An In-Depth Symbolic Security Analysis of the ACME Standard
Karthikeyan Bhargavan, Abhishek Bichhawat, Quoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz, Tim Würtele
Abstract
The ACME certificate issuance and management protocol, standardized as IETF RFC 8555, is an essential element of the web public key infrastructure (PKI). It has been used by Let's Encrypt and other certification authorities to issue over a billion certificates, and a majority of HTTPS connections are now secured with certificates issued through ACME. Despite its importance, however, the security of ACME has not been studied at the same level of depth as other protocol standards like TLS 1.3 or OAuth. Prior formal analyses of ACME only considered the cryptographic core of early draft versions of ACME, ignoring many security-critical low-level details that play a major role in the 100 page RFC, such as recursive data structures, long-running sessions with asynchronous sub-protocols, and the issuance for certificates that cover multiple domains. We present the first in-depth formal security analysis of the ACME standard. Our model of ACME is executable and comprehensive, with a level of detail that lets our ACME client interoperate with other ACME servers. We prove the security of this model using a recent symbolic protocol analysis framework called DY⋆, which in turn is based on the F⋆ programming language. Our analysis accounts for all prior attacks on ACME in the literature, including both cryptographic attacks and low-level attacks on stateful protocol execution. To analyze ACME, we extend DY⋆ with authenticated channels, key substitution attacks, and a concrete execution framework, which are of independent interest. Our security analysis of ACME totaling over 16,000 lines of code is one of the largest proof developments for a cryptographic protocol standard in the literature, and it serves to provide formal security assurances for a crucial component of web security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4545bbc5-117a-4137-93f9-bf7d468f5226Cited by top-tier papers6
- Formal Model-Driven Analysis of Resilience of GossipSub to Attacks from Misbehaving PeersAnkit Kumar, Max von Hippel, Panagiotis Manolios, Cristina Nita-RotaruS&P 2024 · 8 citations
- A Generic Methodology for the Modular Verification of Security Protocol ImplementationsLinard Arquint, Malte Schwerhoff, Vaibhav Mehta, Peter MüllerCCS 2023 · 6 citations
- Securing Verified IO Programs Against Unverified Code in FCezar-Constantin Andrici, Stefan Ciobaca, Catalin Hritcu, Guido Martínez et al.POPL 2024 · 5 citations
- SOAP: A Social Authentication ProtocolFelix Linker, David A. BasinUSENIX Security 2024 · 4 citations
- Cryptis: Cryptographic Reasoning in Separation LogicArthur Azevedo de Amorim, Amal Ahmed, Marco GaboardiPOPL 2026 · 1 citation
Builds on9
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 228 citations
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet et al.S&P 2021 · 169 citations
Related papers
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric et al.CCS 2019 · 138 citations
- DY* Unchained: Now with Composable Security Proofs and Precise Compromise ScenariosThéophile WallezS&P 2026 · 1 citation
- ACME++: A Secure Authorization Mechanism for ACME Clients in the Web PKI EcosystemTianyu Zhang, Han Zhang, Yunze Wei, Yahui Li et al.WWW 2025
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker et al.USENIX Security 2021 · 23 citations
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 53 citations
