Checking before output may not be enough against fault-based cryptanalysis
Sung‐Ming Yen, Marc Jóye · IEEE Transactions on Computers · 2000
In order to avoid fault-based attacks on cryptographic security modules (e.g., smart-cards), some authors suggest that the computation results should be checked for faults before being transmitted. In this paper, we describe a potential fault-based attack where key bits leak only through the information whether the device produces a correct answer after a temporary fault or not. This information is available to the adversary even if a check is performed before output.