Fault Cryptanalysis of ElGamal and Related Signature Schemes

In this article the immunity of ElGamal and related signature schemes against fault cryptanalysis (FA) is examined. Although such schemes have been widely adopted, their resistance against fault cryptanalysis has not been verified in detail. Majority of those schemes are not immune to fault cryptanalysis and can be broken without solving discrete logarithm problem. It will be proved that the selected signature schemes can be broken in O(nlogn) steps if single bit-flip errors are inducted during computations. We will also present methods that allow to improve security of ElGamal and DSA.