Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware Architecture
Angus Hammond, Ricardo Almeida, Thomas Bauereiss, Brian Campbell, Ian Stark, Peter Sewell
Abstract
When designing new architectural security mechanisms, a key question is whether they actually provide the intended security, but this has historically been very hard to assess. One cannot gain much confidence by testing, as such mechanisms should provide protection in the presence of arbitrary unknown code. Previously, one also could not gain confidence by mechanised proof, as the scale of production instruction-set architecture (ISA) designs, many tens or hundreds of thousands of lines of specification, made that prohibitive.
We focus in this paper especially on the secure encapsulation of software components, as supported by CHERI architectures in general and by the Arm Morello prototype architecture and hardware design in particular. Secure encapsulation is an essential security mechanism, for fault isolation and to constrain untrusted third-party code. It has previously often been implemented using virtual memory, but that does not scale to large numbers of compartments. Morello provides capability-based mechanisms that do scale, within a single address space.
We prove a strong secure encapsulation property for an example of encapsulated code running on Morello, that holds in the presence of arbitrary untrusted code, above a full-scale sequential model of the Morello ISA. To do so, we build on, extend, and unify three orthogonal lines of previous work: the Cerise proof of such an encapsulation property for a highly idealised capability machine, expressed using a logical relation in Iris; the Islaris approach for reasoning about known code in production-scale ISAs; and the T-CHERI security properties of arbitrary Morello code, previously proved only for executions up to domain crossing.
This demonstrates how one can prove such strong properties of security mechanisms for full-scale industry architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f2ae1908-7518-43c8-8f48-3394d4f47f47Cited by top-tier papers2
- Cerisier: A Program Logic for Attestation in a Capability MachineJune Rousseau, Denis Carnier, Thomas Van Strydonck, Steven Keuchel et al.PLDI 2026
- Endangered by the Language But Saved by the Compiler: Robust Safety via Semantic Back-TranslationNiklas Mück, Aïna Linn Georges, Derek Dreyer, Deepak Garg et al.POPL 2026
Builds on7
- Efficient and provable local capability revocation using uninitialized capabilitiesAïna Linn Georges, Armaël Guéneau, Thomas Van Strydonck, Amin Timany et al.POPL 2021 · 30 citations
- Islaris: verification of machine code against authoritative ISA semanticsMichael Sammler, Angus Hammond, Rodolphe Lepigre, Brian Campbell et al.PLDI 2022 · 28 citations
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- Le temps des cerises: efficient temporal stack safety on capability machines using directed capabilitiesAïna Linn Georges, Alix Trieu, Lars BirkedalOOPSLA 2022 · 17 citations
- Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal SafetyNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke et al.ASPLOS 2024 · 16 citations
Related papers
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox et al.S&P 2020 · 43 citations
- Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and ProvenanceVadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke et al.ASPLOS 2024 · 6 citations
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- Efficient Linkage-Based Compartmentalization on CHERIDapeng Gao, John Baldwin, Jessica Clarke, Nicholas C. Connolly et al.CCS 2026
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan et al.USENIX ATC 2024 · 7 citations
