A Differential Fault Attack Against Deterministic Falcon Signatures
摘要
We describe a fault attack against the deterministic variant of the \(\textsc {Falcon}\) signature scheme. It is the first fault attack that exploits specific properties of deterministic \(\textsc {Falcon}\) . The attack works under a very relaxed and realistic single fault random model. The main idea is to inject a fault into the pseudo-random generator of the pre-image trapdoor sampler, generate different signatures for the same input, find reasonably short lattice vectors this way, and finally use lattice reduction techniques to obtain the private key. We investigate the relationship between fault location, the number of faults, computational effort for a possibly remaining exhaustive search step and success probability.