Paper 2026/2046

Square Root of All Evil: The Dangers of Falcon's Superfluous Square Roots

Hiroto Kaihara, Kyoto University
Calvin Abou Haidar, NTT (Japan)
Mehdi Tibouchi, NTT (Japan)
Masayuki Abe, NTT (Japan)
Abstract

Falcon is one of the 3 post-quantum signature schemes already selected by NIST for standardization (as FN-DSA). It is very compact and efficient, but also infamously difficult to implement correctly and securely. This is due in particular to its reliance of various floating point operations, the most complex and costly of which are square root computations. In this paper, we first point out that those square root computations are in fact wholly unnecessary: the algorithm can be rewritten without them, resulting in a somewhat simpler implementation that is equally fast or even slightly faster. We then observe that they also present security risks, in particular as a singularly sensitive target for physical attacks. We demonstrate this with a fault attack, supported by concrete experiments against an ARM Cortex-M4 microcontroller target. We show that injecting a single glitch in one square root computation, and then generating around a million signatures with the unperturbed signing algorithm, leads to full key recovery with 100% success rate and, moreover, faulty signatures are not easy to distinguish from validly generated ones. This makes this fault attack the most devastating against Falcon to date, in contrast with earlier attacks requiring hundreds of millions of signature samples, many injected faults, or resulting in signatures that are straightforward to distinguish from regular ones. In addition, we mention potential risks of the square root computations from the standpoint of dependency management and supply chain security.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. ACM CCS 2026
DOI
10.1145/3830454.3846751
Keywords
Falcon Signature SchemePost-Quantum CryptographyImplementation SecurityFault AnalysisSoftware Supply Chain
Contact author(s)
kaihara hiroto v85 @ kyoto-u jp
calvin haidar @ ntt com
mehdi tibouchi @ ntt com
msyk abe @ ntt com
History
2026-09-17: approved
2026-09-15: received
See all versions
Short URL
https://ia.cr/2026/2046
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2046,
      author = {Hiroto Kaihara and Calvin Abou Haidar and Mehdi Tibouchi and Masayuki Abe},
      title = {Square Root of All Evil: The Dangers of Falcon's Superfluous Square Roots},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2046},
      year = {2026},
      doi = {10.1145/3830454.3846751},
      url = {https://eprint.iacr.org/2026/2046}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.