Three new proof files over the CurveField extraction, composing the proven group-law layer (no new axioms, no associativity assumed — computational layering over the abstract `edAdd`): - `Proofs/DsmTableSpec.lean` — `NafLookupTable5::from(&A)`: the 8 entries are valid `ProjectiveNielsPoint` caches of valid on-curve points denoting the odd multiples A, 3A, ..., 15A as the `edOdd` double-and-add recursion. 7 explicit loop peels over edwards_as_projective_niels_spec / add_projniels_law / compl_as_extended_law, seeded by edwards_double_law. `select`: both masserts (x odd, x < 16) DISCHARGED — panic-freedom is proven, not assumed; post enumerates all 8 digit cases. - `Proofs/DsmStepSpec.lean` — `proj_double_law` (the projective doubling denotes `edAdd P P`; same Z^2-scaled linear_combination discipline as the extended-coordinate law), `compl_as_projective_law` ((X:Z),(Y:T) to (XT:YZ:ZT) preserves the point), `naf_select_entry` (digit-indexed lookup returns THE entry: NafEntryOf r A ((x-1)/2)), and `dsm_step_p_law` / `dsm_step_b_law`: the three-way NAF digit step denotes `edDigit` — add the d-th odd multiple, add its negation, or pass through. - `Proofs/DsmLoopSpec.lean` — the 256-iteration Straus loop by GENUINE induction on the counter (one symbolic body walk, no unrolling): `dsm_loop_spec` — from the identity, the loop returns a valid on-curve point denoting `dsmFold ... edId 256`, the abstract double-and-add fold of both digit arrays over the table points. Digit and table hypotheses are exactly what the NAF spec and naf_table_spec provide (layering). check.sh wired: PROOFS + AUDIT_IMPORTS + 7 new CERTS (naf_table_spec, naf_select_spec, proj_double_law, compl_as_projective_law, dsm_step_p_law, dsm_step_b_law, dsm_loop_spec), each `#print axioms`-audited to exactly [propext, Classical.choice, Quot.sound]. Full check.sh green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| verification | ||
| .gitignore | ||
| README.md | ||
| TRUSTED-BASE.md | ||
dalek-ed25519-verified
Formal verification of the ed25519 implementation in dalek-cryptography/curve25519-dalek (upstream, v5.0.0-rc.1), built as a coherent proof pyramid in Lean 4 via the Charon/Aeneas transpilation pipeline:
┌──────────────────────────────┐
│ Signature (EdDSA verify) │ accepted ⇒ [8][S]B = [8]R + [8][k]A
├──────────────────────────────┤
│ Scalar arithmetic mod ℓ │ Scalar52 ops correct mod ℓ
├──────────────────────────────┤
│ Group law (twisted Edwards) │ point ops = complete addition law
├──────────────────────────────┤
│ Field 𝔽_p, p = 2²⁵⁵ − 19 │ FieldElement51 ops correct mod p
└──────────────────────────────┘
Every layer states its theorems about the actual Aeneas-transpiled Rust
code (never about a hand-written re-model), and every claim in the status
table below is backed by a compiled proof plus an axiom audit of the named
certificate. Files that do not compile under verification/check.sh are not
in this repository.
Layer status
| Layer | Certificate | Status | Axioms of certificate |
|---|---|---|---|
| Field 𝔽_p | fieldImplementation |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Group law (Edwards) | edwardsImplementation |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Scalar mod ℓ | scalarImplementation (add ✅ sub ✅ mul ✅) |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Signature (EdDSA) | verifyEquation (planned) |
⏳ planned | — |
Status legend: ✅ proven & axiom-audited · ⏳ in progress · ❌ not started.
This table is updated only when verification/check.sh passes for the layer.
Source
- Upstream: dalek-cryptography/curve25519-dalek, commit
4cf8db2 - Pinned/patched source: saymrwulf/curve25519-dalek-source, commit
135ed70 - Patches: minimal Aeneas-compatibility only (documented in the source repo)
- Verified backend:
backend/serial/u64(FieldElement51,Scalar52). SIMD/AVX backends are out of scope (marked opaque).
Toolchain (pinned)
| Component | Version |
|---|---|
| Aeneas | bf13c42e |
| Charon | 9dd7f23c |
| Lean | v4.30.0-rc2 |
| OCaml | 5.3.0 |
Reproducing
source ~/aeneas-toolchain/env.sh
cd verification
./extract.sh # Rust → LLBC → Lean (regenerates gen/)
./check.sh # compiles EVERY shipped file + axiom-audits EVERY certificate
The scalar layer has its own pair of buttons:
./extract-scalar.sh # regenerates gen/CurveScalar (Scalar52 limb arithmetic)
./check-scalar.sh # compiles the scalar gen + all scalar proofs (add, sub,
# Montgomery mul) and kernel-audits 10 certificates,
# including the scalarImplementation aggregate
Trusted base
See TRUSTED-BASE.md for the complete list of assumptions (Lean kernel, mathlib, Charon/Aeneas semantics, external-function models, and — in the signature layer only — an opaque SHA-512 model).
Provenance
Proof engineering in this repository builds on the verification methodology and proof architecture of PlanetMacro/ed25519-verificationtest (the reference solution). All proofs here are checked against this fork's own extracted code; nothing is claimed that the check script does not compile.