SHIFT SNARE: uncovering secret keys in FALCON via single-trace analysis

Jinyi Qiu, Aydın Aysu · Journal of Cryptographic Engineering · 2026

Abstract This paper presents a ground-up approach to attack a novel single-trace side-channel vulnerability in FALCON, a lattice-based post-quantum digital signature protocol recently approved for standardization by NIST. We target the discrete Gaussian sampling operation within FALCON’s key generation scheme. Notably, negating the results of a 63-bit right-shift operation on 64-bit secret values leaks critical information about the assignment of ‘-1’ versus ‘0’ to intermediate coefficients during sampling. These information makes it feasible to extract the full secret key. We demonstrate a ground-up approach to the attack on an ARM Cortex-M4 microcontroller executing both the reference and optimized source code implementations from FALCON’s NIST round 3 software package. Although single-trace attacks generally require a profiling phase involving a substantial number of traces, our experimental results demonstrate that reliable power profiles can be constructed using as few as 10 profiling traces. We further quantify the attacker’s success rate using a univariate Gaussian template model, providing generalizable guarantees. Statistical analysis reveals a projected per-coefficient success rate of 99.9999999478% and a projected full-key recovery rate of 99.99994654% for FALCON-512. We verify that this vulnerability is present in all implementations included in FALCON’s NIST submission package compiled using the optimization flag. This highlights the vulnerability of current software implementations to single-trace attacks and underscores the urgent need for single-trace-resilient software in embedded systems.

Read the paper · More papers on PaperTik