Square Root of All Evil: The Dangers of Falcon's Superfluous Square Roots
Kaihara Hiroto, Calvin Abou Haidar, Mehdi Tibouchi, Masayuki Abe
摘要
Falcon is one of the 3 post-quantum signature schemes already selected by NIST for standardization (as FN-DSA). It is very compact and efficient, but also infamously difficult to implement correctly and securely. This is due in particular to its reliance of various floating point operations, the most complex and costly of which are square root computations.
In this paper, we first point out that those square root computations are in fact wholly unnecessary: the algorithm can be rewritten without them, resulting in a somewhat simpler implementation that is equally fast or even slightly faster.
We then observe that they also present security risks, in particular as a singularly sensitive target for physical attacks. We demonstrate this with a fault attack, supported by concrete experiments against an ARM Cortex-M4 microcontroller target. We show that injecting a single glitch in one square root computation, and then generating around a million signatures with the unperturbed signing algorithm, leads to full key recovery with 100% success rate and, moreover, faulty signatures are not easy to distinguish from validly generated ones. This makes this fault attack the most devastating against Falcon to date, in contrast with earlier attacks requiring hundreds of millions of signature samples, many injected faults, or resulting in signatures that are straightforward to distinguish from regular ones. In addition, we mention potential risks of the square root computations from the standpoint of dependency management and supply chain security.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 被引用 4 次
- FALCON Down: Breaking FALCON Post-Quantum Signature Scheme through Side-Channel AttacksEmre Karabulut, Aydin AysuDAC 2021 · 被引用 65 次
- Toward a Secure Fixed-Point Implementation of the Falcon Signature SchemeDaniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas PrestCRYPTO 2026 · 被引用 1 次
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 被引用 26 次
- Crowhammer: Full Key Recovery Attack on Falcon with a Single Rowhammer Bit FlipCalvin Abou Haidar, Quentin Payet, Mehdi TibouchiCRYPTO 2025 · 被引用 4 次
