[Cryptography] attacks on public keys

sebastien riou matic at nimp.co.uk
Sat Jun 30 15:19:27 EDT 2018

Literature on fault attacks on signature generation to recover private keys
is plentiful. When it comes to fault attacks targeting signature
verification, literature is scarce and rather old:
- RSA public key: https://eprint.iacr.org/2005/458.pdf
- DSA/ElGamal, "Fault Attacks on Public Key Elements: Application to
DLP-based Schemes"
( available here:

For RSA, the 2005 attack is practical it may be as good as it gets. Besides
generic fault attack countermeasures, is there any good countermeasure
against this ?
For DSA, the authors conclude that attacks exist but not practical as is.
This was 10 years ago, is anyone aware of some progress ?

