{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T05:09:41Z","timestamp":1750136981146,"version":"3.37.3"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030268336"},{"type":"electronic","value":"9783030268343"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-26834-3_13","type":"book-chapter","created":{"date-parts":[[2019,8,6]],"date-time":"2019-08-06T19:05:29Z","timestamp":1565118329000},"page":"221-240","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["API Usability of Stateful Signature Schemes"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1717-5029","authenticated-orcid":false,"given":"Alexander","family":"Zeier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1144-549X","authenticated-orcid":false,"given":"Alexander","family":"Wiesmaier","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0240-399X","authenticated-orcid":false,"given":"Andreas","family":"Heinemann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,7,24]]},"reference":[{"key":"13_CR1","doi-asserted-by":"publisher","unstructured":"Acar, Y., et al.: Comparing the usability of cryptographic APIs. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 154\u2013171 (2017). \n                      https:\/\/doi.org\/10.1109\/SP.2017.52","DOI":"10.1109\/SP.2017.52"},{"key":"13_CR2","doi-asserted-by":"publisher","unstructured":"Acar, Y., Backes, M., Fahl, S., Kim, D., Mazurek, M.L., Stransky, C.: You get where you\u2019re looking for: the impact of information sources on code security. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 289\u2013305 (2016). \n                      https:\/\/doi.org\/10.1109\/SP.2016.25","DOI":"10.1109\/SP.2016.25"},{"key":"13_CR3","doi-asserted-by":"publisher","unstructured":"Acar, Y., Stransky, C., Wermke, D., Weir, C., Mazurek, M.L., Fahl, S.: Developers need support, too: a survey of security advice for software developers. In: 2017 IEEE Cybersecurity Development (SecDev), pp. 22\u201326 (2017). \n                      https:\/\/doi.org\/10.1109\/SecDev.2017.17","DOI":"10.1109\/SecDev.2017.17"},{"key":"13_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-662-46800-5_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2015","author":"D Bernstein","year":"2015","unstructured":"Bernstein, D., et al.: SPHINCS: practical stateless hash-based signatures. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9056, pp. 368\u2013397. Springer, Heidelberg (2015). \n                      https:\/\/doi.org\/10.1007\/978-3-662-46800-5_15"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Bloch, J.: Slides on how to design a good API and why it matters. In: Companion to the 21st ACM SIGPLAN Symposium on Object-Oriented Programming Systems, Languages, and Applications. ACM (2006)","DOI":"10.1145\/1176617.1176622"},{"issue":"194","key":"13_CR6","first-page":"4","volume":"189","author":"J Brooke","year":"1996","unstructured":"Brooke, J.: SUS - a quick and dirty usability scale. Usability Eval. Ind. 189(194), 4\u20137 (1996)","journal-title":"Usability Eval. Ind."},{"issue":"2","key":"13_CR7","first-page":"29","volume":"8","author":"J Brooke","year":"2013","unstructured":"Brooke, J.: SUS: retrospective. J. Usability Stud. 8(2), 29\u201340 (2013)","journal-title":"J. Usability Stud."},{"key":"13_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-642-25405-5_8","volume-title":"Post-Quantum Cryptography","author":"J Buchmann","year":"2011","unstructured":"Buchmann, J., Dahmen, E., H\u00fclsing, A.: XMSS - a practical forward secure signature scheme based on minimal security assumptions. In: Yang, B.-Y. (ed.) PQCrypto 2011. LNCS, vol. 7071, pp. 117\u2013129. Springer, Heidelberg (2011). \n                      https:\/\/doi.org\/10.1007\/978-3-642-25405-5_8"},{"key":"13_CR9","doi-asserted-by":"publisher","unstructured":"Butin, D., W\u00e4lde, J., Buchmann, J.: Post-quantum authentication in OpenSSL with hash-based signatures. In: 2017 Tenth International Conference on Mobile Computing and Ubiquitous Network (ICMU), pp. 1\u20136. IEEE (2017). \n                      https:\/\/doi.org\/10.23919\/ICMU.2017.8330093","DOI":"10.23919\/ICMU.2017.8330093"},{"key":"13_CR10","doi-asserted-by":"publisher","unstructured":"Chen, L., et al.: Report on Post-Quantum Cryptography. US Department of Commerce, National Institute of Standards and Technology (2016). \n                      https:\/\/doi.org\/10.6028\/NIST.IR.8105","DOI":"10.6028\/NIST.IR.8105"},{"key":"13_CR11","doi-asserted-by":"publisher","unstructured":"Fahl, S., Harbach, M., Muders, T., Baumg\u00e4rtner, L., Freisleben, B., Smith, M.: Why Eve and Mallory Love Android: an analysis of Android SSL (in) security. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 50\u201361. ACM (2012). \n                      https:\/\/doi.org\/10.1145\/2382196.2382205","DOI":"10.1145\/2382196.2382205"},{"key":"13_CR12","unstructured":"Gorski, P.L., et al.: Developers deserve security warnings, too: on the effect of integrated security advice on cryptographic API misuse. In: Fourteenth Symposium on Usable Privacy and Security, SOUPS 2018, pp. 265\u2013281. USENIX Association (2018)"},{"issue":"5","key":"13_CR13","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/MSP.2016.111","volume":"14","author":"M Green","year":"2016","unstructured":"Green, M., Smith, M.: Developers are not the enemy!: the need for usable security APIs. IEEE Secur. Priv. 14(5), 40\u201346 (2016). \n                      https:\/\/doi.org\/10.1109\/MSP.2016.111","journal-title":"IEEE Secur. Priv."},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Housley, R.: Guidelines for Cryptographic Algorithm Agility and Selecting Mandatory-to-Implement Algorithms. BCP 201, RFC Editor (2015)","DOI":"10.17487\/RFC7696"},{"key":"13_CR15","doi-asserted-by":"crossref","unstructured":"H\u00fclsing, A., Butin, D., Gazdag, S., Rijneveld, J., Mohaisen, A.: XMSS: eXtended Merkle Signature Scheme. RFC 8391, RFC Editor, May 2018","DOI":"10.17487\/RFC8391"},{"key":"13_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1007\/978-3-642-40588-4_14","volume-title":"Security Engineering and Intelligence Informatics","author":"A H\u00fclsing","year":"2013","unstructured":"H\u00fclsing, A., Rausch, L., Buchmann, J.: Optimal parameters for XMSSMT. In: Cuzzocrea, A., Kittl, C., Simos, D.E., Weippl, E., Xu, L. (eds.) CD-ARES 2013. LNCS, vol. 8128, pp. 194\u2013208. Springer, Heidelberg (2013). \n                      https:\/\/doi.org\/10.1007\/978-3-642-40588-4_14"},{"key":"13_CR17","doi-asserted-by":"publisher","DOI":"10.17226\/24636","volume-title":"Cryptographic Agility and Interoperability: Proceedings of a Workshop","year":"2017","unstructured":"Johnson, A.F., Millett, L.I. (eds.): Cryptographic Agility and Interoperability: Proceedings of a Workshop. The National Academies Press, Washington, DC (2017). \n                      https:\/\/doi.org\/10.17226\/24636"},{"key":"13_CR18","doi-asserted-by":"publisher","unstructured":"Kr\u00fcger, S., et al.: CogniCrypt: supporting developers in using cryptography. In: Proceedings of the 32nd IEEE\/ACM International Conference on Automated Software Engineering, pp. 931\u2013936. IEEE Press (2017). \n                      https:\/\/doi.org\/10.1109\/ASE.2017.8115707","DOI":"10.1109\/ASE.2017.8115707"},{"key":"13_CR19","doi-asserted-by":"publisher","unstructured":"Lazar, D., Chen, H., Wang, X., Zeldovich, N.: Why does cryptographic software fail? A case study and open problems. In: Proceedings of 5th Asia-Pacific Workshop on Systems, pp. 1\u20137. ACM Press (2014). \n                      https:\/\/doi.org\/10.1145\/2637166.2637237","DOI":"10.1145\/2637166.2637237"},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"McGrew, D., Curcio, M., Fluhrer, S.: Leighton-Micali Hash-Based Signatures. RFC 8554, RFC Editor, April 2019","DOI":"10.17487\/RFC8554"},{"key":"13_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1007\/978-3-319-49100-4_11","volume-title":"Security Standardisation Research","author":"D McGrew","year":"2016","unstructured":"McGrew, D., Kampanakis, P., Fluhrer, S., Gazdag, S.-L., Butin, D., Buchmann, J.: State management for hash-based signatures. In: Chen, L., McGrew, D., Mitchell, C. (eds.) SSR 2016. LNCS, vol. 10074, pp. 244\u2013260. Springer, Cham (2016). \n                      https:\/\/doi.org\/10.1007\/978-3-319-49100-4_11"},{"key":"13_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/0-387-34805-0_21","volume-title":"Advances in Cryptology \u2014 CRYPTO 1989 Proceedings","author":"RC Merkle","year":"1990","unstructured":"Merkle, R.C.: A certified digital signature. In: Brassard, G. (ed.) CRYPTO 1989. LNCS, vol. 435, pp. 218\u2013238. Springer, New York (1990). \n                      https:\/\/doi.org\/10.1007\/0-387-34805-0_21"},{"key":"13_CR23","doi-asserted-by":"publisher","unstructured":"Nadi, S., Kr\u00fcger, S., Mezini, M., Bodden, E.: Jumping through hoops: why do Java developers struggle with cryptography APIs? In: Proceedings of the 38th International Conference on Software Engineering, pp. 935\u2013946. ACM Press (2016). \n                      https:\/\/doi.org\/10.1145\/2884781.2884790","DOI":"10.1145\/2884781.2884790"},{"key":"13_CR24","doi-asserted-by":"crossref","unstructured":"Nelson, D.: Crypto-Agility Requirements for Remote Authentication Dial-In User Service (RADIUS). RFC 6421, RFC Editor (2011)","DOI":"10.17487\/rfc6421"},{"key":"13_CR25","volume-title":"Usability Engineering","author":"J Nielsen","year":"1994","unstructured":"Nielsen, J.: Usability Engineering. Elsevier, Amsterdam (1994)"},{"key":"13_CR26","doi-asserted-by":"publisher","unstructured":"Scheller, T., Kuhn, E.: Influencing factors on the usability of API classes and methods. In: 2012 IEEE 19th International Conference and Workshops on Engineering of Computer-Based Systems, pp. 232\u2013241 (2012). \n                      https:\/\/doi.org\/10.1109\/ECBS.2012.27","DOI":"10.1109\/ECBS.2012.27"},{"key":"13_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/978-3-642-39062-3_4","volume-title":"Human Factors in Computing and Informatics","author":"T Scheller","year":"2013","unstructured":"Scheller, T., K\u00fchn, E.: Usability evaluation of configuration-based API design concepts. In: Holzinger, A., Ziefle, M., Hitz, M., Debevc, M. (eds.) SouthCHI 2013. LNCS, vol. 7946, pp. 54\u201373. Springer, Heidelberg (2013). \n                      https:\/\/doi.org\/10.1007\/978-3-642-39062-3_4"},{"issue":"5","key":"13_CR28","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997). \n                      https:\/\/doi.org\/10.1137\/S0097539795293172","journal-title":"SIAM J. Comput."},{"key":"13_CR29","unstructured":"Stransky, C., et al.: Lessons learned from using an online platform to conduct large-scale, online controlled security experiments with software developers. In: 10th USENIX Workshop on Cyber Security Experimentation and Test, CSET 2017 (2017)"},{"key":"13_CR30","doi-asserted-by":"publisher","unstructured":"Xie, J., Lipford, H.R., Chu, B.: Why do programmers make security errors? In: 2011 IEEE Symposium on Visual Languages and Human-Centric Computing (VL\/HCC), pp. 161\u2013164 (2011). \n                      https:\/\/doi.org\/10.1109\/VLHCC.2011.6070393","DOI":"10.1109\/VLHCC.2011.6070393"}],"container-title":["Lecture Notes in Computer Science","Advances in Information and Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-26834-3_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,6]],"date-time":"2019-08-06T19:06:26Z","timestamp":1565118386000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-26834-3_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030268336","9783030268343"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-26834-3_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"24 July 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IWSEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tokyo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 August 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 August 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iwsec2019a","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.iwsec.org\/2019\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"61","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.9","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5.6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"https:\/\/www.iwsec.org\/2019\/","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}