An Introduction to CHERI

An Introduction to CHERI
复制标题

奇瑞简介

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
P. Neumann
P. Neumann
中科院分区:
--
文献类型:
--
作者:
R. Watson;S. Moore;Peter Sewell;P. Neumann

文献摘要

参考文献

被引文献

相似文献

CHERI(能力硬件增强的RISC指令)扩展了传统的处理器指令集架构(isa)的架构能力,以实现细粒度的内存保护和高度可扩展的软件划分。CHERI的混合能力系统方法允许架构能力与现代RISC架构和微架构以及基于mmu的C/ c++语言软件堆栈清晰地集成。CHERI的功能是不可伪造的权威令牌,可用于在C和c++中实现显式指针(语言中声明的指针)和隐含指针(运行时和生成的代码使用的指针)。当用于C/ c++内存保护时,CHERI直接减轻了广泛的已知漏洞类型和利用技术。对更可扩展的软件划分的支持促进了软件缓解技术,如沙箱,它还可以防御未来(目前未知的)漏洞类和利用技术。我们已经通过硬件软件原型(包括多个CPU原型和完整的软件堆栈)开发、评估和演示了这种方法。该堆栈包括Clang/LLVM编译器套件的一个改编版本,支持基于功能的C/ c++,以及一个完整的unix风格的操作系统(CheriBSD,基于FreeBSD),实现空间、引用和(目前为用户空间)非堆栈临时内存安全。正式的建模和验证使我们能够对支持cheri的体系结构的安全属性做出强有力的声明。本报告是对CHERI的高级介绍。该报告描述了我们的架构方法、CHERI的关键微架构含义、我们的形式化建模和证明方法、CHERI软件模型、我们的软件堆栈原型、进一步的阅读以及未来研究的潜在领域。
CHERI (Capability Hardware Enhanced RISC Instructions) extends conventional processor Instruction-Set Architectures (ISAs) with architectural capabilities to enable fine-grained memory protection and highly scalable software compartmentalization. CHERI’s hybrid capability-system approach allows architectural capabilities to be integrated cleanly with contemporary RISC architectures and microarchitectures, as well as with MMU-based C/C++- language software stacks. CHERI’s capabilities are unforgeable tokens of authority, which can be used to implement both explicit pointers (those declared in the language) and implied pointers (those used by the runtime and generated code) in C and C++. When used for C/C++ memory protection, CHERI directly mitigates a broad range of known vulnerability types and exploit techniques. Support for more scalable software compartmentalization facilitates software mitigation techniques such as sandboxing, which also defend against future (currently unknown) vulnerability classes and exploit techniques. We have developed, evaluated, and demonstrated this approach through hardware-software prototypes, including multiple CPU prototypes, and a full software stack. This stack includes an adapted version of the Clang/LLVM compiler suite with support for capability-based C/C++, and a full UNIX-style OS (CheriBSD, based on FreeBSD) implementing spatial, referential, and (currently for userspace) non-stack temporal memory safety. Formal modeling and verifi-cation allow us to make strong claims about the security properties of CHERI-enabled architectures. This report is a high-level introduction to CHERI. The report describes our architectural approach, CHERI’s key microarchitectural implications, our approach to formal modeling and proof, the CHERI software model, our software-stack prototypes, further reading, and potential areas of future research.
CHERI Concentrate:实用的压缩功能
DOI: 10.1109/tc.2019.2914037
发表时间: 2019
影响因子: 3.7
作者:
Woodruff J
通讯作者: Woodruff J
DOI: 10.1145/3290384
发表时间: 2019-01-01
影响因子: 1.8
作者:
Armstrong, Alasdair;Bauereiss, Thomas;Sewell, Peter
通讯作者: Sewell, Peter