Ilmu Komputer & AI editorial
Open AccessOA2026
HermiCache: Enclave-Aware Cache Replacement for Trusted Execution Environments
A deterministic, fine-grained cache replacement policy for RISC-V TEEs with 6% area overhead
Oussama Elmnaouri; Pascal Cotret; Vianney Lapôtre; Loïc Lagadec· 2026· DOI 10.48550/arXiv.2609.10634
The core problem
Trusted Execution Environments (TEEs) such as Intel SGX, ARM TrustZone, and RISC-V Keystone isolate sensitive computations from untrusted software. However, TEEs share microarchitectural resources—particularly the last-level cache (LLC)—with untrusted code, leaving them vulnerable to cache-based side-channel attacks. These attacks exploit timing differences in cache hits and misses to infer secret-dependent access patterns. Existing countermeasures, including cache partitioning and randomization, offer protection but often lack fine-grained configurability and deterministic guarantees. This paper introduces HermiCache, an enclave-aware cache replacement policy designed for RISC-V cores. HermiCache is implemented in the OpenHwGroup CVA6 core with a Keystone TEE software layer, achieving deterministic protection with a modest 6% area overhead on the processor core. The work addresses the need for configurable, deterministic cache isolation in TEEs.
Innovation
The implementation of HermiCache on the CVA6 core shows an area overhead of 6% on the processor core. This overhead includes the additional logic for domain tracking and the modified replacement policy. The security evaluation demonstrates that HermiCache effectively mitigates cache-based side-channel attacks by preventing cross-domain cache evictions. Specifically, it eliminates the Prime+Probe and Flush+Reload attack vectors that rely on shared cache sets. Performance impact is minimal, with an average slowdown of less than 2% for enclave workloads and negligible impact on non-enclave workloads. The configurability allows a trade-off between security and performance; for example, a stricter policy may increase slowdown slightly but provides stronger isolation. The design is synthesizable and has been validated on FPGA. The results indicate that HermiCache provides a practical solution for deterministic cache isolation in RISC-V TEEs.
Trusted Execution Environments (TEEs) such as Intel SGX, ARM TrustZone, and RISC-V Keystone isolate sensitive computations from untrusted software. However, TEEs share microarchitectural resources—particularly the last-level cache (LLC)—with untrusted code, leaving them vulnerable to cache-based side-channel attacks. These attacks exploit timing differences in cache hits and misses to infer secret-dependent access patterns. Existing countermeasures, including cache partitioning and randomization, offer protection but often lack fine-grained configurability and deterministic guarantees. This paper introduces HermiCache, an enclave-aware cache replacement policy designed for RISC-V cores. HermiCache is implemented in the OpenHwGroup CVA6 core with a Keystone TEE software layer, achieving deterministic protection with a modest 6% area overhead on the processor core. The work addresses the need for configurable, deterministic cache isolation in TEEs.
HermiCache modifies the cache replacement policy to be aware of enclave execution. The design targets the CVA6 core, an open-source RISC-V processor, and integrates with Keystone, an open-source TEE framework. The key idea is to enforce deterministic cache behavior by controlling which cache lines can be evicted based on the security domain (enclave vs. non-enclave) of the accessing process. This is achieved through a replacement policy that prioritizes eviction of non-enclave lines when an enclave is active, and vice versa, thereby preventing cross-domain cache interference. The policy is configurable, allowing designers to tune the level of isolation. The implementation is evaluated on FPGA, measuring area overhead and security guarantees. The threat model assumes an attacker with the ability to observe cache timing and potentially influence cache state, but without physical access. The methodology includes formal verification of the replacement logic and empirical testing against known cache side-channel attacks.
Why it matters
HermiCache addresses a critical gap in TEE security by providing deterministic, fine-grained cache isolation. Unlike randomization-based approaches, which rely on probabilistic guarantees, HermiCache offers deterministic protection by design. This is particularly important for high-assurance systems where predictability is essential. The 6% area overhead is modest compared to the security benefits, and the configurability allows designers to tailor the policy to specific application requirements. However, the approach has limitations: it assumes a single-level cache hierarchy and may not directly extend to multi-level caches without additional complexity. Future work could explore integration with other microarchitectural defenses and extension to multi-core systems. The use of RISC-V and open-source components (CVA6, Keystone) promotes reproducibility and adoption. Overall, HermiCache represents a significant step towards secure and efficient TEEs.
Who should read this
CS practitioners and researchers
Opening member content…