Paper 2025/1261
FAEST for Memory-Constrained Devices
Abstract
We introduce a new compact and constant-time implementation of the FAEST v1.1 signature scheme that allows it to run in resource-constrained Arm Cortex-M4 microcontrollers under 190M cycles for signing or verifying at level 1 security. The main technique for reducing the memory footprint is a new abstraction to reuse or recompute VOLEs on demand, which reduces memory consumption by at least an order of magnitude.
Note: This revised version includes only the low-memory optimizations and retracts the masked implementation, after an attack was found by a reviewer. See the Disclaimer at the end of the introduction for further details.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- FAESTVOLE-in-the-HeadMaskingSide-Channel Analysis
- Contact author(s)
-
dfaranha @ cs au dk
johantdegn @ gmail com
eilath @ cs au dk
keni @ cs au dk
peter scholl @ cs au dk - History
- 2026-06-29: last of 3 revisions
- 2025-07-08: received
- See all versions
- Short URL
- https://ia.cr/2025/1261
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1261,
author = {Diego F. Aranha and Johan Degn and Jonathan Eilath and Kent Nielsen and Peter Scholl},
title = {{FAEST} for Memory-Constrained Devices},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1261},
year = {2025},
url = {https://eprint.iacr.org/2025/1261}
}