Skip to content
STIMSMITH

CHERI Capability Architecture

Concept

The CHERI capability architecture is a hardware capability-system design that augments conventional ISAs with memory-protecting capabilities. It is the subject of formal ISA-semantics work spanning ARMv8-A, RISC-V, and CHERI-MIPS variants, and has been extended in research prototypes such as BLACKOUT to support data-oblivious computation via blinded capabilities.

First seen 7/3/2026
Last seen 7/3/2026
Evidence 4 chunks
Wiki v1

WIKI

CHERI Capability Architecture

The CHERI Capability Architecture is a hardware capability-system architecture that extends conventional instruction set architectures (ISAs) with architectural capabilities — unforgeable, bounded tokens of authority that authorize memory accesses and other privileged operations. Capabilities are intended as a foundation for fine-grained memory safety and software compartmentalization at hardware speed.

Role in the ISA Specification Landscape

READ FULL ARTICLE →

NEIGHBORHOOD

No graph connections found for this entity yet. It may appear in future ingestion runs.

explore full graph →

RELATIONSHIPS

2 connections
The paper covers CHERI-MIPS architecture semantics.
Capability Architecture part of → 95% 1e
CHERI Capability Architecture is a specific instance of Capability Architecture.

CITATIONS

7 sources
7 citations — click to expand
[1] CHERI is a hardware capability-system architecture that augments conventional ISAs with unforgeable, bounded capabilities authorizing memory access. CHERI: A hybrid capability-system architecture for scalable software compartmentalization
[2] Formal Sail-based ISA semantics have been developed for ARMv8-A, RISC-V, and CHERI-MIPS. ISA semantics for ARMv8-A, RISC-V, and CHERI-MIPS
[3] CHERI is treated as a first-class ISA alongside ARMv8-A and RISC-V in formal-semantics and verification literature. Specifications of instruction set architectures (related-work notes)
[4] The Morello prototype is a capability-enhanced Arm architecture built on CHERI principles. Verified security for the Morello capability-enhanced prototype Arm architecture
[5] A RISC-V processor extended with capability pointers has been formally verified end-to-end. End-to-end formal verification of a RISC-V processor extended with capability pointers
[6] BLACKOUT extends CHERI with blinded capabilities enabling data-oblivious userspace computation, realized on the CHERI-Toooba FPGA softcore with CHERI-enabled Clang/LLVM and CheriBSD support. BLACKOUT: Data-Oblivious Computation with Blinded Capabilities
[7] BLACKOUT reports ~1.5% geometric-mean performance degradation versus the baseline CHERI-Toooba processor while ensuring memory operated on through blinded capabilities is securely allocated, used, and reclaimed. BLACKOUT: Data-Oblivious Computation with Blinded Capabilities