QuTLS Scan은 외부 TLS 표면에 한정한 신속진단입니다. 고객이 지정한 엔드포인트를 읽기 전용으로 식별하고, 자산별 양자 위험도와 전환 우선순위, 그리고 실제로 전환을 시작할 수 있는 시점을 제시하는 PQC 전환 진단 플랫폼입니다. 오픈소스 스캐너가 값을 출력한다면, QuTLS Scan은 그 값이 무엇을 뜻하고 무엇부터 해야 하는지를 답합니다.
QuTLS Scan is a rapid assessment scoped to the external TLS surface. It identifies client-designated endpoints read-only, then reports per-asset quantum risk, migration priority, and the point at which migration can actually begin. Open-source scanners print values. QuTLS Scan answers what those values mean and what to do first.
제공 형태 · 고객이 지정한 외부 TLS 엔드포인트 최대 20개를 대상으로 진단하고, 한국어 · 영어 보고서와 90일 실행계획, 결과 브리핑을 제공합니다. 자산 수가 5개 이하이거나 20개를 넘는 경우 별도로 협의합니다.
What you get · We assess up to 20 external TLS endpoints you designate, and deliver Korean and English reports, a 90-day execution plan and a results briefing. Engagements of five or fewer, or more than twenty, are scoped separately.
TLS 1.3에서 서버 인증에 쓰는 서명 알고리즘과 세션 키를 합의하는 키 설정은 독립적으로 협상됩니다. ECDSA P-256 인증서를 그대로 쓰면서 X25519MLKEM768로 키를 설정할 수 있고, 반대로 RSA 인증서를 쓴다고 해서 RSA로 키를 교환하는 것도 아닙니다. 두 축을 각각 골라 판정 차이를 확인해 보십시오.
In TLS 1.3 the signature algorithm used for server authentication and the key agreement used to establish the session key are negotiated independently. An ECDSA P-256 certificate can be kept while keys are established with X25519MLKEM768, and an RSA certificate does not imply RSA key exchange. Select each axis to see how the judgements differ.
대체 알고리즘은 후보이며 1:1 교체 관계가 아닙니다. 실제 선택은 자산의 수명, 서명 빈도, 핸드셰이크 크기 허용치, 상대 시스템 호환성에 따라 달라집니다.
Replacement algorithms are candidates, not one-to-one substitutions. The actual choice depends on asset lifetime, signing frequency, tolerable handshake size and peer compatibility.
HNDL(Harvest Now, Decrypt Later)은 공격자가 지금 암호화된 통신을 저장해 두었다가 나중에 소급 해독하는 방식입니다. 저장은 오늘 일어납니다. 그러므로 방어도 오늘이어야 합니다. 내일 암호를 바꿔도 오늘 저장된 트래픽은 보호되지 않습니다.
Under HNDL (harvest now, decrypt later), an adversary stores encrypted traffic today and decrypts it retroactively. Collection happens now, so defence has to happen now. Changing algorithms tomorrow does not protect traffic captured today.
RSA는 소인수분해, ECDSA와 ECDH는 타원곡선 이산로그 문제에 안전성을 의존합니다. Shor 알고리즘은 두 문제를 모두 다항시간에 해결합니다. 개별 알고리즘의 결함이 아니라 공개키 암호 전체가 동시에 영향을 받습니다. 키 길이를 늘려서 해결되지 않습니다.
RSA relies on integer factorisation; ECDSA and ECDH on the elliptic-curve discrete logarithm. Shor's algorithm solves both in polynomial time. This is not a flaw in one algorithm: public-key cryptography is affected as a class, and longer keys do not fix it.
계약 문서처럼 10년 보존 의무가 걸린 데이터는 오늘 수집되면 2036년에도 유효합니다. 반면 공개 웹 콘텐츠는 애초에 기밀성 요구가 없습니다. 같은 알고리즘을 쓰더라도 자산마다 실질 위험이 다르며, 우선순위는 여기서 갈립니다.
Data under a ten-year retention obligation, such as contract records, is still meaningful in 2036 if captured today. Public web content has no confidentiality requirement at all. The same algorithm carries different real exposure per asset, and that is where priority is decided.
NIST IR 8547 초기 공개초안은 양자 취약 공개키 알고리즘에 대해 2030년과 2035년을 주요 전환 기준점으로 제안합니다. 확정된 규제가 아니며 적용 범위와 일정은 변경될 수 있습니다. 국내에서는 2023년 「양자내성암호 마스터플랜」이 2035년 국가 암호체계 전환 목표를 제시했습니다. 미국 EO 14412(2026년 6월)는 더 강한 근거이지만 미 연방의 특정 시스템과 연방 계약자에 적용되는 조치이므로, 국내 일반기업의 법정기한으로 인용하기는 어렵습니다.
The NIST IR 8547 initial public draft proposes 2030 and 2035 as reference points for quantum-vulnerable public-key algorithms. It is not settled regulation, and both scope and dates may change. In Korea, the 2023 PQC Master Plan sets a 2035 national transition target. US Executive Order 14412 (June 2026) is stronger authority but applies to designated US federal systems and federal contractors, so it should not be cited as a statutory deadline for private companies in Korea.
진단의 가치는 데이터 수집이 아니라 해석에 있습니다. 아래는 QuTLS Scan 보고서가 실제로 답하는 질문들입니다.
The value of an assessment lies in interpretation, not collection. These are the questions a QuTLS Scan report actually answers.
| 항목 | Item | 일반 TLS 스캐너 | Generic TLS scanner | QuTLS Scan PQC 전환 진단 | QuTLS Scan PQC assessment |
|---|---|---|---|---|---|
| 알고리즘 식별 | Algorithm identification | 가능 | Yes | 가능 | Yes |
| PQC 표준 매핑 | Mapping to PQC standards | 없음 | No | FIPS 203/204/205 기준 대체 알고리즘 지정 | Replacement algorithm named per FIPS 203/204/205 |
| 자산별 우선순위 | Per-asset prioritisation | 없음. 모든 자산이 동일하게 표시 | None. All assets look identical | Shor · Grover · HNDL 가중 점수로 등급 분화 | Graded by a weighted Shor / Grover / HNDL score |
| 업무 맥락 반영 | Business context | 불가 | Not possible | 데이터 민감도 · 보존 수명을 입력값으로 반영 | Data sensitivity and retention life taken as inputs |
| 실행 창구 제시 | Execution window | 만료일 나열에 그침 | Lists expiry dates only | 갱신 주기를 전환 창구로 해석해 웨이브 계획 수립 | Reads the renewal cycle as a migration window and plans waves |
| 배경 · 용어 설명 | Background and terminology | 없음 | None | HNDL, Shor, ML-KEM/ML-DSA/SLH-DSA 해설 포함 | Includes HNDL, Shor, ML-KEM / ML-DSA / SLH-DSA explanations |
| 검증 가능한 조치 | Verifiable actions | 없음 | None | 단계별 조치와 검증 명령·확인 방법을 함께 기술 | Each step paired with a verification command or method |
| 운영 통제 | Operational controls | 실행자 재량 | At the operator's discretion | 승인 게이트 · 역할 분리 · 감사 로그 · 테넌트 격리 | Approval gates, role separation, audit logs, tenant isolation |
보고서는 한국어와 영어로 각각 PDF와 DOCX로 제공됩니다. 구성은 다음과 같습니다.
Reports are delivered in Korean and English, each as PDF and DOCX. The structure is as follows.
전환 대상 범위, 최우선 자산, 가장 이른 실행 창구, 즉시 조치와 대기 조치의 구분을 1페이지로 정리합니다. 예산 결재 문서에 그대로 인용할 수 있는 형태입니다.
Scope, highest-priority assets, earliest execution window, and the split between act-now and wait items, on one page. Written to be quoted directly into a budget approval.
HNDL이 무엇이고 왜 지금인지, Shor 알고리즘이 ECDSA에 무엇을 하는지, ML-KEM · ML-DSA · SLH-DSA가 각각 어디에 쓰이는지를 설명합니다. 용어만 던지고 검색을 시키지 않습니다.
What HNDL is and why it matters now, what Shor's algorithm does to ECDSA, and where ML-KEM, ML-DSA and SLH-DSA each apply. Terms are explained, not just cited.
자산별 TLS 버전, 암호 스위트, 공개키 알고리즘과 키 길이, 인증서 발급자 · 주체 · 유효기간 · 잔여일수를 표로 제공합니다. 전사 암호자산 대장의 출발점이 됩니다.
Per asset: TLS version, cipher suite, public key algorithm and size, certificate issuer, subject, validity and days remaining. The starting point for an enterprise cryptographic register.
Shor · Grover · HNDL 가중 점수와 우선순위 등급, 그리고 그 점수가 나온 근거(민감도, 데이터 수명)를 자산별로 명시합니다. 계산은 재현 가능하며 입력값을 바꾸면 결과가 바뀝니다.
Weighted Shor / Grover / HNDL scores and priority bands, with the inputs behind each score (sensitivity, data lifetime) stated per asset. The calculation is reproducible and responds to changed inputs.
인증서 만료일을 관리 항목이 아니라 전환 기회로 해석합니다. 같은 날짜에 묶인 자산을 군집화하고, 위험도와 창구를 결합해 웨이브 단위 실행 순서를 만듭니다.
Certificate expiry dates are read as migration opportunities, not administrative fields. Assets are clustered by shared expiry, then risk and window are combined into a wave-based execution order.
“담당자 확인”은 조치가 아닙니다. 각 단계마다 무엇을 바꾸고, 그것이 실제로 적용되었는지 어떤 명령이나 화면으로 확인하는지를 함께 기술합니다.
"Confirm the owner" is not a remediation step. Each step states what changes and which command or screen confirms that the change took effect.
5단계 전환 성숙도 모델에서 조직의 현재 위치를 판정하고, 국가 전환 로드맵 및 NIST 일정 대비 어디에 서 있는지를 제시합니다. 다음 단계 진입 조건도 함께 명시합니다.
Places the organisation on a five-stage transition maturity model and against the national roadmap and NIST timeline, including what is required to reach the next stage.
진단하지 않은 영역을 분명히 적습니다. 외부 TLS 표면은 전체 암호자산의 일부이며, 보고서는 다루지 않은 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.
States plainly what was not assessed. The external TLS surface is a subset of the estate, and the report makes no claim about the security of areas outside it.
QuTLS Scan은 승인 게이트, 역할 기반 권한, 테넌트 격리, 추가 전용 감사 로그를 갖춘 에이전트 오케스트레이션 플랫폼입니다. 진단의 모든 단계가 기록되며 재현 가능합니다.
QuTLS Scan is an agent orchestration platform with approval gates, role-based access, tenant isolation and an append-only audit log. Every stage of an assessment is recorded and reproducible.
동의서 별지에 기재된 host:port 목록만 대상으로 등록됩니다. 목록 외 자산은 어떤 경우에도 접근하지 않습니다.
Only the host:port list recorded in the consent form annex is registered. Nothing outside that list is ever contacted.
사설·루프백·링크로컬·멀티캐스트·예약 주소 대역, 허용되지 않은 포트, 도메인 허용목록 위반을 차단하고 사유를 감사 로그에 기록합니다.
Private, loopback, link-local, multicast and reserved ranges, disallowed ports and allowlist violations are blocked, with the reason written to the audit log.
TLS 핸드셰이크를 수립해 서버가 제시하는 공개 정보만 수집합니다. 동시 실행과 전체 시간 예산이 제한되어 대상에 부하를 주지 않습니다.
Establishes a TLS handshake and collects only the public information the server presents. Concurrency and a total time budget are bounded so targets are not loaded.
Shor 취약성, Grover 영향, HNDL 노출도를 가중합해 자산별 점수와 우선순위를 산출하고 표준 대체 알고리즘을 매핑합니다.
Combines Shor vulnerability, Grover impact and HNDL exposure into a weighted per-asset score and priority, and maps the standard replacement algorithm.
한국어·영어 PDF와 DOCX를 생성하고, 산출물 메타데이터와 생성 이력을 감사 로그에 남깁니다.
Generates Korean and English PDF and DOCX, and records artifact metadata and generation history in the audit log.
지정된 host:port에 TLS 연결을 수립하고 즉시 종료합니다. 프로토콜 버전, 협상된 암호 스위트, 서버가 제시하는 공개 인증서 정보만 읽습니다. 대상 1건당 연결 시도는 통상 수 회 이내입니다.
Establishes a TLS connection to the designated host:port and closes it immediately. Reads only the protocol version, negotiated cipher suite and the public certificate the server presents. Typically a small number of connection attempts per target.
인증 시도, 로그인 시도, 자격증명 입력, 취약점 공격, 침투 시도, 데이터 변경·삭제·삽입, 서비스 거부를 유발할 수 있는 부하 발생, 대량·고빈도 요청. 자격증명, 통신 본문, 계정정보는 수집하지 않으며 지정된 대상의 공개 TLS 메타데이터만 처리합니다.
No authentication or login attempts, no credential submission, no exploitation or intrusion, no data modification, deletion or insertion, no load that could cause denial of service, and no high-volume or high-frequency requests. No credentials, message bodies or account data are collected; only public TLS metadata from designated targets is processed.
사설, 루프백, 링크로컬, 멀티캐스트, 예약 주소 대역은 코드 수준에서 차단됩니다. 허용 포트와 도메인 허용목록을 테넌트별로 설정할 수 있으며, 위반 시 실행 전에 차단되고 사유가 기록됩니다.
Private, loopback, link-local, multicast and reserved address ranges are blocked at code level. Allowed ports and a domain allowlist are configurable per tenant; violations are blocked before execution and the reason is recorded.
전역 동시 실행 수, 호스트당 동시 실행 수, 전체 시간 예산이 제한됩니다. 예산을 초과한 대상은 강제 종료되고 결과에 사유가 표기되므로, 진단이 대상 서비스에 주는 부하를 최소로 유지합니다.
Global concurrency, per-host concurrency and a total time budget are bounded. Targets exceeding the budget are terminated and flagged in the results, so the assessment stays within a bounded, low-load connection pattern.
본 진단은 외부 TLS 표면에 한정된 간이 PQC 전환 진단입니다. 아래는 범위에 포함되지 않으며, 보고서는 이들 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.
This is a focused PQC transition assessment limited to the external TLS surface. The following are out of scope, and the report makes no claim about the security of these areas.
실제 진단 결과에서 고객사명과 호스트명만 마스킹한 발췌본입니다. 표지, 경영진 요약, 위험 우선순위 표, 갱신 창구 분석까지 포함되어 있어 분석의 깊이를 그대로 확인하실 수 있습니다. 수치는 가공하지 않았습니다.
An excerpt from a real assessment with only the client name and hostnames masked. It includes the cover, executive summary, risk priority table and renewal window analysis, so the depth of the analysis is visible as delivered. The figures are unaltered.
표지, 경영진 요약 4개 결론, 자산별 위험 우선순위, 인증서 갱신 창구 분석
Cover, four executive conclusions, per-asset risk priority, certificate renewal window analysis
배경과 용어, 방법론과 점수 공식, 트랙별 실행 지침과 검증 방법, 성숙도 판정, 범위 제한, 출처 부록까지 포함
Background and terminology, methodology and the scoring formula, per-track execution guidance with verification steps, maturity assessment, scope limits and a sourced appendix
한국어와 영어 각각 PDF와 DOCX로 제공합니다. 두 언어는 동일한 진단 데이터에서 생성되므로 수치가 어긋나지 않습니다.
Delivered as PDF and DOCX in both Korean and English. Both languages are generated from the same assessment data, so figures cannot diverge.
진단 목적, 대상 범위, 수행 시간대를 협의합니다. 대상이 CDN 뒤에 있는지, 오리진 설정 관리 주체가 누구인지를 이 단계에서 확인합니다.
Agree on objectives, scope and execution window. Confirm at this stage whether targets sit behind a CDN and who manages origin configuration.
진단 범위, 수행·미수행 행위, 데이터 처리와 보관 기간, 중지 요청 절차를 문서로 확정합니다. 고객은 진단 중 언제든 중지를 요청할 수 있습니다.
Scope, permitted and prohibited actions, data handling and retention, and the stop-request procedure are fixed in writing. The client may request a halt at any point.
고객이 별지 양식으로 host:port 목록을 제출합니다. 목록에 없는 자산은 어떤 경우에도 진단 대상이 되지 않습니다.
The client submits the host:port list on the annex form. Assets not on the list are never assessed.
자산별 데이터 민감도와 보존 수명을 입력받습니다. 이 값이 우선순위를 가르는 핵심 입력이며, 없으면 추정값을 사용하고 보고서에 추정임을 명시합니다.
Per-asset data sensitivity and retention life are collected. These inputs drive prioritisation; where unavailable, estimates are used and clearly marked as such in the report.
승인 후 읽기 전용 진단이 실행됩니다. 요청부터 완료까지 모든 이벤트가 감사 로그에 기록됩니다.
The read-only assessment runs after approval. Every event from request to completion is written to the audit log.
한국어·영어 PDF와 DOCX를 인도하고 결과 브리핑을 진행합니다. 질의는 브리핑 이후에도 받습니다.
Korean and English PDF and DOCX are delivered, followed by a results briefing. Questions are taken after the briefing as well.
파일럿 진단 및 도입 문의는 아래로 연락 주십시오. 대상 목록과 일정만 정해지면 착수할 수 있습니다.
For pilot assessments and deployment enquiries, contact us below. Work can begin as soon as the target list and schedule are agreed.