×

img Accessibility Controls

Research Projects Banner

Research Projects

Fault Attack Countermeasures for Post-Quantum Cryptography

Implementing Organization

Indian Institute Of Technology Bombay
Principal Investigator
Dr. Sayandeep Saha
Indian Institute Of Technology Bombay
sayandeep.iitkgp@gmail.com

Project Overview

This proposal aims to develop countermeasures against fault attacks on embedded cryptographic implementations. We shall specifically target one of the major post-quantum (PQC) signature schemes from the ongoing NIST competition for PQC standardization. Fault attacks are active implementation-based attacks that recover the secret by inducing controlled faults in the computation, followed by a mathematical analysis of the faulty system response. With general and custom-built specialized injection equipment, the practicality of this threat has been established for state-of-the-art embedded devices and cryptographic co-processors. For example, a single random fault can extract the entire secret key of AES within seconds. One recent example of such fault attacks is the hack of SpaceX Starlink terminals. Given quantum computers are becoming a reality, the world is rapidly migrating to Post Quantum Cryptography(PQC). NIST is currently standardizing the PQC signature schemes. It is, therefore, immensely important to verify and fix the physical security of these algorithms before deployment. Fault attacks are found to be non-trivial to counter as there is no standard technique known so far that can be adapted for any cryptographic scheme. The most widely used approach is computational redundancy, which, if not utilized properly, may lead to newer attacks. The extent of physical attack threats is still not well-explored, as the PQCs are quite new and complex. The goal of this project is to develop a systematic countermeasure design flow for the PQC schemes based on multivariate signatures. NIST is currently evaluating many such schemes as standardization candidates for PQC signatures. In this project, we shall evaluate the Mayo signature scheme with respect to fault attacks and eventually develop new countermeasures for each attack surface. Mayo is currently the most efficient one with respect to signature size, and an analysis of this scheme will give us a clear understanding of other similar signature schemes in the multivariate class. Our main approach will be to mathematically analyze the target scheme for existing and new fault attack surfaces and then propose countermeasures at the algorithm level, which are deployable irrespective of any specific implementation style. We shall also verify each attack surface and the efficacy of proposed countermeasures (implemented in software) with our practical fault injection setup. Our findings on PQC will be the cornerstone for secure PQC migration. Additionally, in this project, we shall be developing a practical evaluation setup for physical attacks at IIT Bombay. The equipment procured, and skills developed will be useful further to develop a test facility for practical Internet of Things  (IoT) devices running cryptography or Artificial Intelligence (AI) models which will be of immense importance to industry and defense.
Funding Organization
Quick Information
Area of Research
Engineering Sciences
Focus Area
Computer Engineering
Start Date
30 May 2025
End Date
29 May 2028
Status
ongoing
Output
No. of Research Paper
00
Technologies (If Any)
00
No. of PhD Produced
00
Publications
00
No. of Patents
Filed : 00
Grant : 00
arrowtop
Latest Updates
Loading…