🤖 AI Summary
This work addresses the formal verification of Accountable Safety—a critical safety property in Ethereum’s 3SF consensus protocol—hampered by state-space explosion.
Method: We propose a scalable, multi-paradigm verification framework featuring three novel abstraction layers: recursive-to-folded reduction, graph-structure integerization, and chain-configuration decomposition. Our approach integrates TLA+ modeling, Apalache model checking, CVC5 SMT solving, and Alloy relational analysis to enable cross-paradigm validation.
Contribution/Results: We present the first exhaustive verification of Accountable Safety under realistic settings—7 checkpoints and 24 validators—finding no safety violations. This scale significantly exceeds prior efforts. Our results demonstrate that human-guided hierarchical abstraction substantially enhances the verifiability of complex consensus protocols. The framework establishes a new paradigm for formal assurance of core blockchain protocols, advancing both methodological rigor and practical scalability in distributed-system verification.
📝 Abstract
We investigate automated model-checking of the Ethereum specification, focusing on the Accountable Safety property of the 3SF consensus protocol. We select 3SF due to its relevance and the unique challenges it poses for formal verification. Our primary tools are TLA+ for specification and the Apalache model checker for verification.
Our formalization builds on the executable Python specification of 3SF. To begin, we manually translate this specification into TLA+, revealing significant combinatorial complexity in the definition of Accountable Safety. To address these challenges, we introduce several layers of manual abstraction: (1) replacing recursion with folds, (2) substituting abstract graphs with integers, and (3) decomposing chain configurations. To cross-validate our results, we develop alternative encodings in SMT (CVC5) and Alloy.
Despite the inherent complexity, our results demonstrate that exhaustive verification of Accountable Safety is feasible for small instances - supporting up to 7 checkpoints and 24 validator votes. Moreover, no violations of Accountable Safety are observed, even in slightly larger configurations. Beyond these findings, our study highlights the importance of manual abstraction and domain expertise in enhancing model-checking efficiency and showcases the flexibility of TLA+ for managing intricate specifications.