{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T04:20:06Z","timestamp":1775794806787,"version":"3.50.1"},"reference-count":38,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T00:00:00Z","timestamp":1759795200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,12,2]]},"abstract":"<jats:p>The ongoing transition to post-quantum cryptography has highlighted the need for digital signature schemes offering diverse performance and security trade-offs. Among the candidates in NIST\u2019s ongoing post-quantum signature standardisation process is FAEST, a scheme built upon the Vector Oblivious Linear Evaluation in-the-Head (VOLEitH) paradigm introduced in 2023. VOLEitH enables efficient zero-knowledge proofs with competitive signature sizes under conservative assumptions, allowing FAEST to rely primarily on the one-wayness of the Advanced Encryption Standard (AES). Despite their promising efficiency, VOLEitH-based signature schemes have remained relatively unexplored from a physical security perspective.   In this paper, we present the first side-channel security evaluation.   Specifically, we demonstrate two single-trace, deep learning-assisted power analysis attacks on the masked implementation of FAEST by Aranha, Degn, Eilath, Nielsen, and Scholl. These attacks exploit leakage from witness bits and VOLE tag computations, recovering the full secret key with success probability above 0.99 from a single signature on an ARM Cortex-M4 processor.   We further analyse how the VOLEitH construction enables profiling of VOLE tags without knowledge of the secret key and how even partial leakage of these tags compromises security. Finally, we discuss practical countermeasures to mitigate such leakages and strengthen the physical resilience of VOLEitH-based signature implementations.<\/jats:p>","DOI":"10.62056\/aebngyl7s","type":"journal-article","created":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:39:47Z","timestamp":1767915587000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":2,"title":["Side-Channel Attacks on VOLEitH Signature Schemes"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-0070-9595","authenticated-orcid":false,"given":"S\u00f6nke","family":"Jendral","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7382-9408","authenticated-orcid":false,"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"ref1:FIPS203","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.203","volume-title":"Module-Lattice-Based Key Encapsulation Mechanism\n  Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref2:FIPS204","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.204","volume-title":"Module-Lattice-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref3:FIPS205","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.205","volume-title":"Stateless Hash-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref4:nistdigsig","volume-title":"NIST Announces Additional Digital Signature Candidates for\n  the PQC Standardization Process","author":"National Institute of Standards","year":"2023"},{"key":"ref5:nistdigsig2","volume-title":"NIST Announces 14 Candidates to Advance to the Second\n  Round of the Additional Digital Signatures for the Post-Quantum Cryptography\n  Standardization Process","author":"National Institute of Standards","year":"2024"},{"key":"ref6:DBLP:conf\/crypto\/BaumBGKORS22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"581","DOI":"10.1007\/978-3-031-38554-4_19","article-title":"Publicly Verifiable Zero-Knowledge and Post-Quantum\n  Signatures from VOLE-in-the-Head","volume":"14085","author":"Carsten Baum","year":"2023"},{"key":"ref7:faestspec","volume-title":"FAEST: Algorithm Specifications","author":"Carsten Baum","year":"2023"},{"key":"ref8:DBLP:conf\/dac\/KarabulutA21","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1109\/DAC18074.2021.9586131","article-title":"FALCON Down: Breaking FALCON Post-Quantum Signature\n  Scheme through Side-Channel Attacks","author":"Emre Karabulut","year":"2021"},{"key":"ref9:pqm4-faest","volume-title":"FAEST for Memory-Constrained Devices with Side-Channel\n  Protections","author":"Diego F. Aranha","year":"2025"},{"key":"ref10:sdith2","volume-title":"The Syndrome Decoding in the Head (SD-in-the-Head)\n  Signature Scheme","author":"Carlos Aguilar Melchor","year":"2025"},{"key":"ref11:perk","volume-title":"PERK","author":"Najwa Araj","year":"2025"},{"key":"ref12:DBLP:journals\/siamcomp\/IshaiKOS09","doi-asserted-by":"publisher","first-page":"1121","DOI":"10.1137\/080725398","article-title":"Zero-Knowledge Proofs from Secure Multiparty Computation","volume":"39","author":"Yuval Ishai","year":"2009","journal-title":"SIAM J. Comput."},{"key":"ref13:DBLP:journals\/iacr\/GodardAGLM24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-3-031-86602-9_10","article-title":"Single Trace Side-Channel Attack on the MPC-in-the-Head\n  Framework","volume":"15578","author":"Julie Godard","year":"2025"},{"key":"ref14:DBLP:conf\/asiacrypt\/FeneuilR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1007\/978-981-99-8721-4_14","article-title":"Threshold Linear Secret Sharing to the Rescue of\n  MPC-in-the-Head","volume":"14438","author":"Thibauld Feneuil","year":"2023"},{"key":"ref15:DBLP:conf\/pqcrypto\/GellersenSE21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1007\/978-3-030-81293-5_10","article-title":"Differential Power Analysis of the Picnic Signature\n  Scheme","volume":"12841","author":"Tim Gellersen","year":"2021"},{"key":"ref16:DBLP:conf\/ccs\/SekerBW020","doi-asserted-by":"publisher","first-page":"1033","DOI":"10.1145\/3372297.3417889","article-title":"SNI-in-the-head: Protecting MPC-in-the-head Protocols\n  against Side-channel Analysis","author":"Okan Seker","year":"2020"},{"key":"ref17:DBLP:journals\/tches\/AranhaBESTWZ21","doi-asserted-by":"publisher","first-page":"239","DOI":"10.46586\/TCHES.V2021.I4.239-282","article-title":"Side-Channel Protections for Picnic Signatures","volume":"2021","author":"Diego F. Aranha","year":"2021","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref18:DBLP:conf\/focs\/GoldreichGM84","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1109\/SFCS.1984.715949","article-title":"How to Construct Random Functions (Extended Abstract)","author":"Oded Goldreich","year":"1984"},{"key":"ref19:DBLP:conf\/crypto\/Roy22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"657","DOI":"10.1007\/978-3-031-15802-5_23","article-title":"SoftSpokenOT: Quieter OT Extension from Small-Field\n  Silent VOLE in the Minicrypt Model","volume":"13507","author":"Lawrence Roy","year":"2022"},{"key":"ref20:DBLP:conf\/ccs\/YangSWW21","doi-asserted-by":"publisher","first-page":"2986","DOI":"10.1145\/3460120.3484556","article-title":"QuickSilver: Efficient and Affordable Zero-Knowledge Proofs\n  for Circuits and Polynomials over Any Field","author":"Kang Yang","year":"2021"},{"key":"ref21:DBLP:conf\/crypto\/FiatS86","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","article-title":"How to Prove Yourself: Practical Solutions to Identification\n  and Signature Problems","volume":"263","author":"Amos Fiat","year":"1986"},{"key":"ref22:DBLP:conf\/asiacrypt\/BaumBMORRRS24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-981-96-0875-1_15","article-title":"One Tree to Rule Them All: Optimizing GGM Trees and OWFs\n  for Post-Quantum Signatures","volume":"15484","author":"Carsten Baum","year":"2024"},{"key":"ref23:faest2","volume-title":"FAEST v2: Algorithm Specifications","author":"Carsten Baum","year":"2025"},{"key":"ref24:DBLP:conf\/ches\/RivainP10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1007\/978-3-642-15031-9_28","article-title":"Provably Secure Higher-Order Masking of AES","volume":"6225","author":"Matthieu Rivain","year":"2010"},{"key":"ref25:cryptoeprint:2025\/471","volume-title":"A Practical Tutorial on Deep Learning-based Side-channel\n  Analysis","author":"Sengim Karayalcin","year":"2025"},{"key":"ref26:DBLP:conf\/pqcrypto\/AmietCLZ20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-030-44223-1_11","article-title":"Defeating NewHope with a Single Trace","volume":"12100","author":"Dorian Amiet","year":"2020"},{"key":"ref27:DBLP:journals\/access\/SimKLKLHYCH20","doi-asserted-by":"publisher","first-page":"183175","DOI":"10.1109\/ACCESS.2020.3029521","article-title":"Single-Trace Attacks on Message Encoding in Lattice-Based\n  KEMs","volume":"8","author":"Bo-Yeon Sim","year":"2020","journal-title":"IEEE Access"},{"key":"ref28:DBLP:conf\/fps\/WangD23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1007\/978-3-031-57537-2_26","article-title":"A Shared Key Recovery Attack on a Masked Implementation of\n  CRYSTALS-Kyber's Encapsulation Algorithm","volume":"14551","author":"Ruize Wang","year":"2023"},{"key":"ref29:DBLP:journals\/iacr\/JendralD24a","volume-title":"Single-trace side-channel attacks on MAYO exploiting leaky\n  modular multiplication","author":"S\u00f6nke Jendral","year":"2024"},{"key":"ref30:DBLP:conf\/ccs\/NgoD021","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1145\/3474376.3487277","article-title":"Breaking Masked and Shuffled CCA Secure Saber KEM by\n  Power Analysis","author":"Kalle Ngo","year":"2021"},{"key":"ref31:Masure_Cristiani_Lecomte_Standaert_2022","doi-asserted-by":"publisher","first-page":"32","DOI":"10.46586\/tches.v2023.i1.32-59","article-title":"Don\u2019t Learn What You Already Know: Scheme-Aware Modeling\n  for Profiling Side-Channel Analysis against Masking","volume":"2023","author":"Lo\u00efc Masure","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref32:stm32f415-rm","author":"STMicroelectronics","year":"2024"},{"key":"ref33:mirath","volume-title":"Mirath Signature Scheme","author":"Gora Adj","year":"2025"},{"key":"ref34:DBLP:conf\/asiapkc\/DubrovaNGW23","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/3591866.3593072","article-title":"Breaking a Fifth-Order Masked Implementation of\n  CRYSTALS-Kyber by Copy-Paste","author":"Elena Dubrova","year":"2023"},{"key":"ref35:DBLP:conf\/crypto\/ChariJRR99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/3-540-48405-1_26","article-title":"Towards Sound Approaches to Counteract Power-Analysis\n  Attacks","volume":"1666","author":"Suresh Chari","year":"1999"},{"key":"ref36:DBLP:conf\/acns\/BacklundNGD23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-031-41181-6_9","article-title":"Secret Key Recovery Attack on Masked and Shuffled\n  Implementations of CRYSTALS-Kyber and Saber","volume":"13907","author":"Linus Backlund","year":"2023"},{"key":"ref37:DBLP:conf\/host\/JendralNWD24","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/HOST55342.2024.10545390","article-title":"Breaking SCA-Protected CRYSTALS-Kyber with a Single\n  Trace","author":"S\u00f6nke Jendral","year":"2024"},{"key":"ref38:shufflemasked","doi-asserted-by":"publisher","first-page":"140","DOI":"10.46586\/tches.v2022.i2.140-165","article-title":"Bitslice Masking and Improved Shuffling: How and When to Mix\n  Them in Software?","volume":"2022","author":"Melissa Azouaoui","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:41:22Z","timestamp":1767915682000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/4\/24"}},"subtitle":["Breaking Masked FAEST"],"short-title":[],"issued":{"date-parts":[[2026,1,8]]},"references-count":38,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,1,8]]}},"URL":"https:\/\/doi.org\/10.62056\/aebngyl7s","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,8]]},"assertion":[{"value":"2025-10-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-4-47"}}