HermiCache: Enclave-Aware Cache Replacement for Trusted Execution Environments

arXiv:2609.10634 · cs.CR, cs.AR · Submitted 2026-09-09 · Read on arXiv

cs.CR, cs.AR

Submitted: 2026-09-09

Updated: 2026-09-09

License: http://creativecommons.org/licenses/by-nc-nd/4.0/

The gist: Trusted Execution Environments (TEEs) protect enclave memory from untrusted software but remain vulnerable to cache-based side-channel attacks due to shared microarchitectural resources.

Terminology

Abstract

Trusted Execution Environments (TEEs) protect enclave memory from untrusted software but remain vulnerable to cache-based side-channel attacks due to shared microarchitectural resources. Existing countermeasures use techniques such as cache partitioning or randomization: these solutions are not ideal if a designer wants fine-grained configurations and a deterministic protection. In this paper, we introduce HermiCache which is an answer to these requirements. HermiCache is designed for RISC-V cores and has been implemented in the OpenHwGroup CVA6 core with a Keystone TEE for the software layer. The solution has an area overhead of 6% on the processor core.

Related papers