Paper 2026/2347
HyBind: Structural Analysis of PQ/T Hybrid Cryptographic Usage
Abstract
The quantum threat to traditional public-key cryptography makes migration to post-quantum cryptography necessary. During migration, the presence of both post-quantum and traditional (PQ/T) algorithms does not establish that their outputs jointly determine a key or verification decision. We propose HyBind, an intraprocedural Python source-analysis framework using registered API contracts. HyBind traces component secrets to returned keys and checks whether signature acceptance requires both verifiers to succeed. Function-return and execution-effect checks account for alternative outcomes and changes to local bindings. Two internal presence-based heuristics give identical decisions for joint versus omitted secret contribution and AND versus OR verification, while HyBind distinguishes these structures. All 50 controlled fixtures match their specified outputs with the annotation assumption enabled. A separate suite of 33 programs, including 15 using native cryptographic APIs, matches its specified positive-finding counts in both settings. Native runtime checks exercise ML-KEM/X25519 key derivation and ML-DSA/Ed25519 acceptance. Relaxing return or effect requirements admits traditional-only key results as hybrid findings in the evaluated cases. HyBind provides the contributing calls and outcome evidence needed to review whether an individual traditional invocation participates in a PQ/T hybrid.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- Post-quantum cryptographyPQ/T hybrid cryptographyStatic analysisCryptographic migrationPython
- Contact author(s)
-
ajb11191128 @ gmail com
msq000212 @ gmail com
ky060261 @ gmail com
chosubin1208 @ gmail com
hwajeong84 @ gmail com - History
- 2026-10-07: approved
- 2026-10-05: received
- See all versions
- Short URL
- https://ia.cr/2026/2347
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/2347,
author = {Jongbeom Ahn and Minseo Kim and Moonsun Heo and Subeen Cho and Hwajeong Seo},
title = {{HyBind}: Structural Analysis of {PQ}/T Hybrid Cryptographic Usage},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2347},
year = {2026},
url = {https://eprint.iacr.org/2026/2347}
}