[Ufmrg] Proposal: The Verified Internet
Hans-Dieter Hiep <hdh@nlnet.nl> Sat, 29 August 2026 15:40 UTC
Return-Path: <hdh@nlnet.nl>
X-Original-To: ufmrg@mail2.ietf.org
Delivered-To: ufmrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3119B13188E21 for <ufmrg@mail2.ietf.org>; Sat, 29 Aug 2026 08:40:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788018058; bh=YaA6JJOMQmEaAbpMm02njZApct/TOa0HwxAe/TJkaIA=; h=Date:To:From:Cc:Subject; b=EPMQ+3j4nrGG3DjwTKPdDRAlt9eI6B8R2dLD4QxHtUSCfLSoWuRL2Wbvivvbkjr+m oIcPu1dpj95cZOwa3j06ia6qtnXaW3o3KHAVJkDz6aLj0hY1Q/GRwlIIj62egba1YT 1ZScbs9KOK7/6SmunlF9Ue2jqO0rTQxLbGb6nbBQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=nlnet.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3UYb_I6zzzJE for <ufmrg@mail2.ietf.org>; Sat, 29 Aug 2026 08:40:57 -0700 (PDT)
Received: from open.nlnet.nl (open.nlnet.nl [IPv6:2001:67c:6ec:253:145:220:53:132]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7750313188E14 for <ufmrg@irtf.org>; Sat, 29 Aug 2026 08:40:57 -0700 (PDT)
Message-ID: <d5d089e7-39ce-4a3b-b25b-8a2c6df45537@nlnet.nl>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nlnet.nl; s=mail; t=1788018050; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type:autocrypt:autocrypt; bh=YaA6JJOMQmEaAbpMm02njZApct/TOa0HwxAe/TJkaIA=; b=FnzJGXD77aP3bv8qeP5ncDeeIQKmmfoBLRQOP+Al8m0u99ODuK2H6lcIeteHd2lV7bCVHu KIIp4Np/gLVqWmIYw4DEIEJ7XRcUi0ZnA7XJa1TbdWfrnjFb/pFKY6XCpdS9ieV+mzcNTS lP9LFewcagiXHRa00CX4XbhJYXiqrTI=
Date: Sat, 29 Aug 2026 17:40:49 +0200
MIME-Version: 1.0
Content-Language: en-US, nl
To: ufmrg@irtf.org
From: Hans-Dieter Hiep <hdh@nlnet.nl>
Autocrypt: addr=hdh@nlnet.nl; keydata= xsFNBGdpcdQBEADO5UMd6bsMXe9uj7hPpSjUL0ztiijeMG6qaUs+MHt+S8QYJ4CJinyKk3pg U+uZUeWFPOqJbQIbP3GesZrLP/N/jwQujM77C94anOiPMTxN7n+6DKmp+hV1F0Mhg09NAX8e /L4UWmXX7Cx25J+XUOFLLFXf6hpBKqEwCcNj523FuXEwsa16/qFZ3UsnifntraRYusJIbuWu Nun+WJFE8Cwo2nwmiVc4HjawzKXOoBjVHjmIPns34i31DR5fILEUT6KoPZt2AQqrCMdPBOG3 xu/LbE5FDJzmEJ2tkdhc95WA1ZQu0HjDQhjFUjdDZ5yzzYnvCaL1cJx2LyZhu6WSoVdB+1Ie V0OVyAGo/LFM5LiGiLUSCI81XA9GqIYoXtUKzMAf6ushNomT/GqJLV5BDvPIGDcxlFMydGSD dVlKg6elseVBljy3o+hKkdQASKI6KZmkuCWg9Ssls6212cGRFLc1sozMgWMlS7OeZ7jdxsW5 Gtp+G+tlIqu6NPY9OEtAc9U2o/Lxv042FTGwrlI7NZD5wd8+51dYxNbmsiM3ujVF0ldQeUck vW1lN13MJiFCS8ySCNg9IICRFNjezOYGFgiWyPgy7EyiSyrKefynIRfFSb3JLIl3R8R50kau i9XiGjY/dUtyxa3ddCFxpiry17ooApUQMrUpepVhhIfDHhgCqQARAQABzR9IYW5zLURpZXRl ciBIaWVwIDxoZGhAbmxuZXQubmw+wsGNBBMBCAA3FiEEsnNl4ENFgE+HsezOxN/FfQLIVSgF AmdpcdQFCQeEzgACGwMECwkIBwUVCAkKCwUWAgMBAAAKCRDE38V9AshVKCSUD/0d+7aoSR38 H/SsusZ2yLe/r+N4N2BPf8KJ/sFX4dtm1bfAe2nZTPJN+c2dCQqAuoFNM2tm92ITDaL53ke+ zyxegUL+e/LWhciixlvfT3DHkiM6oHRP+mNzL+LM4vS1zqGOFz/pl4NmCLn5uIpo23W60XBf fTehZahiyCpOnzxgSD9UBnQo9giC3q//o8Ldu0HnBNKmILqTLIlOF+UdTNYOlWANYIxoEC08 ogB8WON2PcW1yR8HznmDOqAWGBdvKKgRr2G3Y+hJ9pZVZnXE+jm1/1PGZY/PycZpGcYRCFfI lAwP57KuC45YLyFHnvYOybbHxpxdnDNr1qHKKRIzgsg6ncA4RJ+WmUM6xe1hUX9YpU8l+lBz uCP4JSf9sMD08wOuJ23DcbBN8cEsK1UdmqlRvC/WYzMV8qiwLHNoAGDIhQUEdOwhHciQTGea 5zwh19FcWzC8CoLFHgeYPTscVRKqFS1hu4s6eP6eI/lBnnLCJ+G9drfJv3QxLGpiWI4BNU4V MTCuBc9b3efy7sEbSHW8x346774iB1YN64w6mc7Qd1g2B+XZWBdLS+uQ7PgqVzTZk3jr+xuI cvEkKwRwqQy3PhkOKGDincxP/HHTofHZDKS/bPb3UfNOFouE14PFv4T/s4uIWfRl8DHA4plb +RRVJCbA8a3AUdSPhYNF3ovP287BTQRnaXHVARAAvKH/xwnNsYT8QO/4UbaGJRm+TIl5938F oZ69LXXW7tIQqsD6vYU6DD0lC9LZnHwY/Qo3lXZquLhZjQMBKQrIE5XrlUdmdvRQ/vs0/Aqo 4yWJiPNCqo/fFtqzjaS+twmSykpG1uuUxS4XKHlen8lHeNKmKcUcQOlTq62Ir6wFB01JtRrr jJpFA2MI0gzd3OMDZm0wdgHDPVw5nbeNMM/JCBu8YnPk7WEa++sSE9ZslJQA1UGFEt2vU+bt AGJCaGshpaDsylLYs9WpIZM5Bx9VJEXKnsA5OUF+138yQdg0/J+L6rarwiz0RmbAGxQ0MpuA zxs0eASHMP8IMfGFNP5W57IVGnxQ8xByzjYn8YSyc/jidDoU9AsRnZ/dxP6usLvYO3WZguWA s2Hltou+s54hqZm/RMYbAb2si/S6UgRfHWS0CYTvx9/6DpsY2raoHCyUId8Q+xegD2SfXGPz EgVCAYVWQeM+FkyTl459Tt804vyZETGqJlTS2/mptGO98zQzOIVPiBIp6zugiR6WCHZd1oXW 5zZMnJN0d5Q3VPGtrXwnGjyHlX6DWxu314qzZsBxT3Kotb/3suintruWWB4BauIXz817vk01 3NocYXOJI2aryBjbKtg0xlvLRjKUeVht1nUk43Rdm3bYqlSDXuFtQT4uN8UUnvCdQ7fkj50S CE0AEQEAAcLBfAQYAQgAJhYhBLJzZeBDRYBPh7HszsTfxX0CyFUoBQJnaXHWBQkHhM4AAhsM AAoJEMTfxX0CyFUo0J0QAK+Tueu+Nra6BeMevLvtnYJOJacUcNDHy/6i150ppkaL7suApe85 +K+7jnND6b6KeeW8xVCWFDRO0ijMfB77ZEyi1x3/5UerHI2RzigKw3BAVSmefodLsGkaIMYn o/iXEsGOSE1EMeGvdtZ5XwtKoi0iDb/l+YWISsI7eyilnA11QdgtTJBGJIrD3sVrsX2hnoCA yvspvq0lmuTwmNx/MsPcDUgb/ykEBXgfiHCUaH8qKHw7CFBR5wk9TOjQ40lXYUXYga7l2/BC U6bcA3xbvnJAfdAJCDUtIxbHyjPk1G0DpVa1ZA08v4m9ufYZ46wQbxQift5mMNRUKuQ3DbNy SqzPshHaLhEhc6c2MSksA3jc9+W5VkG2tiW+15NQqJJThQ8bB519/T0Bq3W3Wk9KGJ91uvei HpH8o/EB/bz5/5hVt7A85k3CEpDXnSyW3PvDDxHZtYsFkC6fdn88/bfL9mogdTMEoyZoj7E+ ycmyufSCouGyAYuoipaYjpVEZp0SFVJirTIjDsoMxLUF1Mj/BbvDHkbwon7xUKD/wjayI+5l lGuqGGaacolBNZVr6U2JqYw5SQKz19fV5/K9Kxe2UEJfHC0Lj8Ms6MAUFaKDuxGRTgIFF2pX xkuEhfgFlZUYefpeoJ/JexGM5mi5C5+UM5idHIeljVaRW46Wu3dFm4xa
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------9hSosgdHbA8knRvvJTICtsiu"
Message-ID-Hash: FK3VRA7V6VEBOUZK5VS5MGBYT6T75RZD
X-Message-ID-Hash: FK3VRA7V6VEBOUZK5VS5MGBYT6T75RZD
X-MailFrom: hdh@nlnet.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: fmontesi@imada.sdu.dk
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ufmrg] Proposal: The Verified Internet
List-Id: Usable Formal Methods Research Group <ufmrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ufmrg/BycOAPGvzngV_MkcvYeBD9taGmI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ufmrg>
List-Help: <mailto:ufmrg-request@irtf.org?subject=help>
List-Owner: <mailto:ufmrg-owner@irtf.org>
List-Post: <mailto:ufmrg@irtf.org>
List-Subscribe: <mailto:ufmrg-join@irtf.org>
List-Unsubscribe: <mailto:ufmrg-leave@irtf.org>
Dear Usable Formal Methods Research Group members, Quick status update from my side, the below is a rough draft of a new concept I am working on: the "Verified Internet" is a full-stack formal model of the protocols employed to communicate on the Internet, making use of the Lean theorem prover [1] and seeking collaboration with the people working on CSlib [2]. It follows the 5 layers of the TCP/IP model where the functionality of each layer is formally specified. It also covers cross-layer functional and non-functional concerns, including security and privacy concepts such as confidentiality, integrity, and availability. - Physical Layer: abstracting from the underlying physical techniques, most basically modeled as pushing bits/trits/etc. on some medium in spacetime. Scope is near-Earth, so Euclidean R^4 is fine here. No 'intergalactic' ambitions, let's solve our Earthly problems first ;) - Datalink Layer: abstract model for medium access control and the various techniques used to communicate within one network. The specification should be abstract enough to cover various kinds of implementations, such as Ethernet/Wi-Fi based networks and mesh networks, but also leave some room for innovation. - Internetwork Layer: abstract model of the Internet Protocol on the data plane, and an abstraction that covers both BGP and SCION control planes, including control plane failure isolation. - Transport Layer: abstract model of communication between ports, including data streams and datagrams. Again, should be broad enough to cover TCP, UDP, SCTP, but also MPTCP and other novel techniques applied at this level. - Application Layer: end-to-end communication between processes, as if by a dumb pipe, including an abstract model of a BSD socket. - Cross-layer concerns such as CIA. Abstracts from the details of cryptography, but should be able to cover concepts such as 'perfect secrecy', KQD protocols, and pre-shared keys such as PUFs. The purpose is to *define* a formal specification of the Internet technology suite, already deployed widely, that allows vendors: (a) to validate their implementation against as test oracle, and (b) to verify/certify the correctness of their implementation against. The model must be 'usable' in every domain, world-wide, including military/governmental and civil/non-governmental contexts, focusing on delivering high-assurance computer networking technology. The specification approach is to keep the specs as simple/elegant as possible and to avoid higher-order arguments and complex mathematical structures (i.e. we use first-order logic and separation logic). Includes an executable reference implementation, that can be used to check that the formal model indeed works w.r.t. current practice, but this reference implementation will not focus on delivering the highest possible performance. The specifications should be liberal enough to allow for such high performance implementations. We follow the traditional philosophy of the Internet (The design philosophy of the DARPA internet protocols, David D. Clark, 1988 [3]): 1. Continue despite loss of networks or gateways (survivability) 2. Support multiple communications services 3. Variety of networks (interoperability) 4. Distributed management of its resources 5. Cost effective 6. Permit host attachment with low effort (extensibility) 7. Resources used must be accountable Fully aware that this project will be a multi-year multi-person endeavor. Having finally settled on a fixed academic position, I no longer have any reason not to start with this project, and am reasonably certain I will be able to lead it the coming 30 or so years. So no rush. For additional motivation why such a 'verified Internet protocol stack' is urgently needed, see the recent publication: CHAPTER 13 The Critical State of Cyberspace Hans-Dieter Hiep In Advances in Anti-Access and Area Denial (A2/AD): From Defensive Technologies to A Whole-of-Society Approach, NLARMS 2026 (Netherlands Annual Review of Military Studies), 2026, pp. 267-290 https://www.jstor.org/content/oa_chapter_edited/jj.40494811.19?seq=1 Do let me know if you are interested in working together on such a formalization effort, then we can set-up some common infrastructure and agree on ways of working together. All the best, Hans-Dieter Hiep [1] https://lean-lang.org/ [2] https://www.cslib.io/ [3] https://doi.org/10.1145/52325.52336
- [Ufmrg] Proposal: The Verified Internet Hans-Dieter Hiep