International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Secret Key Recovery of FALCON using Simple Power Analysis in Conditional Calculator


GyuSang Kim
Korea University, Seoul, South Korea

JeongHwan Lee
Korea University, Seoul, South Korea

Myeonghoon Lee
Korea University, Seoul, South Korea

Seokhie Hong
Korea University, Seoul, South Korea

HeeSeok Kim
Korea University, Sejong, South Korea


Keywords: FALCON, Simple Power Analysis, Key Recovery, Conditional calculator


Abstract

Among the NIST-standardized algorithms, FALCON is a lattice-based digital signature scheme that offers strong security and compactness. However, FALCON’s reliance on floating-point arithmetic makes it vulnerable to side-channel attacks. In particular, certain operations in FALCON, such as floating-point conversion and floating-point addition within the FFT transform, may result in data-dependent power consumption patterns. These patterns can be exploited by Simple Power Analysis to extract secret key information, even from a single trace.We present a Simple Power Analysis against the FALCON digital signature scheme, focusing on the Conditional calculator involved in floating-point conversion and floating-point addition. We also analyze the effectiveness of two countermeasures for the Conditional calculator. We propose a post-processing procedure that computes all possible candidates and applies a pruning strategy to eliminate impossible ones. The secret key can be recovered within 0.12 seconds for secret keys generated from a discrete Gaussian distribution and 21.02 seconds for those generated from a uniform distribution. We further propose an advanced post-processing procedure that ranks candidate keys based on their consistency with observed side-channel information, enabling full secret key recovery even when partial information is incorrect. The proposed attack is evaluated with up to 5,000 intentionally corrupted side-channel information entries (≈ 9.3% of the leakage bits); within this range, the correct key was consistently recovered with a 100% success rate. Additionally, we successfully recovered the correct secret key across 1,000 distinct FALCON secret keys.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 2

Paper

Artifact

Artifact number
tches/2026/a31

Artifact published
June 02, 2026

Badge
IACR CHES Artifacts Functional

README

ZIP (625259 Bytes)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

GyuSang Kim, JeongHwan Lee, Myeonghoon Lee, Seokhie Hong, HeeSeok Kim. (2026). Secret Key Recovery of FALCON using Simple Power Analysis in Conditional Calculator. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(2), 953–975. https://doi.org/10.46586/tches.v2026.i2.953-975. Artifact at https://artifacts.iacr.org/tches/2026/a31.