A new venture has been launched to enhance cybersecurity through hardware memory safety technologies, specifically on application-class systems-on-chips (SoCs).
Cambridge, U.K.-based non-profit LowRISC and British consultancy Capabilities Limited announced a three-year project to apply Capability Hardware Enhanced RISC Instructions (CHERI) in a commercial-quality, open source security enclave capacity within SoC designs.
Founding members of the CHERI alliance, the two firms envision the enclave to handle tasks such as keyring management and authentication, with the CHERI architecture propping up its memory safety vulnerabilities.
Known as COSMIC (CHERI for Operational Safety in Memory-Isolated Cores), the tech uses OpenTitan Darjeeling, a system-on-a-chip secure execution environment that acts as the hardware root-of-trust system, and CVA6-CHERI, the 64-bit RISC-V processor core within the setup.
The CHERI system itself is a technology architecture designed to shore up memory safety vulnerabilities, often a leading access point for threat actors.
The project is backed by the U.K. Department for Science, Innovation, and Technology (DSIT) and InnovateUK, as well as commercial partners such as Google, which utilizes the OpenTitan model in its Chromebook laptops.
"At LowRISC, we believe strongly in our mission to make commercial open-source silicon real, and in security by openness, not obscurity," said LowRISC chief executive officer Javier Orensanz Martinez. "It is fantastic that not only is this supported by commercial partners such as Google and Rivos, but also by funds from the U.K. government."
"The CHERI Alliance is thrilled to see two of its founding members unveil a new product leveraging CHERI security technology," says founding director Mike Eftimakis of the project's announcement. "As cyber threats skyrocket and regulations tighten at an unprecedented pace, manufacturers must embed rock-solid security in their products, now. COSMIC provides a solid base for this."
The COSMIC project is expected to run through to March 2028, with the first stage projected to be completed in March 2026, with the release of an initial reference design under an open source license.
The CHERI Alliance recently welcomed British Telecom (BT) into its fold, with the U.K. telecoms giant joining Google, TechWorks, Light Momentum Technology Corp., and CyberWhiz, among other members.
The group aims to enhance CHERI adoption to tackle vulnerabilities in hardware memory safety tech, often a leading access point for threat actors.
Besides DSIT and Innovate UK, the Alliance is also backed by the U.K.’s Defense Science and Technology Laboratory (Dstl) and the National Cyber Security Center, lending authority to its cybersecurity credentials.
Comments