{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T02:34:06Z","timestamp":1760236446992,"version":"build-2065373602"},"reference-count":19,"publisher":"MDPI AG","issue":"22","license":[{"start":{"date-parts":[[2021,11,22]],"date-time":"2021-11-22T00:00:00Z","timestamp":1637539200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Commodity processor architectures are releasing various instruction set extensions to support security solutions for the efficient mitigation of memory vulnerabilities. Among them, tagged memory extension (TME), such as ARM MTE and SPARC ADI, can prevent unauthorized memory access by utilizing tagged memory. However, our analysis found that TME has performance and security issues in practical use. To alleviate these, in this paper, we propose CoMeT, a new instruction set extension for tagged memory. The key idea behind CoMeT is not only to check whether the tag values in the address tag and memory tag are matched, but also to check the access permissions for each tag value. We implemented the prototype of CoMeT on the RISC-V platform. Our evaluation results confirm that CoMeT can be utilized to efficiently implement well-known security solutions, i.e., shadow stack and in-process isolation, without compromising security.<\/jats:p>","DOI":"10.3390\/s21227771","type":"journal-article","created":{"date-parts":[[2021,12,1]],"date-time":"2021-12-01T01:45:02Z","timestamp":1638323102000},"page":"7771","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["CoMeT: Configurable Tagged Memory Extension"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9572-9205","authenticated-orcid":false,"given":"Jinjae","family":"Lee","sequence":"first","affiliation":[{"name":"Information Security and AIoT Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 46241, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2246-3017","authenticated-orcid":false,"given":"Derry","family":"Pratama","sequence":"additional","affiliation":[{"name":"Information Security and AIoT Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 46241, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4917-5971","authenticated-orcid":false,"given":"Minjae","family":"Kim","sequence":"additional","affiliation":[{"name":"Information Security and AIoT Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 46241, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8475-7294","authenticated-orcid":false,"given":"Howon","family":"Kim","sequence":"additional","affiliation":[{"name":"Information Security and AIoT Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 46241, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7507-3111","authenticated-orcid":false,"given":"Donghyun","family":"Kwon","sequence":"additional","affiliation":[{"name":"Computer Security Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 46241, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,11,22]]},"reference":[{"unstructured":"Zeldovich, N., Kannan, H., Dalton, M., and Kozyrakis, C. (2008, January 8\u201310). Hardware Enforcement of Application Security Policies Using Tagged Memory. Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI 08), San Diego, CA, USA.","key":"ref_1"},{"doi-asserted-by":"crossref","unstructured":"Song, C., Moon, H., Alam, M., Yun, I., Lee, B., Kim, T., Lee, W., and Paek, Y. (2016, January 22\u201326). HDFI: Hardware-assisted data-flow isolation. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","key":"ref_2","DOI":"10.1109\/SP.2016.9"},{"doi-asserted-by":"crossref","unstructured":"Woodruff, J., Watson, R.N., Chisnall, D., Moore, S.W., Anderson, J., Davis, B., Laurie, B., Neumann, P.G., Norton, R., and Roe, M. (2014, January 14\u201318). The CHERI capability model: Revisiting RISC in an age of risk. Proceedings of the 2014 ACM\/IEEE 41st International Symposium on Computer Architecture (ISCA), Minneapolis, MN, USA.","key":"ref_3","DOI":"10.1109\/ISCA.2014.6853201"},{"doi-asserted-by":"crossref","unstructured":"Weiser, S., Werner, M., Brasser, F., Malenko, M., Mangard, S., and Sadeghi, A.R. (2019, January 24\u201327). TIMBER-V: Tag-Isolated Memory Bringing Fine-grained Enclaves to RISC-V. Proceedings of the Network and Distributed System Security (NDSS) Symposium 2019, San Diego, CA, USA.","key":"ref_4","DOI":"10.14722\/ndss.2019.23068"},{"unstructured":"Seal, D. (2001). ARM Architecture Reference Manual, Pearson Education.","key":"ref_5"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1109\/MM.2015.35","article-title":"M7: Oracle\u2019s Next-Generation Sparc Processor","volume":"35","author":"Aingaran","year":"2015","journal-title":"IEEE Micro"},{"key":"ref_7","first-page":"5","article-title":"ARM Memory Tagging Extension and How It Improves C\/C++ Memory Safety","volume":"44","author":"Serebryany","year":"2019","journal-title":"Login USENIX Mag."},{"unstructured":"(2021, September 29). Tagged Pointers in Android. Available online: https:\/\/source.android.com\/devices\/tech\/debug\/tagged-pointers.","key":"ref_8"},{"unstructured":"Park, S., Lee, S., Xu, W., Moon, H., and Kim, T. (2019, January 9\u201312). libmpk: Software abstraction for intel memory protection keys (intel MPK). Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC 19), Renton, WA, USA.","key":"ref_9"},{"unstructured":"Vahldiek-Oberwagner, A., Elnikety, E., Duarte, N.O., Sammler, M., Druschel, P., and Garg, D. (2019, January 14\u201316). ERIM: Secure, efficient in-process isolation with protection keys (MPK). Proceedings of the 28th USENIX Security Symposium (USENIX Security 19), Santa Clara, CA, USA.","key":"ref_10"},{"unstructured":"(2021, May 29). PolarFire SoC FPGA. Available online: https:\/\/www.microsemi.com\/existing-parts\/parts\/152514.","key":"ref_11"},{"unstructured":"Gattaca-Lab (2021, May 28). RISC-V MTE. Available online: https:\/\/github.com\/gattaca-lab\/riscv_mte.","key":"ref_12"},{"unstructured":"Frascino, V. (2019, January 10). ARM v8. 5 Memory Tagging Extension. Proceedings of the Linux Plumbers Conference, Lisbon, Portugal.","key":"ref_13"},{"doi-asserted-by":"crossref","unstructured":"Burow, N., Zhang, X., and Payer, M. (2019, January 19\u201323). SoK: Shining light on shadow stacks. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","key":"ref_14","DOI":"10.1109\/SP.2019.00076"},{"doi-asserted-by":"crossref","unstructured":"Chen, Y., Reymondjohnson, S., Sun, Z., and Lu, L. (2016, January 22\u201326). Shreds: Fine-grained execution units with private memory. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","key":"ref_15","DOI":"10.1109\/SP.2016.12"},{"unstructured":"Lattner, C. (2008, January 16\u201317). LLVM and Clang: Next generation compiler technology. Proceedings of the BSD Conference, Ottawa, ON, Canada.","key":"ref_16"},{"unstructured":"Pallister, J., Hollis, S.J., and Bennett, J. (2013). BEEBS: Open Benchmarks for Energy Measurements on Embedded Platforms. arXiv.","key":"ref_17"},{"doi-asserted-by":"crossref","unstructured":"Zhou, Y., Wang, X., Chen, Y., and Wang, Z. (2014, January 3\u20137). Armlock: Hardware-based fault isolation for arm. Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Scottsdale, AZ, USA.","key":"ref_18","DOI":"10.1145\/2660267.2660344"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.cose.2018.01.009","article-title":"Domain Isolated Kernel: A lightweight sandbox for untrusted kernel extensions","volume":"74","author":"Jang","year":"2018","journal-title":"Comput. Secur."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/22\/7771\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:34:06Z","timestamp":1760168046000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/22\/7771"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,22]]},"references-count":19,"journal-issue":{"issue":"22","published-online":{"date-parts":[[2021,11]]}},"alternative-id":["s21227771"],"URL":"https:\/\/doi.org\/10.3390\/s21227771","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2021,11,22]]}}}