Researchers introduced NACRE, a RISC-V hardware-software design intended to protect Linux containers even if the host kernel or administrator is compromised. The architecture gives protected processes hardware-recognized container identities and separates host resource-management capabilities from authority to read private container memory or commit protected state. Its design uses an isolated supervisor-mode agent and machine-mode monitor to support container lifecycle functions, including paging, fork, copy-on-write, and teardown.
A QEMU-based prototype modifies QEMU, OpenSBI, Linux, a trusted agent, and runc. The authors reported syscall and pipe performance within 3.5% of the runc baseline and nginx throughput 1.9% lower in an equally weighted aggregate. NACRE remains a research prototype rather than a production control: attestation, secure cross-container sharing and ownership, rollback protection, stale-identity handling, and multicore-concurrency security are still unimplemented or unevaluated, and its performance findings have not been independently reproduced.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Linke Song, Wenhao Wang, Weijie Liu, and Rui Hou submitted a position paper proposing NACRE, a RISC-V hardware-software design for native confidential containers that protects container private state from an untrusted host kernel or administrator. The authors described a QEMU-based prototype extending QEMU, OpenSBI, Linux, a trusted agent, and runc, with preliminary single-container performance results.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.