International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Fault Attack Countermeasures for SPHINCS+:

WOTS+ with Checksum Segmentation and Subtree Root Children Caching


Yan Li
China Agricultural University, Beijing, China

Tianlong Yan
China Agricultural University, Beijing, China

Gechen Liu
China Agricultural University, Beijing, China

Shuang Yao
CEC Huada Electronic Design Co., Ltd., Beijing, China

Ningning He
CEC Huada Electronic Design Co., Ltd., Beijing, China

Hao Wen
China Agricultural University, Beijing, China

Yiming Xue
China Agricultural University, Beijing, China


Keywords: SPHINCS+, post-quantum cryptography, fault attack


Abstract

SPHINCS+ is a stateless hash-based digital signature algorithm (SLHDSA), standardized by NIST (FIPS 205). However, it is vulnerable to fault attacks, especially in embedded and IoT systems where devices are often more accessible to attackers. Additionally, existing countermeasures against fault attacks on SPHINCS+ generally require either additional hardware resources, substantial memory capacity, or redundant computations. The fault attacks in SPHINCS+ arise from the reuse of a WOTS+ instance, leading to security degradation and signature forgery. Prior research on this security degradation was limited to inaccurate probabilistic assumptions or slow computations.In this paper, we introduce a novel analytical method based on Generating Functions to efficiently and precisely compute the post-reuse security of WOTS+. Through this rigorous analysis, we discover that the security degradation follows a bimodal distribution, and the key to improving the security floor lies in the number of possible values for the checksum’s most significant block. Based on this insight, we propose WOTS+ with Checksum Segmentation (WOTS+CS), the first enhancement of the WOTS+ designed to improve post-reuse security (e.g., raising the security floor from 34.9 to 49.8 bits in the 256-bit instance) by structurally eliminating the weak instances. To strengthen protection further, we introduce the Subtree Root Children Caching (SRCC) scheme, which validates the subtree root to prevent WOTS+ from signing an incorrect root. By caching the subtree roots of the top few layers, the storage overhead remains manageable.Finally, we conducted fault injection experiments on SPHINCS+ using a ChipWhisperer to evaluate the difficulty of fault injection. Subsequently, we evaluated the effectiveness of our countermeasures in a complete fault attack, demonstrating that our methods increase the attacker’s difficulty across all phases of fault attacks.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a34

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (1722661 Bytes)  

View on Github

License
This work is licensed under the MIT License.

Some files in this archive are licensed under a different license. See the contents of this archive for more information.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Yan Li, Tianlong Yan, Gechen Liu, Shuang Yao, Ningning He, Hao Wen, Yiming Xue. (2026). Fault Attack Countermeasures for SPHINCS+: WOTS+ with Checksum Segmentation and Subtree Root Children Caching. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 1–23. https://doi.org/10.46586/tches.v2026.i3.1-23. Artifact at https://artifacts.iacr.org/tches/2026/a34.