ADSAP은 조직의 외부 TLS 암호자산을 읽기 전용으로 식별하고, 자산별 양자 위험도와 전환 우선순위, 그리고 실제로 전환을 시작할 수 있는 시점을 제시하는 PQC 전환 진단 플랫폼입니다. 오픈소스 스캐너가 값을 출력한다면, ADSAP은 그 값이 무엇을 뜻하고 무엇부터 해야 하는지를 답합니다.
ADSAP identifies an organisation's external TLS cryptographic assets read-only, then reports per-asset quantum risk, migration priority, and the point at which migration can actually begin. Open-source scanners print values. ADSAP answers what those values mean and what to do first.
제공 형태 · 고객이 지정한 외부 TLS 엔드포인트 최대 20개를 대상으로 진단하고, 한국어 · 영어 보고서와 90일 실행계획, 결과 브리핑을 제공합니다. 자산 수가 5개 이하이거나 20개를 넘는 경우 별도로 협의합니다.
What you get · We assess up to 20 external TLS endpoints you designate, and deliver Korean and English reports, a 90-day execution plan and a results briefing. Engagements of five or fewer, or more than twenty, are scoped separately.
조직에서 사용 중인 주요 TLS 암호 알고리즘을 선택해 위험 등급과 NIST 대체 표준, 권장 조치 방향을 확인하세요.
Select an encryption algorithm currently deployed in your organisation to inspect its quantum risk, NIST FIPS replacement, and recommended action track.
HNDL(Harvest Now, Decrypt Later)은 공격자가 지금 암호화된 통신을 저장해 두었다가 나중에 소급 해독하는 방식입니다. 저장은 오늘 일어납니다. 그러므로 방어도 오늘이어야 합니다. 내일 암호를 바꿔도 오늘 저장된 트래픽은 보호되지 않습니다.
Under HNDL (harvest now, decrypt later), an adversary stores encrypted traffic today and decrypts it retroactively. Collection happens now, so defence has to happen now. Changing algorithms tomorrow does not protect traffic captured today.
RSA는 소인수분해, ECDSA와 ECDH는 타원곡선 이산로그 문제에 안전성을 의존합니다. Shor 알고리즘은 두 문제를 모두 다항시간에 해결합니다. 개별 알고리즘의 결함이 아니라 공개키 암호 전체가 동시에 영향을 받습니다. 키 길이를 늘려서 해결되지 않습니다.
RSA relies on integer factorisation; ECDSA and ECDH on the elliptic-curve discrete logarithm. Shor's algorithm solves both in polynomial time. This is not a flaw in one algorithm: public-key cryptography is affected as a class, and longer keys do not fix it.
계약 문서처럼 10년 보존 의무가 걸린 데이터는 오늘 수집되면 2036년에도 유효합니다. 반면 공개 웹 콘텐츠는 애초에 기밀성 요구가 없습니다. 같은 알고리즘을 쓰더라도 자산마다 실질 위험이 다르며, 우선순위는 여기서 갈립니다.
Data under a ten-year retention obligation, such as contract records, is still meaningful in 2036 if captured today. Public web content has no confidentiality requirement at all. The same algorithm carries different real exposure per asset, and that is where priority is decided.
NIST IR 8547 초안은 양자 취약 공개키 알고리즘을 2030년 이후 사용 중단, 2035년 이후 사용 금지 대상으로 제시합니다. 국내에서도 2023년 「양자내성암호 마스터플랜」이 2035년 국가 암호체계 전환 목표를 명시했습니다. 이제 기술 선택이 아니라 일정 준수 사안입니다.
The draft NIST IR 8547 deprecates quantum-vulnerable public-key algorithms after 2030 and disallows them after 2035. In Korea, the 2023 PQC Master Plan sets a 2035 national transition target. This is no longer a technology choice; it is schedule compliance.
진단의 가치는 데이터 수집이 아니라 해석에 있습니다. 아래는 ADSAP 보고서가 실제로 답하는 질문들입니다.
The value of an assessment lies in interpretation, not collection. These are the questions an ADSAP report actually answers.
| 항목 | Item | 일반 TLS 스캐너 | Generic TLS scanner | ADSAP PQC 전환 진단 | ADSAP PQC assessment |
|---|---|---|---|---|---|
| 알고리즘 식별 | Algorithm identification | 가능 | Yes | 가능 | Yes |
| PQC 표준 매핑 | Mapping to PQC standards | 없음 | No | FIPS 203/204/205 기준 대체 알고리즘 지정 | Replacement algorithm named per FIPS 203/204/205 |
| 자산별 우선순위 | Per-asset prioritisation | 없음. 모든 자산이 동일하게 표시 | None. All assets look identical | Shor · Grover · HNDL 가중 점수로 등급 분화 | Graded by a weighted Shor / Grover / HNDL score |
| 업무 맥락 반영 | Business context | 불가 | Not possible | 데이터 민감도 · 보존 수명을 입력값으로 반영 | Data sensitivity and retention life taken as inputs |
| 실행 창구 제시 | Execution window | 만료일 나열에 그침 | Lists expiry dates only | 갱신 주기를 전환 창구로 해석해 웨이브 계획 수립 | Reads the renewal cycle as a migration window and plans waves |
| 배경 · 용어 설명 | Background and terminology | 없음 | None | HNDL, Shor, ML-KEM/ML-DSA/SLH-DSA 해설 포함 | Includes HNDL, Shor, ML-KEM / ML-DSA / SLH-DSA explanations |
| 검증 가능한 조치 | Verifiable actions | 없음 | None | 단계별 조치와 검증 명령·확인 방법을 함께 기술 | Each step paired with a verification command or method |
| 운영 통제 | Operational controls | 실행자 재량 | At the operator's discretion | 승인 게이트 · 역할 분리 · 감사 로그 · 테넌트 격리 | Approval gates, role separation, audit logs, tenant isolation |
보고서는 한국어와 영어로 각각 PDF와 DOCX로 제공됩니다. 구성은 다음과 같습니다.
Reports are delivered in Korean and English, each as PDF and DOCX. The structure is as follows.
전환 대상 범위, 최우선 자산, 가장 이른 실행 창구, 즉시 조치와 대기 조치의 구분을 1페이지로 정리합니다. 예산 결재 문서에 그대로 인용할 수 있는 형태입니다.
Scope, highest-priority assets, earliest execution window, and the split between act-now and wait items, on one page. Written to be quoted directly into a budget approval.
HNDL이 무엇이고 왜 지금인지, Shor 알고리즘이 ECDSA에 무엇을 하는지, ML-KEM · ML-DSA · SLH-DSA가 각각 어디에 쓰이는지를 설명합니다. 용어만 던지고 검색을 시키지 않습니다.
What HNDL is and why it matters now, what Shor's algorithm does to ECDSA, and where ML-KEM, ML-DSA and SLH-DSA each apply. Terms are explained, not just cited.
자산별 TLS 버전, 암호 스위트, 공개키 알고리즘과 키 길이, 인증서 발급자 · 주체 · 유효기간 · 잔여일수를 표로 제공합니다. 전사 암호자산 대장의 출발점이 됩니다.
Per asset: TLS version, cipher suite, public key algorithm and size, certificate issuer, subject, validity and days remaining. The starting point for an enterprise cryptographic register.
Shor · Grover · HNDL 가중 점수와 우선순위 등급, 그리고 그 점수가 나온 근거(민감도, 데이터 수명)를 자산별로 명시합니다. 계산은 재현 가능하며 입력값을 바꾸면 결과가 바뀝니다.
Weighted Shor / Grover / HNDL scores and priority bands, with the inputs behind each score (sensitivity, data lifetime) stated per asset. The calculation is reproducible and responds to changed inputs.
인증서 만료일을 관리 항목이 아니라 전환 기회로 해석합니다. 같은 날짜에 묶인 자산을 군집화하고, 위험도와 창구를 결합해 웨이브 단위 실행 순서를 만듭니다.
Certificate expiry dates are read as migration opportunities, not administrative fields. Assets are clustered by shared expiry, then risk and window are combined into a wave-based execution order.
“담당자 확인”은 조치가 아닙니다. 각 단계마다 무엇을 바꾸고, 그것이 실제로 적용되었는지 어떤 명령이나 화면으로 확인하는지를 함께 기술합니다.
"Confirm the owner" is not a remediation step. Each step states what changes and which command or screen confirms that the change took effect.
5단계 전환 성숙도 모델에서 조직의 현재 위치를 판정하고, 국가 전환 로드맵 및 NIST 일정 대비 어디에 서 있는지를 제시합니다. 다음 단계 진입 조건도 함께 명시합니다.
Places the organisation on a five-stage transition maturity model and against the national roadmap and NIST timeline, including what is required to reach the next stage.
진단하지 않은 영역을 분명히 적습니다. 외부 TLS 표면은 전체 암호자산의 일부이며, 보고서는 다루지 않은 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.
States plainly what was not assessed. The external TLS surface is a subset of the estate, and the report makes no claim about the security of areas outside it.
ADSAP은 승인 게이트, 역할 기반 권한, 테넌트 격리, 추가 전용 감사 로그를 갖춘 에이전트 오케스트레이션 플랫폼입니다. 진단의 모든 단계가 기록되며 재현 가능합니다.
ADSAP is an agent orchestration platform with approval gates, role-based access, tenant isolation and an append-only audit log. Every stage of an assessment is recorded and reproducible.
동의서 별지에 기재된 host:port 목록만 대상으로 등록됩니다. 목록 외 자산은 어떤 경우에도 접근하지 않습니다.
Only the host:port list recorded in the consent form annex is registered. Nothing outside that list is ever contacted.
사설·루프백·링크로컬·멀티캐스트·예약 주소 대역, 허용되지 않은 포트, 도메인 허용목록 위반을 차단하고 사유를 감사 로그에 기록합니다.
Private, loopback, link-local, multicast and reserved ranges, disallowed ports and allowlist violations are blocked, with the reason written to the audit log.
TLS 핸드셰이크를 수립해 서버가 제시하는 공개 정보만 수집합니다. 동시 실행과 전체 시간 예산이 제한되어 대상에 부하를 주지 않습니다.
Establishes a TLS handshake and collects only the public information the server presents. Concurrency and a total time budget are bounded so targets are not loaded.
Shor 취약성, Grover 영향, HNDL 노출도를 가중합해 자산별 점수와 우선순위를 산출하고 표준 대체 알고리즘을 매핑합니다.
Combines Shor vulnerability, Grover impact and HNDL exposure into a weighted per-asset score and priority, and maps the standard replacement algorithm.
한국어·영어 PDF와 DOCX를 생성하고, 산출물 메타데이터와 생성 이력을 감사 로그에 남깁니다.
Generates Korean and English PDF and DOCX, and records artifact metadata and generation history in the audit log.
지정된 host:port에 TLS 연결을 수립하고 즉시 종료합니다. 프로토콜 버전, 협상된 암호 스위트, 서버가 제시하는 공개 인증서 정보만 읽습니다. 대상 1건당 연결 시도는 통상 수 회 이내입니다.
Establishes a TLS connection to the designated host:port and closes it immediately. Reads only the protocol version, negotiated cipher suite and the public certificate the server presents. Typically a small number of connection attempts per target.
인증 시도, 로그인 시도, 자격증명 입력, 취약점 공격, 침투 시도, 데이터 변경·삭제·삽입, 서비스 거부를 유발할 수 있는 부하 발생, 대량·고빈도 요청. 개인정보는 수집하지 않습니다.
No authentication or login attempts, no credential submission, no exploitation or intrusion, no data modification, deletion or insertion, no load that could cause denial of service, and no high-volume or high-frequency requests. No personal data is collected.
사설, 루프백, 링크로컬, 멀티캐스트, 예약 주소 대역은 코드 수준에서 차단됩니다. 허용 포트와 도메인 허용목록을 테넌트별로 설정할 수 있으며, 위반 시 실행 전에 차단되고 사유가 기록됩니다.
Private, loopback, link-local, multicast and reserved address ranges are blocked at code level. Allowed ports and a domain allowlist are configurable per tenant; violations are blocked before execution and the reason is recorded.
전역 동시 실행 수, 호스트당 동시 실행 수, 전체 시간 예산이 제한됩니다. 예산을 초과한 대상은 강제 종료되고 결과에 사유가 표기되므로, 진단이 대상 서비스에 영향을 주지 않습니다.
Global concurrency, per-host concurrency and a total time budget are bounded. Targets exceeding the budget are terminated and flagged in the results, so the assessment does not affect the target service.
본 진단은 외부 TLS 표면에 한정된 간이 PQC 전환 진단입니다. 아래는 범위에 포함되지 않으며, 보고서는 이들 영역의 안전성에 대해 어떤 판단도 제시하지 않습니다.
This is a focused PQC transition assessment limited to the external TLS surface. The following are out of scope, and the report makes no claim about the security of these areas.
실제 진단 결과에서 고객사명과 호스트명만 마스킹한 발췌본입니다. 표지, 경영진 요약, 위험 우선순위 표, 갱신 창구 분석까지 포함되어 있어 분석의 깊이를 그대로 확인하실 수 있습니다. 수치는 가공하지 않았습니다.
An excerpt from a real assessment with only the client name and hostnames masked. It includes the cover, executive summary, risk priority table and renewal window analysis, so the depth of the analysis is visible as delivered. The figures are unaltered.
표지, 경영진 요약 4개 결론, 자산별 위험 우선순위, 인증서 갱신 창구 분석
Cover, four executive conclusions, per-asset risk priority, certificate renewal window analysis
배경과 용어, 방법론과 점수 공식, 트랙별 실행 지침과 검증 방법, 성숙도 판정, 범위 제한, 출처 부록까지 포함
Background and terminology, methodology and the scoring formula, per-track execution guidance with verification steps, maturity assessment, scope limits and a sourced appendix
한국어와 영어 각각 PDF와 DOCX로 제공합니다. 두 언어는 동일한 진단 데이터에서 생성되므로 수치가 어긋나지 않습니다.
Delivered as PDF and DOCX in both Korean and English. Both languages are generated from the same assessment data, so figures cannot diverge.
진단 목적, 대상 범위, 수행 시간대를 협의합니다. 대상이 CDN 뒤에 있는지, 오리진 설정 관리 주체가 누구인지를 이 단계에서 확인합니다.
Agree on objectives, scope and execution window. Confirm at this stage whether targets sit behind a CDN and who manages origin configuration.
진단 범위, 수행·미수행 행위, 데이터 처리와 보관 기간, 중지 요청 절차를 문서로 확정합니다. 고객은 진단 중 언제든 중지를 요청할 수 있습니다.
Scope, permitted and prohibited actions, data handling and retention, and the stop-request procedure are fixed in writing. The client may request a halt at any point.
고객이 별지 양식으로 host:port 목록을 제출합니다. 목록에 없는 자산은 어떤 경우에도 진단 대상이 되지 않습니다.
The client submits the host:port list on the annex form. Assets not on the list are never assessed.
자산별 데이터 민감도와 보존 수명을 입력받습니다. 이 값이 우선순위를 가르는 핵심 입력이며, 없으면 추정값을 사용하고 보고서에 추정임을 명시합니다.
Per-asset data sensitivity and retention life are collected. These inputs drive prioritisation; where unavailable, estimates are used and clearly marked as such in the report.
승인 후 읽기 전용 진단이 실행됩니다. 요청부터 완료까지 모든 이벤트가 감사 로그에 기록됩니다.
The read-only assessment runs after approval. Every event from request to completion is written to the audit log.
한국어·영어 PDF와 DOCX를 인도하고 결과 브리핑을 진행합니다. 질의는 브리핑 이후에도 받습니다.
Korean and English PDF and DOCX are delivered, followed by a results briefing. Questions are taken after the briefing as well.
파일럿 진단 및 도입 문의는 아래로 연락 주십시오. 대상 목록과 일정만 정해지면 착수할 수 있습니다.
For pilot assessments and deployment enquiries, contact us below. Work can begin as soon as the target list and schedule are agreed.