A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack

Daniel J. Bernstein. A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack. IACR Cryptology ePrint Archive, 2022:1125, 2022. [doi]

Abstract

Abstract is missing.