A cryptographic discovery and analysis tool for security teams that scans code and binaries to inventory cryptographic assets, assess quantum risks, and recommend post-quantum alternatives.
National Technical Research Organisation (NTRO) · Software
Signing in saves it for your whole team — everyone on your invite link sees the same two entries. Anything you shortlisted while signed out comes with you.
Decomposed from what the description asks for. Nothing added.
Asset Discovery Scanner
Scans source code repositories, binaries, libraries, and container images to identify cryptographic artefacts.
Quantum Risk Engine
Performs comprehensive quantum risk assessments on identified systems and classifies assets using Mosca's algorithm.
Classification Module
Classifies all discovered cryptographic artefacts by type, lifetime, and business criticality.
Alternative Recommender
Recommends suitable post-quantum or hybrid cryptographic alternatives based on risk profile, latency, and cost.
Reporting and GUI Dashboard
Provides an interactive graphical user interface to visualise scans and risks, and produces standardized reports.
Both columns are read off the brief's own wording. Nothing here is inferred from the ministry's name.
The evaluators will check if your tool can successfully scan various targets like source code, binaries, and container images, correctly apply Mosca's algorithm for risk assessment, and display the results clearly in an interactive GUI along with a standardized report.
A jury can still ask about these. Decide them deliberately rather than by accident.
Generated from the brief's own wording and the competition's published rules — never from a guess about what this ministry prefers.
Specific supported programming languages and binary formats?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Target standardized formats for the report?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Specific post-quantum cryptographic algorithms to include in recommendations?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Has any part of this been shown at a previous event, hackathon or college project?
The guidelines are explicit: your solution must not have appeared in any previous event or programme, of any sort. A recycled project is what a team under time pressure reaches for.
What the organisers attached, and what the brief assumes you can get.
Same organisation, same year. Reading two of theirs tells you more about what they care about than reading one.
Pick what you are about to do and copy the prompt. It carries the organisers' own wording, the constraints they never spell out, and an instruction not to invent requirements they never set.
Who has this problem, what already exists, and what you would have to find out.
The brief asks for asset discovery scanner. How would you build that?
Decoded from SIH26164 itself — Scans source code repositories, binaries, libraries, and container images to identify cryptographic artefacts. The brief asks for it by name.
The brief asks for quantum risk engine. How would you build that?
Decoded from SIH26164 itself — Performs comprehensive quantum risk assessments on identified systems and classifies assets using Mosca's algorithm. The brief asks for it by name.
The brief asks for classification module. How would you build that?
Decoded from SIH26164 itself — Classifies all discovered cryptographic artefacts by type, lifetime, and business criticality. The brief asks for it by name.
The brief asks for alternative recommender. How would you build that?
Decoded from SIH26164 itself — Recommends suitable post-quantum or hybrid cryptographic alternatives based on risk profile, latency, and cost. The brief asks for it by name.
The brief asks for reporting and gui dashboard. How would you build that?
Decoded from SIH26164 itself — Provides an interactive graphical user interface to visualise scans and risks, and produces standardized reports. The brief asks for it by name.
Why not use what already exists? Name the closest thing to this that is already running.
A team that has not named the alternative themselves is answering this for the first time in the room.
Which single thing will you demonstrate end to end, start to finish, with nothing skipped?
Ours, not a rule: a narrow thing that fully works survives questioning better than a broad thing that half works. If nobody on the team can name it, that is the finding.
Show me this working: the evaluators will check if your tool can successfully scan various targets like source code, binaries, and container images, correctly apply Mosca's algorithm for risk assessment, and display the results clearly in an interactive GUI along with a standardized report.
This is the evaluator read for your problem statement, decoded from the brief's own wording.