Formally verified ed25519 (risc0 curve25519-dalek fork v4.1.3): field + complete Edwards addition law proven in Lean 4 via Charon/Aeneas; axiom-audited certificates
Find a file
mrwulf 6fe31be80d Add scalar-layer foundation (Scalar52 arithmetic mod ℓ)
Transpile the Scalar52 limb backend (backend::serial::u64::scalar
add/sub/mul/square/montgomery_*) from Rust to Lean via Charon/Aeneas,
scoped at the function level to the iterator-free arithmetic core.

  - verification/extract-scalar.sh: function-level Charon/Aeneas extraction.
    This fork (v4.1.3) inlines a local `black_box` (a volatile read used as an
    optimization barrier) inside Scalar52::sub; charon cannot translate the
    `&raw const` it lowers to, so it is marked --opaque and modeled below.
  - verification/gen/CurveScalar/{Types,Funs}.lean: transpiled model (27 defs)
  - verification/gen/CurveScalar/FunsExternal.lean: hand-written model of
    Scalar52::sub::black_box as the identity on u64 (a volatile read returns
    the value written; the qualifier is only an optimization barrier).
    TypesExternal.lean is decl-free — this fork pulls in no external types
    (unlike v5 dalek, which routes sub through subtle::Choice).
  - verification/Proofs/ScalarDenote.lean: semantic foundation — Scalar52
    denotation into ℤ/ℓℤ, limb-bound invariant, and L_val (the transpiled
    constants::L denotes exactly the group order ℓ, kernel-checked).
  - verification/check-scalar.sh: guarded compile of the gen modules plus the
    denotation foundation.

check-scalar.sh passes: gen compiles; denotation + L = ℓ proven.
add/sub/mul remain in progress.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 21:24:39 +02:00
verification Add scalar-layer foundation (Scalar52 arithmetic mod ℓ) 2026-07-02 21:24:39 +02:00
.gitignore skeleton: proof-pyramid layout, honest status table, trusted-base doc 2026-07-02 13:10:26 +02:00
README.md Add scalar-layer foundation (Scalar52 arithmetic mod ℓ) 2026-07-02 21:24:39 +02:00
TRUSTED-BASE.md skeleton: proof-pyramid layout, honest status table, trusted-base doc 2026-07-02 13:10:26 +02:00

risc0-ed25519-verified

Formal verification of the ed25519 implementation in risc0/curve25519-dalek (RISC Zero fork, v4.1.3), built as a coherent proof pyramid in Lean 4 via the Charon/Aeneas transpilation pipeline:

        ┌──────────────────────────────┐
        │  Signature (EdDSA verify)    │   accepted ⇒ [8][S]B = [8]R + [8][k]A
        ├──────────────────────────────┤
        │  Scalar arithmetic mod      │   Scalar52 ops correct mod 
        ├──────────────────────────────┤
        │  Group law (twisted Edwards) │   point ops = complete addition law
        ├──────────────────────────────┤
        │  Field 𝔽_p, p = 2²⁵⁵  19    │   FieldElement51 ops correct mod p
        └──────────────────────────────┘

Every layer states its theorems about the actual Aeneas-transpiled Rust code (never about a hand-written re-model), and every claim in the status table below is backed by a compiled proof plus an axiom audit of the named certificate. Files that do not compile under verification/check.sh are not in this repository.

Layer status

Layer Certificate Status Axioms of certificate
Field 𝔽_p fieldImplementation proven [propext, Classical.choice, Quot.sound]
Group law (Edwards) edwardsImplementation proven [propext, Classical.choice, Quot.sound]
Scalar mod scalarImplementation 🔨 foundation denotation + L= proven; add/sub/mul in progress
Signature (EdDSA) verifyEquation in progress

Status legend: proven & axiom-audited · in progress · not started. This table is updated only when verification/check.sh passes for the layer.

Source

  • Upstream: risc0/curve25519-dalek, commit 385adda
  • Pinned/patched source: saymrwulf/risc0-curve25519-dalek-source, commit 2643444
  • Patches: minimal Aeneas-compatibility only (documented in the source repo)
  • Scope caveat: this verifies the fork's pure-Rust serial/u64 path. The RISC Zero zkVM accelerator/syscall path is different code and is NOT covered by these proofs.

Toolchain (pinned)

Component Version
Aeneas bf13c42e
Charon 9dd7f23c
Lean v4.30.0-rc2
OCaml 5.3.0

Reproducing

source ~/aeneas-toolchain/env.sh
cd verification
./extract.sh    # Rust → LLBC → Lean (regenerates gen/)
./check.sh      # compiles EVERY shipped file + axiom-audits EVERY certificate

Trusted base

See TRUSTED-BASE.md for the complete list of assumptions (Lean kernel, mathlib, Charon/Aeneas semantics, external-function models, and — in the signature layer only — an opaque SHA-512 model).