A Fault Analysis on SNOVA

📅 2025-09-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work conducts a fault-security analysis of the post-quantum signature scheme SNOVA, revealing its vulnerability to both permanent and transient hardware faults during signature generation. We propose a novel fault-assisted coordinate attack: by injecting single-bit-flip faults to obtain erroneous signatures, we construct and solve a system of quadratic polynomial equations, enabling full private-key recovery using only 22–68 faulty signatures. This is the first approach to integrate algebraic cryptanalysis with fine-grained fault modeling, precisely identifying the physical security weakness in SNOVA’s Rejection Sampling module. Experimental simulations confirm the practical feasibility of the attack. Furthermore, we design a lightweight countermeasure that reduces the fault injection success probability by over two orders of magnitude, with negligible overhead in computation and memory.

Technology Category

Computer Vision: Adversarial Attacks & RobustnessMachine Learning: Quantum Machine LearningConstraint Satisfaction and Optimization: Satisfiability

Application Category

Security and Privacy: Large-scale security measurementsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsResponsible Web: Measurement, analysis, and circumvention of Web censorship
📝 Abstract
SNOVA is a post-quantum cryptographic signature scheme known for its efficiency and compact key sizes, making it a second-round candidate in the NIST post-quantum cryptography standardization process. This paper presents a comprehensive fault analysis of SNOVA, focusing on both permanent and transient faults during signature generation. We introduce several fault injection strategies that exploit SNOVA's structure to recover partial or complete secret keys with limited faulty signatures. Our analysis reveals that as few as 22 to 68 faulty signatures, depending on the security level, can suffice for key recovery. We propose a novel fault-assisted reconciliation attack, demonstrating its effectiveness in extracting the secret key space via solving a quadratic polynomial system. Simulations show transient faults in key signature generation steps can significantly compromise SNOVA's security. To address these vulnerabilities, we propose a lightweight countermeasure to reduce the success of fault attacks without adding significant overhead. Our results highlight the importance of fault-resistant mechanisms in post-quantum cryptographic schemes like SNOVA to ensure robustness.
Problem

Research questions and friction points this paper is trying to address.

Analyzing fault vulnerabilities in SNOVA post-quantum signature scheme
Developing fault injection strategies to recover secret keys
Proposing lightweight countermeasures against fault attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Fault injection strategies exploit SNOVA structure
Fault-assisted reconciliation attack extracts secret keys
Lightweight countermeasure reduces fault attack success
💼 Related Jobs
No related jobs found.
G
Gustavo Banegas
Inria and Laboratoire d’Informatique de l’Ecole polytechnique, Institut Polytechnique de Paris, Palaiseau, France
Ricardo Villanueva-Polanco
Ricardo Villanueva-Polanco
Cryptography Researcher
CryptographyCryptographic EngineeringComputer SecurityAlgorithms