95 lines
5.4 KiB
Markdown
95 lines
5.4 KiB
Markdown
# aere-research
|
|
|
|
Formal verification models, post-quantum cryptography reference implementations, known-answer
|
|
tests (KATs), and research specifications for Aere Network.
|
|
|
|
This repository is the "prove it yourself" half of the Aere Network verify-yourself core. It lets
|
|
a third party re-run the machine-checked proofs, re-derive the cryptographic reference vectors, and
|
|
read the research that underpins the protocol, without trusting any claim on faith.
|
|
|
|
## Scope, stated up front
|
|
|
|
Aere Network runs post-quantum signature verification natively on mainnet: Falcon-512 (`0x0AE1`),
|
|
Falcon-1024 (`0x0AE2`), ML-DSA-44 (`0x0AE3`), SLH-DSA-128s (`0x0AE4`) and SHAKE256 (`0x0AE5`)
|
|
have been live as precompiles since block 9,189,161. You can call them yourself against
|
|
`https://rpc.aere.network` without asking us for anything.
|
|
|
|
**Consensus on chain 2800 is classical secp256k1 ECDSA QBFT on every block, with a post-quantum
|
|
checkpoint every 32 blocks.** Since block 13,014,000 anchor blocks carry, under the block hash, a
|
|
certificate of validator Falcon-512 seals, and since 2026-08-14 a node rejects an anchor block with
|
|
fewer than three valid seals (f+1 of nine, not a quorum; eight or nine are carried in practice). That
|
|
checkpoint lives in the aere-node repository (patch 0003 and `anchor/`), not in this one: nothing in
|
|
this repository makes consensus post-quantum, and the chain is not "post-quantum consensus" without
|
|
that qualification (the per-block quorum claim published on 2026-08-15 was withdrawn on 2026-08-19).
|
|
|
|
Two further limits worth knowing before you judge anything else here:
|
|
|
|
- `0x0AE6` (ML-KEM-768) and `0x0AE7` (Falcon HashToPoint) are **testnet only**. They are not
|
|
active on mainnet.
|
|
- The on-chain zero-knowledge verifiers are classical BN254. They are broken by Shor's algorithm
|
|
like any other elliptic-curve construction, and we do not describe them as quantum-safe.
|
|
|
|
The network is operated by nine Foundation-run validators (f=2, commit quorum 6 of 9; seven until
|
|
2026-08-09), so its Nakamoto coefficient is effectively one today. That is a real limitation, it is on the roadmap, and it is not fixed by any
|
|
code in this repository.
|
|
|
|
Two more limits, both of which cut against claims made in this repository:
|
|
|
|
- **Some citations point at files we did not publish, and you cannot open those.** MEASURED
|
|
2026-08-11: 101 distinct cited paths in this repository do not resolve to any published file. All
|
|
101 are listed, with the documents that cite them, in `CITATIONS-UNRESOLVED.md`, and that list is
|
|
enforced by a check rather than maintained by hand. A claim supported only by such a path is our
|
|
assertion, not something you can independently check. Citations that DO resolve are written
|
|
relative to a side-by-side checkout of the Aere repositories, so they begin with a repository
|
|
name. See the fuller note in the `aere-docs` README.
|
|
- **AERE is not deflationary today.** The burn mechanism is live and immutable, and it has burned
|
|
approximately 0.137 AERE in total against a 2.8 billion fixed supply, because the burn is a
|
|
percentage of validator coinbase revenue and that revenue is currently zero. The percentages in
|
|
`research/specs/spec-flywheel-economics.md` are conditional rates on future revenue, not
|
|
descriptions of present token destruction. Check it yourself with one `eth_getBalance` call
|
|
against `0x696afDF4f814e6Fd6aa45CE14C498ed9375fB2c6`.
|
|
|
|
## Layout
|
|
|
|
- `formal-consensus/` Z3 / SMT models of consensus and contract safety properties (30 Python
|
|
models plus a Quint spec `FalconQuorum.qnt`), driven by `run_consensus_verification.py`. These
|
|
cover QBFT safety and liveness, the money-contract invariants, and a PROPOSED hybrid
|
|
dual-quorum activation that is modelled research and is NOT running on chain 2800, and the
|
|
invariants. `CONSENSUS-VERIFICATION-2026-07-12.md` documents the results.
|
|
- `pq-stark/` reference implementations and self-tests for the STARK verifier port: BabyBear field,
|
|
Poseidon2, MMCS, FRI, the Fiat-Shamir challenger, and AIR quotient logic. Each component ships a
|
|
Python reference, a JavaScript (`.mjs`) reference, a Java self-test, ground-truth JSON vectors, and
|
|
a spec. The `*-extractor/` directories are small Rust reference extractors (source only). This is
|
|
reference and test material, not key material.
|
|
- `precompiles/` Java sources for the post-quantum EVM precompiles (ML-KEM-768, Falcon
|
|
HashToPoint, SP1 STARK verifier).
|
|
- `kat/` and `vectors/` NIST ACVP and Falcon known-answer test vectors and their generators.
|
|
- `pq-finality-circuit/` XMSS verify-core reference (Rust source) for the post-quantum finality
|
|
circuit.
|
|
- `bench/` and `results/` benchmark harness and recorded KAT / benchmark result JSON.
|
|
- `aips/` the Aere Improvement Proposal process and the accepted AIPs.
|
|
- `research/` research notes and long-form specifications (`research/specs/`).
|
|
|
|
## Verify
|
|
|
|
The formal models run with Python 3 and z3:
|
|
|
|
```bash
|
|
cd formal-consensus
|
|
python run_consensus_verification.py
|
|
```
|
|
|
|
The STARK references are cross-checked against their ground-truth vectors; see each
|
|
`spec-*.md` and the `test_*.py` files. Full commands and expected outputs are in the `aere-docs`
|
|
repository (`REPRODUCE.md`).
|
|
|
|
## What is deliberately not here
|
|
|
|
No private keys, no validator or Foundation key material, no infrastructure hostnames or
|
|
credentials. Heavy prover runs must be executed on a throwaway non-infrastructure machine, never on
|
|
production infrastructure.
|
|
|
|
## License
|
|
|
|
MIT. See `LICENSE`.
|