Session

Know Your Crypto: Standardizing and Detecting Crypto Algorithms the open source way

Regulatory pressures, quantum computing threats or security breaches in complex supply chains have elevated cryptographic algorithm management to unprecedented importance. Understanding which crypto algorithms your software includes, and the implications for downstream users, is increasingly valued by developers and organizations. Several open source initiatives are now emerging to make cryptographic algorithm detection and declaration universal, enhancing the existing Bill of Materials (xBOM) generation.

This presentation explores some of those emerging initiatives, putting focus in two of the most promising ones:
* SPDX Crypto Algorithms List (https://github.com/spdx/crypto-algorithms): This aims to standardize crypto algorithm declaration.
* Open Dataset for Keyword-Based Detection (https://github.com/scanoss/crypto_algorithms_open_dataset): open dataset for detecting crypto algorithms via keywords, useful for automated scanning.

After a short demo of a simple PoC on how to implement them, the talk will cover the background behind these efforts, the latest news and plans, their relevance for security and transparency, and how participants can use and contribute to them.

Agustin Benito Bethencourt

Independent Consultant

Los Llanos de Aridane, Spain

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top