Skip to main navigation Skip to search Skip to main content

Mechanized Proofs of Adversarial Complexity and Application to Universal Composability

  • Ipatimup Diagnósticos
  • MPI-SP
  • IMDEA Software Institute
  • INRIA
  • INRIA Institut National de Recherche en Informatique et en Automatique
  • Meta France

Research output: Contribution to journalArticlepeer-review

Abstract

In this work, we enhance the EasyCrypt proof assistant to reason about the computational complexity of adversaries. The key technical tool is a Hoare logic for reasoning about computational complexity (execution time and oracle calls) of adversarial computations. Our Hoare logic is built on top of the module system used by EasyCrypt for modeling adversaries. We prove that our logic is sound w.r.t. the semantics of EasyCrypt programs - we also provide full semantics for the EasyCrypt module system, which was lacking previously. We showcase (for the first time in EasyCrypt and in other computer-aided cryptographic tools) how our approach can express precise relationships between the probability of adversarial success and their execution time. In particular, we can quantify existentially over adversaries in a complexity class and express general composition statements in simulation-based frameworks. Moreover, such statements can be composed to derive standard concrete security bounds for cryptographic constructions whose security is proved in a modular way. As a main benefit of our approach, we revisit security proofs of some well-known cryptographic constructions and present a new formalization of universal composability.

Original languageEnglish
Article number41
JournalACM Transactions on Privacy and Security
Volume26
Issue number3
DOIs
Publication statusPublished - 19 Jul 2023
Externally publishedYes

Keywords

  • Verification of cryptographic primitives
  • complexity analysis
  • formal methods
  • interactive proof system

Fingerprint

Dive into the research topics of 'Mechanized Proofs of Adversarial Complexity and Application to Universal Composability'. Together they form a unique fingerprint.

Cite this