SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)

arXiv:2609.17399 · cs.CR, cs.AR · Submitted 2026-09-15 · Read on arXiv

cs.CR, cs.AR

Submitted: 2026-09-15

Updated: 2026-09-15

Code: https://github.com/riscv/riscv-cheri

License: http://creativecommons.org/licenses/by/4.0/

The gist: Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components.

Terminology

Abstract

Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalidate the constant-time guarantees and leak isolated secrets transiently. In this work, we show that providing secure speculation for CHERI is non-trivial, and that existing proposals fail to preserve the confidentiality guarantees. We develop a formal framework for reasoning jointly about capability safety, speculative execution, and information-flow security, and use it to demonstrate potential leaks. We then present SCHERI, a new processor design within this framework, and formally prove that it provides end-to-end secure speculation guarantees for the constant-time policy. Our results provide formal foundations and practical guidance for building future capability-based processors, which are resilient to Spectre attacks for constant-time programs.

Related papers