Aller au contenu principal
2025 conference-paper

Everything Depends on Your Hammer: A Systematic Rowhammer Attack Exploration on SPHINCS+

0Citations signalées, ce qui n’est pas une note de qualité
1Institutions déclarées
1Pays d’affiliation déclarés

Rattachement africain : in. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

Secure implementation of Post-Quantum Cryptosystems (PQC) is becoming critical as the world migrates towards quantum-safe cryptography. Fault attacks (FA) are practical threats affecting cryptographic implementations on both embedded and native, multi-user systems. Although research on FAs targeting PQC algorithms is well-paced for embedded systems (typically with physical adversarial access), exploration of such threats for native systems (typically with remote adversarial access) requires further attention. The type of faults and, consequently, the attack algorithms differ significantly between embedded and native systems.In this paper, we present a systematic approach to evaluate PQC algorithms against Rowhammer – a remote, software-controlled fault injection vector in native and cloud-based systems. Unlike conventional ways in cryptography, where an attack is first developed in theory and then demonstrated on target platform(s), we take a system-specific approach by first characterizing the fault model of a target platform and then exploiting these faults to devise a suitable theoretical attack. This approach helps the attacker quickly converge to an attack optimized for the target system. Also, if exercised successfully for targets with low fault susceptibility, it finds attacks potentially affecting a large number of targets. Our approach is demonstrated for SPHINCS+, the NIST standard for stateless hash-based digital signatures. We discovered a novel Rowhammer-based forgery attack and demonstrated it for DDR3 and DDR4 DRAMs. The attacks were carried out on the standard implementation of SPHINCS+ and for the liboqs library. To the best of our knowledge, this is the first work proposing a forgery attack using Rowhammer on SPHINCS+.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
Everything Depends on Your Hammer: A Systematic Rowhammer Attack Exploration on SPHINCS+
Date Crossref
26/10/2025
Éditeur
IEEE
Type
proceedings-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Les institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Cryptographic Implementations and SecurityCryptography and Data SecuritySecurity and Verification in Computing

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.