Navigation and service

Laser Fault Injection Attack on the eXtended Merkle Signature Scheme (XMSS)

date 05.03.2024

Laser Fault Injection Attack on the eXtended Merkle Signature Scheme

Since the need for post-quantum cryptography emerged the interest in hash-based signatures (HBS) has significantly increased. Since their standardization especially stateful HBS like XMSS have been deployed in several products ranging from embedded devices up to servers. The Fraunhofer institute AISEC has authored a study on behalf of the BSI, which describes the practical evaluation of a new kind of Laser Fault Injection Attack on the Winternitz One-Time Signature (WOTS) scheme, which is also used in XMSS. The study describes the preparation and implementation of the attack on a standard microcontroller as well as the difficulties the attacker has to overcome. Additionally it presents a countermeasure, which is easy to implement and can increase the effort for an attacker significantly.