Capability Hardware Enhanced RISC Instructions
Capability Hardware Enhanced RISC Instructions (CHERI) is a security extension to conventional hardware instruction set architectures. It improves system security at runtime by adding architectural features that enforce fine‑grained memory protection and scalable compartmentalisation. The technology was initially developed by the University of Cambridge and has matured to the point where general use is now possible. The CHERI Alliance provides a framework to drive commercial adoption so that CHERI becomes an efficient security standard【344521458137384†L150-L166】.
What CHERI security means
CHERI security takes a preventive approach: by replacing traditional pointers with capabilities that include bounds and permissions, it prevents many classes of memory misuse that underpin modern cyberattacks. The hardware enforces the boundaries of every capability so that out‑of‑bounds accesses or buffer overflows become impossible【344521458137384†L253-L264】. Because CHERI checks the bounds of memory at runtime, many attacks based on exploiting C/C++ pointer semantics are mitigated【344521458137384†L266-L276】. The technology is horizontal: it applies across markets — from automotive and IoT to defence — wherever software runs【344521458137384†L286-L291】. CHERI currently has implementations on Arm, x86, RISC‑V and MIPS architectures【344521458137384†L293-L299】.
Frequently asked questions (FAQ) (summary)
- What does CHERI stand for? Capability Hardware Enhanced RISC Instructions.
- What is a CHERI capability? A capability is an unforgeable token conveying memory access rights; it replaces a pointer and carries bounds and permissions【344521458137384†L302-L306】.
- What is fine‑grained memory protection? CHERI can specify permissions down to individual memory objects, ensuring that every memory access is checked at runtime【344521458137384†L311-L317】.
- What is compartmentalisation? CHERI allows isolation at any scale, from individual functions to whole subsystems, providing watertight boundaries between components【344521458137384†L319-L327】.
- Why CHERI when we have Rust? The two technologies complement each other: Rust’s compiler catches many bugs at compile time, whereas CHERI provides hardware‑backed checks at runtime. Existing C/C++ code and unsafe Rust can benefit from CHERI without complete rewrites【344521458137384†L332-L344】.
- How can I get involved? There are many ways: learn about the technology via the University of Cambridge’s CHERI resources, join the CHERI Alliance to promote adoption, port software to CHERI, design processors, create modules or products using CHERI chips, or help educate the engineering community【344521458137384†L356-L377】.
External resources
The official University of Cambridge CHERI page, the CHERI software stack, CHERI FAQ and RISC‑V specification, as well as videos and guides, are linked from the original website. These remain external resources and should be consulted on the CHERI Alliance site【344521458137384†L190-L233】.
