off-chain security formalization

Design formal models and precise security specifications for off-chain protocols and services, formalizing system state, participant roles, and properties such as integrity (e.g., no double-spending), liveness/availability (no blocking), and privacy. Build formal protocol descriptions and produce provable security arguments (game- or simulation-based reductions, formal protocol proofs) that relate adversary capabilities and assumptions to concrete security guarantees.

off-chainsecurityformalization

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.19
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Protocol designers often face a high barrier to entry in using formal verification tools such as ProVerif and Tamarin due to the lack of systematic guidance on translating security properties into executable models. This work addresses this gap by conducting a systematic review of 53 studies published between 2022 and 2025, resulting in the first comprehensive taxonomy of security properties tailored to mainstream verification tools. The taxonomy integrates informal explanations, first-order logic definitions, and tool-specific modeling exemplars. By bridging the gap between theoretical formulations and practical modeling, this study significantly enhances the accuracy and efficiency of protocol modeling. An accompanying open-source repository of illustrative examples further lowers the practical barrier to adopting formal verification in real-world protocol design.

executable taxonomyformal verificationProVerif

Must-Read Papers

Most classic and influential ideas
View more

Verification and Attack Synthesis for Network Protocols

Nov 02, 2025
MV
Max von Hippel
🏛️ Northeastern University

Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.

Applying formal methods to analyze protocols under normal and attack conditionsSynthesizing attacks that prevent protocol requirement achievementVerifying network protocol functionality and performance requirements

It Takes a Village: Bridging the Gaps between Current and Formal Specifications for Protocols

Sep 16, 2025
DB
David Basin
🏛️ ETH Zürich | Cornell University | University of Texas, Austin | Nokia Bell Labs | Northeastern University | University of Pennsylvania | Princeton University | University of Illinois Chicago

This work addresses the semantic gap between informal protocol specifications—such as IETF RFCs—and formal specifications. It introduces a cognitive discrepancy analysis framework that identifies fundamental limitations in RFCs, including semantic ambiguity, unstated assumptions, and logical inconsistency. Methodologically, the approach integrates formal specification languages (e.g., TLA⁺), state-machine modeling, and protocol conformance testing to perform semantic parsing and cross-version consistency checking on real-world RFC texts and reference implementations. A key contribution is the establishment of a collaborative paradigm bridging industry practitioners and formal methods researchers, facilitating the evolution of RFCs into verifiable, executable formal specifications. Empirical evaluation demonstrates that this methodology significantly improves defect detection rates, interoperability assurance, and depth of security verification. The proposed framework provides a reusable, scalable foundation for formalizing next-generation Internet protocol standards.

Addressing underuse of formal specifications in Internet standardsBridging gaps between informal and formal protocol specificationsIdentifying benefits of formal methods for network protocols

This work addresses the absence of a systematic security framework in existing AI agent protocols—such as MCP and A2A—which undermines secure interactions across trust boundaries. We propose a six-layer protocol stack model tailored for AI agent communication and an implementation-agnostic Agent-Centric Security Model (AASM). To enforce and validate this model, we develop AgentConform, a two-stage conformance checking tool that integrates TLA+ formal modeling, a typed Protocol Intermediate Representation (IR), model checking, and runtime replay verification. For the first time, we formally define eleven security principles and introduce a mechanism for composition safety. Applying our approach to mainstream protocols reveals systemic flaws concerning credential lifecycle management, authorization enforcement, audit integrity, and compositional security; several identified vulnerabilities are already undergoing coordinated disclosure.

agent protocolscomposition safetyconformance testing

This work addresses the challenge of verifying that confidential software adheres to publicly specified temporal functional properties without revealing its internal implementation. It introduces, for the first time, zero-knowledge proofs into deductive model checking and proposes a novel method capable of generating verifiable correctness certificates. The approach supports both explicit-state transition graphs and symbolic linear guarded command representations of systems, integrating key techniques including polynomial commitments, Farkas’ lemma, piecewise-linear ranking functions, and Sigma protocols—encompassing matrix multiplication and range proofs. A prototype implementation demonstrates the practicality of the method on LTL verification benchmarks, achieving strong formal guarantees while preserving system confidentiality.

confidentialityformal verificationmodel checking

Generalized Security-Preserving Refinement for Concurrent Systems

Nov 10, 2025
HS
Huan Sun
🏛️ Zhejiang University | Singapore Institute of Technology | Singapore Management University

Verifying compliance of concurrent systems—particularly multicore OS kernels—with complex information-flow security (IFS) policies remains challenging due to the difficulty of establishing rigorous, compositional security guarantees under concurrency. Method: This paper proposes a generalized security-preserving refinement method that introduces *gait mapping*, a mechanism establishing fine-grained stepwise correspondence between concrete and abstract executions. For the first time, it extends security refinement to concurrent settings supporting higher-order, compositional security properties—including nontransitive noninterference. A formal framework is built in Isabelle/HOL, unifying the modeling of refinement relations and IFS policies to enable fully mechanized reasoning. Contribution/Results: The approach is validated on two nontrivial case studies: (i) it formally reproduces and verifies the previously overlooked single-core covert channel flaw in the ARINC 653 multicore standard; and (ii) it rigorously proves the correctness of the proposed mitigation mechanism.

Addressing limitations of existing methods restricted to sequential systemsDeveloping refinement techniques for security preservation in concurrent implementationsVerifying Information Flow Security in concurrent systems with complex policies

Latest Papers

What's happening recently
View more

This work addresses the challenge of formally verifying mature, safety-critical industrial C++ codebases by strategically integrating theorem proving (PVS) and model checking (SeaHorn), augmented with large language models to assist in specification construction. The approach is applied to the core order book algorithm of Stellar’s SDEX blockchain module. The verification effort successfully establishes critical correctness properties—including state consistency and unreachability of erroneous states—uncovers discrepancies between documentation and implementation, and produces reusable formal artifacts. These assets enable continuous validation of invariants during future code evolution, thereby enhancing long-term reliability and maintainability of the system.

blockchainformal verificationlegacy code

This work addresses behavioral inconsistencies and deadlocks arising from protocol refinement in distributed systems by proposing a novel approach that integrates multiparty session types (MPST) formal specifications with large language models. By deeply embedding behavioral correctness constraints—such as deadlock freedom—into the generation process, the method achieves, for the first time, formal-specification-guided automatic protocol refinement. Evaluated across multiple large language models, the approach demonstrates high effectiveness, yielding valid protocols in 95.6%–99.5% of cases while maintaining strong syntactic correctness. It successfully generates diverse and non-trivial deadlock-free protocol variants, substantially enhancing the safety, compatibility, and scalability of protocol replacement in distributed environments.

behavioural correctnessdeadlock-freelarge language models

This work addresses the absence of a machine-checked formal model for zk-STARK transparent proof protocols, which hinders rigorous assurance of their security and correctness. We present the first complete formalization of the zk-STARK protocol in Isabelle/HOL, constructing executable models of both prover and verifier, and carry out their specification and verification using a finite probabilistic state monad equipped with weakest preconditions calculus. Our main contributions include a phased soundness theorem with an explicit error probability bound, a rigorous proof of perfect completeness for honest executions, and the public release of all key definitions and theorems as Isabelle source code, thereby laying a foundation for high-assurance implementations of zero-knowledge proof protocols.

formal verificationIsabelle/HOLtransparent proof protocol

Hot Scholars

MB

Marco Bernardo

University of Urbino
Theoretical computer scienceConcurrency theoryProcess algebraFormal methods
RM

Roberto Metere

Lecturer (Assistant Professor), University of York
information securitycryptographyformal verificationsecure computation
ZZ

Zibin Zheng

IEEE Fellow, Highly Cited Researcher, Sun Yat-sen University, China
BlockchainSmart ContractServices ComputingSoftware Reliability
ER

Elvinia Riccobene

Professore, Università di Milano, Italy
Formal MethodsSoftware Engineering
HS

Haochen Sun

Beijing University of Posts and Telecommunications
Large Language ModelMulti-Agent System