From Struggle to Simplicity with a Usable and Secure API for Encryption in Java

Ehsan Firouzi,Ammar Mansuri,Mohammad Ghafari,Maziar Kaveh
DOI: https://doi.org/10.1145/3674805.3695405
2024-09-08
Abstract:Cryptography misuses are prevalent in the wild. Crypto APIs are hard to use for developers, and static analysis tools do not detect every misuse. We developed SafEncrypt, an API that streamlines encryption tasks for Java developers. It is built on top of the native Java Cryptography Architecture, and it shields developers from crypto complexities and erroneous low-level details. Experiments showed that SafEncrypt is suitable for developers with varying levels of experience.
Cryptography and Security,Software Engineering
What problem does this paper attempt to address?