  • Algorithm type: signature
  • Main cryptographic assumption: hardness of NTRU lattice problems
  • Scheme authors: Thomas Prest, Pierre-Alain Fouque, Jeffrey Hoffstein, Paul Kirchner, Vadim Lyubashevsky, Thomas Pornin, Thomas Ricosset, Gregor Seiler, William Whyte, Zhenfei Zhang
  • Authors’ website:
  • Version: 20201018


  • Source of implementation: supercop-20201018 via
  • Implementation version:, master, 19b438ba5c7c3a6f2194cd8bda14821dc33c64a3
  • License: CC0 1.0 Universal
  • Constant-time: Yes
  • Optimizations: Portable C with AVX2 instructions (if available at run-time)

Parameter sets

Parameter set Security model Claimed NIST security level Public key size (bytes) Secret key size (bytes) Signature size (bytes)
Falcon-512 EUF-CMA 1 897 1281 690
Falcon-1024 EUF-CMA 5 1793 2305 1330

