kirancodes.me
To Proof Maintenance & Beyond!

CogniCrypt: supporting developers in using cryptography

Stefan Krüger, Sarah Nadi, Michael Reif, Karim Ali, Mira Mezini, Eric Bodden, Florian Göpfert, Felix Günther, Christian Weinert, Daniel Demmler, Ram Kamath

Abstract

Previous research suggests that developers often struggle using low-level cryptographic APIs and, as a result, produce insecure code. When asked, developers desire, among other things, more tool support to help them use such APIs. In this paper, we present CogniCrypt, a tool that supports developers with the use of cryptographic APIs. CogniCrypt assists the developer in two ways. First, for a number of common cryptographic tasks, CogniCrypt generates code that implements the respective task in a secure manner. Currently, CogniCrypt supports tasks such as data encryption, communication over secure channels, and long-term archiving. Second, CogniCrypt continuously runs static analyses in the background to ensure a secure integration of the generated code into the developer's workspace. This video demo showcases the main features of CogniCrypt: youtube.com/watch?v=JUq5mRHfAWY.

BibTeX
@inproceedings{Krueger-al:ASE17,
  author    = {Stefan Kr{\"{u}}ger and
               Sarah Nadi and
               Michael Reif and
               Karim Ali and
               Mira Mezini and
               Eric Bodden and
               Florian G{\"{o}}pfert and
               Felix G{\"{u}}nther and
               Christian Weinert and
               Daniel Demmler and
               Ram Kamath},
  title     = {{CogniCrypt:} supporting developers in using cryptography},
  booktitle = {ASE},
  pages     = {931--936},
  publisher = {{IEEE} Computer Society},
  year      = {2017},
}

Related papers