Projects per year
Abstract
Memory safety concerns continue to be a major source of security vulnerabilities. The CHERI architecture, as instantiated in prototype CHERI-RISC-V cores, the Arm Morello system, and Microsoft’s CHERIoT embedded core, provides fine-grained memory access control through unforgeable hardware capabilities. The impact of CHERI on spatial memory safety is well understood. This paper systematically examines temporal memory safety within CHERI C – a dialect of the C programming language for CHERI – and proposes a formal approach to defining and ensuring it. In particular: 1) we examine the impact of five existing capability revocation mechanisms on CHERI C semantics and present a specialised object memory model tailored to CHERI C; 2) we introduce a new CHERI-specific pointer provenance tracking scheme; and 3) we formally define the security guarantees provided by this memory model, supported by a Coq proof of their correctness, expressed as invariants of the memory state.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 14th ACM SIGPLAN International Conference on Certified Programs and Proofs (CPP ’25) |
| Place of Publication | New York, NY, USA |
| Publisher | ACM |
| Pages | 1-15 |
| Number of pages | 15 |
| DOIs | |
| Publication status | Accepted/In press - 19 Nov 2024 |
| Event | The 14th ACM SIGPLAN International Conference on Certified Programs and Proofs - Curtis Hotel, Denver, United States Duration: 19 Jan 2025 → 25 Jan 2025 Conference number: 14 https://popl25.sigplan.org/home/CPP-2025 |
Conference
| Conference | The 14th ACM SIGPLAN International Conference on Certified Programs and Proofs |
|---|---|
| Abbreviated title | CPP 2025 |
| Country/Territory | United States |
| City | Denver |
| Period | 19/01/25 → 25/01/25 |
| Internet address |
Keywords / Materials (for Non-textual outputs)
- CHERI
- memory safety
- temporal safety
- formal verification
- memory model
- pointer provenance
- C language
- Coq
- capability revocation
Fingerprint
Dive into the research topics of 'A CHERI C memory model for verified temporal safety'. Together they form a unique fingerprint.-
Copy of Secure Foundations: Verified Systems Software Above Full-Scale Integrated Semantics
Stark, I. (Principal Investigator)
1/05/24 → 30/04/29
Project: Research
-
Digital Security by Design (DSbD) Technology Platform Prototype
Stark, I. (Principal Investigator)
1/11/19 → 28/02/25
Project: Research
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver