Toward a Secure Fixed-Point Implementation of the Falcon Signature Scheme
Daniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas Prest
摘要
Falcon was selected by NIST in 2022 for standardization as a post-quantum digital signature scheme. Among all standardized signature schemes, Falcon achieves the smallest signature size. Its main drawback, however, is its reliance on floating-point arithmetic, which plays a critical role in the security analysis. This reliance poses significant challenges for practical implementations: some platforms lack floating-point units, floating-point division is not constant time on many processors, and protecting floating-point computations against side-channel attacks using masking techniques is particularly difficult on embedded devices.
To address portability issues, Pornin (ePrint 2019/893) proposed an implementation of that emulates floating-point arithmetic using integer operations. While it enables deployment on a wider range of platforms, this approach incurs a substantial performance penalty compared to the native floating-point implementation.
This work studies the theory and practice of implementing Falcon's signing procedure in fixed-point arithmetic. This requires a specific analysis of the boundedness and precision of intermediate variables.
-
Our boundedness analysis revolves around a key fact: almost every intermediate variable arising during key expansion and signing is bounded by a function of four quantities that can be computed at key generation time. Our modified key generation enforces thresholds on these quantities through a light rejection step that rejects less than 50% of initial Falcon keys. This then yields sharp, unconditional bounds on all fixed-point variables. Establishing these bounds is highly nontrivial, and relies on Gaussian concentration arguments as well as on symplectic pairs, a generalization of symplecticity.
-
Our precision analysis remains, for now, partly empirical. Following a Rényi divergence argument, our main theorem proves the security of fixed-point Falcon conditioned on error bounds of certain intermediate values. These error bounds are derived empirically based on extensive experiments.
We provide a C fixed-point implementation. It is approximately a factor of two slower than the original floating-point implementation, but achieves a speedup of an order of magnitude compared to emulated floating-point implementations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper6
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi 等EUROCRYPT 2022 · 被引用 67 次
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt 等S&P 2022 · 被引用 61 次
- Integral Matrix Gram Root and Lattice Gaussian Sampling Without FloatsLéo Ducas, Steven D. Galbraith, Thomas Prest, Yang YuEUROCRYPT 2020 · 被引用 22 次
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck 等EUROCRYPT 2026 · 被引用 15 次
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
相关 Paper
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 被引用 4 次
- Square Root of All Evil: The Dangers of Falcon's Superfluous Square RootsKaihara Hiroto, Calvin Abou Haidar, Mehdi Tibouchi, Masayuki AbeCCS 2026
- FALCON Down: Breaking FALCON Post-Quantum Signature Scheme through Side-Channel AttacksEmre Karabulut, Aydin AysuDAC 2021 · 被引用 65 次
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 被引用 26 次
- Crowhammer: Full Key Recovery Attack on Falcon with a Single Rowhammer Bit FlipCalvin Abou Haidar, Quentin Payet, Mehdi TibouchiCRYPTO 2025 · 被引用 4 次
