A Closer Look at Falcon
Pierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck, Eike Kiltz
Abstract
Falcon is a winner of NIST's six-year post-quantum cryptography standardisation competition. Based on the celebrated full-domain-hash framework of Gentry, Peikert and Vaikuntanathan (GPV) (STOC'08), Falcon leverages NTRU lattices to achieve the most compact signatures among standardised lattice-based schemes. Its security hinges on a Rényi divergence-based argument for Gaussian samplers. However, the GPV proof, which uses statistical distance to argue closeness of distributions, fails when applied naively to Falcon due to parameter choices resulting in statistical distances as large as 2 -34 . Additional implementation-driven deviations from the GPV framework further invalidate the original proof, leaving Falcon without a security proof despite its selection for standardisation. In this work, we provide the first formal security proof of Falcon in the random oracle model, achieved through a few conservative modifications, now incorporated into the forthcoming standard. At the heart of our analysis lies an adaptation of the GPV framework to work with the Rényi divergence, along with an optimised method for parameter selection under this measure. We also analyse the FFO Sampler that is used in Falcon. Further, we prove the equivalence of plain unforgeability to a multi-target inhomogeneous SIS problem, and strong unforgeability to a second-preimage version of this problem, providing clear targets for cryptanalysis. Assuming these problems are as hard as standard SIS, we demonstrate that Falcon-512 barely satisfies the claimed 120-bit security target, while Falcon-1024 achieves the claimed security level.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 20f8efca-1720-49fd-ab26-1005c13e9a82Cited by top-tier papers1
Ask how each one uses itBuilds on13
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- Breaking Rainbow Takes a Weekend on a LaptopWard BeullensCRYPTO 2022 · 170 citations
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
Related papers
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 4 citations
- Thresholdizing Standardized FALCON SignaturesRadhika Garg, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi et al.CCS 2026
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 26 citations
- Shorter Hash-and-Sign Lattice-Based SignaturesThomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang YuCRYPTO 2022 · 38 citations
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
