{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:30:16Z","timestamp":1781533816453,"version":"3.54.5"},"reference-count":31,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2024,9,12]],"date-time":"2024-09-12T00:00:00Z","timestamp":1726099200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100018833","name":"Agence de l'innovation de d\u00e9fense","doi-asserted-by":"publisher","award":["2022156"],"award-info":[{"award-number":["2022156"]}],"id":[{"id":"10.13039\/501100018833","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018833","name":"Agence de l'innovation de d\u00e9fense","doi-asserted-by":"publisher","award":["2023151"],"award-info":[{"award-number":["2023151"]}],"id":[{"id":"10.13039\/501100018833","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,12,3]]},"abstract":"<jats:p>FALCON is a signature selected for standardisation of the new Post-Quantum Cryptography (PQC) primitives by the National Institute of Standards and Technology (NIST). However, it remains a challenge to define efficient countermeasures against side-channel attacks (SCA) for this algorithm. FALCON is a lattice-based signature that relies on rational numbers, which is unusual in the cryptography field. Although recent work proposed a solution to mask the addition and the multiplication, some roadblocks remain, most noticeably, how to protect the floor function. In this work, we propose to complete the first existing tests of hardening FALCON against SCA. We perform the mathematical proofs of our methods as well as formal security proofs in the probing model by ensuring Multiple Input Multiple Output Strong Non-Interference (MIMO-SNI) security. We provide performances on a laptop computer of our gadgets as well as of a complete masked FALCON. We notice significant overhead in doing so and discuss the deployability of our method in a real-world context.<\/jats:p>","DOI":"10.62056\/ay73zl7s","type":"journal-article","created":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T12:00:52Z","timestamp":1736769652000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":2,"title":["Masked Computation of the Floor Function and Its Application to the FALCON Signature"],"prefix":"10.62056","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-5065-2730","authenticated-orcid":false,"given":"Pierre-Augustin","family":"Berthet","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/057er4c39","id-type":"ROR","asserted-by":"publisher"}],"name":"Institut Polytechnique de Paris","place":["Palaiseau, France"],"department":["T\u00e9l\u00e9com Paris, LTCI"]},{"name":"Hensoldt France SAS","place":["Plaisir, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6056-7766","authenticated-orcid":false,"given":"Justine","family":"Paillet","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean-Monnet Saint-\u00c9tienne","place":["Saint-\u00c9tienne, F-42023, France"],"department":["CNRS, Institut d'Optique Graduate School, Laboratoire Hubert Curien UMR 5516"]},{"name":"Hensoldt France SAS","place":["Plaisir, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5224-492X","authenticated-orcid":false,"given":"C\u00e9dric","family":"Tavernier","sequence":"additional","affiliation":[{"name":"Hensoldt France SAS","place":["Plaisir, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7964-3137","authenticated-orcid":false,"given":"Lilian","family":"Bossuet","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean-Monnet Saint-\u00c9tienne","place":["Saint-\u00c9tienne, F-42023, France"],"department":["CNRS, Institut d'Optique Graduate School, Laboratoire Hubert Curien UMR 5516"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6028-3028","authenticated-orcid":false,"given":"Brice","family":"Colombier","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean-Monnet Saint-\u00c9tienne","place":["Saint-\u00c9tienne, F-42023, France"],"department":["CNRS, Institut d'Optique Graduate School, Laboratoire Hubert Curien UMR 5516"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref1:doi:10.1137\/S0036144598347011","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1137\/S0036144598347011","article-title":"Polynomial-Time Algorithms for Prime Factorization and\n  Discrete Logarithms on a Quantum Computer","volume":"41","author":"Peter W. Shor","year":"1999","journal-title":"SIAM Review"},{"key":"ref2:chen2016report","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.8105","volume-title":"Report on post-quantum cryptography","volume":"12","author":"Lily Chen","year":"2016"},{"key":"ref3:8406610","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1109\/EuroSP.2018.00032","article-title":"CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM","author":"Joppe Bos","year":"2018"},{"key":"ref4:nistfips203mlkem","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.203.ipd","article-title":"Module-Lattice-Based Key-Encapsulation Mechanism Standard","author":"NIST","year":"2024","journal-title":"NIST FIPS"},{"key":"ref5:Ducas_Kiltz_Lepoint_Lyubashevsky_Schwabe_Seiler_Stehl\u00e9_2018","doi-asserted-by":"publisher","first-page":"238","DOI":"10.13154\/tches.v2018.i1.238-268","article-title":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature\n  Scheme","volume":"2018","author":"L\u00e9o Ducas","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref6:nistfips204mldsa","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.204.ipd","article-title":"Module-Lattice-Based Digital Signature Standard","author":"NIST","year":"2024","journal-title":"NIST FIPS"},{"key":"ref7:10.1145\/3319535.3363229","series-title":"CCS '19","isbn-type":"print","doi-asserted-by":"publisher","first-page":"2129","DOI":"10.1145\/3319535.3363229","article-title":"The SPHINCS+ Signature Framework","author":"Daniel J. Bernstein","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450367479"},{"key":"ref8:nistfips205shdsa","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.205.ipd","article-title":"Stateless Hash-Based Digital Signature Standard","author":"NIST","year":"2024","journal-title":"NIST FIPS"},{"key":"ref9:prest2020falcon","volume-title":"FALCON","author":"Thomas Prest","year":"2020"},{"key":"ref10:10.1007\/3-540-68697-5_9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","volume":"1109","author":"Paul C. Kocher","year":"1996"},{"key":"ref11:10.1145\/3603170","doi-asserted-by":"publisher","DOI":"10.1145\/3603170","article-title":"Side-channel and Fault-injection attacks over Lattice-based\n  Post-quantum Schemes (Kyber, Dilithium): Survey and New Results","volume":"23","author":"Prasanna Ravi","year":"2024","journal-title":"ACM Trans. Embed. Comput. Syst.","ISSN":"https:\/\/id.crossref.org\/issn\/1539-9087","issn-type":"electronic"},{"key":"ref12:9586131","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1109\/DAC18074.2021.9586131","article-title":"FALCON Down: Breaking FALCON Post-Quantum Signature Scheme\n  through Side-Channel Attacks","author":"Emre Karabulut","year":"2021","ISSN":"https:\/\/id.crossref.org\/issn\/0738-100X","issn-type":"electronic"},{"key":"ref13:Guerreau_Martinelli_Ricosset_Rossi_2022","doi-asserted-by":"publisher","first-page":"141","DOI":"10.46586\/tches.v2022.i3.141-164","article-title":"The Hidden Parallelepiped Is Back Again: Power Analysis\n  Attacks on Falcon","volume":"2022","author":"Morgane Guerreau","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref14:Chen_Chen_2024","doi-asserted-by":"publisher","first-page":"276","DOI":"10.46586\/tches.v2024.i2.276-303","article-title":"Masking Floating-Point Number Multiplication and Addition of\n  Falcon: First- and Higher-order Implementations and Evaluations","volume":"2024","author":"Keng-Yu Chen","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref15:karabulut2024masking","doi-asserted-by":"publisher","first-page":"483","DOI":"10.46586\/tches.v2024.i4.483-508","article-title":"Masking FALCON\u2019s Floating-Point Multiplication in\n  Hardware","volume":"2024","author":"Emre Karabulut","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref16:10.1007\/978-3-662-53140-2_16","isbn-type":"print","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/978-3-662-53140-2_16","volume-title":"Cryptographic Hardware and Embedded Systems \u2013 CHES 2016","author":"Leon Groot Bruinderink","year":"2016","ISBN":"https:\/\/id.crossref.org\/isbn\/9783662531402","ISSN":"https:\/\/id.crossref.org\/issn\/1611-3349","issn-type":"electronic"},{"key":"ref17:10.1145\/3133956.3134028","series-title":"CCS '17","isbn-type":"print","doi-asserted-by":"publisher","first-page":"1857","DOI":"10.1145\/3133956.3134028","article-title":"Side-Channel Attacks on BLISS Lattice-Based Signatures:\n  Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations\n  in Microcontrollers","author":"Thomas Espitau","year":"2017","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450349468"},{"key":"ref18:cryptoeprint:2019\/478","doi-asserted-by":"publisher","first-page":"61","DOI":"10.5220\/0007834800610071","article-title":"BEARZ Attack FALCON: Implementation Attacks with\n  Countermeasures on the FALCON Signature Scheme","author":"Sarah McCarthy","year":"2019"},{"key":"ref19:10.1145\/3133956.3134023","series-title":"CCS '17","isbn-type":"print","doi-asserted-by":"publisher","first-page":"1843","DOI":"10.1145\/3133956.3134023","article-title":"To BLISS-B or not to be: Attacking strongSwan's\n  Implementation of Post-Quantum Signatures","author":"Peter Pessl","year":"2017","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450349468"},{"key":"ref20:10.1007\/978-3-030-44223-1_4","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/978-3-030-44223-1_4","article-title":"Isochronous Gaussian Sampling: From Inception to\n  Implementation","author":"James Howe","year":"2020"},{"key":"ref21:10.1007\/978-3-031-30634-1_19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/978-3-031-30634-1_19","article-title":"Improved Power Analysis Attacks on Falcon","volume":"14007","author":"Shiduo Zhang","year":"2023"},{"key":"ref22:10.1007\/978-3-031-07082-2_9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/978-3-031-07082-2_9","article-title":"Mitaka: A Simpler, Parallelizable, Maskable Variant of\n  Falcon","volume":"13277","author":"Thomas Espitau","year":"2022"},{"key":"ref23:barthe2016strong","series-title":"CCS '16","isbn-type":"print","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1145\/2976749.2978427","article-title":"Strong Non-Interference and Type-Directed Higher-Order\n  Masking","author":"Gilles Barthe","year":"2016","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450341394"},{"key":"ref24:cassiers2020trivially","doi-asserted-by":"publisher","first-page":"2542","DOI":"10.1109\/tifs.2020.2971153","article-title":"Trivially and Efficiently Composing Masked Gadgets With\n  Probe Isolating Non-Interference","volume":"15","author":"Gaetan Cassiers","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security","ISSN":"https:\/\/id.crossref.org\/issn\/1556-6021","issn-type":"electronic"},{"key":"ref25:kahan1996ieee","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/IEEESTD.2019.8766229","article-title":"IEEE Standard for Floating-Point Arithmetic","author":"IEEE","year":"2019","journal-title":"IEEE Std 754-2019 (Revision of IEEE 754-2008)"},{"key":"ref26:mangard2008power","volume-title":"Power analysis attacks: Revealing the secrets of smart\n  cards","volume":"31","author":"Stefan Mangard","year":"2008"},{"key":"ref27:ishai2003private","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref28:barthe2018masking","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1007\/978-3-319-78375-8_12","article-title":"Masking the GLP Lattice-Based Signature Scheme at Any\n  Order","volume":"10821","author":"Gilles Barthe","year":"2018"},{"key":"ref29:coron2015conversion","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/978-3-662-48116-5_7","article-title":"Conversion from Arithmetic to Boolean Masking with\n  Logarithmic Complexity","volume":"9054","author":"Jean-S\u00e9bastien Coron","year":"2015"},{"key":"ref30:schneider2019efficiently","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"534","DOI":"10.1007\/978-3-030-17259-6_18","article-title":"Efficiently Masking Binomial Sampling at Arbitrary Orders\n  for Lattice-Based Crypto","volume":"11443","author":"Tobias Schneider","year":"2019"},{"key":"ref31:bettale2018improved","doi-asserted-by":"publisher","first-page":"22","DOI":"10.13154\/tches.v2018.i2.22-45","article-title":"Improved High-Order Conversion From Boolean to Arithmetic\n  Masking","volume":"2018","author":"Luk Bettale","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T12:11:07Z","timestamp":1736770267000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/4\/9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,13]]},"references-count":31,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,1,13]]}},"URL":"https:\/\/doi.org\/10.62056\/ay73zl7s","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,13]]},"assertion":[{"value":"2024-09-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-6"}}