implement cryptographic protocols

Designs, implements, and integrates cryptographic protocols, primitives, and infrastructure — including public-key systems and PKI, signature schemes (signing and verification), secure communication protocols, key generation and handling, commitment schemes, and interactive or non-interactive zero-knowledge constructions. Analyzes and proves their security by constructing formal proofs and reductions under stated assumptions, bounding adversary advantage and establishing properties such as IND‑CPA/IND‑CCA security, forward secrecy, non‑malleability, unlinkability, selective opening resistance, and composability to ensure correct instantiation and secure composition.

implementcryptographicprotocols

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
1.06
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$208K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Protocol designers often face a high barrier to entry in using formal verification tools such as ProVerif and Tamarin due to the lack of systematic guidance on translating security properties into executable models. This work addresses this gap by conducting a systematic review of 53 studies published between 2022 and 2025, resulting in the first comprehensive taxonomy of security properties tailored to mainstream verification tools. The taxonomy integrates informal explanations, first-order logic definitions, and tool-specific modeling exemplars. By bridging the gap between theoretical formulations and practical modeling, this study significantly enhances the accuracy and efficiency of protocol modeling. An accompanying open-source repository of illustrative examples further lowers the practical barrier to adopting formal verification in real-world protocol design.

executable taxonomyformal verificationProVerif

This work presents the first formal security analysis of the LINEv2 protocol, revealing its lack of forward secrecy (FS) and post-compromise security (PCS), which poses significant long-term communication risks. Leveraging an enhanced multi-stage key exchange (MSKE) model, the study rigorously evaluates LINEv2’s security properties under realistic adversarial scenarios. To address these vulnerabilities, the authors propose a strengthened protocol variant that seamlessly integrates FS and PCS while preserving the original functionality and performance. The enhanced protocol is supported by formal proofs of security and empirical performance benchmarks, demonstrating its practical feasibility and substantially improved resilience against long-term threats.

cryptographic securityend-to-end encryptionforward secrecy

On the Formalization of Cryptographic Migration

Aug 12, 2024
DL
Daniel Loebenberger
🏛️ Fraunhofer AISEC | OTH Amberg-Weiden | genua GmbH | XITASO GmbH

The migration of cryptographic systems from classical to post-quantum cryptography (PQC) under the threat of quantum computing poses significant practical and analytical challenges, particularly due to complex interdependencies among cryptographic components and heterogeneous deployment constraints. Method: This work introduces the first analytically tractable combinatorial model of cryptographic migration, formalized as a semi-formal dependency graph capturing structural complexity and ordering constraints. Leveraging combinatorics, probability theory, and analytic combinatorics, the model is empirically validated against real-world migration patterns. Contribution/Results: Theoretically, we establish the first tight asymptotic bounds on the expected time complexity of PQC migration. Practically, we provide the first formal theoretical foundation for migration strategy design, evaluation, and standardization—bridging the gap between abstract complexity analysis and engineering implementation. This framework enables rigorous trade-off analysis among security, performance, and operational feasibility during large-scale cryptographic agility transitions.

Cryptographic TransitionPost-Quantum CryptographySystem Security

The Secrets Must Not Flow: Scaling Security Verification to Large Codebases (extended version)

Jul 01, 2025
LA
Linard Arquint
🏛️ ETH Zurich | Amazon Web Services

Existing program verification tools struggle to scale to large codebases due to their heavy reliance on manual intervention. This paper introduces Diodon, a modular verification methodology that partitions systems into a security-critical core and peripheral applications. It combines semi-automated (auto-active) verification—using Gobra to formally verify core protocol properties such as key confidentiality and injection resistance—with fully automated static analysis for the periphery. A key innovation is I/O independence verification: a static analysis technique that automatically enforces interface constraints and guarantees isolation of I/O behavior, ensuring peripheral code cannot compromise core security. Evaluated on an industrial-grade Go codebase exceeding 100,000 lines, Diodon required verification of only ~1% of the codebase as the core, achieving end-to-end security certification within three months. This approach significantly improves the feasibility and efficiency of verifying large-scale systems.

Ensuring I/O independence to maintain security properties in large codebasesScaling security verification to large codebases with minimal manual effortSplitting code into Core and Application for efficient verification

This work presents the first three-round authenticated key exchange (AKE) protocol secure in the commitment model without relying on long-term secret key material. Building upon the MT authenticator framework, the authors design dedicated protocols tailored to key agreement (KA) and key encapsulation mechanism (KEM) primitives, respectively, and establish session key security via a game-based proof in the unauthenticated setting. Compared to existing four-round constructions, this approach reduces communication overhead by one round while achieving comparable security guarantees under standard models. The protocol also supports unilateral authentication, thereby offering enhanced efficiency and practicality without compromising security strength.

3-pass AKEauthenticationcommitment-based model

Latest Papers

What's happening recently
View more

The Jasmin Compiler Preserves Cryptographic Security

Nov 14, 2025
SA
Santiago Arranz-Olmos
🏛️ MPI-SP | IMDEA Software Institute | Inria | Université de Lorraine

The existing correctness proof for the Jasmin compiler fails to cover non-termination and probabilistic computation—critical aspects in cryptographic implementations—thus hindering its trusted deployment in post-quantum cryptography. Method: We develop, for the first time within the Rocq proof framework, a formal verification framework preserving cryptographic security. We introduce Relational Hoare Logic (RHL) and integrate it with denotational semantics based on interaction trees to rigorously verify all 25 frontend compilation phases. Contribution/Results: We are the first to formally model and prove core cryptographic security properties—including IND-CCA—in a compiler verification setting. Moreover, we establish security equivalence preservation under both probabilistic and non-terminating executions. This work delivers the first end-to-end formal guarantee for efficient, verifiably secure implementations of post-quantum cryptographic algorithms.

Developing Relational Hoare Logic for compiler correctness with interaction treesFormalizing IND-CCA security preservation through compiler front-end verificationProving Jasmin compiler preserves cryptographic security for probabilistic computations

This work addresses the frequent disconnect between the mathematical certainty of numerical values in cryptographic protocols and their concrete representations, which undermines interoperability and formal verification. Drawing from representation theory, the paper introduces three classes of representations—algorithmically approximable, finitely precisely describable, and canonically normalizable—and proves that no universal computable canonicalizer can transform arbitrary approximate programs into a unique finite encoding. It extends the canonical encoding paradigm of the rational number system Σ_Q to practical cryptographic objects. By integrating computability theory with canonical serialization techniques, the approach is applied to symmetric and asymmetric encryption, hashing, and blockchain integrity protocols. Case studies such as Snaproot demonstrate that canonical representations are essential for achieving precise protocol specifications, ensuring interoperability, and enabling byte-level correctness arguments.

algorithmic presentationcanonical representationcomputable real numbers

This work addresses the high barrier to entry in formal verification of cryptographic protocols and the difficulty of tracing verification results back to concrete implementations. The authors propose a domain-specific language (DSL)-centric development methodology that pioneers a “language-first” modeling paradigm. Their approach automatically translates protocol implementations into Tamarin-verifiable models and integrates symbolic execution to ensure memory safety. This framework guarantees that general trace properties established through formal verification are correctly mapped back to the original source code. Empirical evaluation demonstrates the successful generation of precise models for Signed Diffie-Hellman and WireGuard protocols; notably, the resulting WireGuard implementation achieves interoperability, practical usability, and compositional security guarantees.

cryptographic protocolsformal verificationprotocol implementation

This work addresses the limitations of current cryptographic APIs, which are tightly coupled to specific algorithms and lack policy-driven control and key migration capabilities, thereby hindering smooth transitions to post-quantum cryptography. To overcome these challenges, the paper proposes a novel API architecture designed for cryptographic agility, grounded in five core principles: abstraction, stability, temporal flexibility, separation of concerns, and extensibility. By introducing scoped intent vocabularies and abstract policy interfaces, the design decouples algorithm selection from key management. Leveraging Protocol Buffers schemas alongside stable key identifiers and evolvable operations—such as rotation, transformation, and migration—the approach transforms algorithm updates into operational procedures that require no application code changes, significantly enhancing the feasibility and efficiency of migrating systems to post-quantum cryptographic standards.

algorithm migrationcryptographic agilitycryptographic API

Hot Scholars

GC

Giuseppe Caire

Professor, Technical University of Berlin, Germany, and Professor of Electrical Engineering (on
Information TheoryCommunicationsSignal ProcessingStatistics
RB

Rawad Bitar

Research Group Leader (and Habiliation Candidate), Technical University of Munich
Coding theoryDistributed learningDNA-based data storageData privacy and security
XZ

Xiang Zhang

Technical University of Berlin
Information TheorySecurityPrivate Information RetrievalDistributed Computation
ZL

Zhou Li

Guangxi University
Information TheoryCoding TheoryPrivacySecurity