VerIso: Verifiable Isolation Guarantees for Database Transactions

📅 2025-03-08
📈 Citations: 1
✨ Influential: 0
📄 PDF
🤖 AI Summary
Database transaction isolation anomalies—particularly those arising from design flaws—are prevalent in production systems, yet existing approaches lack a mathematically rigorous, systematic, and tool-supported formal verification framework. This paper introduces the first fully automated verification framework for transaction isolation, built in Isabelle/HOL. It enables full-path formal verification of core isolation properties—including strict serializability—for the first time. The framework precisely models concurrent transaction semantics, defines formal isolation specifications, and integrates counterexample generation. Applied during protocol design, it uncovers deep correctness flaws: it formally verifies that Strict Two-Phase Locking satisfies strict serializability, and—critically—identifies for the first time that the TAPIR protocol violates atomic visibility, automatically generating an executable counterexample. This work establishes a verifiable, reusable theoretical foundation and practical toolset for database isolation assurance.

Technology Category

Knowledge Representation and Reasoning: Automated Reasoning and Theorem ProvingConstraint Satisfaction and Optimization: Satisfiability Modulo TheoriesData Mining & Knowledge Management: Representing, Reasoning, and Using Provenance, Trust

Application Category

Security and Privacy: Data transparency and provenanceSemantics and Knowledge: Provenance, trust, security and privacy, and ethical issues in managing semantic dataSystems and Infrastructure for Web, Mobile and WoT: Web performance, measurement, and characterization
📝 Abstract
Isolation bugs, stemming especially from design-level defects, have been repeatedly found in carefully designed and extensively tested production databases over decades. In parallel, various frameworks for modeling database transactions and reasoning about their isolation guarantees have been developed. What is missing however is a mathematically rigorous and systematic framework with tool support for formally verifying a wide range of such guarantees for all possible system behaviors. We present the first such framework, VerIso, developed within the theorem prover Isabelle/HOL. To showcase its use in verification, we model the strict two-phase locking concurrency control protocol and verify that it provides strict serializability isolation guarantee. Moreover, we show how VerIso helps identify isolation bugs during protocol design. We derive new counterexamples for the TAPIR protocol from failed attempts to prove its claimed strict serializability. In particular, we show that it violates a much weaker isolation level, namely, atomic visibility.
Problem

Research questions and friction points this paper is trying to address.

Lack of rigorous framework for verifying database isolation guarantees.
Need for tool support to verify isolation across all system behaviors.
Identification and correction of isolation bugs in protocol design.
Innovation

Methods, ideas, or system contributions that make the work stand out.

VerIso: rigorous framework for verifying isolation guarantees
Modeling strict two-phase locking in Isabelle/HOL
Identifying isolation bugs via formal verification