Toward a Secure Fixed-Point Implementation of the Falcon Signature Scheme
Daniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas Prest
Abstract
Falcon was selected by NIST in 2022 for standardization as a post-quantum digital signature scheme. Among all standardized signature schemes, Falcon achieves the smallest signature size. Its main drawback, however, is its reliance on floating-point arithmetic, which plays a critical role in the security analysis. This reliance poses significant challenges for practical implementations: some platforms lack floating-point units, floating-point division is not constant time on many processors, and protecting floating-point computations against side-channel attacks using masking techniques is particularly difficult on embedded devices.
To address portability issues, Pornin (ePrint 2019/893) proposed an implementation of that emulates floating-point arithmetic using integer operations. While it enables deployment on a wider range of platforms, this approach incurs a substantial performance penalty compared to the native floating-point implementation.
This work studies the theory and practice of implementing Falcon's signing procedure in fixed-point arithmetic. This requires a specific analysis of the boundedness and precision of intermediate variables.
-
Our boundedness analysis revolves around a key fact: almost every intermediate variable arising during key expansion and signing is bounded by a function of four quantities that can be computed at key generation time. Our modified key generation enforces thresholds on these quantities through a light rejection step that rejects less than 50% of initial Falcon keys. This then yields sharp, unconditional bounds on all fixed-point variables. Establishing these bounds is highly nontrivial, and relies on Gaussian concentration arguments as well as on symplectic pairs, a generalization of symplecticity.
-
Our precision analysis remains, for now, partly empirical. Following a Rényi divergence argument, our main theorem proves the security of fixed-point Falcon conditioned on error bounds of certain intermediate values. These error bounds are derived empirically based on extensive experiments.
We provide a C fixed-point implementation. It is approximately a factor of two slower than the original floating-point implementation, but achieves a speedup of an order of magnitude compared to emulated floating-point implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fcb13901-aa65-4347-9f8f-bbb5bf8a8a22Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
- Integral Matrix Gram Root and Lattice Gaussian Sampling Without FloatsLéo Ducas, Steven D. Galbraith, Thomas Prest, Yang YuEUROCRYPT 2020 · 22 citations
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck et al.EUROCRYPT 2026 · 15 citations
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt et al.USENIX Security 2024 · 15 citations
Related papers
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 4 citations
- Square Root of All Evil: The Dangers of Falcon's Superfluous Square RootsKaihara Hiroto, Calvin Abou Haidar, Mehdi Tibouchi, Masayuki AbeCCS 2026
- FALCON Down: Breaking FALCON Post-Quantum Signature Scheme through Side-Channel AttacksEmre Karabulut, Aydin AysuDAC 2021 · 65 citations
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 26 citations
- Crowhammer: Full Key Recovery Attack on Falcon with a Single Rowhammer Bit FlipCalvin Abou Haidar, Quentin Payet, Mehdi TibouchiCRYPTO 2025 · 4 citations
