Detecting Inconsistencies in Arm CCA's Formally Verified Specification
Changho Choi, Xiang Cheng, Bokdeuk Jeong, Taesoo Kim
Abstract
Formal verification offers strong guarantees of correctness, robustness, and security. However, these guarantees depend on specification correctness, and even minor flaws can invalidate proofs and introduce critical vulnerabilities. We present Scope, an automated system that identifies specification inconsistencies by combining formal modeling with rule-based consistency checking. Unlike traditional approaches that rely on implementations, Scope treats the specification as the sole ground truth. It translates the specification into a machine-verifiable model using Verus and SMT solvers, then detects inconsistencies in success/failure conditions, dependency rules, and state transitions. We apply Scope to the Realm Management Monitor (RMM) specifications for Arm's Confidential Compute Architecture (CCA), uncovering 35 previously unknown bugs—including security-critical flaws in ABI semantics and missing state transitions—all confirmed by Arm. Compared to modern LLM-based tools, Scope improves inconsistency-detection precision by 7x over GPT-o1 and up to 40× over leading chat models (LLaMA 3.1, GPT-4o, Claude 3.7).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 95800a55-ae9e-45d0-bde8-488c180bc498Builds on24
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- A Formal Foundation for Secure Remote Execution of EnclavesPramod Subramanyan, Rohit Sinha, Ilia A. Lebedev, Srinivas Devadas et al.CCS 2017 · 146 citations
- A Secure and Formally Verified Linux KVM HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.S&P 2021 · 72 citations
- Design and Verification of the Arm Confidential Compute ArchitectureXupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu et al.OSDI 2022 · 60 citations
- Formally Verified Memory Protection for a Commodity Multiprocessor HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.USENIX Security 2021 · 48 citations
Related papers
- A Verification Methodology for the Arm® Confidential Computing Architecture: From a Secure Specification to Safe ImplementationsAnthony C. J. Fox, Gareth Stockwell, Shale Xiong, Hanno Becker et al.OOPSLA 2023 · 19 citations
- RFCScope: Detecting Logical Ambiguities in Internet Protocol SpecificationsMrigank Pawagi, Lize Shao, Hyeonmin Lee, Yixin Sun et al.ASE 2025
- Language-Agnostic Detection of Computation-Constraint Inconsistencies in ZKP Programs Via Value InferenceArman Kolozyan, Bram Vandenbogaerde, Janwillem Swalens, Lode Hoste et al.S&P 2026 · 4 citations
- sfGPUMC: A Stateless Model Checker for GPU Weak Memory ConcurrencySoham Chakraborty, S. Krishna, Andreas Pavlogiannis, Omkar TuppeCAV 2025 · 2 citations
- A Tale of 1001 LoC: Potential Runtime Error-Guided Specification Synthesis for Verifying Large-Scale ProgramsZhongyi Wang, Tengjie Lin, Mingshuai Chen, Haokun Li et al.OOPSLA 2026 · 1 citation
