Skip to main content

Lund University Publications

LUND UNIVERSITY LIBRARIES

Correction Fault Attack on CROSS under Unknown Bit Flips

Jendral, Sönke ; Dubrova, Elena ; Guo, Qian LU and Johansson, Thomas LU orcid (2026) In IACR Transactions on Cryptographic Hardware and Embedded Systems 2026(2). p.192-217
Abstract

Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the... (More)

Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO’22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.

(Less)
Please use this url to cite or link to this publication:
author
; ; and
organization
publishing date
type
Contribution to journal
publication status
published
subject
keywords
Code-based Cryptography, CROSS, Fault Injection, Key Recovery Attack, Partial Key Exposure Attack, Post-Quantum Digital Signature
in
IACR Transactions on Cryptographic Hardware and Embedded Systems
volume
2026
issue
2
pages
26 pages
publisher
Ruhr-University of Bochum
external identifiers
  • scopus:105036954132
ISSN
2569-2925
DOI
10.46586/tches.v2026.i2.192-217
language
English
LU publication?
yes
id
9d089d1c-0af6-417d-87b8-4fc5fe45db5d
date added to LUP
2026-05-26 13:30:23
date last changed
2026-05-26 13:31:00
@article{9d089d1c-0af6-417d-87b8-4fc5fe45db5d,
  abstract     = {{<p>Recognising the need for PQC signature schemes with different sizes and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023, NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&amp;P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO’22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.</p>}},
  author       = {{Jendral, Sönke and Dubrova, Elena and Guo, Qian and Johansson, Thomas}},
  issn         = {{2569-2925}},
  keywords     = {{Code-based Cryptography; CROSS; Fault Injection; Key Recovery Attack; Partial Key Exposure Attack; Post-Quantum Digital Signature}},
  language     = {{eng}},
  number       = {{2}},
  pages        = {{192--217}},
  publisher    = {{Ruhr-University of Bochum}},
  series       = {{IACR Transactions on Cryptographic Hardware and Embedded Systems}},
  title        = {{Correction Fault Attack on CROSS under Unknown Bit Flips}},
  url          = {{http://dx.doi.org/10.46586/tches.v2026.i2.192-217}},
  doi          = {{10.46586/tches.v2026.i2.192-217}},
  volume       = {{2026}},
  year         = {{2026}},
}