This release is a pre-release and may not be stable for production use.
pqhybridsign (Python)
Python bindings for pqhybridsign, a suite of six hybrid classical /
post-quantum signature schemes (H1 through H6), built on
pyo3 over the workspace's type-erased pqhybridsign-abi
crate.
H1 through H4 are stateless: sign and verify with bytes in, bytes out.
H5 and H6 pair a classical scheme with SHRINCS, a stateful hash-based
scheme whose post-quantum half spends a one-time leaf per signature.
Their secret key is StatefulSecretKey, not bytes: reusing a leaf is a
total loss of the key's post-quantum security, so StatefulSecretKey
refuses to be copied, deep-copied or pickled.
keygen_stateful_from_seed and load_stateful_secret_key both bind a
journal to the StatefulSecretKey they return, for that key's whole
lifetime; sign_stateful always spends leaves through that bound journal
and takes no journal argument of its own. Loading the same exported key
twice must reuse the same journal object, or the same durable store behind
it, every time: two independent journals that have never seen the key both
correctly report leaf 0 as next, and nothing in this crate can tell that
apart from a legitimate restart. What binding a journal at construction
does catch, the moment the key is asked to sign, is every case where a
single journal was meant to be shared and was not kept in step: a stale
blob loaded against an already-advanced journal, an advanced blob loaded
against a journal that missed a commit, or two key objects sharing one
journal instance where the second tries to sign after the first already
has. Each of those raises CountersDivergedError.
keygen_from_seed returns the secret key as a Python bytes object.
A bytes object is immutable. This binding cannot zeroize it once the
caller holds it. The binding zeroizes every Rust copy it makes before
that copy drops. That covers only the memory this crate controls.
Callers that need the binding to zeroize the secret key on drop must use
StatefulSecretKey or the C ABI.
import pqhybridsign as phs
sk, pk = phs.keygen_from_seed(phs.Suite.H1, seed)
sig = phs.sign(phs.Suite.H1, sk, b"message", b"context")
assert phs.verify(phs.Suite.H1, pk, b"message", b"context", sig)
Every wheel this crate ships is built against exactly one SHRINCS profile;
compare pqhybridsign.profile_name() between the two sides of an
integration before trusting anything on the wire.
Building
maturin develop
Testing
maturin develop
pytest
Metadata
Release files for pqhybridsign 0.0.0rc2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pqhybridsign-0.0.0rc2.tar.gz | 593.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pqhybridsign-0.0.0rc2-cp39-abi3-manylinux_2_34_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.34+ x86-64 | Details |
Total release size: 1.3 MB
Release files / pqhybridsign-0.0.0rc2.tar.gz
| Download URL | pqhybridsign-0.0.0rc2.tar.gz |
|---|---|
| Size | 593.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6149bda0b0d1fd2f963622e73246753a0fdc3c6de0ccfb792ec1bad2e09b90e7
|
|
BLAKE2b-256 checksum How to use checksums |
95023011d04e600783f10a71ada3195c045253a06b0d680224fa5c5234e8f17c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.11.16
|
Release files / pqhybridsign-0.0.0rc2-cp39-abi3-manylinux_2_34_x86_64.whl
| Download URL | pqhybridsign-0.0.0rc2-cp39-abi3-manylinux_2_34_x86_64.whl |
|---|---|
| Size | 751.7 kB |
| Tags | CPython 3.9 Linux glibc 2.34+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
cf5702b6922d3406cff0437ace7c2b0059b6fc75defafe5d6f92ff6fa37c1ec7
|
|
BLAKE2b-256 checksum How to use checksums |
af0543138bcd55984edf207c5a1beb437e05a79e2c16e5e1bb3cdcdba171a673
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.11.16
|