Pré-Publication, Document De Travail Année : 2026

Functional correctness of an optimized modular inversion algorithm

Résumé

This article describes the first mechanized proof of functional correctness of an algorithm due to Pornin (2020), for computing modular inverses via an optimized extended binary GCD algorithm. This algorithm is widely used in cryptography applications, due to its speed and constant-timeness. But this speed comes from the use of approximate computations during its loop iterations. In particular, the pen-and-paper proof of the fact that sufficiently many loop iterations were performed is especially intricate (and the originally published version was actually wrong), which negatively impacts the trust in the applications that rely on the algorithm. In this work, we expand the notes provided in the original description by Pornin into a complete formal proof. We discuss the challenges raised by its mechanization, which eventually relies on the collaboration of deductive program verification and interactive theorem proving through the use of the tools Rocq and Why3

Fichier principal
Vignette du fichier
main.pdf (593.76 Ko) Télécharger le fichier
Origine Fichiers produits par l'(les) auteur(s)
licence

Dates et versions

hal-05554365 , version 1 (16-03-2026)
hal-05554365 , version 2 (07-07-2026)

Licence

Identifiants

  • HAL Id : hal-05554365 , version 2

Citer

Assia Mahboubi, Guillaume Melquiond, Pierre-Yves Strub, Tomás Vallejos Parada. Functional correctness of an optimized modular inversion algorithm. 2026. ⟨hal-05554365v2⟩
492 Consultations
195 Téléchargements

Partager

  • More