Correction Fault Attack on CROSS under Unknown Bit Flips
(2026) In IACR Transactions on Cryptographic Hardware and Embedded Systems 2026(2). p.192-217- Abstract
Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the... (More)
Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO’22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.
(Less)
- author
- Jendral, Sönke
; Dubrova, Elena
; Guo, Qian
LU
and Johansson, Thomas
LU
- organization
- publishing date
- 2026-04
- type
- Contribution to journal
- publication status
- published
- subject
- keywords
- Code-based Cryptography, CROSS, Fault Injection, Key Recovery Attack, Partial Key Exposure Attack, Post-Quantum Digital Signature
- in
- IACR Transactions on Cryptographic Hardware and Embedded Systems
- volume
- 2026
- issue
- 2
- pages
- 26 pages
- publisher
- Ruhr-University of Bochum
- external identifiers
-
- scopus:105036954132
- ISSN
- 2569-2925
- DOI
- 10.46586/tches.v2026.i2.192-217
- language
- English
- LU publication?
- yes
- id
- 9d089d1c-0af6-417d-87b8-4fc5fe45db5d
- date added to LUP
- 2026-05-26 13:30:23
- date last changed
- 2026-05-26 13:31:00
@article{9d089d1c-0af6-417d-87b8-4fc5fe45db5d,
abstract = {{<p>Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO’22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.</p>}},
author = {{Jendral, Sönke and Dubrova, Elena and Guo, Qian and Johansson, Thomas}},
issn = {{2569-2925}},
keywords = {{Code-based Cryptography; CROSS; Fault Injection; Key Recovery Attack; Partial Key Exposure Attack; Post-Quantum Digital Signature}},
language = {{eng}},
number = {{2}},
pages = {{192--217}},
publisher = {{Ruhr-University of Bochum}},
series = {{IACR Transactions on Cryptographic Hardware and Embedded Systems}},
title = {{Correction Fault Attack on CROSS under Unknown Bit Flips}},
url = {{http://dx.doi.org/10.46586/tches.v2026.i2.192-217}},
doi = {{10.46586/tches.v2026.i2.192-217}},
volume = {{2026}},
year = {{2026}},
}