-3-540-68914-0_15","article-title":"New Differential-Algebraic Attacks and Reparametrization of\n  Rainbow","volume":"5037","author":"Jintai Ding","year":"2008"},{"key":"ref26:patarin1997oil","article-title":"The oil and vinegar signature scheme","author":"Jacques Patarin","year":"1997"},{"key":"ref27:DBLP:conf\/fdtc\/BarenghiBPP09","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1109\/FDTC.2009.30","article-title":"Low Voltage Fault Attacks on the RSA Cryptosystem","author":"Alessandro Barenghi","year":"2009"},{"key":"ref28:DBLP:journals\/iacr\/BarenghiBBPP10","doi-asserted-by":"publisher","first-page":"1864","DOI":"10.1016\/J.JSS.2013.02.021","article-title":"A fault induction technique based on voltage underfeeding\n  with application to attacks against AES and RSA","volume":"86","author":"Alessandro Barenghi","year":"2013","journal-title":"J. Syst. Softw."},{"key":"ref29:DBLP:journals\/iacr\/OFlynn16","first-page":"810","article-title":"Fault Injection using Crowbars on Embedded Systems","author":"Colin O'Flynn","year":"2016","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref30:DBLP:journals\/tches\/BozzatoFP19","doi-asserted-by":"publisher","first-page":"199","DOI":"10.13154\/tches.v2019.i2.199-224","article-title":"Shaping the Glitch: Optimizing Voltage Fault Injection\n  Attacks","volume":"2019","author":"Claudio Bozzato","year":"2019","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref31:FIPS202","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.202","volume-title":"SHA-3 Standard: Permutation-Based Hash and\n  Extendable-Output Functions","author":"National Institute of Standards","year":"2015"},{"key":"ref32:guido2011cryptographic","volume-title":"Cryptographic sponge functions","author":"Guido Bertoni","year":"2011"},{"key":"ref33:9206547","doi-asserted-by":"publisher","first-page":"1058","DOI":"10.1109\/TIFS.2020.3027143","article-title":"ARMORY: Fully Automated and Exhaustive Fault Simulation on\n  ARM-M Binaries","volume":"16","author":"Max Hoffmann","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref34:9565584","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/FDTC53659.2021.00013","article-title":"ARCHIE: A QEMU-Based Framework for\n  Architecture-Independent Evaluation of Faults","author":"Florian Hauschild","year":"2021"},{"key":"ref35:fisim","volume-title":"Riscure FiSim","author":"Riscure"},{"key":"ref36:5abf123a70ca4d18b2b2444b0dbfbb11","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1145\/3689939.3695788","article-title":"FaultFinder: Lightning-fast, Multi-architectural Fault\n  Injection Simulation","author":"Kit Murdock","year":"2024"},{"key":"ref37:qemu","first-page":"41","article-title":"QEMU, a Fast and Portable Dynamic Translator","author":"Fabrice Bellard","year":"2005"},{"key":"ref38:unicorn","article-title":"Unicorn: Next generation CPU emulator framework","volume":"476","author":"Anh Quynh Nguyen","year":"2015","journal-title":"BlackHat USA"},{"key":"ref39:Lacombe2024","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/s13389-023-00310-8","article-title":"Combining static analysis and dynamic symbolic execution in\n  a toolchain to detect fault injection vulnerabilities","volume":"14","author":"Guilhem Lacombe","year":"2024","journal-title":"Journal of Cryptographic Engineering","ISSN":"https:\/\/id.crossref.org\/issn\/2190-8516","issn-type":"electronic"},{"key":"ref40:9847500","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ECAI54874.2022.9847500","article-title":"Detecting fault injection vulnerabilities in binaries with\n  symbolic execution","author":"Julien Lancia","year":"2022"},{"key":"ref41:4567068","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1109\/IOLTS.2008.59","article-title":"A New Approach for Transient Fault Injection Using Symbolic\n  Simulation","author":"Ashish Darbari","year":"2008"},{"key":"ref42:9153386","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1109\/DSN48063.2020.00052","article-title":"ProFIPy: Programmable Software Fault Injection\n  as-a-Service","author":"Domenico Cotroneo","year":"2020"},{"key":"ref43:6296658","doi-asserted-by":"publisher","first-page":"2292","DOI":"10.1109\/TC.2012.219","article-title":"SymPLFIED: Symbolic Program-Level Fault Injection and\n  Error Detection Framework","volume":"62","author":"Karthik Pattabiraman","year":"2013","journal-title":"IEEE Transactions on Computers"},{"key":"ref44:10.1145\/360248.360252","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","article-title":"Symbolic execution and program testing","volume":"19","author":"James C. King","year":"1976","journal-title":"Commun. ACM","ISSN":"https:\/\/id.crossref.org\/issn\/0001-0782","issn-type":"electronic"},{"key":"ref45:shoshitaishvili2016state","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1109\/SP.2016.17","article-title":"SOK: (State of) The Art of War: Offensive Techniques in\n  Binary Analysis","author":"Yan Shoshitaishvili","year":"2016"},{"key":"ref46:NIPS2000_61b1fb3f","first-page":"689","article-title":"Generalized Belief Propagation","author":"Jonathan S. Yedidia","year":"2000"},{"key":"ref47:doi:10.1126\/sciadv.abf1211","doi-asserted-by":"publisher","DOI":"10.1126\/sciadv.abf1211","article-title":"Belief propagation for networks with loops","volume":"7","author":"Alec Kirkley","year":"2021","journal-title":"Science Advances"},{"key":"ref48:abdulrahman2022","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"853","DOI":"10.1007\/978-3-031-09234-3_42","article-title":"Faster Kyber and Dilithium on the Cortex-M4","volume":"13269","author":"Amin Abdulrahman","year":"2022"},{"key":"ref49:10.1007\/978-3-031-62746-0_5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1007\/978-3-031-62746-0_5","article-title":"One Vector to Rule Them All: Key Recovery from One Vector in\n  UOV Schemes","volume":"14772","author":"Pierre P\u00e9bereau","year":"2024"},{"key":"ref50:mayotentativeround2","volume-title":"MAYO: Overview + Updates","author":"Ward Beullens","year":"2024"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:11:34Z","timestamp":1736788294000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/4\/17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,13]]},"references-count":50,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,1,13]]}},"URL":"https:\/\/doi.org\/10.62056\/ab0ljbkrz","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,13]]},"assertion":[{"value":"2024-10-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-29"}}