CHERIoT: Complete Memory Safety for Embedded Devices
Saar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo, Ben Laurie, Kunyan Liu, Robert M. Norton, Simon W. Moore, Yucong Tao, Robert N. M. Watson, Hongyan Xia
Abstract
The ubiquity of embedded devices is apparent. The desire for increased functionality and connectivity drives ever larger software stacks, with components from multiple vendors and entities. These stacks should be replete with isolation and memory safety technologies, but existing solutions impinge upon development, unit cost, power, scalability, and/or real-time constraints, limiting their adoption and production-grade deployments. As memory safety vulnerabilities mount, the situation is clearly not tenable and a new approach is needed.
To slake this need, we present a novel adaptation of the CHERI capability architecture, co-designed with a green-field, securitycentric RTOS. It is scaled for embedded systems, is capable of fine-grained software compartmentalization, and provides affordances for full inter-compartment memory safety. We highlight central design decisions and offloads and summarize how our prototype RTOS uses these to enable memory-safe, compartmentalized applications. Unlike many state-of-the-art schemes, our solution deterministically (not probabilistically) eliminates memory safety vulnerabilities while maintaining source-level compatibility. We characterize the power, performance, and area microarchitectural impacts, run microbenchmarks of key facilities, and exhibit the * These authors made significant contributions to the design and implementation without which the project would not have been possible.
† Work conducted while at Microsoft.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal SafetyNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke et al.ASPLOS 2024 · 16 citations
- PICASSO: Scaling CHERI Use-After-Free Protection to Millions of Allocations using Colored CapabilitiesMerve Gülmez, Ruben Sturm, Hossam ElAtali, Håkan Englund et al.USENIX Security 2026 · 5 citations
- Adaptive CHERI Compartmentalization for Heterogeneous AcceleratorsJianyi Cheng, A. Theodore Markettos, Alexandre Joannou, Paul Metzger et al.ISCA 2025 · 4 citations
- Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware ArchitectureAngus Hammond, Ricardo Almeida, Thomas Bauereiss, Brian Campbell et al.PLDI 2025 · 2 citations
- ArchSem: Reusable Rigorous Semantics of Relaxed ArchitecturesThibaut Pérami, Thomas Bauereiss, Brian Campbell, Zongyuan Liu et al.POPL 2026 · 1 citation
Builds on1
Related papers
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox et al.S&P 2020 · 43 citations
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and ProvenanceVadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke et al.ASPLOS 2024 · 6 citations
- BLACKOUT: Data-Oblivious Computation with Blinded CapabilitiesHossam ElAtali, Merve Gülmez, Thomas Nyman, N. AsokanCCS 2025
- Trust Nothing: RTOS Security without Run-Time Software TCBEric Ackermann, Sven BugielUSENIX Security 2026
