<div class="csl-bib-body">
<div class="csl-entry">Torlak, E. (2026). SymCert: Verifying SMT-Based Policy Analyses. In B. Dutertre & B. Könighofer (Eds.), <i>Proceedings of the 26th Conference on Formal Methods in Computer-Aided Design – FMCAD 2026</i> (pp. 238–247). TU Wien Academic Press. https://doi.org/10.34727/2026/isbn.978-3-85448-093-8_30</div>
</div>
Cedar is a popular authorization language designed to support sound and complete policy analysis by reduction to SMT. But building these analyses is error-prone: subtle encoding mistakes can silently compromise soundness or completeness, and are hard to catch through testing alone. Cedar’s high-assurance development process therefore requires writing and maintaining formal proofs of correctness for each new analysis. This paper presents SymCert, a framework implemented in Lean for building verified SMT-based analyses of Cedar policies. SymCert provides a verified symbolic compiler and authorizer for reducing policies to SMT formulas, a hierarchy enforcer for ensuring well-formedness of counterexamples, and a counterexample extractor for converting infinite SMT models into finite Cedar inputs, which is essential for proving analysis completeness. To make verification practical, we develop a modular proof approach that decomposes symbolic compiler correctness into two general properties, reducibility and interpretability, yielding reusable lemmas that simplify proofs across all components. We evaluate SymCert by verifying five analyses used in a Cedar analysis service at Amazon Web Services. Modeling and proving these analyses took just one work day, resulting in efficient executable models that service developers use for prototyping and differential random testing of production code. We demonstrate SymCert’s maintainability through three extensions to support new Cedar features, requiring only modest effort (4 to 8 days each) thanks to our modular proof approach.
en
dc.language.iso
en
-
dc.rights.uri
http://creativecommons.org/licenses/by/4.0/
-
dc.subject
formal methods
en
dc.subject
computer-aided system design
en
dc.subject
hardware and system verification
en
dc.title
SymCert: Verifying SMT-Based Policy Analyses
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.rights.license
Creative Commons Namensnennung 4.0 International
de
dc.rights.license
Creative Commons Attribution 4.0 International
en
dc.identifier.doi
10.34727/2026/isbn.978-3-85448-093-8_30
-
dc.contributor.editoraffiliation
Amazon Web Services
-
dc.contributor.editoraffiliation
Graz University of Technology (Graz, AT)
-
dc.relation.isbn
978-3-85448-093-8
-
dc.description.volume
7
-
dc.description.startpage
238
-
dc.description.endpage
247
-
dc.rights.holder
Emina Torlak
-
dc.type.category
Full-Paper Contribution
-
dc.relation.eissn
2708-7824
-
tuw.booktitle
Proceedings of the 26th Conference on Formal Methods in Computer-Aided Design – FMCAD 2026
-
tuw.peerreviewed
true
-
tuw.relation.ispartof
10.34727/2026/isbn.978-3-85448-093-8
-
tuw.relation.publisher
TU Wien Academic Press
-
tuw.book.chapter
30
-
tuw.researchTopic.id
I1
-
tuw.researchTopic.id
I2
-
tuw.researchTopic.id
C5
-
tuw.researchTopic.name
Logic and Computation
-
tuw.researchTopic.name
Computer Engineering and Software-Intensive Systems
-
tuw.researchTopic.name
Computer Science Foundations
-
tuw.researchTopic.value
40
-
tuw.researchTopic.value
40
-
tuw.researchTopic.value
20
-
tuw.publication.orgunit
E000 - Technische Universität Wien
-
dc.identifier.libraryid
AC17999080
-
dc.description.numberOfPages
10
-
tuw.relation.ispartoftuwseries
Conference Series: Formal Methods in Computer-Aided Design