Smart contracts are programs that execute inside blockchains such as Ethereum to manipulate digital assets. Since bugs in smart contracts may lead to substantial financial losses, there is considerable interest in formally proving their correctness. However, the specification and verification of smart contracts faces challenges that do not arise in other application domains. Smart contracts frequently interact with unverified, potentially adversarial outside code, which substantially weakens the assumptions that formal analyses can (soundly) make. Moreover, the core functionality of smart contracts is to manipulate and transfer resources; describing this functionality concisely requires dedicated specification support. Current reasoning techniques do not fully address these challenges, being restricted in their scope or expressiveness (in particular, in the presence of re-entrant calls), and offering limited means of expressing the resource transfers a contract performs. In this paper, we present a novel specification methodology tailored to the domain of smart contracts. Our specification constructs and associated reasoning technique are the first to enable: (1) sound and precise reasoning in the presence of unverified code and arbitrary re-entrancy, (2) modular reasoning about collaborating smart contracts, and (3) domain-specific specifications based on resources and resource transfers, which allow expressing a contract's behavior in intuitive and concise ways and exclude typical errors by default. We have implemented our approach in 2vyper, an SMT-based automated verification tool for Ethereum smart contracts written in the Vyper language, and demonstrated its effectiveness in succinctly capturing and verifying strong correctness guarantees for real-world contracts.
翻译:由于智能合同中的错误可能导致巨大的财务损失,因此人们非常希望正式证明其准确性。然而,智能合同的规格和核查面临着其他应用领域没有出现的挑战。智能合同经常与未经核实的、潜在的对抗性外部代码发生互动,这大大削弱了正式分析能够(准确地)作出的假设。此外,智能合同的核心功能是操纵和转移资源;简明地描述这一功能需要专门的规格支持。当前推理技术无法充分应对这些挑战,其范围或表达性受到限制(特别是在重新输入的电话中),并且提供了有限的表达资源转让的手段,而其他应用领域没有出现这样的挑战。在本文件中,我们提出了一种针对智能合同领域的新规格方法。此外,我们的规格构建和相关推理技术首先能够:(1) 在存在未经核实的代码和任意重新投入的情况下,正确和精确地解释;(2) 有关协作的智能合同的模块推理,以及(3) 以智能合同为基础,其范围有限或明确性(特别是在重新输入的电话中),为资源和资源转让提供有限的格式化核查提供有限的手段。我们通过简化的准确性合同和标准,我们通过执行的准确性合同的方式,在正常的核查中可以以显示一种合同和精确的正确性做法。