Papers for

security-focused operating system developers

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Secure speculation design improves software isolation with CHERI

SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)

Abstract: Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalidate the constant-time guarantees and leak isolated secrets transiently. In this work, we show that providing secure speculation for CHERI is non-trivial, and that existing proposals fail to preserve the confidentiality guarantees. We develop a formal framework for reasoning jointly about capability safety, speculative execution, and information-flow security, and use it to demonstrate potential leaks. We then present SCHERI, a new processor design within this framework, and formally prove that it provides end-to-end secure speculation guarantees for the constant-time policy. Our results provide formal foundations and practical guidance for building future capability-based processors, which are resilient to Spectre attacks for constant-time programs.

Tue 15 SeptCryptography and SecurityHardware Architecture
The gist
Speculative execution in modern processors can accidentally reveal secret information, even when software is designed to keep things secret. The authors show that securing speculation on CHERI, a special processor architecture that keeps software parts well-isolated, is difficult and past solutions did not fully protect secrets. They created a new method and processor design called SCHERI that formally guarantees secure speculation while maintaining these secrecy rules. This means software running on SCHERI can better protect secrets from attacks that exploit processor tricks.
Open → 2609.17399v1