Keystone with Linux PREEMPT_RT: Real-Time Enclaves on RISC-V?

Oscar Van Slijpe, Jean‐Michel Dricot, Jan Tobias Mühlberg · 2026

Trusted Execution Environments (TEEs) are increasingly relevant in embedded and cyber-physical systems, where both security and real-time guarantees are essential. While Keystone has gained traction as an open-source framework for RISC-V, its interaction with real-time scheduling and, in particular, with the PREEMPT_RT patches remains unstudied, despite the potential and relevance of real-time Linux and enclaves for secure mixed-criticality applications. This paper presents an evaluation methodology to assess implications of enclaved execution on scheduling latency, which we apply to Keystone on a PREEMPT_RT-patched Linux kernel on a HiFive Unmatched board. Using cyclictest to measure scheduling latencies under high-load conditions, two scenarios are examined: mixed contexts, where high-priority non-secure tasks run concurrently with active enclaves, and real-time enclaves, where time-critical tasks execute inside the enclave itself. Results show that Keystone’s Secure Monitor and enclaves do not measurably interfere with high-priority non-secure processes. However, while PREEMPT_RT improves enclave startup determinism, Keystone introduces substantial latencies when multiple enclaves are executing concurrently, partially limiting its suitability for applications that require predictable timing alongside confidentiality.

Read the paper · More papers on PaperTik