Transactions on Cryptographic Hardware and Embedded Systems 2026
Secret Key Recovery of FALCON using Simple Power Analysis in Conditional Calculator
GyuSang Kim
Korea University, Seoul, South Korea
JeongHwan Lee
Korea University, Seoul, South Korea
Myeonghoon Lee
Korea University, Seoul, South Korea
Seokhie Hong
Korea University, Seoul, South Korea
HeeSeok Kim
Korea University, Sejong, South Korea
Keywords: FALCON, Simple Power Analysis, Key Recovery, Conditional calculator
Abstract
Among the NIST-standardized algorithms, FALCON is a lattice-based digital signature scheme that offers strong security and compactness. However, FALCON’s reliance on floating-point arithmetic makes it vulnerable to side-channel attacks. In particular, certain operations in FALCON, such as floating-point conversion and floating-point addition within the FFT transform, may result in data-dependent power consumption patterns. These patterns can be exploited by Simple Power Analysis to extract secret key information, even from a single trace.We present a Simple Power Analysis against the FALCON digital signature scheme, focusing on the Conditional calculator involved in floating-point conversion and floating-point addition. We also analyze the effectiveness of two countermeasures for the Conditional calculator. We propose a post-processing procedure that computes all possible candidates and applies a pruning strategy to eliminate impossible ones. The secret key can be recovered within 0.12 seconds for secret keys generated from a discrete Gaussian distribution and 21.02 seconds for those generated from a uniform distribution. We further propose an advanced post-processing procedure that ranks candidate keys based on their consistency with observed side-channel information, enabling full secret key recovery even when partial information is incorrect. The proposed attack is evaluated with up to 5,000 intentionally corrupted side-channel information entries (≈ 9.3% of the leakage bits); within this range, the correct key was consistently recovered with a 100% success rate. Additionally, we successfully recovered the correct secret key across 1,000 distinct FALCON secret keys.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 2
PaperArtifact
Artifact number
tches/2026/a31
Artifact published
June 02, 2026
Badge
✅ IACR CHES Artifacts Functional
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
GyuSang Kim, JeongHwan Lee, Myeonghoon Lee, Seokhie Hong, HeeSeok Kim. (2026). Secret Key Recovery of FALCON using Simple Power Analysis in Conditional Calculator. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(2), 953–975. https://doi.org/10.46586/tches.v2026.i2.953-975. Artifact at https://artifacts.iacr.org/tches/2026/a31.