FALCON Down: Breaking FALCON Post-Quantum Signature Scheme through Side-Channel Attacks
Emre Karabulut, Aydin Aysu
Abstract
This paper proposes the first side-channel attack on FALCON—a NIST Round-3 finalist for the post-quantum digital signature standard. We demonstrate a known-plaintext attack that uses the electromagnetic measurements of the device to extract the secret signing keys, which then can be used to forge signatures on arbitrary messages. The proposed attack targets the unique floating-point multiplications within FALCON’s Fast Fourier Transform through a novel extend-and-prune strategy that extracts the sign, mantissa, and exponent variables without false positives. The extracted floating-point values are then mapped back to the secret key’s coefficients. Our attack, notably, does not require pre-characterizing the power profile of the target device or crafting special inputs. Instead, the statistical differences on obtained traces are sufficient to successfully execute our proposed differential electromagnetic analysis. The results on an ARM-Cortex-M4 running the FALCON NIST’s reference software show that approximately 10k measurements are sufficient to extract the entire key.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- Plover: Masking-Friendly Hash-and-Sign Lattice SignaturesMuhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest et al.EUROCRYPT 2024 · 14 citations
- High-Order Masking of Lattice Signatures in Quasilinear TimeRafaël del Pino, Thomas Prest, Mélissa Rossi, Markku-Juhani O. SaarinenS&P 2023
Builds on2
- CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side ChannelLejla Batina, Shivam Bhasin, Dirmanto Jap, Stjepan PicekUSENIX Security 2019 · 334 citations
- Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersThomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi TibouchiCCS 2017 · 145 citations
Related papers
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 26 citations
- Square Root of All Evil: The Dangers of Falcon's Superfluous Square RootsKaihara Hiroto, Calvin Abou Haidar, Mehdi Tibouchi, Masayuki AbeCCS 2026
- Toward a Secure Fixed-Point Implementation of the Falcon Signature SchemeDaniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas PrestCRYPTO 2026 · 1 citation
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 4 citations
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
