Paper 2026/2313

When Masking Preimage Computation Isn’t Enough: A Power Analysis Attack on Masked Implementations of Falcon

Keng-Yu Chen, École Polytechnique Fédérale de Lausanne
Abstract

In this paper, we present a novel power analysis attack targeting a Falcon implementation protected by a masked preimage computation. By analyzing the ratio between the real and imaginary parts of the public hash polynomial, we demonstrate that the leakage during the share recombination phase can be exploited to recover the secret key. We propose two attack variants: a chosen-message attack, where the adversary controls input messages to force extreme coefficient ratios, and a non-chosen-message attack that filters for naturally occurring vulnerable hashes. Through experimental evaluations using the ELMO leakage simulator for an ARM Cortex-M0 architecture, our experiments achieve a 98.3% success rate with 4,000 traces. Finally, while a fully masked implementation of Falcon prevents our attack, we propose a practical countermeasure based on rejection sampling to avoid the prohibitive computational overhead of a fully masked Gaussian sampler.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
FalconSide-Channel AnalysisPost-Quantum CryptographyFloating-Point ArithmeticMasking
Contact author(s)
keng-yu chen @ epfl ch
History
2026-10-04: approved
2026-10-02: received
See all versions
Short URL
https://ia.cr/2026/2313
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2313,
      author = {Keng-Yu Chen},
      title = {When Masking Preimage Computation Isn’t Enough: A Power Analysis Attack on Masked Implementations of Falcon},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2313},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2313}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.