Formally-verified Security against Forgery of Remote Attestation using SSProve

📅 2025-02-24
📈 Citations: 0
Influential: 0
📄 PDF

career value

220K/year
🤖 AI Summary
This work addresses the absence of rigorous, machine-checked security definitions—particularly unforgeability—for Remote Attestation (RA) in semantic models. We present the first formal modeling and verification of RA protocols within the State-Separating Proofs (SSP) framework, implemented in the Rocq Prover. Our approach establishes a layered security reduction, formally proving that RA’s unforgeability is tightly reducible to the security of underlying digital signature primitives under a strong existential attack model; all proofs are fully machine-checked. Key contributions are: (1) the first mechanized security definition and verification of RA in the semantic model; (2) a formally verified security dependency between RA and its constituent signature primitives; and (3) an analysis of the feasibility boundary of the SSP framework for formalizing low-level cryptographic primitives, thereby advancing library-level security reasoning.

Technology Category

Application Category

📝 Abstract
Remote attestation (RA) is the foundation for trusted execution environments in the cloud and trusted device driver onboarding in operating systems. However, RA misses a rigorous mechanized definition of its security properties in one of the strongest models, i.e., the semantic model. Such a mechanization requires the concept of State-Separating Proofs (SSP). However, SSP was only recently implemented as a foundational framework in the Rocq Prover. Based on this framework, this paper presents the first mechanized formalization of the fundamental security properties of RA. Our Rocq Prover development first defines digital signatures and formally verifies security against forgery in the strong existential attack model. Based on these results, we define RA and reduce the security of RA to the security of digital signatures. Our development provides evidence that the RA protocol is secure against forgery. Additionally, we extend our reasoning to the primitives of RA and reduce their security to the security of the primitives of the digital signatures. Finally, we found that proving the security of the primitives for digital signatures was not feasible. This observation contrasts textbook formalizations and sparks a discussion on reasoning about the security of libraries in SSP-based frameworks.
Problem

Research questions and friction points this paper is trying to address.

Mechanized formalization of RA security
Verification of security against forgery
Reduction of RA security to signatures
Innovation

Methods, ideas, or system contributions that make the work stand out.

State-Separating Proofs framework
Rocq Prover formal verification
security reduction to digital signatures
S
Sara Zain
Barkhausen Institut, Dresden, Germany
J
Jannik Mahn
Barkhausen Institut, Dresden, Germany
S
Stefan Kopsell
Barkhausen Institut, Dresden, Germany
Sebastian Ertel
Sebastian Ertel
Barkhausen Institute, Dresden, Germany
programming languagesformal verificationtheorem provingcompilers