arXiv · 2609.17399
SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)
Abstract
Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalidate the constant-time guarantees and leak isolated secrets transiently. In this work, we show that providing secure speculation for CHERI is non-trivial, and that existing proposals fail to preserve the confidentiality guarantees. We develop a formal framework for reasoning jointly about capability safety, speculative execution, and information-flow security, and use it to demonstrate potential leaks. We then present SCHERI, a new processor design within this framework, and formally prove that it provides end-to-end secure speculation guarantees for the constant-time policy. Our results provide formal foundations and practical guidance for building future capability-based processors, which are resilient to Spectre attacks for constant-time programs.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Shixin Song, Davide Davoli, Elias Storme, Marton Bognar, Dominique Devriese, Frank Piessens, Tamara Rezk. 2026-09-15. SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version). https://arxiv.org/abs/2609.17399
Cite the original work for its findings. Save a collection to share your selection of sources.