Replacing Falcon with RISC-V
Each NVIDIA chip contains 10 to 50 microcontrollers on one die. The legacy Falcon architecture could not scale to meet demand for AI and other complex workloads. NVIDIA chose RISC-V as the replacement. Marko Mitic cited RISC-V’s better baseline performance, flexibility for custom extensions, and layered security isolation primitives as key factors. The goal was a single configurable platform for all microcontrollers across all products. RISC-V was first introduced in the Turing architecture and now ships in every NVIDIA product.
Hardware Security Extensions
Adam Zabrocki created the Pointer Masking extension for RISC-V after finding that software address sanitizers were too slow for NVIDIA’s ecosystem. The extension serves as a framework for hardware-assisted memory tagging. Zabrocki spent over four years standardizing it as an umbrella of five extensions split per privilege level. NVIDIA also contributed to hardware Control Flow Integrity (CFI), which includes a shadow stack for backward edge protection and landing pads for forward edge protection. Zabrocki claimed RISC-V hardware CFI is the strongest CFI implementation due to its 20-bit label space. NVIDIA committed to bringing CFI to production in the Rubin timeframe.
Formally Verified Separation Kernel
The Paragrine ecosystem uses a separation kernel written in the SPARK programming language. Mitic explained that SPARK is a strict subset of Ada with a formally defined specification and no undefined behavior. The kernel is formally verified to be free of runtime errors. It creates and manages isolated execution environments called partitions. Partition policies are signed and encrypted separately from application images. The boot ROM is also written in SPARK and uses execute-only memory, leaf functions with no return address on the stack, and hardware glitch attack mitigations. Some cores run in Dual Core Lock Step (DCLS) mode for safety and security.
Lessons Learned and Future Work
Zabrocki stated that hardware extensions alone are not enough. The biggest attack surface remains software. Hardware and software must be co-designed. Formally verified languages like SPARK provide significant security returns but at substantial cost. Zabrocki predicted a hybrid world of memory-safe and unsafe languages for the foreseeable future. He noted that non-memory safety bugs still exist in any language. NVIDIA is actively contributing to the RISC-V memory tagging extension and plans to extend the shadow stack to M mode. The speakers emphasized that scalability, flexibility, reliability, performance, and security must be considered collectively.
Notable Quotes
we believe that hybrid attacks not just pure software attack not just pure hardware attack are going to be on rise Adam “pi3” Zabrocki · ▶ 36:33
being just different does not imply innovation Marko Mitic · ▶ 33:32
Key Takeaways
- NVIDIA replaced Falcon with RISC-V across all products shipping over 1 billion cores.
- Pointer Masking and CFI extensions were standardized over four years at RISC-V International.
- The separation kernel is written in SPARK and formally verified for no runtime errors.
- Hardware and software co-design is required, not just hardware extensions.
- Hybrid hardware-software attacks like Rowhammer are expected to increase.