Veda-Core: An Object-Centric, Address-Less, Capability-Based RISC-V Extension for Deterministic Memory Safety
Prabhudasu Vatala · Zenodo (CERN European Organization for Nuclear Research) · 2026
Veda-Core is a RISC-V custom extension that removes the raw memory address as a software-visible concept and replaces it with an Object_ID: a system-wide handleresolved, at bind time, through a flat Object Descriptor Table (ODT) into a 128-bit hardware capability register carrying bounds, permissions, a type tag, and a genera-tion counter. Every subsequent access through that capability is checked in hardware -- bounds, permissions, tag validity, and staleness -- before it reaches memory. We built and verified this architecture at two independent layers: a complete Sail formal model (30/30 self-checking tests) and a from-scratch TL-Verilog RTL implementation (27/27) milestone regressions, plus 51/51 on RISC-V International’s own ACT4 RV64I conformance suite with zero regressions). We report real, measured results from both layers: a deterministic tag-validity guarantee (P(bypass)=0) against Arm MTE’s probabilistic 4-bit tagging (up to 96% attacker success by 50 retries); a hardware-checked protected-return instruction (OCJALR) that is simultaneously safer and ~30% cheaper than the software-checked sequence it replaces; an object-descriptor-con-struction fast path (VEDA_ODT_POPULATE_FAST) that cuts per-object setup cost by 32.5%–40%, a ~6.5x larger improvement than the best software-only workaround for the same RV64I immediate-encoding limitation; a synthesis-based finding that the full per-access capability-check chain is shorter, not longer, than a plain load’s address computation (95 vs. 114 logic-gate levels); and five real, RTL-executed attack demonstrations (out-of-bounds read/write, return-address hijack, use-after-free,pointer forgery) in which an unmodified RV64I core fails silently and Veda-Core hard-traps with the exact, verified cause code. We also report two real security bugsfound and fixed during own development -- an ODT index-aliasing collision and a generation-counter ABA wraparound -- and We state plainly what is not yet built: nosilicon, no compiler toolchain, single-hart only, and a measured +20% dynamic-activity overhead. We position Veda-Core precisely against CHERI (the closest real precedent) using a comprehensive October 2025 literature survey of the object-aware-memory landscape, and invite critical feedback specifically from researchers with CHERI or capability-architecture experience.