왜 지금인가Why now 산출물Deliverables 차별점Difference 플랫폼Platform 안전성Safety 진행 절차Process 산출물 발췌Deliverable FAQFAQ 진단 문의하기Contact us
AI Depot Security Agent Platform AI Depot Security Agent Platform

양자내성암호 전환의 첫 단계는
스캔이 아니라 판단입니다.

The first step in post-quantum migration is not a scan.
It is a judgement.

ADSAP은 조직의 외부 TLS 암호자산을 읽기 전용으로 식별하고, 자산별 양자 위험도와 전환 우선순위, 그리고 실제로 전환을 시작할 수 있는 시점을 제시하는 PQC 전환 진단 플랫폼입니다. 오픈소스 스캐너가 값을 출력한다면, ADSAP은 그 값이 무엇을 뜻하고 무엇부터 해야 하는지를 답합니다.

ADSAP identifies an organisation's external TLS cryptographic assets read-only, then reports per-asset quantum risk, migration priority, and the point at which migration can actually begin. Open-source scanners print values. ADSAP answers what those values mean and what to do first.

제공 형태 · 고객이 지정한 외부 TLS 엔드포인트 최대 20개를 대상으로 진단하고, 한국어 · 영어 보고서와 90일 실행계획, 결과 브리핑을 제공합니다. 자산 수가 5개 이하이거나 20개를 넘는 경우 별도로 협의합니다.

What you get · We assess up to 20 external TLS endpoints you designate, and deliver Korean and English reports, a 90-day execution plan and a results briefing. Engagements of five or fewer, or more than twenty, are scoped separately.

ADSAP :: READ-ONLY DISCOVERY MATRIX
20 ENDPOINTS
100%
CRITICAL
api.client.com:443 ECDSA P-256 (HNDL WAVE 1)
auth.client.net:443 RSA-2048 (SHOR 2030)
adsap.comnetwork.net X25519MLKEM768 (PQC READY)
FIPS 203/204/205NIST 표준 기준 위험 해석Risk mapped to NIST standards
2030 / 2035사용 중단 · 사용 금지 시한Deprecated · disallowed deadlines
읽기 전용Read-only공격·인증 시도·데이터 변경 없음No exploitation, auth attempts or data change
KO / ENPDF · DOCX 이중 언어 보고서Bilingual PDF and DOCX reports
암호자산 탐색기
Asset Explorer

PQC 전환 위험도 & NIST 대체 표준 탐색기

PQC Cryptographic Asset Risk & Migration Explorer

조직에서 사용 중인 주요 TLS 암호 알고리즘을 선택해 위험 등급과 NIST 대체 표준, 권장 조치 방향을 확인하세요.

Select an encryption algorithm currently deployed in your organisation to inspect its quantum risk, NIST FIPS replacement, and recommended action track.

왜 지금인가
Why now

양자컴퓨터가 언제 나오는지는 이 문제의 변수가 아닙니다.

When quantum computers arrive is not the variable in this problem.

HNDL(Harvest Now, Decrypt Later)은 공격자가 지금 암호화된 통신을 저장해 두었다가 나중에 소급 해독하는 방식입니다. 저장은 오늘 일어납니다. 그러므로 방어도 오늘이어야 합니다. 내일 암호를 바꿔도 오늘 저장된 트래픽은 보호되지 않습니다.

Under HNDL (harvest now, decrypt later), an adversary stores encrypted traffic today and decrypts it retroactively. Collection happens now, so defence has to happen now. Changing algorithms tomorrow does not protect traffic captured today.

01

기반 수학이 무너집니다

The underlying mathematics collapses

RSA는 소인수분해, ECDSA와 ECDH는 타원곡선 이산로그 문제에 안전성을 의존합니다. Shor 알고리즘은 두 문제를 모두 다항시간에 해결합니다. 개별 알고리즘의 결함이 아니라 공개키 암호 전체가 동시에 영향을 받습니다. 키 길이를 늘려서 해결되지 않습니다.

RSA relies on integer factorisation; ECDSA and ECDH on the elliptic-curve discrete logarithm. Shor's algorithm solves both in polynomial time. This is not a flaw in one algorithm: public-key cryptography is affected as a class, and longer keys do not fix it.

02

데이터 수명이 위험을 결정합니다

Data lifetime determines exposure

계약 문서처럼 10년 보존 의무가 걸린 데이터는 오늘 수집되면 2036년에도 유효합니다. 반면 공개 웹 콘텐츠는 애초에 기밀성 요구가 없습니다. 같은 알고리즘을 쓰더라도 자산마다 실질 위험이 다르며, 우선순위는 여기서 갈립니다.

Data under a ten-year retention obligation, such as contract records, is still meaningful in 2036 if captured today. Public web content has no confidentiality requirement at all. The same algorithm carries different real exposure per asset, and that is where priority is decided.

03

일정이 확정되었습니다

The schedule is fixed

NIST IR 8547 초안은 양자 취약 공개키 알고리즘을 2030년 이후 사용 중단, 2035년 이후 사용 금지 대상으로 제시합니다. 국내에서도 2023년 「양자내성암호 마스터플랜」이 2035년 국가 암호체계 전환 목표를 명시했습니다. 이제 기술 선택이 아니라 일정 준수 사안입니다.

The draft NIST IR 8547 deprecates quantum-vulnerable public-key algorithms after 2030 and disallows them after 2035. In Korea, the 2023 PQC Master Plan sets a 2035 national transition target. This is no longer a technology choice; it is schedule compliance.

차별점
The difference

스캐너는 만료일을 출력합니다. 컨설턴트는 그 날짜가 전환 창구라고 말합니다.

A scanner prints an expiry date. A consultant tells you that date is your migration window.

진단의 가치는 데이터 수집이 아니라 해석에 있습니다. 아래는 ADSAP 보고서가 실제로 답하는 질문들입니다.

The value of an assessment lies in interpretation, not collection. These are the questions an ADSAP report actually answers.

“취약 자산이 18개라는 건 알겠습니다. 그래서 뭐부터 합니까?”
“I see 18 vulnerable assets. So which one do I start with?”
이 질문에 답하지 못하는 보고서는 우선순위 표가 아니라 목록입니다. ADSAP은 자산별 데이터 민감도와 보존 수명을 위험 점수에 반영하고, 여기에 인증서 갱신 일정을 겹쳐 실행 순서를 만듭니다. 결과는 “가장 위험한 자산”이 아니라 “가장 먼저 손댈 수 있는 가장 위험한 자산”입니다.
A report that cannot answer this is a list, not a priority table. ADSAP feeds per-asset data sensitivity and retention life into the risk score, then overlays the certificate renewal calendar to produce an execution order. The output is not "the riskiest asset" but "the riskiest asset you can actually touch first".
항목Item 일반 TLS 스캐너Generic TLS scanner ADSAP PQC 전환 진단ADSAP PQC assessment
알고리즘 식별Algorithm identification 가능Yes 가능Yes
PQC 표준 매핑Mapping to PQC standards 없음No FIPS 203/204/205 기준 대체 알고리즘 지정Replacement algorithm named per FIPS 203/204/205
자산별 우선순위Per-asset prioritisation 없음. 모든 자산이 동일하게 표시None. All assets look identical Shor · Grover · HNDL 가중 점수로 등급 분화Graded by a weighted Shor / Grover / HNDL score
업무 맥락 반영Business context 불가Not possible 데이터 민감도 · 보존 수명을 입력값으로 반영Data sensitivity and retention life taken as inputs
실행 창구 제시Execution window 만료일 나열에 그침Lists expiry dates only 갱신 주기를 전환 창구로 해석해 웨이브 계획 수립Reads the renewal cycle as a migration window and plans waves
배경 · 용어 설명Background and terminology 없음None HNDL, Shor, ML-KEM/ML-DSA/SLH-DSA 해설 포함Includes HNDL, Shor, ML-KEM / ML-DSA / SLH-DSA explanations
검증 가능한 조치Verifiable actions 없음None 단계별 조치와 검증 명령·확인 방법을 함께 기술Each step paired with a verification command or method
운영 통제Operational controls 실행자 재량At the operator's discretion 승인 게이트 · 역할 분리 · 감사 로그 · 테넌트 격리Approval gates, role separation, audit logs, tenant isolation
산출물
Deliverables

임원이 읽고 예산을 승인할 수 있고, 엔지니어가 읽고 바로 실행할 수 있는 하나의 문서.

One document an executive can approve a budget from and an engineer can execute from.

보고서는 한국어와 영어로 각각 PDF와 DOCX로 제공됩니다. 구성은 다음과 같습니다.

Reports are delivered in Korean and English, each as PDF and DOCX. The structure is as follows.

경영진 요약

Executive summary

전환 대상 범위, 최우선 자산, 가장 이른 실행 창구, 즉시 조치와 대기 조치의 구분을 1페이지로 정리합니다. 예산 결재 문서에 그대로 인용할 수 있는 형태입니다.

Scope, highest-priority assets, earliest execution window, and the split between act-now and wait items, on one page. Written to be quoted directly into a budget approval.

배경 · 용어 해설

Background and terminology

HNDL이 무엇이고 왜 지금인지, Shor 알고리즘이 ECDSA에 무엇을 하는지, ML-KEM · ML-DSA · SLH-DSA가 각각 어디에 쓰이는지를 설명합니다. 용어만 던지고 검색을 시키지 않습니다.

What HNDL is and why it matters now, what Shor's algorithm does to ECDSA, and where ML-KEM, ML-DSA and SLH-DSA each apply. Terms are explained, not just cited.

암호자산 인벤토리

Cryptographic asset inventory

자산별 TLS 버전, 암호 스위트, 공개키 알고리즘과 키 길이, 인증서 발급자 · 주체 · 유효기간 · 잔여일수를 표로 제공합니다. 전사 암호자산 대장의 출발점이 됩니다.

Per asset: TLS version, cipher suite, public key algorithm and size, certificate issuer, subject, validity and days remaining. The starting point for an enterprise cryptographic register.

위험 우선순위

Risk prioritisation

Shor · Grover · HNDL 가중 점수와 우선순위 등급, 그리고 그 점수가 나온 근거(민감도, 데이터 수명)를 자산별로 명시합니다. 계산은 재현 가능하며 입력값을 바꾸면 결과가 바뀝니다.

Weighted Shor / Grover / HNDL scores and priority bands, with the inputs behind each score (sensitivity, data lifetime) stated per asset. The calculation is reproducible and responds to changed inputs.

갱신 창구 분석

Renewal window analysis

인증서 만료일을 관리 항목이 아니라 전환 기회로 해석합니다. 같은 날짜에 묶인 자산을 군집화하고, 위험도와 창구를 결합해 웨이브 단위 실행 순서를 만듭니다.

Certificate expiry dates are read as migration opportunities, not administrative fields. Assets are clustered by shared expiry, then risk and window are combined into a wave-based execution order.

실행 지침과 검증 방법

Execution guidance and verification

“담당자 확인”은 조치가 아닙니다. 각 단계마다 무엇을 바꾸고, 그것이 실제로 적용되었는지 어떤 명령이나 화면으로 확인하는지를 함께 기술합니다.

"Confirm the owner" is not a remediation step. Each step states what changes and which command or screen confirms that the change took effect.

현 위치 판정

Position assessment

5단계 전환 성숙도 모델에서 조직의 현재 위치를 판정하고, 국가 전환 로드맵 및 NIST 일정 대비 어디에 서 있는지를 제시합니다. 다음 단계 진입 조건도 함께 명시합니다.

Places the organisation on a five-stage transition maturity model and against the national roadmap and NIST timeline, including what is required to reach the next stage.

범위 제한 명시

Explicit scope limits

진단하지 않은 영역을 분명히 적습니다. 외부 TLS 표면은 전체 암호자산의 일부이며, 보고서는 다루지 않은 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.

States plainly what was not assessed. The external TLS surface is a subset of the estate, and the report makes no claim about the security of areas outside it.

플랫폼
Platform

사람이 스크립트를 돌리는 방식이 아니라, 통제된 파이프라인으로 수행합니다.

Not a person running a script, but a controlled pipeline.

ADSAP은 승인 게이트, 역할 기반 권한, 테넌트 격리, 추가 전용 감사 로그를 갖춘 에이전트 오케스트레이션 플랫폼입니다. 진단의 모든 단계가 기록되며 재현 가능합니다.

ADSAP is an agent orchestration platform with approval gates, role-based access, tenant isolation and an append-only audit log. Every stage of an assessment is recorded and reproducible.

01 SCOPE

범위 등록

Scope registration

동의서 별지에 기재된 host:port 목록만 대상으로 등록됩니다. 목록 외 자산은 어떤 경우에도 접근하지 않습니다.

Only the host:port list recorded in the consent form annex is registered. Nothing outside that list is ever contacted.

02 GUARD

정책 검사

Policy guard

사설·루프백·링크로컬·멀티캐스트·예약 주소 대역, 허용되지 않은 포트, 도메인 허용목록 위반을 차단하고 사유를 감사 로그에 기록합니다.

Private, loopback, link-local, multicast and reserved ranges, disallowed ports and allowlist violations are blocked, with the reason written to the audit log.

03 DISCOVER

읽기 전용 수집

Read-only discovery

TLS 핸드셰이크를 수립해 서버가 제시하는 공개 정보만 수집합니다. 동시 실행과 전체 시간 예산이 제한되어 대상에 부하를 주지 않습니다.

Establishes a TLS handshake and collects only the public information the server presents. Concurrency and a total time budget are bounded so targets are not loaded.

04 SCORE

위험 산정

Risk scoring

Shor 취약성, Grover 영향, HNDL 노출도를 가중합해 자산별 점수와 우선순위를 산출하고 표준 대체 알고리즘을 매핑합니다.

Combines Shor vulnerability, Grover impact and HNDL exposure into a weighted per-asset score and priority, and maps the standard replacement algorithm.

05 REPORT

보고서 생성

Report generation

한국어·영어 PDF와 DOCX를 생성하고, 산출물 메타데이터와 생성 이력을 감사 로그에 남깁니다.

Generates Korean and English PDF and DOCX, and records artifact metadata and generation history in the audit log.

승인 게이트
Approval gates
진단 작업은 승인 없이 실행되지 않습니다. 위험도가 높은 단계는 별도의 승인 경계를 다시 확인합니다
No assessment runs without approval. Higher-risk steps re-confirm a separate approval boundary
접근 인증 · 권한 분리
Authentication and role separation
모든 접근은 인증을 거치며, 진단 실행 권한은 지정된 역할에만 부여됩니다
All access is authenticated, and permission to run an assessment is granted only to designated roles
고객사 데이터 격리
Client data isolation
고객사 데이터는 데이터베이스 계층에서 강제 분리되어 다른 고객의 조회 대상이 되지 않습니다
Client data is separated at the database layer and is not reachable from another client's context
감사 추적
Audit trail
요청 · 차단 · 완료 이벤트가 수행자와 시각과 함께 추가 전용으로 기록되어 사후 변경이 불가능합니다
Requested, blocked and completed events are written append-only with actor and timestamp, and cannot be altered afterwards
실행 내구성
Durable execution
장시간 실행되는 작업이 중단되어도 진행 상태가 유실되지 않습니다
Long-running work retains its state across interruption
이중 언어 일관성
Bilingual consistency
동일한 진단 데이터에서 한국어 · 영어 보고서를 생성하므로 두 언어의 수치와 결론이 어긋나지 않습니다
Korean and English reports are generated from the same assessment data, so figures and conclusions cannot diverge
회귀 검증
Regression testing
대상 통제, 위험 점수 산정, 보고서 생성, 권한 처리에 대한 자동화 테스트를 상시 유지합니다
Automated tests covering target controls, risk scoring, report generation and authorisation are maintained continuously
재현 가능성
Reproducibility
위험 점수 공식과 입력값을 보고서에 공개하므로 고객이 직접 계산을 검증할 수 있습니다
The risk scoring formula and its inputs are published in the report, so the client can verify the calculation independently
NIST FIPS 203 / 204 / 205NIST IR 8547 읽기 전용Read-only 승인 게이트Approval gates 감사 로그Audit logging 고객사 데이터 격리Client data isolation DOCX / PDF · KO · EN
안전성
Safety

진단이 사고가 되어서는 안 됩니다. 읽기 전용은 정책이 아니라 코드로 강제됩니다.

An assessment must not become an incident. Read-only is enforced in code, not policy.

수행하는 행위

What is performed

지정된 host:port에 TLS 연결을 수립하고 즉시 종료합니다. 프로토콜 버전, 협상된 암호 스위트, 서버가 제시하는 공개 인증서 정보만 읽습니다. 대상 1건당 연결 시도는 통상 수 회 이내입니다.

Establishes a TLS connection to the designated host:port and closes it immediately. Reads only the protocol version, negotiated cipher suite and the public certificate the server presents. Typically a small number of connection attempts per target.

수행하지 않는 행위

What is never performed

인증 시도, 로그인 시도, 자격증명 입력, 취약점 공격, 침투 시도, 데이터 변경·삭제·삽입, 서비스 거부를 유발할 수 있는 부하 발생, 대량·고빈도 요청. 개인정보는 수집하지 않습니다.

No authentication or login attempts, no credential submission, no exploitation or intrusion, no data modification, deletion or insertion, no load that could cause denial of service, and no high-volume or high-frequency requests. No personal data is collected.

대상 통제

Target controls

사설, 루프백, 링크로컬, 멀티캐스트, 예약 주소 대역은 코드 수준에서 차단됩니다. 허용 포트와 도메인 허용목록을 테넌트별로 설정할 수 있으며, 위반 시 실행 전에 차단되고 사유가 기록됩니다.

Private, loopback, link-local, multicast and reserved address ranges are blocked at code level. Allowed ports and a domain allowlist are configurable per tenant; violations are blocked before execution and the reason is recorded.

부하 통제

Load controls

전역 동시 실행 수, 호스트당 동시 실행 수, 전체 시간 예산이 제한됩니다. 예산을 초과한 대상은 강제 종료되고 결과에 사유가 표기되므로, 진단이 대상 서비스에 영향을 주지 않습니다.

Global concurrency, per-host concurrency and a total time budget are bounded. Targets exceeding the budget are terminated and flagged in the results, so the assessment does not affect the target service.

이 진단이 다루지 않는 것

What this assessment does not cover

본 진단은 외부 TLS 표면에 한정된 간이 PQC 전환 진단입니다. 아래는 범위에 포함되지 않으며, 보고서는 이들 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.

This is a focused PQC transition assessment limited to the external TLS surface. The following are out of scope, and the report makes no claim about the security of these areas.

  • SSH, VPN/IPsec, 데이터베이스 TLS, 내부 PKI, 코드 서명 인증서
  • 웹 애플리케이션 취약점 진단, 모의해킹, 내부망 자산 탐지
  • 「정보통신기반 보호법」상 주요정보통신기반시설의 취약점 분석·평가
  • 암호 라이브러리 사용 현황 수집 및 PQC 적용 시 성능 영향 예측
  • 대상이 CDN 또는 리버스 프록시 뒤에 있는 경우, 결과는 오리진 서버가 아닌 중개 서비스의 TLS 설정을 반영할 수 있습니다. 보고서에 이를 명시합니다.
  • SSH, VPN/IPsec, database TLS, internal PKI and code signing certificates
  • Web application vulnerability testing, penetration testing and internal network asset discovery
  • Statutory vulnerability analysis and evaluation of critical information infrastructure under Korean law
  • Cryptographic library inventory and performance impact prediction for PQC adoption
  • Where a target sits behind a CDN or reverse proxy, results may reflect the intermediary's TLS configuration rather than the origin server. This is stated explicitly in the report.
산출물 미리보기
See the deliverable

보고서를 먼저 보시고 판단하십시오.

Look at the report before you decide.

실제 진단 결과에서 고객사명과 호스트명만 마스킹한 발췌본입니다. 표지, 경영진 요약, 위험 우선순위 표, 갱신 창구 분석까지 포함되어 있어 분석의 깊이를 그대로 확인하실 수 있습니다. 수치는 가공하지 않았습니다.

An excerpt from a real assessment with only the client name and hostnames masked. It includes the cover, executive summary, risk priority table and renewal window analysis, so the depth of the analysis is visible as delivered. The figures are unaltered.

발췌본
EXCERPT

5페이지

5 pages

표지, 경영진 요약 4개 결론, 자산별 위험 우선순위, 인증서 갱신 창구 분석

Cover, four executive conclusions, per-asset risk priority, certificate renewal window analysis

실제 산출물
FULL REPORT

16페이지 · KO / EN

16 pages · KO / EN

배경과 용어, 방법론과 점수 공식, 트랙별 실행 지침과 검증 방법, 성숙도 판정, 범위 제한, 출처 부록까지 포함

Background and terminology, methodology and the scoring formula, per-track execution guidance with verification steps, maturity assessment, scope limits and a sourced appendix

형식
FORMATS

PDF · DOCX

PDF and DOCX

한국어와 영어 각각 PDF와 DOCX로 제공합니다. 두 언어는 동일한 진단 데이터에서 생성되므로 수치가 어긋나지 않습니다.

Delivered as PDF and DOCX in both Korean and English. Both languages are generated from the same assessment data, so figures cannot diverge.

이 사이트 자체가 첫 번째 증거입니다.
This site is our first piece of evidence.
보고서 7.1이 권고하는 하이브리드 키 교환(X25519MLKEM768)을 이 사이트에 먼저 적용했고, HSTS preload 도 등록했습니다. 고객에게 권고하는 조치를 우리가 먼저 적용하지 않을 이유가 없습니다. 브라우저 개발자도구의 보안 탭에서 직접 확인하실 수 있습니다.
The hybrid key agreement this report recommends (X25519MLKEM768) is applied to this site, and HSTS preload is registered. There is no reason to recommend a control to clients that we have not applied ourselves. You can verify it in your browser's security panel.
진행 절차
Process

서명된 동의서와 확정된 대상 목록 없이는 스캔이 시작되지 않습니다.

No scan starts without a signed consent form and a finalised target list.

STEP 1

사전 협의

Initial discussion

진단 목적, 대상 범위, 수행 시간대를 협의합니다. 대상이 CDN 뒤에 있는지, 오리진 설정 관리 주체가 누구인지를 이 단계에서 확인합니다.

Agree on objectives, scope and execution window. Confirm at this stage whether targets sit behind a CDN and who manages origin configuration.

STEP 2

스캔 동의서 체결

Consent form

진단 범위, 수행·미수행 행위, 데이터 처리와 보관 기간, 중지 요청 절차를 문서로 확정합니다. 고객은 진단 중 언제든 중지를 요청할 수 있습니다.

Scope, permitted and prohibited actions, data handling and retention, and the stop-request procedure are fixed in writing. The client may request a halt at any point.

STEP 3

대상 목록 제출

Target list

고객이 별지 양식으로 host:port 목록을 제출합니다. 목록에 없는 자산은 어떤 경우에도 진단 대상이 되지 않습니다.

The client submits the host:port list on the annex form. Assets not on the list are never assessed.

STEP 4

자산 맥락 입력

Asset context

자산별 데이터 민감도와 보존 수명을 입력받습니다. 이 값이 우선순위를 가르는 핵심 입력이며, 없으면 추정값을 사용하고 보고서에 추정임을 명시합니다.

Per-asset data sensitivity and retention life are collected. These inputs drive prioritisation; where unavailable, estimates are used and clearly marked as such in the report.

STEP 5

진단 수행

Assessment

승인 후 읽기 전용 진단이 실행됩니다. 요청부터 완료까지 모든 이벤트가 감사 로그에 기록됩니다.

The read-only assessment runs after approval. Every event from request to completion is written to the audit log.

STEP 6

보고서 인도 및 브리핑

Report and briefing

한국어·영어 PDF와 DOCX를 인도하고 결과 브리핑을 진행합니다. 질의는 브리핑 이후에도 받습니다.

Korean and English PDF and DOCX are delivered, followed by a results briefing. Questions are taken after the briefing as well.

파일럿 진단은 고객이 지정한 핵심 외부 TLS 엔드포인트 최대 20개를 대상으로 수행합니다.
A pilot assessment covers up to 20 core external TLS endpoints the client designates.
목적은 전사 진단이 아니라, PQC 전환이 필요한 구간을 식별하고 우선순위 초안을 세우는 것입니다. 결과가 실제 의사결정에 쓰일 수 있는지 먼저 확인한 뒤 범위를 넓히는 순서를 권장합니다.
The objective is not enterprise-wide coverage but identifying where PQC migration is required and drafting an initial priority order. We recommend confirming that the output supports real decisions before widening scope.
자주 묻는 질문
Frequently asked questions

PQC 전환 진단에 대해 가장 많이 받는 질문

The questions we are asked most about PQC transition assessment

PQC 전환 준비도 진단이란 무엇입니까?What is a PQC transition readiness assessment?
조직이 사용 중인 암호 알고리즘을 식별하고, 양자컴퓨터 환경에서 안전하지 않은 자산을 가려낸 뒤 어떤 순서로 무엇부터 교체할지 결정하는 진단입니다. ADSAP은 그중 외부 TLS 표면을 대상으로 하며, 자산별 공개키 알고리즘과 키 길이, Shor · Grover · HNDL 가중 위험 점수, NIST FIPS 203/204/205 기준 대체 알고리즘, 인증서 갱신 창구 기반 실행 순서를 한국어 · 영어 보고서로 제공합니다.
An assessment that identifies which cryptographic algorithms an organisation uses, isolates the assets that are not safe against quantum computing, and decides what to replace in what order. ADSAP covers the external TLS surface, reporting per-asset public key algorithm and size, a weighted Shor / Grover / HNDL risk score, the replacement algorithm under NIST FIPS 203/204/205, and an execution order derived from certificate renewal windows, in Korean and English.
진단이 운영 중인 서비스에 영향을 줍니까?Does the assessment affect production services?
영향을 주지 않습니다. 진단은 읽기 전용이며, 지정된 host:port에 TLS 연결을 수립하고 즉시 종료합니다. 인증 시도, 자격증명 입력, 취약점 공격, 데이터 변경이나 삭제, 서비스 거부를 유발할 수 있는 부하 발생, 대량 · 고빈도 요청을 일절 수행하지 않습니다. 전역 동시 실행 수, 호스트당 동시 실행 수, 전체 시간 예산이 코드 수준에서 제한되며 사설 · 루프백 · 링크로컬 · 멀티캐스트 · 예약 주소 대역은 차단됩니다.
No. The assessment is read-only: it opens a TLS connection to the designated host:port and closes it immediately. It performs no authentication attempts, no credential submission, no exploitation, no data modification or deletion, no load that could cause denial of service, and no high-volume or high-frequency requests. Global concurrency, per-host concurrency and a total time budget are bounded in code, and private, loopback, link-local, multicast and reserved address ranges are blocked.
오픈소스 TLS 스캐너와 무엇이 다릅니까?How does this differ from an open-source TLS scanner?
스캐너는 기술값을 출력하고, ADSAP은 그 값이 무엇을 뜻하는지와 무엇부터 해야 하는지를 답합니다. 구체적으로는 네 가지입니다. 첫째, NIST FIPS 203/204/205 기준으로 자산별 대체 알고리즘을 지정합니다. 둘째, 데이터 민감도와 보존 수명을 입력값으로 받아 자산 간 우선순위를 실제로 분화시킵니다. 셋째, 인증서 만료일을 관리 항목이 아니라 전환 창구로 해석해 웨이브 단위 실행 순서를 만듭니다. 넷째, 각 조치마다 적용 여부를 확인하는 검증 명령이나 방법을 함께 제시합니다.
A scanner prints technical values; ADSAP answers what those values mean and what to do first. Four differences in particular. First, it names the replacement algorithm per asset under NIST FIPS 203/204/205. Second, it takes data sensitivity and retention life as inputs, so priorities actually separate between assets. Third, it reads certificate expiry as a migration window rather than an administrative field, producing a wave-based execution order. Fourth, each action is paired with a command or method that verifies it took effect.
지금 당장 인증서를 PQC 인증서로 교체해야 합니까?Should we replace our certificates with PQC certificates right now?
아닙니다. PQC 전환은 성격이 다른 두 트랙으로 나뉩니다. 트랙 A는 키 교환이며 통신의 기밀성을 보호합니다. 하이브리드 키 교환 X25519MLKEM768은 주요 CDN과 브라우저에서 이미 동작하므로 오늘 적용할 수 있고, HNDL 위험을 해소하는 것은 인증서 교체가 아니라 이 설정입니다. 트랙 B는 인증서 서명이며 서버 신원을 증명합니다. 공인 인증서에 ML-DSA를 넣으려면 CA/Browser Forum 기준 개정과 IETF X.509 인코딩 확정이 선행되어야 하며 2027년 전후로 전망됩니다. 인증서의 ECDSA 서명은 소급 위조가 불가능하므로 HNDL 대상이 아니며, 규제 일정에 맞춘 계획 사안입니다.
No. PQC migration splits into two tracks with different mechanics. Track A is key exchange, which protects confidentiality. The hybrid key agreement X25519MLKEM768 already operates across major CDNs and browsers, so it can be applied today, and HNDL risk is resolved by that setting rather than by replacing certificates. Track B is the certificate signature, which proves server identity. Putting ML-DSA into publicly trusted certificates requires a CA/Browser Forum baseline revision and finalised IETF X.509 encodings, expected around 2027. A certificate's ECDSA signature cannot be forged retroactively, so it is not an HNDL exposure; it is a planning item governed by the regulatory timeline.
PQC 전환은 언제까지 완료해야 합니까?By when must PQC migration be completed?
NIST IR 8547 초안은 RSA-2048, ECC P-256 등 약 112비트 강도의 양자 취약 공개키 알고리즘을 2030년 이후 사용 중단(deprecated), 2035년 이후 사용 금지(disallowed) 대상으로 제시합니다. 대한민국은 2023년 7월 국가정보원과 과학기술정보통신부 주도로 「양자내성암호 마스터플랜」을 수립해 2035년 국가 암호체계 전환 목표를 명시했습니다. 2030년부터는 신규 시스템에 취약 알고리즘을 쓸 수 없으므로 실제 가용 기간은 명목 기한보다 짧습니다.
The draft NIST IR 8547 deprecates quantum-vulnerable public-key algorithms of roughly 112-bit strength, such as RSA-2048 and ECC P-256, after 2030 and disallows them after 2035. In Korea, the PQC Master Plan established in July 2023 by the National Intelligence Service and the Ministry of Science and ICT sets a 2035 national transition target. Because vulnerable algorithms cannot be used in new systems from 2030, the usable runway is shorter than the nominal deadline.
진단을 받으려면 무엇을 준비해야 합니까?What do we need to prepare?
세 가지입니다. 첫째, 스캔 동의서에 서명합니다. 진단 범위, 수행 및 미수행 행위, 데이터 처리와 보관 기간, 중지 요청 절차가 문서로 확정됩니다. 둘째, 별지 양식으로 진단 대상 host:port 목록을 제출합니다. 목록에 없는 자산은 어떤 경우에도 진단 대상이 되지 않습니다. 셋째, 자산별 데이터 민감도와 보존 수명을 알려주시면 우선순위 정확도가 크게 올라갑니다. 제공되지 않으면 추정값을 사용하고 보고서에 추정임을 명시합니다.
Three things. First, sign the scan consent form, which fixes scope, permitted and prohibited actions, data handling and retention, and the stop-request procedure in writing. Second, submit the host:port target list on the annex form; assets not on the list are never assessed. Third, tell us each asset's data sensitivity and retention life, which materially improves prioritisation accuracy. Where these are not provided we use estimates and mark them as estimates in the report.
내부 시스템이나 SSH, VPN도 진단합니까?Do you assess internal systems, SSH or VPN?
포함되지 않습니다. 본 진단은 외부 TLS 표면에 한정됩니다. SSH 호스트키와 사용자키, VPN/IPsec 터널, 데이터베이스 TLS, 내부 PKI, 코드 서명 인증서, 백업 암호화, 애플리케이션 코드 내 암호 라이브러리 사용 현황은 범위 밖이며, 보고서는 이들 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다. 웹 애플리케이션 취약점 진단과 모의해킹, 「정보통신기반 보호법」상 주요정보통신기반시설의 취약점 분석 · 평가도 포함되지 않습니다.
No. This assessment is limited to the external TLS surface. SSH host and user keys, VPN/IPsec tunnels, database TLS, internal PKI, code signing certificates, backup encryption and cryptographic library usage inside application code are out of scope, and the report makes no claim about the security of those areas. Web application vulnerability testing, penetration testing, and statutory vulnerability analysis of critical information infrastructure under Korean law are likewise excluded.
수집된 데이터는 어떻게 처리됩니까?How is collected data handled?
수집 항목은 TLS 프로토콜 버전, 협상된 암호 스위트, 서버가 제시하는 공개 인증서 정보에 한정되며 개인정보는 수집하지 않습니다. 수집된 데이터와 산출된 보고서는 암호화하여 보관하고 접근 권한을 담당 인력으로 제한하며 접근 이력을 기록합니다. 보관 기간은 동의서에서 합의하며, 기간 종료 시 파기하고 요청이 있으면 파기 확인서를 제공합니다. 고객은 기간 중 언제든 즉시 파기를 요청할 수 있습니다.
Collection is limited to the TLS protocol version, the negotiated cipher suite and the public certificate the server presents. No personal data is collected. Collected data and generated reports are stored encrypted, access is restricted to assigned personnel, and access is logged. The retention period is agreed in the consent form; data is destroyed at the end of that period and a destruction certificate is provided on request. The client may request immediate destruction at any time.
대상이 CDN 뒤에 있으면 결과가 정확합니까?Are results accurate if targets sit behind a CDN?
진단 대상이 CDN이나 리버스 프록시 뒤에 있는 경우 관측되는 TLS 설정은 해당 중개 서비스의 설정이며 오리진 서버의 설정이 아닐 수 있습니다. ADSAP은 이 사실을 보고서에 명시하고, CDN과 오리진 사이 구간을 별도로 점검하는 절차를 실행 지침에 포함합니다. 프론트 구간만 PQC이고 오리진 구간이 고전 암호이면 HNDL 노출이 남기 때문입니다.
Where targets sit behind a CDN or reverse proxy, the observed TLS configuration is the intermediary's and may not be the origin server's. ADSAP states this explicitly in the report and includes a separate procedure for checking the CDN-to-origin leg in the execution guidance, because HNDL exposure persists if only the front leg is PQC while the origin leg remains classical.
진단 과정 자체는 어떻게 통제됩니까?How is the assessment process itself controlled?
사람이 스크립트를 돌리는 방식이 아니라 통제된 파이프라인으로 수행합니다. 진단 작업은 승인 없이 실행되지 않으며, 실행 권한은 지정된 역할로 제한되고 접근은 인증을 거칩니다. 고객사 데이터는 다른 고객과 격리되어 저장되고, 요청 · 차단 · 완료 이벤트는 수행자와 시각과 함께 추가 전용 감사 로그에 기록되어 사후에 변경할 수 없습니다. 장시간 실행되는 작업은 중단되어도 상태가 유실되지 않도록 처리하며, 동일한 진단 데이터에서 한국어와 영어 보고서를 생성하므로 두 언어의 내용이 어긋나지 않습니다.
The work runs as a controlled pipeline rather than a person executing a script. No assessment runs without approval, execution is restricted to designated roles, and access is authenticated. Each client's data is stored in isolation from other clients, and requested, blocked and completed events are written to an append-only audit log with actor and timestamp, so they cannot be altered afterwards. Long-running work is handled so that state survives interruption, and Korean and English reports are generated from the same assessment data, so the two languages cannot drift apart.

전환은 인증서 갱신일에 시작됩니다. 그 날짜가 언제인지 아십니까?

Migration starts on a renewal date. Do you know when yours is?

파일럿 진단 및 도입 문의는 아래로 연락 주십시오. 대상 목록과 일정만 정해지면 착수할 수 있습니다.

For pilot assessments and deployment enquiries, contact us below. Work can begin as soon as the target list and schedule are agreed.