Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

pqhybridsign (Python)

Python bindings for pqhybridsign, a suite of six hybrid classical / post-quantum signature schemes (ED-ML-44, ED-FN-512, SR-ML-44, SR-FN-512, ED-SH, SR-SH), built on pyo3 over the workspace's type-erased pqhybridsign-abi crate.

ED-ML-44 through SR-FN-512 are stateless: sign and verify with bytes in, bytes out.

ED-SH and SR-SH pair a classical scheme with SHRINCS, a stateful hash-based scheme whose post-quantum half spends a one-time leaf per signature. Their secret key is StatefulSecretKey, not bytes: reusing a leaf is a total loss of the key's post-quantum security, so StatefulSecretKey refuses to be copied, deep-copied or pickled.

keygen_stateful_from_seed and load_stateful_secret_key both bind a journal to the StatefulSecretKey they return, for that key's whole lifetime; sign_stateful always spends leaves through that bound journal and takes no journal argument of its own. Loading the same exported key twice must reuse the same journal object, or the same durable store behind it, every time: two independent journals that have never seen the key both correctly report leaf 0 as next, and nothing in this crate can tell that apart from a legitimate restart. What binding a journal at construction does catch, the moment the key is asked to sign, is every case where a single journal was meant to be shared and was not kept in step: a stale blob loaded against an already-advanced journal, an advanced blob loaded against a journal that missed a commit, or two key objects sharing one journal instance where the second tries to sign after the first already has. Each of those raises CountersDivergedError.

keygen_from_seed returns the secret key as a Python bytes object. A bytes object is immutable. This binding cannot zeroize it once the caller holds it. The binding zeroizes every Rust copy it makes before that copy drops. That covers only the memory this crate controls. Callers that need the binding to zeroize the secret key on drop must use StatefulSecretKey or the C ABI.

import pqhybridsign as phs

sk, pk = phs.keygen_from_seed(phs.Suite.ED_ML_44, seed)
sig = phs.sign(phs.Suite.ED_ML_44, sk, b"message", b"context")
assert phs.verify(phs.Suite.ED_ML_44, pk, b"message", b"context", sig)

Every wheel this crate ships is built against exactly one SHRINCS profile; compare pqhybridsign.profile_name() between the two sides of an integration before trusting anything on the wire.

Building

maturin develop

Testing

maturin develop
pytest

Metadata

Release files for pqhybridsign 0.0.0rc9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pqhybridsign 0.0.0rc9
File Size Uploaded
pqhybridsign-0.0.0rc9.tar.gz 677.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pqhybridsign 0.0.0rc9
File Interpreter ABI Platform
pqhybridsign-0.0.0rc9-cp39-abi3-manylinux_2_34_x86_64.whl CPython 3.9 abi3 Linux glibc 2.34+ x86-64 Details

Total release size: 1.5 MB

Release files / pqhybridsign-0.0.0rc9.tar.gz

Download URL pqhybridsign-0.0.0rc9.tar.gz
Size 677.3 kB
Tags Source
SHA-256 checksum
How to use checksums
b80b77a7fe3b375a3a934f387aca01fec230256a4bf1ca36c75e63104c6811e4
BLAKE2b-256 checksum
How to use checksums
827d2ae23c9258783ef925524078bb0bcbc372d47f90e5579a2702ce3ab1b543
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / pqhybridsign-0.0.0rc9-cp39-abi3-manylinux_2_34_x86_64.whl

Download URL pqhybridsign-0.0.0rc9-cp39-abi3-manylinux_2_34_x86_64.whl
Size 845.4 kB
Tags CPython 3.9 Linux glibc 2.34+ x86-64 abi3
SHA-256 checksum
How to use checksums
cc208292eeb105b1e14670c68cdc16f86f5c465b6e8f2953bcd6a76ea4d4839d
BLAKE2b-256 checksum
How to use checksums
264d5baa338e94f8de0e8027f05fb88665bb909b3e7aec2fd5c70cdacdf976f3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.11.16
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page