Score
Designs, constructs, and analyzes formal models and proof artifacts showing that a distributed replication protocol implements a sequential state machine abstraction; this includes proving properties of logs, command ordering, linearizations, and causal orderings and demonstrating that command execution preserves the intended sequential semantics under the protocol's timing and failure assumptions.
This paper addresses the paradigmatic equivalence between state-based and operation-based CRDTs—a longstanding challenge arising from their differing dependencies on network causality and message granularity, with prior work lacking a rigorous formalization of their simulation relationship. To resolve this, we introduce a novel weak simulation framework based on labeled transition systems extended with network interactions, precisely defining cross-paradigm simulation semantics and establishing necessary conditions for property preservation. We prove that, under causal consistency, no client can distinguish between state-based and operation-based implementations—thereby achieving representation independence. Our results formally delineate the equivalence boundary between the two paradigms, enabling correctness-preserving cross-paradigm property transfer, verification reuse, and flexible system design. This work provides a unified semantic foundation for both CRDT theory and practical implementation.
Traditional typestate systems struggle to capture quantitative constraints—such as quorum requirements—and concurrent I/O behaviors inherent in distributed protocols, and they lack resilience to runtime network failures. This work proposes a probabilistic runtime verification approach that integrates mutable internal state, hybrid session mechanisms, and expected action ratios into an extended typestate model. The resulting framework enables dynamic modeling and monitoring of critical properties like concurrent message exchange and quorum satisfaction. Evaluated on commit and voting-based consensus protocols, the method effectively detects runtime behavioral deviations, significantly enhancing the expressiveness and practical applicability of typestate reasoning in distributed systems.
This work addresses the problem of verifying serializability in concurrent programs—determining whether all their concurrent executions are equivalent to some serial execution. To this end, the authors propose SER, a dedicated modeling language, together with an end-to-end automated verification pipeline that, for the first time, enables fully automatic serializability checking under unbounded thread counts and execution lengths. The approach reduces the problem to reachability queries in Petri nets and incorporates several scalability-enhancing optimizations, including Petri net slicing, semilinear set compression, and Presburger arithmetic manipulations. The system produces either machine-checkable certificates of correctness or concrete counterexamples, and has been successfully applied to real-world network system models such as stateful firewalls and BGP routers, demonstrating both theoretical rigor and practical utility.
Traditional network protocol modeling via Markov chains heavily relies on manual expert knowledge, resulting in poor generalizability and scalability. This paper proposes the first end-to-end automated framework integrating large language models (LLMs) with state-aware fuzzing: an LLM automatically synthesizes executable state-transition models from protocol specifications and source code, then generates feedback-driven test sequences; program synthesis techniques further produce runnable fuzzers. The approach significantly lowers the barrier to protocol modeling and enhances cross-protocol transferability. Evaluated on three mainstream protocol implementations—TLS, DNS, and HTTP/2—the method discovered 12 previously unknown security vulnerabilities, all confirmed by developers. These findings validate the framework’s effectiveness and practical utility in real-world protocol security analysis.
Existing swarm protocols lack compositionality, hindering modular development and code reuse in large-scale, complex systems. This work proposes a compositional approach grounded in a local-first, asynchronous communication model, establishing the first theoretical framework for compositional swarm protocols that enables independent component design, formal specification, and correct integration. By integrating formal methods, asynchronous event propagation, and local-first computation paradigms, the authors develop a verifiable protocol composition technique accompanied by an automated toolchain. This ensures that verified components retain global system correctness upon integration, substantially enhancing both development efficiency and system reliability.
This work addresses the state explosion problem inherent in asynchronous, parameterized distributed protocols, which arises from communication asynchrony and unbounded participant counts. The authors propose an automated safety verification method based on backward unreachableness analysis. Their key innovation lies in distinguishing parameterized unboundedness into affine and non-affine categories, focusing specifically on affine protocols. By integrating goal-directed instantiation, causal reasoning, and state summarization, the approach efficiently prunes the state space. The prototype tool DissProve successfully verifies multiple affine protocols featuring infinitely many participants and unbounded execution lengths, achieving—for the first time—scalable, fully automatic safety verification for such asynchronous parameterized systems.
This work investigates whether coordination is inherently required by specifications in distributed systems, independent of any particular protocol or implementation. Operating within the asynchronous message-passing model, it introduces a semantic characterization of coordination requirements based on the monotonicity of history extensions, leveraging Lamport’s happens-before partial order and the observable outcomes defined by the specification. Notably, this approach requires no assumptions about programming languages or protocols. The framework unifies and explains several foundational results—including CAP, CALM, snapshot consistency, and transaction isolation—by precisely delineating the boundary between specifications that can be implemented without coordination and those that fundamentally require it, thereby offering a cohesive theoretical foundation for distributed computing.
We present CryptoChoreo, a choreography language for the specification of cryptographic protocols. Choreographies can be regarded as an extension of Alice-and-Bob notation, providing an intuitive high-level view of the protocol as a whole (rather than specifying each protocol role in isolation). The extensions over standard Alice-and-Bob notation that we consider are non-deterministic choice, conditional branching, and mutable long-term memory. We define the semantics of CryptoChoreo by translation to a process calculus. This semantics entails an understanding of the protocol: it determines how agents parse and check incoming messages and how they construct outgoing messages, in the presence of an arbitrary algebraic theory and non-deterministic choices made by other agents. While this semantics entails algebraic problems that are in general undecidable, we give an implementation for a representative theory. We connect this translation to ProVerif and show on a number of case studies that the approach is practically feasible.
Protocol model checking often suffers from state-space explosion, particularly when channel capacity or window size increases. This work proposes a compositional verification approach based on bidirectional simulation relations, constructing a hierarchy of protocol abstractions—SCP → ABP → SWP—with progressively refined semantics. By reducing the verification of complex protocols to that of the most abstract protocol, SCP, the method circumvents direct model checking of large state machines. Correctness of ABP and SWP is then derived from the invariance properties verified solely on SCP. This abstraction-based reduction significantly lowers computational complexity and enables efficient formal verification of protocols under high parameter settings.
Interfaces play a central role in determining compatible component compositions by prescribing permissible interactions between a service provider (server) and its consumers (clients). The high degree of concurrency in asynchronous communicating systems increases the risk of unintentionally introducing deadlocks and livelocks. The weak termination property serves as a basic sanity check to avoid such problems. It assures that in each reachable state, the system has the option to eventually terminate. This paper generalizes existing results that, by construction, guarantee weakly terminating interface compositions. Our generalizations make the theory applicable more broadly in practice. Starting with an interface specification of a server satisfying certain properties, we show how a class of clients modeling different usage contexts can be derived using a partial mirroring relation. Furthermore, we discuss an embedding of our results in an open-source tool to guide modelers in designing weakly terminating interfaces.