Formal Verification of the Safegcd Implementation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: O'Connor, Russell, Poelstra, Andrew
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915407631220736
author O'Connor, Russell
Poelstra, Andrew
author_facet O'Connor, Russell
Poelstra, Andrew
contents The modular inverse is an essential piece of computation required for elliptic curve operations used for digital signatures in Bitcoin and other applications. A novel approach to the extended Euclidean algorithm has been developed by Bernstein and Yang within the last few years and incorporated into the libsecp256k1 cryptographic library used by Bitcoin. However, novel algorithms introduce new risks of errors. To address this we have completed a computer verified proof of the correctness of (one of) libsecp256k1's modular inverse implementations with the Coq proof assistant using the Verifiable C's implementation of separation logic.
format Preprint
id arxiv_https___arxiv_org_abs_2507_17956
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Formal Verification of the Safegcd Implementation
O'Connor, Russell
Poelstra, Andrew
Cryptography and Security
Logic in Computer Science
The modular inverse is an essential piece of computation required for elliptic curve operations used for digital signatures in Bitcoin and other applications. A novel approach to the extended Euclidean algorithm has been developed by Bernstein and Yang within the last few years and incorporated into the libsecp256k1 cryptographic library used by Bitcoin. However, novel algorithms introduce new risks of errors. To address this we have completed a computer verified proof of the correctness of (one of) libsecp256k1's modular inverse implementations with the Coq proof assistant using the Verifiable C's implementation of separation logic.
title Formal Verification of the Safegcd Implementation
topic Cryptography and Security
Logic in Computer Science
url https://arxiv.org/abs/2507.17956