Skip to main content

DuoKey CPM (formerly PQC Scanner) — Overview

ScanTLS · X.509 · codeCBOMCycloneDX inventoryQuantum Risk Scoregrade exposureMigration planNIST IR 8413 · CNSA 2.0
Discover your cryptography, inventory it as a CBOM, score its quantum exposure, and plan the migration — aligned to NIST IR 8413 and CNSA 2.0.
Applies to:
CLITLS/SSL DiscoveryCBOM GenerationSource Code AnalysisCompliance CheckingServiceNow Integration

Introduction​

The DuoKey PQC Scanner is a high-performance Post-Quantum Cryptography (PQC) readiness assessment tool. It provides comprehensive cryptographic discovery and analysis across your entire infrastructure - from filesystem certificates and TLS endpoints to source code repositories and cloud KMS services.

The scanner evaluates quantum vulnerability using a 0-10 risk scoring scale with priority levels (P0-P4), generates CycloneDX 1.7 CBOM reports, checks compliance against 8+ frameworks (NIST, ISO 27001, PCI DSS, HIPAA, GDPR, FedRAMP, SOC 2), and integrates directly with ServiceNow for asset tracking and incident management.

Note
In the DuoKey Cockpit v2 the scanner lives under the PQC Readiness module. On top of the per-asset 0–10 risk score, it computes a composite Quantum Readiness Score (QRS, 0–100) for the whole scan — see QRS Scoring.

Quantum Readiness Dashboard in the DuoKey Cockpit

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are believed to be secure against attacks by both classical and quantum computers. In August 2024, NIST standardized the first set of PQC algorithms:

  • ML-KEM (FIPS 203) - Module-Lattice-Based Key-Encapsulation Mechanism, formerly CRYSTALS-Kyber
  • ML-DSA (FIPS 204) - Module-Lattice-Based Digital Signature Algorithm, formerly CRYSTALS-Dilithium
  • SLH-DSA (FIPS 205) - Stateless Hash-Based Digital Signature Algorithm, formerly SPHINCS+

CLI Commands​

The scanner exposes the following commands via the dke-scanner-agent binary:

CommandPurposeOutput Formats
filesystemScan local directories for certificates, keystores, and keysJSON, summary
domainClassic SSL/TLS audit of a remote endpoint; add --pqc for the PQ readiness reportreport, table, JSON, summary
sshDiscover SSH keys (ssh-agent, user keys, host keys) and classify themJSON, summary
inventoryOne-shot full host inventory: filesystem sweep + SSH keys, plus (Windows) cert store, installed apps, and registry crypto policyJSON, summary
source-codeStatic analysis of source code for cryptographic usage patternsJSON
ciCI/CD mode with SARIF output and fail-on-severity thresholdsJSON, SARIF
cbomExport findings as CycloneDX 1.7 Cryptographic Bill of MaterialsJSON
qrsCompute and render the Quantum Risk Score from a saved scan resulttext, JSON, HTML
cloudScan a cloud KMS (AWS KMS; Azure/GCP placeholder) for key materialJSON, summary
vaultScan a cockpit-managed vault for quantum-vulnerable keys (thin client)JSON
fortinetScan a FortiGate/FortiOS device via its REST APIJSON, summary
jfrogScan a JFrog Artifactory instance for cryptographic materialJSON, summary
terraformScan Terraform state and HCL for cryptographic resourcesJSON, summary
packet-captureOffline analysis of a .pcap/.pcapng file for TLS handshakes + PQ group usageJSON, summary (feature-gated)
networkLive capture from a network interface for TLS handshakes + PQ group usageJSON, summary (feature-gated)
agentRun as a persistent process reporting heartbeats to a DKE Cockpit server-
enrollFirst-time enrollment with a cockpit server-
upload-scanRun a one-shot TLS scan and upload the result to the cockpit-
Note

Packet capture (.pcap/.pcapng) analysis and live network capture are feature-gated — they require the pcap / pcap-live build features respectively. All other commands are fully implemented.

Scanning Capabilities​

From Run a Scan → Step 1 (Source) in the Cockpit you pick what to scan. Sources are grouped into Filesystem, Agent (host inventory), Network (Domain/TLS, TLS Probe, Network Live, Packet Capture), Code & Repos (Source Code, SSH Keys), Cloud / Vault, and SaaS / DevOps (JFrog Artifactory, Terraform IaC, Fortinet).

PQC Readiness — scan source selection

Filesystem Scanner

  • PEM, DER, PKCS#12/PFX, JKS/JCEKS certificates
  • Private key algorithm and size detection
  • Windows Certificate Store (LocalMachine, CurrentUser)
  • Configurable depth, extensions, exclusions

Domain Scanner

  • TLS handshake inspection (TLS 1.2/1.3)
  • Full certificate chain extraction
  • Cipher suite and key exchange detection
  • Subdomain discovery via WhoisXML API
  • Optional PQ key exchange detection (packet capture)

Source Code Scanner

  • 150+ detection rules across 8 languages
  • Java, Python, Go, Rust, C#, TypeScript, JavaScript, C/C++
  • GitHub, GitLab, Azure DevOps integration
  • SARIF output for CI/CD pipelines

Cloud Scanner

  • AWS KMS key inventory and algorithm analysis
  • Azure Key Vault enumeration
  • GCP Cloud KMS metadata retrieval
  • REST API-based (no SDK dependencies)

Risk Scoring​

Tip
This section covers the per-asset 0–10 score. For the scan-level Quantum Readiness Score (0–100) and its four signals, see QRS Scoring.

The scanner uses a 0-10 quantum risk scale with priority levels:

PriorityScoreSeverityAction TimelineExamples
P09.0-10.0CriticalImmediateRSA <2048, DSA, 3DES, RC4
P17.0-8.9HighWithin 3 monthsRSA-2048, ECDSA P-256, EdDSA
P25.0-6.9MediumWithin 6 monthsRSA-3072
P33.0-4.9LowWithin 12 monthsRSA-4096
P40-2.9InfoMonitorML-KEM, ML-DSA, SLH-DSA (PQC algorithms)

Output Formats​

FormatFlagUse Case
JSON--format jsonAPI integration, automation, programmatic processing
YAML--format yamlHuman-readable configuration and documentation
HTML--format htmlInteractive visual reports with embedded CSS
Terminal--format terminalANSI colored output with Unicode box drawing
SARIF--format sarifGitHub/GitLab security tabs (CI mode only)
CBOMdke-scanner-agent cbomCycloneDX 1.7 Cryptographic Bill of Materials

Compliance Engine​

Built-in compliance checking against 8+ regulatory frameworks:

NIST Standards

  • SP 800-52 (TLS Guidelines)
  • SP 800-131A (Cryptographic Standards)
  • CNSA 2.0 (NSA PQC guidance)

International Standards

  • ISO 27001 / 27002
  • ETSI Quantum-Safe
  • BSI TR-02102 (German PQC Migration)

Industry Compliance

  • PCI DSS v4.0
  • HIPAA (US Healthcare)
  • GDPR (EU Data Protection)

Audit Frameworks

  • SOC 2 Type II
  • FedRAMP
  • Custom PDF-based policies

ServiceNow Integration​

Direct integration with ServiceNow for centralized asset tracking and automated incident management.

ServiceNow Features

Asset Publishing

Push findings to custom CMDB tables

Auto-Incidents

Automatically create incidents for P0/Critical findings

Authentication

Basic Auth or OAuth Bearer tokens

Architecture​

The PQC Scanner uses a modular architecture: independent scanner modules feed a shared quantum risk-scoring engine and a common output layer, with an optional web dashboard for interactive review.

Target Infrastructure
TLS Endpoints
Dependencies
Source Code
Certificates
Keystores
Continuous scanning
PQC Scanner Engine

Cryptographic Discovery Engine

Multi-protocol scanning & deep inspection

Parallel analysis
Detection & Analysis Modules
TLS Version Analyzer

Protocol & cipher-suite detection

TLS 1.0–1.3
CBOM Generator

Cryptographic Bill of Materials

OpenSSLBouncyCastleCNG
Source Code Scanner

Vulnerable crypto-function detection

RSAECDSAAES
Certificate Inspector

X.509 algorithm & key-size analysis

RSA-2048ECDSA P-256
Keystore Scanner

Filesystem & Windows cert store

JKSPKCS#12TPM
Risk scoring
Quantum Risk Assessment

PQC Readiness Analyzer

Quantum Readiness Score (0–100) & per-asset prioritization

Comprehensive report

PQC Readiness Dashboard

Actionable insights & migration roadmap

Vulnerability Matrix+CBOM Export+Migration Plan
Key Scanner Capabilities

Automated Discovery

Network-wide crypto inventory

Continuous Monitoring

Real-time vulnerability tracking

Compliance Reports

NIST, BSI PQC standards

Migration Tracking

Progress monitoring & validation

Scanner Pipeline

1
CLI ParsingThe command, flags, and options are parsed from CLI arguments
2
Scanner ExecutionFilesystem, Domain, Agent, Source Code, or Cloud scanner runs
3
Parsing & AnalysisPEM/DER/PKCS#12/JKS parsers extract certificate metadata
4
Risk ScoringEach finding scored 0-10 with P0-P4 priority and recommendations
5
Output GenerationJSON, YAML, HTML, Terminal, CBOM, or SARIF report generated

Web Dashboard​

The interactive dashboard is the PQC Readiness module inside DuoKey Cockpit — dke-scanner-agent is a CLI/agent for running scans, not a standalone web server. Upload or push a scan result to the Cockpit to view it on the dashboard.

Dashboard Capabilities

Real-Time Visualization

Scan results with risk scoring and distribution charts

Authentication

Cockpit session authentication (SSO / password), same as the rest of the platform

REST API

Cockpit REST API for scans, findings, CBOMs and compliance

Use Cases​

Financial Services

PCI DSS 4.0 compliance with quantum risk assessment for payment systems

Healthcare

HIPAA compliance with 'harvest now, decrypt later' protection for PHI

Enterprise IT

Full crypto inventory across legacy systems, cloud KMS, and source code

Cloud Infrastructure

AWS KMS, Azure Key Vault, and GCP Cloud KMS quantum readiness

Government & Defense

CNSA 2.0 and FedRAMP compliance for classified systems

DevSecOps

CI/CD integration with SARIF output and fail-on-severity thresholds

System Requirements​

ComponentMinimumRecommended
Operating SystemWindows 10, Linux (Ubuntu 20.04+), macOS 11+Windows 11, Ubuntu 22.04+
Memory4GB RAM8GB RAM
Storage5GB available10GB SSD
NetworkOutbound HTTPS to scan targetsDedicated scanning network
Warning

Current estimates suggest large-scale quantum computers capable of breaking RSA-2048 and ECC P-256 could emerge in the 2030s. However, "harvest now, decrypt later" attacks are already a concern for long-lived sensitive data. Start your PQC assessment today!