Simple High-Level Code for Cryptographic Arithmetic - With Proofs, Without Compromises
Name
FiatCryptoSP19.pdf
Description
Accepted version
Size
405.93 KB
Format
Adobe PDF
Checksum (MD5)
7017bfa0e4f2d9ff1d9f738c0eeb8ab8
Author(s) • • • •
Erbsen, Andres
Philipoom, Jade D.
Gross, Jason S.
Sloan, Robert Hal
Chlipala, Adam
Date Issued
April 2019
Journal
Proceedings - IEEE Symposium on Security and Privacy
Publisher
Institute of Electrical and Electronics Engineers (IEEE)
Citation
Erbsen, Andres et al. “Simple High-Level Code for Cryptographic Arithmetic - With Proofs, Without Compromises.” Proceedings - IEEE Symposium on Security and Privacy, May-2019 (May 2019) © 2019 The Author(s)
Version
Author's final manuscript
Abstract
We introduce a new approach for implementing cryptographic arithmetic in short high-level code with machine-checked proofs of functional correctness. We further demonstrate that simple partial evaluation is sufficient to transform into the fastest-known C code, breaking the decades-old pattern that the only fast implementations are those whose instruction-level steps were written out by hand. These techniques were used to build an elliptic-curve library that achieves competitive performance for 80 prime fields and multiple CPU architectures, showing that implementation and proof effort scales with the number and complexity of conceptually different algorithms, not their use cases. As one outcome, we present the first verified high-performance implementation of P-256, the most widely used elliptic curve. implementations from our library were included in BoringSSL to replace existing specialized code, for inclusion in several large deployments for Chrome, Android, and CloudFlare.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1109/SP.2019.00005