SHAFI: Securing Hash-Based Post-Quantum Cryptography from Hardware Fault Injection Attacks
Research Paper Showcase 2026
Abstract
SPHINCS+ has emerged as a hash-based scheme to win the National Institute of Standards and Technology's (NIST) post-quantum cryptography (PQC) standardization competition. Unfortunately, recent research has demonstrated that fault injection (FI) attacks on SPHINCS+ can significantly compromise the security of the signing process. This paper introduces SHAFI, a countermeasure to FI attacks on SPHINCS+, that protects the signature generation and verification process via address masking. Experiments on a standard fault injection platform, ChipWhisperer, demonstrate that the proposed method renders faulty signatures unanalyzable by an attacker, eliminating the possibility of universal forgery attempts. This proposed technique is simple, memory and computation budget efficient, and applicable to virtually any SPHINCS+-derived hash-based signing technique. The code and experiment artifacts for the fault injection experiment and the countermeasure are published on GitHub.
Authors
- Yanze Wu, Ph.D. student, cybersecurity, George Mason University
- Qian Wang, assistant professor, electrical engineering, University of California, Merced
- Md Tanvir Arafin, assistant professor, cybersecurity, George Mason University
Publication
- Venue: 2025 Asian Hardware Oriented Security and Trust Symposium (Asian-HOST 2025)
- Date: Dec. 19, 2025