Skip to main content

Module Architecture

Applies to:
PQC ScannerModule ArchitectureScanning Pipeline

Module overview​

The scanner is organized into a small set of functional areas that form a clear pipeline — from the command line, through scanning and analysis, to formatted output.

ModuleResponsibility
Command-line interfaceParse arguments, validate input, load configuration, initialize logging, and dispatch to a scanning mode
Core analysisDetect cryptographic algorithms and compute risk scores
ScannersImplement the scanning modes (agent, filesystem, domain, network)
ParsersRead the supported certificate, keystore, and configuration formats
OutputRender results as JSON, YAML, SARIF, or a terminal report
UtilitiesLogging, error handling, and platform-specific helpers

Core analysis​

Identifies the cryptographic algorithm used by a certificate and assesses its quantum vulnerability. It determines the algorithm family and key size, then returns a quantum-risk value. Recognized categories include RSA, ECDSA, DSA, Ed25519, 3DES, RC4, post-quantum (PQC) algorithms, and an "unknown" fallback for anything it cannot classify.

Turns each finding into a single risk score with a derived priority level (P0 Critical through P4 Info) and a short breakdown explaining how the score was reached. The detailed model is documented in QRS Scoring.

When a certificate is parsed, the following metadata is extracted and used throughout the rest of the pipeline:

FieldDescription
SubjectCertificate subject distinguished name
IssuerIssuer distinguished name
SerialCertificate serial number
Valid from / untilValidity period
AlgorithmDetected cryptographic algorithm
Key sizePublic key size
Quantum-vulnerableWhether the certificate is vulnerable to quantum attack

A reference list of known algorithms (keyed by object identifier) records each algorithm's name, category, quantum-vulnerability, and deprecation status.

Scanners​

Agent

Performs a full system scan of the local host: it inspects the operating-system certificate stores and, unless disabled, also examines running processes and the filesystem (with dedicated certificate-store handling for Linux, Windows, and macOS). All discovered items are aggregated into a single result.

Filesystem

Recursively walks a directory tree (with configurable depth and optional symlink following) and inspects files in parallel, routing each to the right parser by type: PEM/CRT/CER, DER, PKCS#12 (.p12/.pfx), and Java keystores (.jks/.jceks). Unrecognized files are skipped.

Domain

Connects to a target host and port over TLS, retrieves the presented certificate chain, analyzes each certificate, and can enumerate the cipher suites the server supports.

Network

Passively captures network traffic and reassembles TCP streams to extract TLS handshakes; capture and parsing run concurrently until a configured duration elapses or the scan is interrupted. Certificates seen in the handshakes are analyzed and reported.

Parsers​

Output​

Utilities​

Data model​

A scan produces a single result that bundles:

  • Scan metadata — scanner version, scan mode, date, host name, and duration.
  • Findings — each describes a discovered asset: an identifier, its type (certificate or keystore), its location, the extracted certificate information, and its risk assessment.
  • Statistics — aggregate counts across the findings.