Limitations and Opportunities of Modern Hardware Isolation Mechanisms
Xiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan, Anton Burtsev
Abstract
A surge in the number, complexity, and automation of targeted security attacks has triggered a wave of interest in hardware support for isolation. Intel memory protection keys (MPK), ARM pointer authentication (PAC), ARM memory tagging extensions (MTE), and ARM Morello capabilities are just a few hardware mechanisms aimed at supporting lowoverhead isolation in recent CPUs. These new mechanisms aim to bring practical isolation to a broad range of systems, e.g., browser plugins, device drivers and kernel extensions, user-defined database and network functions, serverless cloud platforms, and many more. However, as these technologies are still nascent, their advantages and limitations are yet unclear. In this work, we do an in-depth look at modern hardware isolation mechanisms with the goal of understanding their suitability for the isolation of subsystems with the tightest performance budgets. Our analysis shows that while a huge step forward, the isolation mechanisms in commodity CPUs are still lacking implementation of several design principles critical for supporting low-overhead enforcement of isolation boundaries, zero-copy exchange of data, and secure revocation of access permissions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0908245e-6cde-4e7d-be1f-57b3cae03710Cited by top-tier papers4
- Mohabi: Disaggregating and Sandboxing the Firefox JavaScript EngineAbhishek Sharma, Anand Balaji, Zachary Yedidia, Anthony Du et al.OSDI 2026 · 1 citation
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.S&P 2025
- SoK: On the Fragility of Memory Error Exploit MitigationsAdriaan Jacobs, Mahmoud Ammar, Stijn VolckaertUSENIX Security 2026
- ARM MTE Performance in PracticeTaehyun Noh, Yingchen Wang, Tal Garfinkel, Mahesh Madhav et al.USENIX Security 2026
Builds on15
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun et al.S&P 2016 · 146 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- ORION and the Three Rights: Sizing, Bundling, and Prewarming for Serverless DAGsAshraf Mahgoub, Edgardo Barsallo Yi, Karthick Shankar, Sameh Elnikety et al.OSDI 2022 · 111 citations
Related papers
- Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM ArchitecturesKha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon LeeCCS 2023 · 5 citations
- ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity AttacksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Simha SethumadhavanISCA 2021 · 17 citations
- DriverJar: Lightweight Device Driver Isolation for ARMHuamao Wu, Yuan Chen, Yajin Zhou, Yifei Wang et al.DAC 2023 · 3 citations
- EPK: Scalable and Efficient Memory Protection KeysJinyu Gu, Hao Li, Wentai Li, Yubin Xia et al.USENIX ATC 2022
- PeTAL: Ensuring Access Control Integrity against Data-only Attacks on LinuxJuhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song et al.CCS 2024 · 6 citations
