USENIX Security2023Top-tier venue
Capstone: A Capability-based Foundation for Trustless Secure Memory Access
Jason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson, Prateek Saxena
Abstract
Capability-based memory isolation is a promising new architectural primitive. Software can access low-level memory only via capability handles rather than raw pointers, which provides a natural interface to enforce security restrictions. Existing architectural capability designs such as CHERI provide spatial safety, but fail to extend to other memory models that security-sensitive software designs may desire. In this paper, we propose Capstone, a more expressive architectural capability design that supports multiple existing memory isolation models in a trustless setup, i.e., without relying on trusted software components. We show how Capstone is well-suited for environments where privilege boundaries are fluid (dynamically extensible), memory sharing/delegation are desired both temporally and spatially, and where such needs are to be balanced with availability concerns. Capstone can also be implemented efficiently. We present an implementation sketch and through evaluation show that its overhead is below 50% in common use cases. We also prototype a functional emulator for Capstone and use it to demonstrate the runnable implementations of six real-world memory models without trusted software components: three types of enclave-based TEEs, a thread scheduler, a memory allocator, and Rust-style memory safety -- all within the interface of Capstone.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM ArchitecturesKha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon LeeCCS 2023 · 5 citations
- NetCap: Data-Plane Capability-Based Defense Against Token Theft in Network AccessOsama Bajaber, Bo Ji, Peng GaoNDSS 2026 · 2 citations
- Securing Mixed Rust with Hardware CapabilitiesJason Zhijingcheng Yu, Fangqi Han, Kaustab Choudhury, Trevor E. Carlson et al.CCS 2025 · 1 citation
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana et al.S&P 2026 · 1 citation
- SoK: Capability Operating Systems: Is the Future Finally Here?Noah Mauthe, Eric Ackermann, Sven BugielUSENIX Security 2026
Builds on10
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- Nested Enclave: Supporting Fine-grained Hierarchical Isolation with SGXJoongun Park, Naegyeong Kang, Taehoon Kim, Youngjin Kwon et al.ISCA 2020 · 33 citations
Related papers
- CAP-VMs: Capability-Based Isolation and Sharing in the CloudVasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa et al.OSDI 2022 · 24 citations
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg et al.CCS 2026 · 3 citations
- Mon CHERI: Mitigating Uninitialized Memory Access with Conditional CapabilitiesMerve Gülmez, Håkan Englund, Jan Tobias Mühlberg, Thomas NymanS&P 2025
- Efficient and provable local capability revocation using uninitialized capabilitiesAïna Linn Georges, Armaël Guéneau, Thomas Van Strydonck, Amin Timany et al.POPL 2021 · 30 citations
