Smart Casual Verification of the Confidential Consortium Framework
Heidi Howard, Markus A. Kuppe, Edward Ashton, Amaury Chamayou, Natacha Crooks
Abstract
The Confidential Consortium Framework (CCF) is an opensource platform for developing trustworthy and reliable cloud applications. CCF powers Microsoft's Azure Confidential Ledger service and as such it is vital to build confidence in the correctness of CCF's design and implementation. This paper reports our experiences applying smart casual verification to validate the correctness of CCF's novel distributed protocols, focusing on its unique distributed consensus protocol and its custom client consistency model. We use the term smart casual verification to describe our hybrid approach, which combines the rigor of formal specification and model checking with the pragmatism of automated testing, in our case binding the formal specification in TLA + to the C++ implementation. While traditional formal methods approaches require substantial buy-in and are often one-off efforts by domain experts, we have integrated our smart casual verification approach into CCF's CI pipeline, allowing contributors to continuously validate CCF as it evolves. We describe the challenges we faced in applying smart casual verification to a complex existing codebase and how we overcame them to find six subtle bugs in the design and implementation before they could impact production.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da9a040a-878a-4beb-bbb2-a16b901270f7Cited by top-tier papers4
- Runtime Protocol Refinement Checking for Distributed Protocol ImplementationsDing Ding, Zhanghan Wang, Jinyang Li, Aurojit PandaNSDI 2025 · 6 citations
- Converos: Practical Model Checking for Verifying Rust OS Kernel ConcurrencyRuize Tang, Minghua Wang, Xudong Sun, Lin Huang et al.USENIX ATC 2025 · 4 citations
- SysMoBench: Evaluating AI on Formally Specifying Complex Real-World SystemsQian Cheng, Ruize Tang, Emilie Ma, Finn Hackett et al.ICLR 2026 · 1 citation
- TraceLinking Implementations with Their Verified DesignsFinn Hackett, Ivan BeschastnikhOOPSLA 2025 · 1 citation
Builds on11
- HyperTree Proof Search for Neural Theorem ProvingGuillaume Lample, Timothée Lacroix, Marie-Anne Lachaux, Aurélien Rodriguez et al.NeurIPS 2022 · 271 citations
- Using Lightweight Formal Methods to Validate a Key-Value Storage Node in Amazon S3James Bornholt, Rajeev Joshi, Vytautas Astrauskas, Brendan Cully et al.SOSP 2021 · 63 citations
- Storage Systems are Distributed Systems (So Verify Them That Way!)Travis Hance, Andrea Lattuada, Chris Hawblitzel, Jon Howell et al.OSDI 2020 · 52 citations
- Greybox Fuzzing of Distributed SystemsRuijie Meng, George Pîrlea, Abhik Roychoudhury, Ilya SergeyCCS 2023 · 22 citations
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou et al.VLDB 2024 · 22 citations
Related papers
- Agora: Trust Less and Open More in Verification for Confidential ComputingHongbo Chen, Quan Zhou, Sen Yang, Sixuan Dang et al.OOPSLA 2025
- Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AIHeng Jin, Chaoyu Zhang, Hexuan Yu, Shanghao Shi et al.USENIX Security 2026 · 4 citations
- Formal Verification of a JavaCard Virtual Machine with Frama-CAdel Djoudi, Martin Hána, Nikolai KosmatovFM 2021 · 16 citations
- A Verified Confidential Computing as a Service Framework for Privacy PreservationHongbo Chen, Haobin Hiroki Chen, Mingshen Sun, Kang Li et al.USENIX Security 2023
- Verifying Indistinguishability of Privacy-Preserving ProtocolsKirby Linvill, Gowtham Kaki, Eric WustrowOOPSLA 2023 · 2 citations
