In this paper several attacks are presented that allow information to be derived on faults injected at the beginning of cryptographic
algorithm implementations that use Boolean masking to defend against Differential Power Analysis (DPA). These attacks target
the initialisation functions that are used to enable the algorithm to be protected, allowing a fault attack even in the presence
of round redundancy. A description of the experiments leading to the development of these attacks is also given.