Academic Papers
Academic papers
This selected bibliography covers CHERI architecture, software, formal methods, memory safety, compartmentalisation, and implementation experience. Entries link to the paper or its publisher record and are ordered newest first.
-
Robert N. M. Watson, John Baldwin, Tony Chen, David Chisnall, Jessica Clarke, Brooks Davis, Nathaniel Wesley Filardo, Brett Gutstein, Graeme Jenkinson, Ben Laurie, Alfredo Mazzinghi, Simon W. Moore, Peter G. Neumann, Hamed Okhravi, Alex Rebert, Alex Richardson, Peter Sewell, Laurence Tratt, Murali Vijayaraghavan, Hugo Vincent, and Konrad Witaszczyk. Communications of the ACM, 68(2), 2025.
Sets out technology-neutral principles and terminology for specifying and assessing strong software memory safety.
-
Jianyi Cheng, A. Theodore Markettos, Alexandre Joannou, Paul Metzger, Matthew Naylor, Peter Rugg, and Timothy M. Jones. ACM/IEEE ISCA 2025, 2025.
Explores capability protection across CPUs and heterogeneous accelerators that share memory.
-
Academic paper
CHERIoT RTOS: An OS for Fine-Grained Memory-Safe Compartments on Low-Cost Embedded Devices
Saar Amar, Tony Chen, David Chisnall, Nathaniel Wesley Filardo, Ben Laurie, Hugo Lefeuvre, Kunyan Liu, Simon W. Moore, Robert Norton-Wright, Margo Seltzer, Yucong Tao, Robert N. M. Watson, and Hongyan Xia. ACM SOSP 2025, 2025.
Describes the CHERIoT RTOS and its fine-grained compartment model for resource-constrained embedded systems.
-
Academic paper
Deprivileging Low-Level GPU Drivers Efficiently with User-Space Processes and CHERI Compartments
Paul Metzger, A. Theodore Markettos, Edward Tomasz Napierała, Matthew Naylor, Robert N. M. Watson, and Timothy M. Jones. ACM CCS 2025, 2025.
Evaluates process and CHERI-compartment designs for moving a performance-sensitive GPU driver out of the kernel.
-
Academic paper
Formal Mechanised Semantics of CHERI C: Capabilities, Provenance, and Undefined Behaviour
Vadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke, Brooks Davis, Alex Richardson, David Chisnall, Brian Campbell, Ian Stark, Robert N. M. Watson, and Peter Sewell. ACM ASPLOS 2024, 2024.
Gives a mechanised semantics for CHERI C covering capabilities, pointer provenance, and undefined behaviour.
-
Nathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke, Peter Rugg, Brooks Davis, Mark Johnston, Robert Norton-Wright, David Chisnall, Simon W. Moore, Peter G. Neumann, and Robert N. M. Watson. ACM ASPLOS 2024, 2024.
Develops a load-barrier approach to temporal heap safety for CHERI systems.
-
Academic paper
CHERI: Hardware-Enabled C/C++ Memory Protection at Scale
Robert N. M. Watson, David Chisnall, Jessica Clarke, Brooks Davis, Nathaniel Wesley Filardo, Ben Laurie, Simon W. Moore, Peter G. Neumann, Alexander Richardson, Peter Sewell, Konrad Witaszczyk, and Jonathan Woodruff. IEEE Security & Privacy, 22(4), 2024.
Reviews CHERI's hardware-supported protection model and experience applying it to large C and C++ software stacks.
-
Academic paper
The Arm Morello Evaluation Platform—Validating CHERI-Based Security in a High-Performance System
Richard Grisenthwaite, Graeme Barnes, Robert N. M. Watson, Simon W. Moore, Peter Sewell, and Jonathan Woodruff. IEEE Micro, 43(3), 2023.
Introduces the Morello evaluation platform and its role in testing CHERI ideas in a high-performance Arm system.
-
Academic paper
CHERIoT: Complete Memory Safety for Embedded Devices
Saar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo, Ben Laurie, Kunyan Liu, Robert Norton, Simon W. Moore, Yucong Tao, Robert N. M. Watson, and Hongyan Xia. IEEE/ACM MICRO 2023, 2023.
Presents the CHERIoT hardware-software design for spatial and temporal memory safety on embedded devices.
-
Academic paper
Rigorous Engineering for Hardware Security: Formal Modelling and Proof in the CHERI Design and Implementation Process
Kyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony Fox, Michael Roe, Brian Campbell, Matthew Naylor, Robert M. Norton, Simon W. Moore, Peter G. Neumann, Ian Stark, Robert N. M. Watson, and Peter Sewell. IEEE Symposium on Security and Privacy 2020, 2020.
Describes the formal models and proof work used alongside CHERI architecture and hardware development.
-
Academic paper
Cornucopia: Temporal Safety for CHERI Heaps
Nathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth, Lucian Paul-Trifu, Brooks Davis, Hongyan Xia, Edward Tomasz Napierała, Alexander Richardson, John Baldwin, David Chisnall, and others. IEEE Symposium on Security and Privacy 2020, 2020.
Investigates capability revocation and temporal safety for heap allocations in CHERI systems.
-
Academic paper
CheriABI: Enforcing Valid Pointer Provenance and Minimizing Pointer Privilege in the POSIX C Run-time Environment
Brooks Davis, Robert N. M. Watson, Alexander Richardson, Peter G. Neumann, Simon W. Moore, John Baldwin, David Chisnall, Jessica Clarke, Nathaniel Wesley Filardo, Khilan Gudka, Alexandre Joannou, and others. ACM ASPLOS 2019, 2019.
Presents the pure-capability CheriABI process environment and its treatment of pointer provenance and privilege.
-
Academic paper
CHERI Concentrate: Practical Compressed Capabilities
Jonathan Woodruff, Alexandre Joannou, Hongyan Xia, Anthony Fox, Robert Norton, Thomas Bauereiss, David Chisnall, Brooks Davis, Khilan Gudka, Nathaniel W. Filardo, A. Theodore Markettos, Michael Roe, Peter G. Neumann, Robert N. M. Watson, and Simon W. Moore. IEEE Transactions on Computers, 2019.
Explains the compressed capability representation used to carry bounds and permissions efficiently.
-
Academic paper
CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization
Robert N. M. Watson, Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie, Steven J. Murdoch, Robert Norton, Michael Roe, Stacey Son, and Munraj Vadera. IEEE Symposium on Security and Privacy 2015, 2015.
Establishes CHERI's hybrid architecture for fine-grained, scalable software compartmentalisation.
-
Jonathan Woodruff, Robert N. M. Watson, David Chisnall, Simon W. Moore, Jonathan Anderson, Brooks Davis, Ben Laurie, Peter G. Neumann, Robert Norton, and Michael Roe. ACM/IEEE ISCA 2014, 2014.
Introduces the practical RISC capability model that underpins the early CHERI architecture.
