Paper 2026/2345

Randomness-Anchored Runtime Discovery of Cryptographic Operations on Linux Using eBPF

Sumin Jeong, Hansung University
Yulim Hyoung, Hansung University
Hagyeong Kim, Hansung University
Huiju Kang, Hansung University
Hwajeong Seo, Hansung University
Abstract

Migration to post-quantum cryptography requires knowing not only which cryptographic libraries are present on a system, but which algorithms are actually executed at runtime. Static binary analysis answers the former question; the latter requires dynamic observation. We present a runtime cryptographic discovery system for Linux, built on eBPF user-space probes, that detects classical and post-quantum operations as they execute. Because key generation and encapsulation consume fresh randomness, the system treats randomness observations as temporal anchors and correlates them with the cryptographic calls that follow in the same process, producing a stream of confidence-scored events for a runtime cryptographic inventory. An ablation over three detection configurations shows that randomness alone is not a sound detector, while API detection reaches perfect precision and recall on classical and ML-KEM workloads with no false positives on random-only negatives, and the randomness anchor raises the confidence of those detections without adding any. A single probe set also covers native post-quantum support in current OpenSSL releases. Median detection latency is 28 μs (P99 48 μs), largely insensitive to a four-round tuning sweep, with overhead of 14–18% on a key-generation-bound workload, full detection under sustained and concurrent load, and stable behavior over a one-hour run. A case study across nine application cases drawn from or paired with the QED datasets shows where static and runtime views agree and how probe coverage determines what runtime discovery can observe.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
Post-quantum cryptographyeBPFRuntime detectionRandomnessCryptographic bill of materialsDynamic analysis
Contact author(s)
jeong9sumin @ gmail com
yulim4hyoung @ gmail com
kimhaha4420 @ gmail com
huiju9190 @ gmail com
hwajeong84 @ gmail com
History
2026-10-07: approved
2026-10-05: received
See all versions
Short URL
https://ia.cr/2026/2345
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/2345,
      author = {Sumin Jeong and Yulim Hyoung and Hagyeong Kim and Huiju Kang and Hwajeong Seo},
      title = {Randomness-Anchored Runtime Discovery of Cryptographic Operations on Linux Using {eBPF}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2345},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2345}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.