Skip to main content

Architecture Overview

Applies to:
PQC ScannerLinuxmacOSWindows

Introduction​

The DuoKey PQC Scanner is a comprehensive Post-Quantum Cryptography (PQC) readiness assessment tool for high-performance, cross-platform cryptographic asset discovery and analysis.

High-Level Architecture​

PQC Scanner Architecture

High-performance Rust CLI for post-quantum cryptographic discovery and risk assessment

Ffilesystem
Ddomain
Aagent
Nnetwork
Ssourcecode
Ccompliance
Wserve
Ici
Nservicenow
Bcbom
Clap 4.5Tokio Async10 Subcommands
Command Dispatch
▼

Infrastructure Scanners

Async I/O
Filesystem
PEM, DER, JKS, PKCS#12
Domain / TLS
Rustls handshake capture
Agent
System-wide inventory
Network
Passive packet capture
+
SCAN

Advanced Scanners

Extensible
Source Code
150+ rules, 8 languages
Cloud KMS
AWS, Azure, GCP
SSH Keys
Host key algorithms
Compliance
8+ frameworks
Raw Cryptographic Data
▼
Parser Layer
PEM
x509-parser
DER
x509-parser
PKCS#12
x509-parser
Win Store
schannel
CBOM
serde
▼
Crypto Detector
Algorithm identification via OID lookup
RSAECDSADSAEd25519PQC
Risk Scorer
7-factor weighted quantum vulnerability score
P0
P1
P2
P3
P4
Scored Findings
▼
Output Formatters
{}
JSON
Machine-readable
Ym
YAML
Human-readable
<>
HTML
Stakeholder reports
>>_
Terminal
ANSI color output
Cd
CycloneDX
CBOM 1.7 export
Sr
SARIF
CI/CD integration
Report Generated
▼

PQC Readiness Assessment

Complete cryptographic inventory with quantum vulnerability scoring and migration roadmap

Discovery+Risk Score= Quantum-Ready
Single Binary
Native executable per platform, no runtime deps
Async-First
Tokio for I/O, Rayon for CPU-bound work
Zero OpenSSL
Pure Rust TLS via Rustls, no C deps
Modular Scanners
Each command is independent and extensible

Architecture Flow​

1

CLI Entry Point

Parses one of the scanner's subcommands (filesystem, domain, inventory, source-code, ci, cbom, qrs, ssh, fortinet, jfrog, terraform, cloud, vault, agent, enroll, upload-scan, and feature-gated packet-capture / network). Validates inputs and dispatches to the corresponding scanner.

2

Scanner Execution

The selected scanner collects raw cryptographic data -- TLS handshakes, certificate files, source code patterns, cloud KMS metadata, or SSH host keys. Scanners run concurrently and parallelize file traversal where applicable.

3

Parser Layer (PEM / DER / PKCS#12)

Raw data is fed to format-specific parsers that extract certificate metadata, key algorithms, and signature schemes.

4

Risk Scoring (0-10)

Each parsed finding passes through the risk scorer, which assigns a quantum risk score from 0 to 10, maps it to a severity level (Critical through Info), assigns a priority (P0-P4), and generates recommendations.

5

Output Formatting

The scored result is serialized by the chosen output formatter -- JSON, YAML, HTML, ANSI terminal, or CycloneDX 1.7 CBOM -- and written to file or stdout.

Module Architecture​

The scanner is organized into distinct functional areas, each with a focused responsibility:

AreaResponsibility
CLICommand-line parsing and command dispatch
CoreCrypto algorithm detection, quantum risk scoring, X.509 operations, and the crypto algorithms database
ScannersOne module per scan kind -- host inventory, filesystem, domain/TLS, source code, SSH, Fortinet, JFrog, Terraform, cloud KMS, vault, and (feature-gated) offline packet capture / live network capture
ParsersFormat parsers for JKS, PKCS#12, PEM, DER, and nginx/apache configuration files
OutputOutput formatters -- JSON, YAML, SARIF (for CI/CD), and terminal
UtilitiesLogging, error handling, and OS-specific helpers

Core Scanning Modes​

The scanner covers several discovery scenarios; these four are the most commonly used entry points (see CLI Reference for the full command list):

Quantum Risk Scoring Algorithm​

The scanner uses a multi-criteria scoring system that blends several weighted factors into a final score from 0 to 100, which is then mapped to a priority level. The factors and their weights are:

FactorWeight
Quantum risk30%
Business criticality25%
Data sensitivity20%
Exposure10%
Compliance10%
Migration complexity3%
Migration cost2%

The resulting score is mapped to one of five priority levels:

PriorityMeaningRecommended action
P0CriticalImmediate action required
P1HighAction within 3 months
P2MediumAction within 6 months
P3LowAction within 12 months
P4InfoMonitor

Vulnerable Algorithms Detected

AlgorithmKey SizeQuantum Risk ScoreSeverity
RSA< 2048-bit10/10Critical
RSA2048-bit8/10High
RSA3072-bit6/10Medium
RSA4096-bit4/10Medium
ECDSAP-2568/10High
ECDSAP-3847/10High
ECDSAP-5216/10Medium
DSAAny9/10Critical
3DESN/A10/10Critical
RC4N/A10/10Critical

Output Formats​

The scanner supports multiple output formats for different use cases:

The default machine-readable format. Each JSON report contains the scan metadata, the list of findings, a risk summary, and a set of recommendations.

Performance Characteristics​

Scalability

  • TLS Endpoints: Can scan thousands per hour
  • Filesystem: Processes 100K+ files efficiently with parallel scanning
  • Memory: Low memory footprint (<100MB typical)
  • CPU: Multi-threaded for optimal performance

Benchmarks

Filesystem scanning is highly efficient; throughput is environment-dependent — as an indicative figure, on the order of 1,000 PEM certificates process in tens of milliseconds.

Cross-Platform Support​

PlatformStatusNotes
LinuxFull SupportPreferred platform, all features
macOSFull SupportIntel & Apple Silicon
WindowsFull SupportWindows 10/11, Server 2019+

Integration Capabilities​

The scanner can be embedded as a library. A caller configures a scan -- choosing the mode (for example, domain), the targets, and the output format -- runs it, and reads back the results, including the overall PQC readiness score.

Security Considerations​

Privilege Requirements

ModePrivilege Required
Agent ModeRequires root/admin for full system access
Network ModeRequires CAP_NET_RAW or equivalent
Filesystem ModeStandard user privileges sufficient
Domain ModeStandard user privileges sufficient

Data Protection

Important

Private keys are never extracted or exported. Only metadata and public information are collected. All network communication is encrypted (TLS 1.3). Audit logging is enabled for all operations.

Next Steps​