{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T14:06:59Z","timestamp":1769350019905,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,1,30]],"date-time":"2023-01-30T00:00:00Z","timestamp":1675036800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Development of Cryptographic Library and Support System","award":["LP180101062"],"award-info":[{"award-number":["LP180101062"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,1,30]]},"DOI":"10.1145\/3579375.3579388","type":"proceedings-article","created":{"date-parts":[[2023,3,13]],"date-time":"2023-03-13T22:09:58Z","timestamp":1678745398000},"page":"102-111","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["A Comparative Study on Design and Usability of Cryptographic Libraries"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2974-8835","authenticated-orcid":false,"given":"Junwei","family":"Luo","sequence":"first","affiliation":[{"name":"RMIT University, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5621-767X","authenticated-orcid":false,"given":"Xuechao","family":"Yang","sequence":"additional","affiliation":[{"name":"RMIT University, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7351-5724","authenticated-orcid":false,"given":"Xun","family":"Yi","sequence":"additional","affiliation":[{"name":"RMIT University, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8756-7197","authenticated-orcid":false,"given":"Fengling","family":"Han","sequence":"additional","affiliation":[{"name":"RMIT University, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7963-2446","authenticated-orcid":false,"given":"Iqbal","family":"Gondal","sequence":"additional","affiliation":[{"name":"RMIT University, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2480-4965","authenticated-orcid":false,"given":"Guang-Bin","family":"Huang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,3,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"2017 IEEE Symposium on Security and Privacy (SP). IEEE, 154\u2013171","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar , Michael Backes , Sascha Fahl , Simson Garfinkel , Doowon Kim , Michelle\u00a0 L Mazurek , and Christian Stransky . 2017 . Comparing the usability of cryptographic apis . In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 154\u2013171 . Yasemin Acar, Michael Backes, Sascha Fahl, Simson Garfinkel, Doowon Kim, Michelle\u00a0L Mazurek, and Christian Stransky. 2017. Comparing the usability of cryptographic apis. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 154\u2013171."},{"key":"e_1_3_2_1_2_1","volume-title":"2016 IEEE Symposium on Security and Privacy (SP). IEEE, 289\u2013305","author":"Acar Yasemin","year":"2016","unstructured":"Yasemin Acar , Michael Backes , Sascha Fahl , Doowon Kim , Michelle\u00a0 L Mazurek , and Christian Stransky . 2016 . You get where you\u2019re looking for: The impact of information sources on code security . In 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 289\u2013305 . Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle\u00a0L Mazurek, and Christian Stransky. 2016. You get where you\u2019re looking for: The impact of information sources on code security. In 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 289\u2013305."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330213"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978333"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33481-8_9"},{"key":"e_1_3_2_1_6_1","volume-title":"Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications. 506\u2013507.","author":"Bloch Joshua","unstructured":"Joshua Bloch . 2006. How to design a good API and why it matters . In Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications. 506\u2013507. Joshua Bloch. 2006. How to design a good API and why it matters. In Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications. 506\u2013507."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2019.2937214"},{"key":"e_1_3_2_1_8_1","volume-title":"2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 255\u2013265","author":"Brito Aline","year":"2018","unstructured":"Aline Brito , Laerte Xavier , Andre Hora , and Marco\u00a0Tulio Valente . 2018 . Why and how Java developers break APIs . In 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 255\u2013265 . Aline Brito, Laerte Xavier, Andre Hora, and Marco\u00a0Tulio Valente. 2018. Why and how Java developers break APIs. In 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 255\u2013265."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516693"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382205"},{"key":"e_1_3_2_1_11_1","volume-title":"2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). IEEE, 388\u2013398","author":"Gao Jun","year":"2019","unstructured":"Jun Gao , Pingfan Kong , Li Li , Tegawend\u00e9\u00a0 F Bissyand\u00e9 , and Jacques Klein . 2019 . Negative results on mining crypto-api usage rules in android apps . In 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). IEEE, 388\u2013398 . Jun Gao, Pingfan Kong, Li Li, Tegawend\u00e9\u00a0F Bissyand\u00e9, and Jacques Klein. 2019. Negative results on mining crypto-api usage rules in android apps. In 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). IEEE, 388\u2013398."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382204"},{"key":"e_1_3_2_1_13_1","volume-title":"Fourteenth Symposium on Usable Privacy and Security ({SOUPS}","author":"Gorski Peter\u00a0Leo","year":"2018","unstructured":"Peter\u00a0Leo Gorski , Luigi\u00a0Lo Iacono , Dominik Wermke , Christian Stransky , Sebastian M\u00f6ller , Yasemin Acar , and Sascha Fahl . 2018 . Developers Deserve Security Warnings, Too: On the Effect of Integrated Security Advice on Cryptographic {API} Misuse . In Fourteenth Symposium on Usable Privacy and Security ({SOUPS} 2018). 265\u2013281. Peter\u00a0Leo Gorski, Luigi\u00a0Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian M\u00f6ller, Yasemin Acar, and Sascha Fahl. 2018. Developers Deserve Security Warnings, Too: On the Effect of Integrated Security Advice on Cryptographic {API} Misuse. In Fourteenth Symposium on Usable Privacy and Security ({SOUPS} 2018). 265\u2013281."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.111"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8452"},{"key":"e_1_3_2_1_16_1","volume-title":"International Conference on Cryptology and Information Security in Latin America. Springer, 150\u2013172","author":"Guo Chun","year":"2019","unstructured":"Chun Guo , Olivier Pereira , Thomas Peters , and Fran\u00e7ois-Xavier Standaert . 2019 . Authenticated encryption with nonce misuse and physical leakage: definitions, separation results and first construction . In International Conference on Cryptology and Information Security in Latin America. Springer, 150\u2013172 . Chun Guo, Olivier Pereira, Thomas Peters, and Fran\u00e7ois-Xavier Standaert. 2019. Authenticated encryption with nonce misuse and physical leakage: definitions, separation results and first construction. In International Conference on Cryptology and Information Security in Latin America. Springer, 150\u2013172."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2019.8870184"},{"key":"e_1_3_2_1_18_1","volume-title":"Annual Cryptology Conference. Springer, 493\u2013517","author":"Hoang Viet\u00a0Tung","year":"2015","unstructured":"Viet\u00a0Tung Hoang , Reza Reyhanitabar , Phillip Rogaway , and Damian Viz\u00e1r . 2015 . Online authenticated-encryption and its nonce-reuse misuse-resistance . In Annual Cryptology Conference. Springer, 493\u2013517 . Viet\u00a0Tung Hoang, Reza Reyhanitabar, Phillip Rogaway, and Damian Viz\u00e1r. 2015. Online authenticated-encryption and its nonce-reuse misuse-resistance. In Annual Cryptology Conference. Springer, 493\u2013517."},{"key":"e_1_3_2_1_19_1","volume-title":"2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 931\u2013936","author":"Kr\u00fcger Stefan","year":"2017","unstructured":"Stefan Kr\u00fcger , Sarah Nadi , Michael Reif , Karim Ali , Mira Mezini , Eric Bodden , Florian G\u00f6pfert , Felix G\u00fcnther , Christian Weinert , Daniel Demmler , 2017 . Cognicrypt: Supporting developers in using cryptography . In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 931\u2013936 . Stefan Kr\u00fcger, Sarah Nadi, Michael Reif, Karim Ali, Mira Mezini, Eric Bodden, Florian G\u00f6pfert, Felix G\u00fcnther, Christian Weinert, Daniel Demmler, 2017. Cognicrypt: Supporting developers in using cryptography. In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 931\u2013936."},{"key":"e_1_3_2_1_20_1","volume-title":"Crysl: An extensible approach to validating the correct usage of cryptographic apis","author":"Kr\u00fcger Stefan","year":"2019","unstructured":"Stefan Kr\u00fcger , Johannes Sp\u00e4th , Karim Ali , Eric Bodden , and Mira Mezini . 2019 . Crysl: An extensible approach to validating the correct usage of cryptographic apis . IEEE Transactions on Software Engineering( 2019). Stefan Kr\u00fcger, Johannes Sp\u00e4th, Karim Ali, Eric Bodden, and Mira Mezini. 2019. Crysl: An extensible approach to validating the correct usage of cryptographic apis. IEEE Transactions on Software Engineering(2019)."},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of 5th Asia-Pacific Workshop on Systems. 1\u20137.","author":"Lazar David","year":"2014","unstructured":"David Lazar , Haogang Chen , Xi Wang , and Nickolai Zeldovich . 2014 . Why does cryptographic software fail? A case study and open problems . In Proceedings of 5th Asia-Pacific Workshop on Systems. 1\u20137. David Lazar, Haogang Chen, Xi Wang, and Nickolai Zeldovich. 2014. Why does cryptographic software fail? A case study and open problems. In Proceedings of 5th Asia-Pacific Workshop on Systems. 1\u20137."},{"key":"e_1_3_2_1_22_1","volume-title":"International Conference on Network and System Security. Springer, 349\u2013362","author":"Li Yong","year":"2015","unstructured":"Yong Li , Yuanyuan Zhang , Juanru Li , and Dawu Gu . 2015 . iCryptoTracer: Dynamic analysis on misuse of cryptography functions in iOS applications . In International Conference on Network and System Security. Springer, 349\u2013362 . Yong Li, Yuanyuan Zhang, Juanru Li, and Dawu Gu. 2015. iCryptoTracer: Dynamic analysis on misuse of cryptography functions in iOS applications. In International Conference on Network and System Security. Springer, 349\u2013362."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897896"},{"key":"e_1_3_2_1_24_1","volume-title":"2018 16th Annual Conference on Privacy, Security and Trust (PST). IEEE, 1\u20132.","author":"Mindermann Kai","year":"2018","unstructured":"Kai Mindermann and Stefan Wagner . 2018 . Usability and security effects of code examples on crypto apis . In 2018 16th Annual Conference on Privacy, Security and Trust (PST). IEEE, 1\u20132. Kai Mindermann and Stefan Wagner. 2018. Usability and security effects of code examples on crypto apis. In 2018 16th Annual Conference on Privacy, Security and Trust (PST). IEEE, 1\u20132."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_2_1_26_1","volume-title":"Fifteenth Symposium on Usable Privacy and Security ({SOUPS}","author":"Patnaik Nikhil","year":"2019","unstructured":"Nikhil Patnaik , Joseph Hallett , and Awais Rashid . 2019 . Usability smells: An analysis of developers\u2019 struggle with crypto libraries . In Fifteenth Symposium on Usable Privacy and Security ({SOUPS} 2019). Nikhil Patnaik, Joseph Hallett, and Awais Rashid. 2019. Usability smells: An analysis of developers\u2019 struggle with crypto libraries. In Fifteenth Symposium on Usable Privacy and Security ({SOUPS} 2019)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00010"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092368"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.708447"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2014.22"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180260"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCRE.2011.26"}],"event":{"name":"ACSW 2023: 2023 Australasian Computer Science Week","location":"Melbourne VIC Australia","acronym":"ACSW 2023"},"container-title":["2023 Australasian Computer Science Week"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579375.3579388","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3579375.3579388","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:40Z","timestamp":1750178800000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579375.3579388"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,30]]},"references-count":32,"alternative-id":["10.1145\/3579375.3579388","10.1145\/3579375"],"URL":"https:\/\/doi.org\/10.1145\/3579375.3579388","relation":{},"subject":[],"published":{"date-parts":[[2023,1,30]]},"assertion":[{"value":"2023-03-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}