Paper 2026/884

Formalizing and Strengthening the Security Proof of NTOR

François Dupressoir, University of Bristol
Kristian Gjøsteen, Norwegian University of Science and Technology
Cameron Low, University of Bristol
Charlotte Mylog, Norwegian University of Science and Technology
Abstract

We present a machine-checked security proof for the NTOR key exchange protocol, which is used to establish connections in the Tor onion routing system. It was previously studied by Goldberg et al. (DCC 2013) and the protocol ladder project, however there is no full proof including forward secrecy in the computational model. Our proof is formalized in EasyCrypt, adding to the still small set of cryptographic protocols verified using EasyCrypt. A key contribution is a systematic treatment of halting reductions involving failure events expressed as global properties of the execution. In the course of this work, we also contributed improvements to the EasyCrypt framework itself. We prove NTOR secure in a model for unilaterally authenticated key exchange (UAKE) similar to the maximum exposure model by Fiedler et al. (Crypto 2025). It captures forward secrecy concretely, and is intentionally close to established bilaterally authenticated key exchange models (such as eCK) while being simple to formalize. By examining more carefully how identities and public keys are used in key exchange protocols, we obtain simpler formal arguments and introduce several variants of the UAKE security model, connected by general reductions that, in the case of NTOR, are also verified in EasyCrypt. This allows us to carry out the main proof in a simpler setting and then derive the desired security guarantee for NTOR via these reductions.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published by the IACR in ASIACRYPT 2026
Keywords
Key exchangeNTORProvable securityFormal verificationEasyCrypt
Contact author(s)
f dupressoir @ bristol ac uk
kristian gjosteen @ ntnu no
cameron low 2018 @ bristol ac uk
charlotte mylog @ ntnu no
History
2026-09-15: last of 2 revisions
2026-05-05: received
See all versions
Short URL
https://ia.cr/2026/884
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/884,
      author = {François Dupressoir and Kristian Gjøsteen and Cameron Low and Charlotte Mylog},
      title = {Formalizing and Strengthening the Security Proof of {NTOR}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/884},
      year = {2026},
      url = {https://eprint.iacr.org/2026/884}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.