Falcon (FN-DSA): NIST's Compact Post-Quantum Signature
Falcon — standardizing as FN-DSA (FFT-over-NTRU-Lattice-Based Digital Signature Algorithm) — is a lattice-based post-quantum signature scheme NIST selected alongside Dilithium and SPHINCS+ in 2022. Unlike those two, Falcon is being finalized separately as FIPS 206, with the draft standard and full publication still in progress. Falcon's defining trait is signature size: at a comparable security level, its signatures run roughly a third the size of Dilithium's, making it the natural pick anywhere bandwidth or storage for signatures is tight — certificates, IoT firmware signing, or protocols with many signature exchanges.
Parameter Sets
| Falcon Variant | Security | pk Size | sk Size | Signature (avg) |
| Falcon-512 | 128-bit (NIST Level 1) | 897 B | 1,281 B | ≈690 B |
| Falcon-1024 | 256-bit (NIST Level 5) | 1,793 B | 2,305 B | ≈1,330 B |
Recommended: Falcon-512 for most applications — it already matches AES-128-equivalent security with the smallest signature footprint of any NIST PQC signature scheme.
Falcon vs. Dilithium vs. SPHINCS+
| Scheme | Basis | Signature Size | Status |
| ML-DSA (Dilithium) | Lattice | Larger | Final (FIPS 204) |
| SLH-DSA (SPHINCS+) | Hash-based | Largest | Final (FIPS 205) |
| FN-DSA (Falcon) | Lattice (NTRU) | Smallest | Draft (FIPS 206) |
Security Analysis
| Attack | Resistance |
| Shor's Algorithm | Secure — no exponential speedup against NTRU lattice problems |
| Grover's Algorithm | Only quadratic speedup — 256-bit key → 128-bit effective security |
| Signing Implementation Risk | Falcon's floating-point signing procedure is more delicate to implement in constant time than Dilithium's — use a vetted library (such as Bouncy Castle) rather than a custom implementation |
Status note: Falcon/FN-DSA is not yet a final FIPS standard. Track its progress on the
PQC Standards Tracker.
References
- NIST CSRC — PQC Standardization Process
- Falcon official specification site
- Open Quantum Safe (OQS)