Paper 2026/2313
When Masking Preimage Computation Isn’t Enough: A Power Analysis Attack on Masked Implementations of Falcon
Abstract
In this paper, we present a novel power analysis attack targeting a Falcon implementation protected by a masked preimage computation. By analyzing the ratio between the real and imaginary parts of the public hash polynomial, we demonstrate that the leakage during the share recombination phase can be exploited to recover the secret key. We propose two attack variants: a chosen-message attack, where the adversary controls input messages to force extreme coefficient ratios, and a non-chosen-message attack that filters for naturally occurring vulnerable hashes. Through experimental evaluations using the ELMO leakage simulator for an ARM Cortex-M0 architecture, our experiments achieve a 98.3% success rate with 4,000 traces. Finally, while a fully masked implementation of Falcon prevents our attack, we propose a practical countermeasure based on rejection sampling to avoid the prohibitive computational overhead of a fully masked Gaussian sampler.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- FalconSide-Channel AnalysisPost-Quantum CryptographyFloating-Point ArithmeticMasking
- Contact author(s)
- keng-yu chen @ epfl ch
- History
- 2026-10-04: approved
- 2026-10-02: received
- See all versions
- Short URL
- https://ia.cr/2026/2313
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2313,
author = {Keng-Yu Chen},
title = {When Masking Preimage Computation Isn’t Enough: A Power Analysis Attack on Masked Implementations of Falcon},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2313},
year = {2026},
url = {https://eprint.iacr.org/2026/2313}
}