{"id":"https://openalex.org/W7138995545","doi":"https://doi.org/10.48550/arxiv.2603.17133","title":"A Longitudinal Study of Usability in Identity-Based Software Signing","display_name":"A Longitudinal Study of Usability in Identity-Based Software Signing","publication_year":2026,"publication_date":"2026-03-17","ids":{"openalex":"https://openalex.org/W7138995545","doi":"https://doi.org/10.48550/arxiv.2603.17133"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.17133","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.17133","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.17133","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129869552","display_name":"Kelechi G. Kalu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kalu, Kelechi G.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046024857","display_name":"Hieu Tran","orcid":"https://orcid.org/0000-0002-0067-0683"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tran, Hieu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025546105","display_name":"Santiago Torres-Arias","orcid":"https://orcid.org/0000-0002-9283-3557"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Torres-Arias, Santiago","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061973924","display_name":"Sooyeon Jeong","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jeong, Sooyeon","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5129991733","display_name":"James C. Davis","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Davis, James C.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11986","display_name":"Scientific Computing and Data Management","score":0.9049000144004822,"subfield":{"id":"https://openalex.org/subfields/1802","display_name":"Information Systems and Management"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11986","display_name":"Scientific Computing and Data Management","score":0.9049000144004822,"subfield":{"id":"https://openalex.org/subfields/1802","display_name":"Information Systems and Management"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.05849999934434891,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.0032999999821186066,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/usability","display_name":"Usability","score":0.8917999863624573},{"id":"https://openalex.org/keywords/workflow","display_name":"Workflow","score":0.6747000217437744},{"id":"https://openalex.org/keywords/cognitive-walkthrough","display_name":"Cognitive walkthrough","score":0.5318999886512756},{"id":"https://openalex.org/keywords/artifact","display_name":"Artifact (error)","score":0.47589999437332153},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.4366999864578247},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4259999990463257},{"id":"https://openalex.org/keywords/pluralistic-walkthrough","display_name":"Pluralistic walkthrough","score":0.4235999882221222},{"id":"https://openalex.org/keywords/usability-goals","display_name":"Usability goals","score":0.40950000286102295}],"concepts":[{"id":"https://openalex.org/C170130773","wikidata":"https://www.wikidata.org/wiki/Q216378","display_name":"Usability","level":2,"score":0.8917999863624573},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7017999887466431},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.6747000217437744},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.5526999831199646},{"id":"https://openalex.org/C87105883","wikidata":"https://www.wikidata.org/wiki/Q1107002","display_name":"Cognitive walkthrough","level":4,"score":0.5318999886512756},{"id":"https://openalex.org/C2779010991","wikidata":"https://www.wikidata.org/wiki/Q2720909","display_name":"Artifact (error)","level":2,"score":0.47589999437332153},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.4366999864578247},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4259999990463257},{"id":"https://openalex.org/C188688815","wikidata":"https://www.wikidata.org/wiki/Q7205541","display_name":"Pluralistic walkthrough","level":3,"score":0.4235999882221222},{"id":"https://openalex.org/C62993174","wikidata":"https://www.wikidata.org/wiki/Q2928808","display_name":"Usability goals","level":4,"score":0.40950000286102295},{"id":"https://openalex.org/C3255780","wikidata":"https://www.wikidata.org/wiki/Q1616517","display_name":"Heuristic evaluation","level":3,"score":0.40689998865127563},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.3869999945163727},{"id":"https://openalex.org/C23456302","wikidata":"https://www.wikidata.org/wiki/Q7901668","display_name":"Usability inspection","level":4,"score":0.3626999855041504},{"id":"https://openalex.org/C11324603","wikidata":"https://www.wikidata.org/wiki/Q2502322","display_name":"Usability lab","level":4,"score":0.361299991607666},{"id":"https://openalex.org/C4237393","wikidata":"https://www.wikidata.org/wiki/Q1636686","display_name":"Web usability","level":3,"score":0.357699990272522},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.357699990272522},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.3515999913215637},{"id":"https://openalex.org/C100302975","wikidata":"https://www.wikidata.org/wiki/Q1642623","display_name":"Usability engineering","level":3,"score":0.33820000290870667},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.2904999852180481},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.2849999964237213},{"id":"https://openalex.org/C33054407","wikidata":"https://www.wikidata.org/wiki/Q6504747","display_name":"Software verification","level":5,"score":0.2632000148296356}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.17133","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.17133","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.17133","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.17133","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Identity-based":[0],"software":[1,7],"signing":[2,47,74,176,194],"tools":[3,40,114,157],"aim":[4],"to":[5,53,93,184],"make":[6],"artifact":[8],"provenance":[9],"verifiable":[10],"while":[11,181],"reducing":[12],"the":[13,66,101,106],"operational":[14],"burden":[15],"of":[16,70],"long-lived":[17],"key":[18],"management.":[19],"However,":[20,146],"there":[21],"is":[22],"limited":[23],"cross-tool":[24],"longitudinal":[25],"evidence":[26],"about":[27],"which":[28],"usability":[29,103,148,179,206],"problems":[30,37],"arise":[31],"in":[32,123,140],"practice":[33],"and":[34,48,81,105,110,115,127,130,151,158,161,164,189,201],"how":[35],"those":[36],"evolve":[38],"as":[39,204],"mature.":[41],"This":[42],"gap":[43],"matters":[44],"because":[45],"unusable":[46],"verification":[49,124,162,185,199],"workflows":[50,163,203],"can":[51],"lead":[52],"incomplete":[54],"adoption,":[55],"misconfiguration,":[56],"or":[57],"skipped":[58],"verification,":[59],"undermining":[60],"intended":[61],"integrity":[62],"guarantees.":[63],"We":[64,84,96],"conducted":[65],"first":[67],"mining-software-repositories":[68],"study":[69],"five":[71],"open-source":[72],"identity-based":[73,175],"ecosystems:":[75],"Sigstore,":[76],"OpenPubKey,":[77],"HashiCorp":[78],"Vault,":[79],"Keyfactor,":[80],"Notary":[82],"v2.":[83],"analyzed":[85],"approximately":[86],"3,900":[87],"GitHub":[88],"issues":[89,142],"from":[90],"Nov.":[91,94],"2021":[92],"2025.":[95],"coded":[97],"each":[98],"issue":[99],"for":[100,143],"reported":[102,120,141],"concern":[104,159],"implicated":[107],"architectural":[108],"component,":[109],"compared":[111],"patterns":[112],"across":[113,147,156],"over":[116],"time.":[117],"Across":[118],"ecosystems,":[119],"concerns":[121,153],"concentrate":[122],"workflows,":[125],"policy":[126,187],"configuration":[128,165],"surfaces,":[129],"integration":[131,211],"boundaries.":[132],"Longitudinal":[133],"Poisson":[134],"trend":[135],"analysis":[136],"shows":[137],"substantial":[138],"declines":[139],"most":[144],"ecosystems.":[145],"themes,":[149],"workflow-":[150],"documentation-related":[152],"decline":[154],"unevenly":[155],"types,":[160],"surfaces":[166],"remain":[167],"persistent":[168],"friction":[169],"points.":[170],"These":[171],"results":[172],"indicate":[173],"that":[174],"reduces":[177],"some":[178],"burdens":[180],"relocating":[182],"complexity":[183],"semantics,":[186],"configuration,":[188],"deployment":[190],"integration.":[191],"Designing":[192],"future":[193],"ecosystems":[195],"therefore":[196],"requires":[197],"treating":[198],"semantics":[200],"release":[202],"first-class":[205],"targets":[207],"rather":[208],"than":[209],"peripheral":[210],"concerns.":[212]},"counts_by_year":[],"updated_date":"2026-07-01T06:00:48.157686","created_date":"2026-03-20T00:00:00"}
