IP Library Granted Patent US 12,556,380
Granted Patent B2
US 12,556,380 · App. 18/383,249 · Granted Feb 17, 2026

Method for analyzing quantum vulnerability and system therefor

Inventors: Eun Kyung Kim (Seoul, KR); Chang Hoon Lee (Seoul, KR); Hyo Jin Yoon (Seoul, KR); Ji Hoon Cho (Seoul, KR)
Assignee: SAMSUNG SDS CO., LTD.
H04L9/0852G06F21/577H04L9/30G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,380
App. No.
18/383,249
Granted
Feb 17, 2026
Kind
B2
Abstract

Provided are a method for analyzing quantum vulnerability and a system therefor. The method according to some embodiments may include configuring quantum-vulnerable algorithm detection rule based on a type of encryption algorithm, configuring an analysis level for analyzing a quantum vulnerability of target software, from among a plurality of predefined analysis levels, analyzing the target software based on the configured quantum-vulnerable algorithm detection rule, using an analysis technique corresponding to the configured analysis level, and assessing the quantum vulnerability of the target software based on a result of the analyzing.

Claims (72)

1 . A method for analyzing quantum vulnerability performed by at least one computing device, the method comprising:

configuring quantum-vulnerable algorithm detection rule based on a type of encryption algorithm;

configuring an analysis level for analyzing a quantum vulnerability of target software, from among a plurality of predefined analysis levels;

analyzing the target software based on the configured quantum-vulnerable algorithm detection rule, using an analysis technique corresponding to the configured analysis level; and

assessing the quantum vulnerability of the target software based on a result of the analyzing,

wherein the analyzing the target software comprises identifying whether functions related to a quantum-vulnerable algorithm are called in a source code of the target software using the configured quantum-vulnerable algorithm detection rule.

2 . The method of claim 1 , wherein the configured quantum-vulnerable algorithm detection rule is defined further based on a key size of the encryption algorithm.

3 . The method of claim 1 , wherein the plurality of predefined analysis levels comprise a source code level, a library level, an application level, and a network level.

4 . The method of claim 1 , wherein

the configured analysis level corresponds to a source code level and a library level, and

the analyzing the target software comprises:

performing static analysis on source code of the target software; and

performing binary analysis on a library referenced in the target software.

5 . The method of claim 1 , wherein

the configured analysis level corresponds to an application code level and a network level, and

the analyzing the target software comprises:

performing dynamic analysis and network analysis on the target software.

6 . The method of claim 1 , wherein

the configured analysis level corresponds to a source code level, and

the analyzing the target software comprises:

extracting functions or classes used in source code of the target software through static analysis; and

analyzing a quantum vulnerability of the source code by applying the configured quantum-vulnerable algorithm detection rule to the extracted functions or classes.

7 . The method of claim 1 , wherein

the configured analysis level corresponds to an application level, and

the analyzing the target software comprises:

measuring memory usage per function or class by analyzing an execution memory of the target software through dynamic analysis;

determining functions or classes used in the target software during execution based on the measured memory usage per function or class; and

analyzing the quantum vulnerability of the target software by applying the configured quantum-vulnerable algorithm detection rule to the determined functions or classes.

8 . The method of claim 1 , wherein

the configured analysis level includes first level and second level, and

the assessing the quantum vulnerability of the target software comprises:

calculating a first quantum vulnerability score based on an analysis result corresponding to the first level;

calculating a second quantum vulnerability score based on an analysis result corresponding to the second level; and

calculating the quantum vulnerability of the target software by aggregating the first and second quantum vulnerability scores based on weights.

9 . The method of claim 8 , wherein

the first level is a source code level,

the second level is an application level or a network level, and

a weight applied to the second quantum vulnerability score is determined to be greater than a weight applied to the first quantum vulnerability score.

10 . The method of claim 8 , wherein weights applied to the first quantum vulnerability score and second quantum vulnerability score are determined based on reliabilities of analysis tools used in analyses at the first level and the second level.

11 . The method of claim 1 , wherein

the result of the analyzing comprises a result of analysis of a plurality of analysis items included in the configured analysis level, and

the assessing the quantum vulnerability of the target software comprises:

calculating vulnerability scores for the analysis items; and

calculating a quantum vulnerability score for the target software by aggregating the calculated vulnerability scores based on an item-specific weight.

12 . The method of claim 11 , wherein

among the analysis items, a specific item relates to a type of a quantum-vulnerable algorithm used by the target software or whether the quantum-vulnerable algorithm is used by the target software, and

a weight for the specific item is determined based on a key size of the quantum-vulnerable algorithm.

13 . The method of claim 11 , wherein

the result of the analysis of the analysis items includes timestamp when usage of the quantum-vulnerable algorithm is detected within the target software, and

the item-specific weight is determined based on a result of comparison of the timestamp.

14 . The method of claim 1 , further comprising:

extracting information on hosts communicating with the target software through network analysis of the target software when the configured analysis level is a network level.

15 . The method of claim 1 , wherein

the configured analysis level is other than a network level, and

further comprising:

extracting information on host communicating with the target software by performing network analysis on the target software when a quantum vulnerability score for the target software, obtained as a result of the assessment, is equal or greater than a threshold value; and

providing the extracted information.

16 . A system for analyzing quantum vulnerability comprising:

at least one physical processor; and

a memory configured to load a computer program executable by the at least one physical processor; and

wherein the computer program comprises instructions for performing:

configuring quantum-vulnerable algorithm detection rule based on a type of encryption algorithm;

configuring an analysis level for analyzing a quantum vulnerability of target software, from among a plurality of predefined analysis levels;

analyzing the target software based on the configured quantum-vulnerable algorithm detection rule, using an analysis technique corresponding to the configured analysis level; and

assessing the quantum vulnerability of the target software based on a result of the analysis,

wherein the analyzing the target software comprises identifying whether functions related to a quantum-vulnerable algorithm are called in a source code of the target software using the configured quantum-vulnerable algorithm detection rule.

17 . A non-transitory computer-readable recording medium storing computer program, which, when executable by at least one processor, causes the at least one processor to execute the steps comprising:

configuring quantum-vulnerable algorithm detection rule based on a type of encryption algorithm;

configuring an analysis level for analyzing a quantum vulnerability of target software, from among a plurality of predefined analysis levels;

analyzing the target software based on the configured quantum-vulnerable algorithm detection rule, using an analysis technique corresponding to the configured analysis level; and

assessing the quantum vulnerability of the target software based on a result of the analysis,

wherein the analyzing the target software comprises identifying whether functions related to a quantum-vulnerable algorithm are called in a source code of the target software using the configured quantum-vulnerable algorithm detection rule.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2023
From: KIM, EUN KYUNG; LEE, CHANG HOON; YOON, HYO JIN; CHO, JI HOON
To: SAMSUNG SDS CO., LTD.
Reel/Frame 065335/0638 →
Priority Claims (1)
KR 10-2023-0041402 · Mar 29, 2023 · national
Continuity (1)
Related Publication 20240333484A1 · Oct 3, 2024
References Cited (10)
US 11265159B1 · Truskovsky et al. · 2022 [cited by applicant]
US 11334667B1 · Ramanathan et al. · 2022 [cited by applicant]
US 11411979B2 · Bulut et al. · 2022 [cited by applicant]
US 11477016B1 · Carter, Jr. et al. · 2022 [cited by applicant]
US 12200116B1 · Rao · 2025 [cited by examiner]
US 20220108010A1 · Bishop, III et al. · 2022 [cited by applicant]
KR 1020180010053A · 2018 [cited by applicant]
Communication issued on Mar. 26, 2024 by the European Patent Office for European Patent Application No. 23205081.5. [cited by applicant]
Joseph J. Kearneya et al., “Vulnerability of blockchain technologies to quantum attacks”, arXiv:2105.01815v1, [quant-ph], May 5, 2021, 16 pages. [cited by applicant]
Raj Badhwar, “The CISO's Next Frontier: AI, Post-Quantum Cryptography and Advanced Security Paradigms”, Springer, 2021, 398 pages, https://doi.org/10.1007/978-3-030-75354-2. [cited by applicant]