Capability Hardware Enhanced RISC Instructions

Capability Hardware Enhanced RISC Instructions (CHERI) is a security extension to conventional hardware instruction set architectures. It improves system security at runtime by adding architectural features that enforce fine‑grained memory protection and scalable compartmentalisation. The technology was initially developed by the University of Cambridge and has matured to the point where general use is now possible. The CHERI Alliance provides a framework to drive commercial adoption so that CHERI becomes an efficient security standard【344521458137384†L150-L166】.

What CHERI security means

CHERI security takes a preventive approach: by replacing traditional pointers with capabilities that include bounds and permissions, it prevents many classes of memory misuse that underpin modern cyberattacks. The hardware enforces the boundaries of every capability so that out‑of‑bounds accesses or buffer overflows become impossible【344521458137384†L253-L264】. Because CHERI checks the bounds of memory at runtime, many attacks based on exploiting C/C++ pointer semantics are mitigated【344521458137384†L266-L276】. The technology is horizontal: it applies across markets — from automotive and IoT to defence — wherever software runs【344521458137384†L286-L291】. CHERI currently has implementations on Arm, x86, RISC‑V and MIPS architectures【344521458137384†L293-L299】.

Frequently asked questions (FAQ) (summary)

External resources

The official University of Cambridge CHERI page, the CHERI software stack, CHERI FAQ and RISC‑V specification, as well as videos and guides, are linked from the original website. These remain external resources and should be consulted on the CHERI Alliance site【344521458137384†L190-L233】.