DOI: 10.1145/3833870 ISSN: 0360-0300

Advanced Security through Hardware Capabilities: A Comprehensive Survey on CHERI Technology

Bruno Sá, Donato Ferraro, Everton de Matos, Rafail Psiakis, Andrea Marongiu, Andrea Bastoni, Sandro Pinto

As next-generation systems become increasingly complex and interconnected, they face the burden of new and numerous critical security challenges. Capability Hardware Enhanced RISC Instructions (CHERI) has emerged as a promising technology to mitigate memory safety vulnerabilities, one of the major security threats in current computing systems. CHERI introduces a hardware-enforced, fine-grained memory protection model that integrates a fat-pointer representation, combining memory bounds and permissions to ensure safer memory access and mitigate common memory-related exploits. Despite its potential, information about CHERI evolution, design principles, and applications is scattered among multiple sources, making it difficult to fully grasp and correlate its features and applications. This paper aims to fill such gap by providing a detailed survey of CHERI technology, covering its historical evolution, key concepts, and current hardware and software implementations. We explore the ongoing challenges of its adoption in industry, the research efforts driving its growth as well as speculating and discussing future research directions.

More from our Archive