{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T06:25:38Z","timestamp":1784183138300,"version":"3.55.0"},"reference-count":82,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,5,1]],"date-time":"2020-05-01T00:00:00Z","timestamp":1588291200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,5,1]],"date-time":"2020-05-01T00:00:00Z","timestamp":1588291200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2020,5,1]],"date-time":"2020-05-01T00:00:00Z","timestamp":1588291200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,5]]},"DOI":"10.1109\/sp40000.2020.00114","type":"proceedings-article","created":{"date-parts":[[2020,7,31]],"date-time":"2020-07-31T00:48:34Z","timestamp":1596156514000},"page":"983-1002","source":"Crossref","is-referenced-by-count":57,"title":["EverCrypt: A Fast, Verified, Cross-Platform Cryptographic Provider"],"prefix":"10.1109","author":[{"given":"Jonathan","family":"Protzenko","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bryan","family":"Parno","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aymeric","family":"Fromherz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chris","family":"Hawblitzel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marina","family":"Polubelova","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karthikeyan","family":"Bhargavan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Benjamin","family":"Beurdouche","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joonwon","family":"Choi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antoine","family":"Delignat-Lavaud","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cedric","family":"Fournet","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Natalia","family":"Kulatova","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tahina","family":"Ramananandro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aseem","family":"Rastogi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nikhil","family":"Swamy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christoph M.","family":"Wintersteiger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Santiago","family":"Zanella-Beguelin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.125"},{"key":"ref72","year":"2017","journal-title":"The Coq Proof Assistant Reference Manual - Version 8 1"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/2837614.2837655"},{"key":"ref70","author":"seacord","year":"2018","journal-title":"Implement abstract data types using opaque types"},{"key":"ref76","article-title":"Start your ENGINEs: Dynamically loadable contemporary crypto","author":"tuveri","year":"2018","journal-title":"Technical Report"},{"key":"ref77","article-title":"CVE-2012-2459 (block merkle calculation exploit)","author":"voight","year":"2012"},{"key":"ref74","author":"tracker","year":"0","journal-title":"libssl1 0 0 illegal instruction crash on amd64"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3290376"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134076"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064183"},{"key":"ref78","year":"2019","journal-title":"Bit manipulation instruction sets"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/1993498.1993532"},{"key":"ref33","author":"donenfeld","year":"2018","journal-title":"kbench9000 - simple kernel land cycle counter"},{"key":"ref32","author":"donenfeld","year":"2017","journal-title":"WireGuard Next Generation Kernel Network Tunnel"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-48869-1_5"},{"key":"ref30","author":"dettman","year":"2018","journal-title":"Problems with field arithmetic"},{"key":"ref37","doi-asserted-by":"crossref","DOI":"10.1098\/rsta.2015.0401","article-title":"The HACMS program: Using formal methods to eliminate exploitable bugs","volume":"375","author":"fisher","year":"2017","journal-title":"Philosophical Transactions Mathematical Physical & Engineering Sciences"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00005"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-015-0087-1"},{"key":"ref34","author":"donenfeld","year":"2018","journal-title":"new 25519 measurements of formally verified implementations"},{"key":"ref60","doi-asserted-by":"crossref","DOI":"10.1145\/3167089","article-title":"&#x0152;uf: Minimizing the coq extraction TCB","author":"mullen","year":"2018","journal-title":"Proceedings of the ACM Conference on Certified Programs and Proofs (CPP)"},{"key":"ref62","article-title":"Recommendation for block cipher modes of operation: Galois\/Counter Mode (GCM) and GMAC","year":"2007","journal-title":"NIST Special Publication 800-38A"},{"key":"ref61","article-title":"National Vulnerability Database","year":"2012","journal-title":"CVE-2012-2459"},{"key":"ref63","article-title":"How to (pre-)compute a ladder: Improving the performance of X25519 and X448","author":"oliveira","year":"2017","journal-title":"Proceedings of Selected Areas in Cryptography (SAC)"},{"key":"ref28","author":"constable","year":"1986","journal-title":"Implementing Mathematics with the Nuprl Proof Development System"},{"key":"ref64","year":"2019","journal-title":"Vulnerabilities"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-31301-6_8"},{"key":"ref65","year":"2005","journal-title":"OpenSSL"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46666-7_4"},{"key":"ref29","article-title":"A design principle for hash functions","author":"damgard","year":"1989","journal-title":"Proc Int'l Cryptology Conf (CRYPTO)"},{"key":"ref67","article-title":"Verifying Arithmetic Assembly Programs in Cryptographic Primitives","author":"polyakov","year":"2018","journal-title":"Concurrency Theory (CONCUR"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3110261"},{"key":"ref69","article-title":"CCF: A framework for building confidential verifiable replicated services","author":"russinovich","year":"2019","journal-title":"Technical Report MSR-TR-201916"},{"key":"ref2","year":"0","journal-title":"curve25519-donna Implementations of a fast Ellipticcurve Diffie-Hellman primitive"},{"key":"ref1","year":"0"},{"key":"ref20","article-title":"TweetNaCl: A crypto library in 100 tweets","author":"bernstein","year":"2014","journal-title":"International Conference on Cryptology and Information Security in Latin America (Latincrypt)"},{"key":"ref22","article-title":"Implementing and proving the TLS 1.3 record layer","author":"bhargavan","year":"2017","journal-title":"Proceedings of the IEEE Symposium on Security and Privacy"},{"key":"ref21","article-title":"Everest: Towards a verified drop-in replacement of HTTPS","author":"bhargavan","year":"2017","journal-title":"Proceedings of the Summit on Advances in Programming Languages (SNAPL)"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14052-5_14"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.31"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660370"},{"key":"ref25","article-title":"Vale: Verifying high-performance cryptographic assembly code","author":"bond","year":"2017","journal-title":"Proceedings of the USENIX Security Symposium"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7748"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-17511-4_20"},{"key":"ref59","year":"2018","journal-title":"Measurement dashboard"},{"key":"ref58","year":"2018","journal-title":"Cryptographic API Next generation - Windows Applications"},{"key":"ref57","article-title":"A certified digital signature","author":"merkle","year":"1989","journal-title":"Proceedings of Crypto"},{"key":"ref56","article-title":"A digital signature based on a conventional encryption function","author":"merkle","year":"1987","journal-title":"Proc Int'l Cryptology Conf (CRYPTO)"},{"key":"ref55","article-title":"Meta-F*: Metaprogramming and tactics in an effectful program verifier","author":"mart\u00b4?nez","year":"2019","journal-title":"European Symposium on Programming (ESOP)"},{"key":"ref54","author":"thompson","year":"2019","journal-title":"Using TLS to Secure QUIC Internet-Draft draft-ietf-quic-tls-20"},{"key":"ref53","year":"2019","journal-title":"Combined AEAD ChaCha\/Poly"},{"key":"ref52","author":"leroy","year":"2016","journal-title":"Embedded Real-Time Software (ERTS)"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134078"},{"key":"ref11","article-title":"The last mile: High-assurance and high-speed cryptographic implementations","author":"almeida","year":"0","journal-title":"arXiv 1904 04606"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2676726.2676975"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-35672-3_1"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19718-5_1"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2701415"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660283"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134043"},{"key":"ref16","article-title":"Computer-aided security proofs for the working cryptographer","author":"barthe","year":"2011","journal-title":"Proc IACR CRYPTO94"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.28"},{"key":"ref17","article-title":"Verified correctness and security of OpenSSL HMAC","author":"beringer","year":"2015","journal-title":"Proceedings of the USENIX Security Symposium"},{"key":"ref18","article-title":"Curve25519: New Diffie-Hellman speed records","author":"bernstein","year":"2006","journal-title":"Proceedings of the IACR Conference on Practice and Theory of Public Key Cryptography (PKC)"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-012-0027-1"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133974"},{"key":"ref4","year":"0","journal-title":"ngtcp2 an effort to implement IETF QUIC protocol"},{"key":"ref3","year":"0","journal-title":"Minimal implementation of the quic protocol"},{"key":"ref6","year":"0","journal-title":"Signal Protocol Library for Java\/Android"},{"key":"ref5","year":"0"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3009837.3009878"},{"key":"ref7","year":"0","journal-title":"The Sodium crypto library (libsodium)"},{"key":"ref49","author":"langley","year":"2014","journal-title":"A shallow survey of formal methods for C code"},{"key":"ref9","first-page":"1","article-title":"Secure Compilation (Dagstuhl Seminar 18201)","volume":"8","author":"ahmed","year":"2018","journal-title":"Dagstuhl Reports"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8032"},{"key":"ref45","article-title":"QUIC: A UDP-Based Multiplexed and Secure Transport","author":"iyengar","year":"2019","journal-title":"draft-ietf-quic-transport-20"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2535838.2535841"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.17487\/rfc5869"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2014.31"},{"key":"ref41","author":"gueron","year":"2012","journal-title":"Intel Advanced Encryption Standard (Aes) Instructions Set"},{"key":"ref44","article-title":"Ironclad Apps: End-to-end security via automated full-system verification","author":"hawblitzel","year":"2014","journal-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI)"},{"key":"ref43","author":"gulley","year":"2013","journal-title":"Intel SHA Extensions"}],"event":{"name":"2020 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2020,5,18]]},"end":{"date-parts":[[2020,5,21]]}},"container-title":["2020 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9144328\/9152199\/09152808.pdf?arnumber=9152808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T15:17:19Z","timestamp":1656602239000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9152808\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,5]]},"references-count":82,"URL":"https:\/\/doi.org\/10.1109\/sp40000.2020.00114","relation":{},"subject":[],"published":{"date-parts":[[2020,5]]}}}