ACE: Towards A High-Assurance Isolated Virtualization Environment for RISC-V

arXiv:2505.12995 · cs.CR · Submitted 2026-08-10 · Read on arXiv

Wojciech Ozga, Guerney D. H. Hunt, Michael V. Le, Lennard Gäher, Avraham Shinnar, Elaine R. Palmer, Hani Jamjoom, Silvio Dragone

cs.CR

Submitted: 2026-08-10

Code: https://github.com/riscv/riscvaia

License: http://creativecommons.org/licenses/by-nc-nd/4.0/

The gist: Confidential computing has proven its value in cloud environments, but its potential for securing edge and high-end embedded systems (e.g., automotive controllers, cryptographic accelerators, telco

Terminology

Abstract

Confidential computing has proven its value in cloud environments, but its potential for securing edge and high-end embedded systems (e.g., automotive controllers, cryptographic accelerators, telco infrastructure) remains largely unexplored. We present ACE, an open-source, royalty-free virtualization-based confidential computing system for RISC-V targeting these environments. ACE isolates software into confidential virtual machines with narrow, well-defined interfaces, building exclusively on commodity RISC-V hardware without specialized hardware extensions or licensing fees. Our prototype evaluation on the first commercially available RISC-V hardware supporting virtualization shows that ACE is a viable candidate for our target systems.

Sources

Related papers