Capability Tag Bit
ConceptA capability tag bit is an out-of-band, single-bit validity marker atomically bound to a capability word that protects capability integrity and derivation in registers and memory, as used in the CHERI capability-based architecture.
First seen 6/21/2026
Last seen 6/21/2026
Evidence 1 chunks
Wiki v1
WIKI
Capability Tag Bit
A capability tag bit is a single-bit validity marker that travels alongside a capability to enforce that the capability has not been forged or corrupted. In capability-based architectures such as CHERI, the tag bit is the mechanism by which the hardware distinguishes a legitimate capability from an arbitrary bit pattern that merely resembles one.
Role and Purpose
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →RELATIONSHIPS
1 connectionsCHERI uses a tag bit stored out-of-band to validate capabilities.
LINKED ENTITIES
1 linksCITATIONS
7 sources7 citations — click to expand
[1] Tags protect capability integrity and derivation in registers and memory. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[2] The tag bit is out-of-band, stored separately from normal data, atomically bound to the capability, and validates the capability. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[3] General-purpose registers are widened to 129 bits (64-bit address + 64-bit metadata + 1-bit validity tag). A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[4] Tagged memory protects capability-sized and -aligned words in DRAM by adding a validity tag. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[5] The bus architecture is extended to transport out-of-bound tags. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[6] CHERI capabilities extend integer memory addresses to 128 bits and carry metadata (bounds, permissions, object type, etc.) controlling how they may be used. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)
[7] The CHERI ISA is extended with instructions that enforce monotonicity and guarded manipulation of capabilities. A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture (ASP-DAC 2026)