Cryptographic Implementation Security Consulting
Cryptographic Implementation Security Consulting
I provide independent security reviews for cryptographic implementations, post-quantum cryptography, and security-critical C/C++ software.
Crypto Implementation Review
C/C++ cryptographic libraries, protocol implementations, memory safety, constant-time properties, implementation correctness.
PQC Implementation Security Review
ML-KEM / ML-DSA implementations, arithmetic bounds, reduction placement, constant-time behavior, interoperability, and implementation-specific security assumptions.
Vulnerability Validation & Root-Cause Analysis
Independent validation of reported findings, PoC development, exploitability assessment, root-cause analysis, remediation review, and regression testing.
My security research has involved production cryptographic software and widely deployed implementations, including wolfSSL, OpenSSL, Bouncy Castle, Microsoft SymCrypt, and post-quantum cryptographic implementations such as ML-DSA and ML-KEM.
My work includes vulnerability discovery and validation, coordinated disclosure, root-cause analysis, regression testing, implementation-level security analysis, and formal or automated reasoning using techniques such as SMT solving and Coq.
Research and selected security work are available on my main profile.
I am available for paid, project-based security reviews and technical consulting.
Engagements can be arranged as fixed-scope projects or on a day-rate basis. Pricing depends on the implementation, scope, expected deliverables, and review timeline.
Typical engagements start from USD 2,500, with larger cryptographic implementation and PQC reviews quoted individually.
I am available for independent, project-based security reviews and technical consulting.
Engagements are scoped based on the implementation, review objectives, expected deliverables, and project timeline.
For project inquiries, please contact:
sunwoolee@kentech.ac.kr