Paper 2025/1261

FAEST for Memory-Constrained Devices

Diego F. Aranha, Aarhus University
Johan Degn, Aarhus University
Jonathan Eilath, Aarhus University
Kent Nielsen, Aarhus University
Peter Scholl, Aarhus University
Abstract

We introduce a new compact and constant-time implementation of the FAEST v1.1 signature scheme that allows it to run in resource-constrained Arm Cortex-M4 microcontrollers under 190M cycles for signing or verifying at level 1 security. The main technique for reducing the memory footprint is a new abstraction to reuse or recompute VOLEs on demand, which reduces memory consumption by at least an order of magnitude.

Note: This revised version includes only the low-memory optimizations and retracts the masked implementation, after an attack was found by a reviewer. See the Disclaimer at the end of the introduction for further details.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
FAESTVOLE-in-the-HeadMaskingSide-Channel Analysis
Contact author(s)
dfaranha @ cs au dk
johantdegn @ gmail com
eilath @ cs au dk
keni @ cs au dk
peter scholl @ cs au dk
History
2026-06-29: last of 3 revisions
2025-07-08: received
See all versions
Short URL
https://ia.cr/2025/1261
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1261,
      author = {Diego F. Aranha and Johan Degn and Jonathan Eilath and Kent Nielsen and Peter Scholl},
      title = {{FAEST} for Memory-Constrained Devices},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1261},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1261}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.