Transactions on Cryptographic Hardware and Embedded Systems 2026
Fault Attack Countermeasures for SPHINCS+:
WOTS+ with Checksum Segmentation and Subtree Root Children Caching
Yan Li
China Agricultural University, Beijing, China
Tianlong Yan
China Agricultural University, Beijing, China
Gechen Liu
China Agricultural University, Beijing, China
Shuang Yao
CEC Huada Electronic Design Co., Ltd., Beijing, China
Ningning He
CEC Huada Electronic Design Co., Ltd., Beijing, China
Hao Wen
China Agricultural University, Beijing, China
Yiming Xue
China Agricultural University, Beijing, China
Keywords: SPHINCS+, post-quantum cryptography, fault attack
Abstract
SPHINCS+ is a stateless hash-based digital signature algorithm (SLHDSA), standardized by NIST (FIPS 205). However, it is vulnerable to fault attacks, especially in embedded and IoT systems where devices are often more accessible to attackers. Additionally, existing countermeasures against fault attacks on SPHINCS+ generally require either additional hardware resources, substantial memory capacity, or redundant computations. The fault attacks in SPHINCS+ arise from the reuse of a WOTS+ instance, leading to security degradation and signature forgery. Prior research on this security degradation was limited to inaccurate probabilistic assumptions or slow computations.In this paper, we introduce a novel analytical method based on Generating Functions to efficiently and precisely compute the post-reuse security of WOTS+. Through this rigorous analysis, we discover that the security degradation follows a bimodal distribution, and the key to improving the security floor lies in the number of possible values for the checksum’s most significant block. Based on this insight, we propose WOTS+ with Checksum Segmentation (WOTS+CS), the first enhancement of the WOTS+ designed to improve post-reuse security (e.g., raising the security floor from 34.9 to 49.8 bits in the 256-bit instance) by structurally eliminating the weak instances. To strengthen protection further, we introduce the Subtree Root Children Caching (SRCC) scheme, which validates the subtree root to prevent WOTS+ from signing an incorrect root. By caching the subtree roots of the top few layers, the storage overhead remains manageable.Finally, we conducted fault injection experiments on SPHINCS+ using a ChipWhisperer to evaluate the difficulty of fault injection. Subsequently, we evaluated the effectiveness of our countermeasures in a complete fault attack, demonstrating that our methods increase the attacker’s difficulty across all phases of fault attacks.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3
PaperArtifact
Artifact number
tches/2026/a34
Artifact published
September 21, 2026
Badge
✅ IACR CHES Artifacts Functional
License
This work is licensed under the MIT License.
Some files in this archive are licensed under a different license. See the contents of this archive for more information.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Yan Li, Tianlong Yan, Gechen Liu, Shuang Yao, Ningning He, Hao Wen, Yiming Xue. (2026). Fault Attack Countermeasures for SPHINCS+: WOTS+ with Checksum Segmentation and Subtree Root Children Caching. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 1–23. https://doi.org/10.46586/tches.v2026.i3.1-23. Artifact at https://artifacts.iacr.org/tches/2026/a34.