CHERI Security Extension
ConceptCapability Hardware Enhanced RISC Instructions (CHERI) is a security extension for conventional instruction-set architectures that introduces capabilities—unforgeable, bounded tokens implemented as fat pointers carrying an address plus permissions and bounds metadata, with validity protected by a hidden tag. CHERI has been instantiated as CHERI-RISC-V, and processors carrying the extension have been validated through model-based randomized testing with TestRIG/QuickCheck VEngine as well as through end-to-end formal verification of CHERI-Flute.
WIKI
Overview
Capability Hardware Enhanced RISC Instructions (CHERI) is a security extension for conventional instruction-set architectures. The extension adds capabilities, described as unforgeable and bounded tokens. A capability is a fat pointer containing an address and metadata, including permissions and bounds information. Capability validity is ensured by a hidden tag, and a capability authorizes access to a region of memory. [C1]
Architectural role
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →