PRODUCT MANUAL

QuantumSafe Discovery Studio
Technical usage guide

Discover cryptographic exposure from packet captures, certificates, software dependencies and declared CBOM data—then turn findings into an owned migration backlog.

OVERVIEW

QuantumSafe Discovery Studio

Organizations cannot prioritize PQC migration when algorithm use is hidden inside networks, certificate stores, code, appliances and supplier declarations.

WORKFLOW

  1. 01 Ingest PCAP/PCAPNG, certificates, manifests and CBOM
  2. 02 Normalize protocols, algorithms, keys and certificate facts
  3. 03 Correlate observed use with declared inventory
  4. 04 Classify classical-secure / quantum-vulnerable / quantum-ready
  5. 05 Assign owner, data lifetime and migration dependency
  6. 06 Publish risk heatmap, exceptions and remediation waves

COMPONENT REFERENCE

COMPONENT ARCHITECTURE

From raw cryptographic signals to a governed migration portfolio.

Three discovery engines run in parallel, then correlation, risk scoring and accountable remediation turn observations into governed action.

SOURCE INPUTS
PCAP / PCAPNGCertificatesSource codeCBOM / SBOM
Discovery & extraction layer
01

Network Capture Analyzer

Extracts endpoints, protocols and cryptographic handshakes from approved PCAP/PCAPNG captures without decrypting protected traffic.

PASSIVE ANALYSIS
02

Certificate & Trust Scanner

Inventories certificate chains, algorithms, validity, SAN/EKU facts and trust-store placement across approved sources.

TRUST INVENTORY
03

Software Crypto Scanner

Maps libraries, providers, packages and configuration references into a versioned cryptographic bill of materials.

SOFTWARE INSPECTION
04

Observed-vs-Declared Correlator

Compares operational observations with declared inventories and highlights unsupported, missing or stale cryptographic facts.

EVIDENCE CORRELATION
05

Quantum Risk Scoring

Prioritizes findings using secrecy horizon, verification lifetime, replacement lead time and external dependency.

POLICY ENGINE
06

Migration Portfolio Board

Assigns owners, remediation waves, exception dates, evidence requirements and closure criteria.

GOVERNED OUTPUT
GOVERNED OUTPUTS
Crypto inventoryExposure heatmapExceptionsRemediation waves

INTERFACES

  • PCAP/PCAPNG
  • X.509/PEM/DER
  • CycloneDX / SPDX extensions
  • CSV/JSON import-export
  • REST collector API
  • PDF/CSV executive reports

LIMITATIONS & ACCEPTANCE

  • Encrypted payloads are not decrypted; classification depends on observable metadata and approved parsers.
  • Discovery results are time-bounded and must be refreshed after material network or application change.
  • A finding is not a vulnerability determination until confirmed by the system owner and supporting evidence.