Reference. Cerisier: A Program Logic for Attestation in a Capability Machine
A key feature in trusted computing is attestation, which allows encapsulated components (enclaves) to prove their identity to (local or remote) distrusting components. Reasoning about software that uses the technique requires tracking how trust evolves after successful attestation. This process is security-critical and non-trivial, but no existing formal verification technique supports modular reasoning about attestation of enclaves and their clients, or proving end-to-end properties for systems combining trusted, untrusted and attested code. We contribute Cerisier, the first program logic for modular reasoning about trusted, untrusted and attested code, fully mechanized in the Iris separation logic and the Rocq Prover. We formalize a recent proposal, CHERI-TrEE, to extend capability machines with enclave primitives, as an extension to the Cerise capability machine and program logic. Our program logic comes with a universal contract for untrusted code, which captures both capability safety and local enclave attestation. Like Cerise, this universal contract is phrased in terms of a logical relation defining capabilities’ authority. We demonstrate Cerisier by proving end-to-end properties for three representative applications of trusted computing: secure outsourced computation, mutual attestation and a modeled trusted sensor component.
Cite
Cites 47 works (2 here)
With notes (2)
Cerise: Program Verification on a Capability Machine in the Presence of Untrusted Code georges-2024-cerise
A capability machine is a type of CPU allowing fine-grained privilege separation using capabilities , machine words that represent certain kinds of authority. We present a mathematical model and accompanying proof methods that can be used for formal verification of functional correctness of programs running on a capability machine, even when they invoke and are invoked by unknown (and possibly malicious) code. We use a program logic called Cerise for reasoning about known code, and an associated logical relation, for reasoning about unknown code. The logical relation formally captures the capability safety guarantees provided by the capability machine. The Cerise program logic, logical relation, and all the examples considered in the paper have been mechanized using the Iris program logic framework in the Coq proof assistant. The methodology we present underlies recent work of the authors on formal reasoning about capability machines [Georges et al. 2021 ; Skorstengaard et al. 2019a ; Van Strydonck et al. 2022 ], but was left somewhat implicit in those publications. In this paper we present a pedagogical introduction to the methodology, in a simpler setting (no exotic capabilities), and starting from minimal examples. We work our way up to new results about a heap-based calling convention and implementations of sophisticated object-capability patterns of the kind previously studied for high-level languages with object-capabilities, demonstrating that the methodology scales to such reasoning.
Iris from the ground up: A modular foundation for higher-order concurrent separation logic jung_etal_iris_ground_up_2018
Iris is a framework for higher-order concurrent separation logic, which has been implemented in the Coq proof assistant and deployed very effectively in a wide variety of verification projects. Iris was designed with the express goal of simplifying and consolidating the foundations of modern separation logics, but it has evolved over time, and the design and semantic foundations of Iris itself have yet to be fully written down and explained together properly in one place. Here, we attempt to fill this gap, presenting a reasonably complete picture of the latest version of Iris (version 3.1), from first principles and in one coherent narrative.
External (45)
- Cerisier: A Program Logic for Attestation in a Capability Machine (2026)
- Cerisier: A Program Logic for Attestation in a Capability Machine (Artifact) (2026)
- Cerisier - Code repository (2026)
- Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware Architecture (2025)
- Formally-verified Security against Forgery of Remote Attestation using SSProve (2025)
- Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal Safety (2024)
- Formal Verification of Virtualization-Based Trusted Execution Environments (2024)
- CHERIoT: Complete Memory Safety for Embedded Devices (2023)
- Formalizing, Verifying and Applying ISA Security Guarantees as Universal Contracts (2023)
- A Survey of Secure Computation Using Trusted Execution Environments (2023)
- CHERI-TrEE: Flexible enclaves on capability machines (2023)
- Capability Hardware Enhanced RISC Instructions: CHERI Instruction-Set Architecture (Version 9) (2023)
- Proteus: An Extensible RISC-V Core for Hardware Extensions (2023)
- Verified Security for the Morello Capability-enhanced Prototype Arm Architecture (2022)
- Mind the Gap: Studying the Insecurity of Provably Secure Embedded Trusted Execution Architectures (2022)
- 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12 (2022)
- Le temps des cerises: efficient temporal stack safety on capability machines using directed capabilities (2022)
- Proving full-system security properties under multiple attacker models on capability machines (2022)
- Arm Architecture Reference Manual Supplement Morello for A-Profile Architecture (2022)
- Proving full-system security properties under multiple attacker models on capability machines (2022)
- SSProve: A Foundational Framework for Modular Cryptographic Proofs in Coq (2021)
- Ph. D. Dissertation (2021)
- Efficient and provable local capability revocation using uninitialized capabilities (2021)
- Demystifying Attestation in Intel Trust Domain Extensions via Formal Verification (2021)
- StkTokens : Enforcing well-bracketed control flow and stack encapsulation using linear capabilities (2021)
- Cornucopia: Temporal Safety for CHERI Heaps (2020)
- CVShield: Guarding Sensor Data in Connected Vehicle with Trusted Execution Environment (2020)
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation process (2020)
- 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16 (2019)
- Komodo: Using verification to disentangle secure-enclave hardware from software (2017)
- Efficient Tagged Memory (2017)
- Hardware-Based Trusted Computing Architectures for Isolation and Attestation (2017)
- Sancus 2.0: A Low-Cost Security Architecture for IoT Devices (2017)
- Establishing Mutually Trusted Channels for Remote Sensing Devices with Trusted Execution Environments (2017)
- Foundations of Hardware-Based Attested Computation and Application to SGX (2016)
- Reasoning about Object Capabilities with Logical Relations and Effect Parametricity (2016)
- Intel SGX Explained (2016)
- TyTAN: tiny trust anchor for tiny devices (2015)
- CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization (2015)
- Separation Logic in the Presence of Garbage Collection (2011)
- Modelling, Controlling and Reasoning About State, 29.08. - 03.09.2010 (Dagstuhl Seminar Proceedings, Vol. 10351) (2010)
- Logical relations for encryption1 (2003)
- Hardware support for fast capability-based addressing (1994)
- Protection in programming languages (1973)
- Programming semantics for multiprogrammed computations (1966)