A hands-on undergraduate curriculum: formal verification of real cryptographic code with Lean 4 — companion to the *-ed25519-verified and pasta-pallas-verified projects
Find a file
mrwulf 60936028a6 book overhaul moves 1+2: the minute-one artifact, and cold-open surgery on ch1
From the 7-reader didactic audit (control/BOOK-OVERHAUL-PLAN.md). The two
highest-leverage moves per the cold-open reader and the panel's most-repeated
finding.

MOVE 1 — the reader touches the real thing in minute one. The panel's single
loudest note: a book that teaches "demand verification" gave the reader
nothing to verify for twelve chapters. Now: the title page names
ltl.zkdefi.org (19 entries, one post-quantum, "verify every entry yourself by
the last chapter"); the preface opens on that page instead of a generic power
claim; ch1 gains a try-it box after the pyramid pointing at entries 13-16 and
18. And ch7's broken promise is honored — it invited "check one leaf" while
never printing the 71-digit Q; the exact Q from P25519.lean is now on the
page, no hidden digits (render-verified against the repo).

MOVE 2 — ch1 cold open. Per the cold reader who hooked at line 13 and wobbled
by line 31: the first worked box (a log10 re-derivation of a punch the prose
already landed) collapses to four lines, the mechanics pushed to Exercise 1.1
— getting the reader ~30 lines sooner to the headroom box, the genuinely novel
bit. The vague "In 2014, researchers…" opener becomes the actual bug: a
two-line diff captioned as the entire defect, anchored to the real Fiat-Crypto
S&P 2019 lineage (no fabricated CVE). Competitor roll-call → footnote.
Syllabus roadmap → a second-person promise ("by Chapter 7 you will have handed
a kernel a certificate…"). "Why Lean" vendor bullets → reader-inheritance
voice ("you start on a million lines of proved mathematics").

Builds here: tectonic, 116 pages, zero errors.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-08 00:14:43 +02:00
chapters book overhaul moves 1+2: the minute-one artifact, and cold-open surgery on ch1 2026-08-08 00:14:43 +02:00
exercises Verifying Cryptography with Lean 4: complete 12-chapter curriculum 2026-07-03 09:44:40 +02:00
solutions Verifying Cryptography with Lean 4: complete 12-chapter curriculum 2026-07-03 09:44:40 +02:00
.gitignore Verifying Cryptography with Lean 4: complete 12-chapter curriculum 2026-07-03 09:44:40 +02:00
build.sh build: the book compiles on this Ubuntu — tectonic + dual-engine preamble 2026-08-08 00:03:34 +02:00
lakefile.toml Verifying Cryptography with Lean 4: complete 12-chapter curriculum 2026-07-03 09:44:40 +02:00
lean-toolchain Verifying Cryptography with Lean 4: complete 12-chapter curriculum 2026-07-03 09:44:40 +02:00
main.pdf book overhaul moves 1+2: the minute-one artifact, and cold-open surgery on ch1 2026-08-08 00:14:43 +02:00
main.tex book overhaul moves 1+2: the minute-one artifact, and cold-open surgery on ch1 2026-08-08 00:14:43 +02:00
preamble.tex build: the book compiles on this Ubuntu — tectonic + dual-engine preamble 2026-08-08 00:03:34 +02:00
README.md ch13: send the reader to the live log — the cross-referencing that did not exist 2026-08-07 23:29:36 +02:00

Verifying Cryptography with Lean 4

A hands-on curriculum for undergraduates with zero formal-verification background — from 1 + 1 = 2 to reading (and extending) real, machine-checked proofs that production elliptic-curve code is correct.

This is the educational companion to a family of verification projects in which complete Ed25519 proof pyramids (from curve25519-dalek and three production forks — field, group law, scalars, and the signature verifier itself) and the Pasta curves' field layer were machine-checked in Lean 4 against models extracted from the actual Rust sources:

Companion project What is verified there
dalek-ed25519-verified the complete pyramid, upstream dalek: field 𝔽ₚ + Edwards group law + scalar arithmetic mod + the four-tier signature apex (accept ⇔ decompress(R) = k+[s]B, hash opaque)
anza-ed25519-verified the complete pyramid, Solana's fork, its own extraction
risc0-ed25519-verified the complete pyramid, RISC Zero's fork
betrusted-ed25519-verified the complete pyramid, Betrusted's fork
pasta-pallas-verified Pallas modulus primality (Lucas/Pratt), Montgomery foundations
formal-verification-control the method: invariants, terrain map, failure map, tooling

The book

main.pdf — thirteen chapters + interlude + three appendices, full color, built with LaTeX/TikZ from the sources in this repo. Honesty note: the committed PDF (109 pages) was built 2026-07-06, before chapter 13 was committed (2026-07-28) — rebuild with the command below to get the current book; the committed PDF lags the committed sources until the next rebuild on a LaTeX-equipped machine. No prior Lean or formal methods assumed; high-school algebra and a little programming suffice.

  1. Why Verify? — the carry bug testing cannot find
  2. Meet Lean — programs, types, inductive data
  3. Propositions as Types — CurryHoward: proofs are programs
  4. Tactics — proving as a dialogue with the goal state
  5. Numbers and Automationomega, ring, norm_num, decide, and the simp discipline
  6. Modular Arithmetic — clock worlds, fields, why 2²⁵⁵ 19
  7. Primality Certificates — convincing a paranoid kernel a 77-digit number is prime
  8. From Rust to Lean — the Charon/Aeneas extraction pipeline
  9. The Denotation Bridge — the commuting square at the heart of it all — Interlude — a complete verification, entirely by hand, then re-enacted in Lean line by line
  10. Verifying a Field — the full campaign, told honestly (including the crash)
  11. Honesty and Axioms#print axioms, hollow certificates, trusted bases
  12. The Pyramid — group law, scalars, signatures, and where you come in
  13. The Attestation Protocol — what it takes to make "it is proven" checkable by a stranger; closes with Go and touch the real thing: a guided reading of the estate's live transparency log (ltl.zkdefi.org — 19 leaves, the four ed25519 pyramids at 44 certificates, the log's own Merkle proofs as leaf 17, and the first post-quantum leaf, SLH-DSA, as leaf 18), including the fifteen-minute verify-it-yourself exercise

Appendices: A — the pen-and-paper toolkit (recipe cards with drills); B — guided walkthroughs of every exercise-file hole; C — a tour of the real repositories. Plus a glossary and a thirteen-week course plan.

The didactic machinery, deliberately heavy:

  • Pen-and-paper worked examples in every chapter — computations with the real constants (2²⁵⁵19, radix 2⁵¹, the fold constant 19, the actual 254-squaring inversion chain, the true Pratt tree p1 = 2²·3·65147·Q), because the real numbers carry the real arguments. Highlights: inverting 19 modulo the 77-digit prime in five lines of Euclid; a fully hand-checked primality certificate for 97; the ×19 fold derived at the real weights; the 16p subtraction constant audited to the bit (8 fails by 151); the complete BernsteinLange completeness chain.
  • Solutions immediately after every exercise set — each one leads with the pathway (how a person finds the answer) before the answer itself.
  • Boxed Big idea / Try it / Pitfall / Aha / Checkpoint elements, TikZ figures throughout.

Everything the book claims about the companion projects reflects their actual, auditable state — including open frontiers.

The exercises (they run!)

exercises/ChNN.lean are working files with sorry holes; solutions/ChNN.lean are complete. Every solution file compiles with zero errors against the pinned toolchain (Lean v4.30.0-rc2, Mathlib 5450b53e); solutions to proof exercises contain no sorry.

Setup (one-time, ~5 min + Mathlib cache download):

# 1. install elan (Lean version manager) if you haven't:
curl https://elan.lean-lang.org/elan-init.sh -sSf | sh
# 2. fetch the Mathlib build cache (do NOT build Mathlib yourself):
cd verifying-crypto-with-lean
lake exe cache get
# 3. open the folder in VS Code with the "Lean 4" extension, or:
lake build Solutions   # compiles all solution files as a check

Chapters 24 need no Mathlib at all — you can start them with any Lean 4 install while the cache downloads.

Building the book

Any TeX Live ≥ 2023 with tikz, tcolorbox, listings, lmodern:

pdflatex main.tex && pdflatex main.tex   # twice for the TOC

Honesty ledger

In the spirit of Chapter 11:

  • All solutions/*.lean were compiled (and their #eval outputs checked against their comments) at authoring time with the pinned versions above.
  • Exercise templates compile with sorry warnings only.
  • The book's claims about the companion projects (what is proven, what is frontier) mirror those repos' own READMEs and TRUSTED-BASE ledgers at the time of writing; the repos, not this book, are the source of truth. Re-audited 2026-07-06 after the signature apex reached its final four-tier form (coherence pass 4): chapter 12's status diagram, apex section, and audit-drill solution, chapter 11's boundary example, chapter 8's extraction notes, the repo tour, and this table were brought up to the proven state.
  • Didactic revision (2026-07-06, same day): the book now states and keeps a "ratchet rule" (chapter 1) — every load-bearing idea worked at napkin scale AND at real scale with the full 77-digit constants printed, nothing elided. Chapter 12 gained the missing rungs: the addition law run by hand on a mod-13 curve and then on the real base point (with a machine-supplied quotient witness audited by casting out nines and elevens), the scalar cycle felt on the napkin curve, decompression run twice (mod-13 sign-bit walk, then the real compressed base point: byte-31 sign bit, and the full-size hand verification 5·y_B 4 = 4·p, every digit printed), plus a new paper exercise (12.4). Every printed constant was machine-verified before typesetting; the PDF (109 pages, 2026-07-06 build — predates ch13) is rebuilt from these sources.
  • The PDF in the repo is built from the committed sources by the command above — but the committed build currently predates chapter 13 (see the honesty note at the top); rebuild it yourself if you don't trust binaries (good instinct), and you will get the thirteen-chapter book.
  • The three named solution certificates were kernel-audited (coherence pass 2, 2026-07-03): Ch09.add_spec depends on [propext, Classical.choice, Quot.sound]; Ch09.mulVal_spec and Ch12.addFixed_spec on [propext, Quot.sound] only. The Interlude's "compiled and axiom-audited" phrase shipped one pass before its audit had actually been run — caught by the verification projects' own coherence process and made true; recorded here in the spirit of Chapter 11.