Lune

S&P2025顶会

"I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIs

Juliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha Fahl

2025年份
3顶会引用

摘要

Cryptographic libraries are a vital security component of software systems, yet their misuse has caused several incidents. Prior work has established that misuse of cryptographic libraries is common, and developers struggle to use their APIs correctly. However, it is currently unknown how the design and implementation decisions that shape cryptographic library APIs are made. To investigate these decisions and associated challenges in the design and implementation process of cryptographic library APIs, we conducted 21 semi-structured interviews with experienced developers of cryptographic libraries and used thematic analysis to identify overarching topics and challenges they encountered. We find that design decisions span a spectrum of abstraction levels and are heavily influenced by cryptographic standards, other libraries, legacy code, and developers' intuitions. Developers are challenged by the optimal level of abstraction for cryptographic APIs to balance security, usability, and flexibility. They lack systematic knowledge on defining usability and achieving such balance. Consequently, developers rely on usability self-tests, personal experiences, and opinions. Based on our findings, we make detailed recommendations to tailor future research toward better empirically validated support of cryptographic library API design and implementation decisions. Further, we advocate for integrating research-based usability guidance into cryptographic standardization to foster community discussion early on and better support secure, usable, and flexible cryptographic library APIs. identify challenges in the design and decision processes by capturing the developers' perspectives. RQ3. "How can cryptographic library designers and implementers be better supported to improve library security and usability?" Cryptographic libraries face unique security and usability challenges for developers, often complicating their use. We seek to identify opportunities to better support cryptographic library designers and implementers with creating secure, usable APIs to improve overall software security. In this paper, we make the following contributions: Insights from Experienced Cryptographic API Developers. We report insights from 21 semi-structured interviews with experienced developers of cryptographic library APIs, including their opinions on API design and strategies for decision processes. We find that levels of abstraction varied across libraries, and decisions were influenced by standards, other libraries, legacy code, and developers' intuitions. Key Challenges of Cryptographic API Design. We identify critical challenges in the design of cryptographic library APIs, such as limited resources for usability engineering, difficulty determining usability, balancing usability, security, and flexibility, and a lack of specific, empirically validated guidance in research and standards. Recommendations for Usability Research and API Design Guidance in Cryptographic Standards. Based on our findings, we identify open research questions and give detailed recommendations for future work on usable cryptographic APIs. We argue that cryptographic standardization should include API design and usability considerations for multiple levels of misuse resistance and flexibility to help cryptographic library developers make informed decisions. * multiple answers allowed † open-ended answers TABLE 2. PARTICIPANTS' PRIMARY PROJECTS AND ROLES.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper3

问问它们各自怎么用它

它引用的顶会 Paper11

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖