Skip to content

fix(DiffieHellman): reject mismatched moduli - #1042

Merged
fmontesi merged 1 commit into
samschles/fix-dh-role-exponentsfrom
samschles/fix-dh-modulus-check
Oct 6, 2026
Merged

fmontesi merged 1 commit into
samschles/fix-dh-role-exponentsfrom
samschles/fix-dh-modulus-check

Conversation

@SamuelSchlesinger

@SamuelSchlesinger SamuelSchlesinger commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

The evaluator expressed modulus equality as an implication, so a call with the wrong modulus accepted every result. Require modulus equality together with the expected computed value.

Adds a regression check rejecting every result for both functions when the modulus differs, while retaining the valid role-evaluation checks. The field elements already have type ZMod params.p, so the corrected relation also avoids the old dependent casts.

Depends on #1041 (the role-exponent fix); this PR targets that branch.

Implemented with Codex.

@fmontesi
fmontesi merged commit 3f3c879 into samschles/fix-dh-role-exponents Oct 6, 2026
3 checks passed
fmontesi pushed a commit that referenced this pull request Oct 6, 2026
The correctness statement assumed that the initial network reached `0`
in one transition, which is impossible. Use `MTr` so the statement
covers complete executions.

Adds a regression proof constructing a four-step execution from any
initial store, with both final keys equal to `g ^ (a * b)`.

Depends on #1042 (the modulus-check fix); this PR targets that branch.

Implemented with Codex.
SamuelSchlesinger added a commit that referenced this pull request Oct 7, 2026
The evaluator expressed modulus equality as an implication, so a call
with the wrong modulus accepted every result. Require modulus equality
together with the expected computed value.

Adds a regression check rejecting every result for both functions when
the modulus differs, while retaining the valid role-evaluation checks.
The field elements already have type `ZMod params.p`, so the corrected
relation also avoids the old dependent casts.

Depends on #1041 (the role-exponent fix); this PR targets that branch.

Implemented with Codex.
SamuelSchlesinger added a commit that referenced this pull request Oct 7, 2026
The correctness statement assumed that the initial network reached `0`
in one transition, which is impossible. Use `MTr` so the statement
covers complete executions.

Adds a regression proof constructing a four-step execution from any
initial store, with both final keys equal to `g ^ (a * b)`.

Depends on #1042 (the modulus-check fix); this PR targets that branch.

Implemented with Codex.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants