Skip to main navigation Skip to search Skip to main content

Faster Verification of Faster Implementations: Combining Deductive and Circuit-Based Reasoning in EasyCrypt

  • José Bacelar Almeida
  • , Gustavo Xavier Delerue Marinho Alves
  • , Manuel Barbosa
  • , Gilles Barthe
  • , Luís Esquível
  • , Vincent Hwang
  • , Tiago Oliveira
  • , Hugo Pacheco
  • , Peter Schwabe
  • , Pierre Yves Strub
  • Universidade de Minho
  • Ipatimup Diagnósticos
  • PQShield Ltd
  • Max Planck Institute for Security and Privacy
  • IMDEA Software Institute
  • SandboxAQ

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We propose a hybrid formal verification approach that combines high-level deductive reasoning and circuit-based reasoning and apply it to highly optimized cryptographic assembly code. Our approach permits scaling up formal verification in two complementary directions: 1) it reduces the proof effort required for low-level functions where the computation logics are obfuscated by the intricate use of architecture-specific instructions and 2) it permits amortizing the effort of proving one implementation by using equivalence checking to propagate the guarantees to other implementations of the same computation using different optimizations or targeting different architectures. We demonstrate our approach via an extension to the EasyCrypt proof assistant and by revisiting formally verified implementations of ML-KEM in Jasmin. As a result, we obtain the first formally verified implementation of ML-KEM that offers performance comparable to the fastest non-verified implementation in x86-64 architectures.

Original languageEnglish
Title of host publicationProceedings - 46th IEEE Symposium on Security and Privacy, SP 2025
EditorsMarina Blanton, William Enck, Cristina Nita-Rotaru
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages3820-3838
Number of pages19
ISBN (Electronic)9798331522360
DOIs
Publication statusPublished - 1 Jan 2025
Externally publishedYes
Event46th IEEE Symposium on Security and Privacy, SP 2025 - San Francisco, United States
Duration: 12 May 202515 May 2025

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
ISSN (Print)1081-6011

Conference

Conference46th IEEE Symposium on Security and Privacy, SP 2025
Country/TerritoryUnited States
CitySan Francisco
Period12/05/2515/05/25

Keywords

  • easycrypt
  • formal verification
  • functional correctness
  • post-quantum cryptography

Fingerprint

Dive into the research topics of 'Faster Verification of Faster Implementations: Combining Deductive and Circuit-Based Reasoning in EasyCrypt'. Together they form a unique fingerprint.

Cite this