Uploaded April 2021 | Updated September 2026, 36 minutes ago
Security certification reports might be long, but they are also a trove of publicly available data about proprietary devices and other products otherwise available only under NDAs. While downloading and reading a single certificate is easy, reasoning about the characteristics of the whole ecosystem, which covers more than ten thousand certified devices based on human-written documents, is different. Are there observable systematic differences between the Common Criteria and FIPS 140-2 certificates? Can I quickly find out if my device is using a certified component recently found vulnerable? Most importantly, can we measure and quantify whether the whole process is actually increasing the security of the products being certificated? This talk address these questions using an open source tool for automatic analysis of publicly available certification reports, accompanied by catchy graphs.
Slides: research.redhat.com/wp-content/uploads/2021/03/BrnoMarch_PetrSvenda_SecurityCertificates_RedHatResearchDay_20210324.pdf
Speaker: Petr Švenda, computer security researcher, associate professor and member of the Centre for Research on Cryptography and Security at Masaryk University
►About the event
Research Days is a series of conversations about research & innovations in open source between researchers and Red Hat experts.
►Are you interested in open source projects we are incubating at Red Hat Research? Visit research.redhat.com to learn more and get involved!
Security certification reports might be long, but they are also a trove of publicly available data about proprietary devices and other products otherwise available only under NDAs. While downloading and reading a single certificate is easy, reasoning about the characteristics of the whole ecosystem, which covers more than ten thousand certified devices based on human-written documents, is different. Are there observable systematic differences between the Common Criteria and FIPS 140-2 certificates? Can I quickly find out if my device is using a certified component recently found vulnerable? Most importantly, can we measure and quantify whether the whole process is actually increasing the security of the products being certificated? This talk address these questions using an open source tool for automatic analysis of publicly available certification reports, accompanied by catchy graphs.
Slides: research.redhat.com/wp-content/uploads/2021/03/BrnoMarch_PetrSvenda_SecurityCertificates_RedHatResearchDay_20210324.pdf
Speaker: Petr Švenda, computer security researcher, associate professor and member of the Centre for Research on Cryptography and Security at Masaryk University
►About the event
Research Days is a series of conversations about research & innovations in open source between researchers and Red Hat experts.
►Are you interested in open source projects we are incubating at Red Hat Research? Visit research.redhat.com to learn more and get involved!










