hybrid_sig AvailableComposite ML-DSA + classical signatures; both must verify.
The Hybrid Signature Engine produces and checks composite signatures binding a PQC and a classical signature under a domain-separated message representative. Composite verify requires both PQC verify AND classical verify to pass. If either component rejects, the composite signature is invalid.
This approach ensures that deployments remain secure during the post-quantum migration period. Even if one algorithm is eventually broken, the other provides a fallback, making the composite scheme safe as long as at least one component holds.
Available Verified combiner. Foundry-portable soft IP, ready for integration.
Firm/hard IP (hardened netlist for a target node) available on foundry enablement.
Learn more about the Hybrid Signature Engine, integration options, and licensing.