
mojo-v mojov-v1.02
RISC-V ISA extension for hardware-enforced secret computation using ML-KEM-512 key encapsulation and SIMON-128 encryption, enabling data-oblivious execution with near-native performance.
Mojo-V: Secret Computation for RISC-V
Mojo-V (pronounced “mojo-five”) is a new RISC-V extension that introduces privacy-oriented programming capabilities for RISC-V. Mojo-V implements secret computation, enabling secure, efficient, and data-oblivious execution without reliance on fragile software and programmer trust. By sequestering sensitive data in dedicated secret registers and encrypting memory under a third-party key, Mojo-V prevents disclosures and enforces computation that is both blind (no direct disclosures) and silent (no side channel leakage). The design integrates seamlessly into the existing RISC-V ISA with only a mode bit and four new instructions, enforced entirely at decode. Early results show near-native execution speeds while offering over 5-7 orders of magnitude performance improvement compared to fully homomorphic encryption (FHE), with a clear roadmap for integration into CPUs, GPUs, and specialized accelerators.
To learn more...
- Here is an intro video describing Mojo-V: https://www.youtube.com/watch?v=HUT46TcNyyM
- Slides that give an overview of the Mojo-V project: https://drive.google.com/file/d/1VVzZqYHvQgnKMgXZjg7I_cX2GzF7awSN
The current Mojo-V ISA Extension Specification (release 1.02):
- [In PDF format.] (https://drive.google.com/file/d/1yfiBqp0xyXD-S_G5d2o7Ggta5wI6nRot)
To contact the developers of Mojo-V:
- Email: [email protected]
🧩 Mojo-V Reference Platform — Release 1.03
🚧 Project Status
The Mojo-V Reference Platform release 1.03 implements a reference Spike simulator platform for RISC-V RV64GC and the EXO compiler for the Mojo-V ISA Specification v1.02. The current implementation supports fast, strong, and proof-carrying encryption modes, along with safe disclosure of encrypted computation results and certified random number generation. The release includes a wide range of Mojo-V tests, privacy-oriented benchmarks, and demonstrator applications for safe disclosure. It also includes the complete Mojo-V ISA specification and developer documentation.
This release is appropriate for use as i) a Mojo-V application development platform, ii) a golden model for validating Mojo-V hardware implementations, and iii) a reference implementation for security analysis. Current work focuses on the development of i) an LLVM-based Mojo-V compiler, ii) a gem5-based Mojo-V model for architectural exploration and analysis, and iii) a reference CVA6 SystemVerilog RTL implementation of RISC-V RV64GC with Mojo-V extensions.
Specification Version: 1.02 (August 2026)
Contact: [email protected]
Current components
-
Mojo-V ISA Spec v1.02
- released in
doc/
- released in
-
Spike (Instruction Set Simulator) with Mojo-V Extensions
- Mojo-V integrated into
riscv-isa-sim, and feature-complete for an RV64GC CPU with ML-KEM-512 key encapsulation for data contract loading, and SIMON-128 symmetric key encryption for secret computation protection. - To run Spike with Mojo-V extensions enabled, add the
--isa=rv64gc_zicond_zkmojov_zicntrflag when runningspike
- Mojo-V integrated into
-
Data Contract Multi-tool
Data contracts are encrypted packets that allow a Mojo-V CPU's hardware to access the data access key and configuration information (e.g., memory encryption mode) for a Mojo-V encrypted data set. The DC Multi-tool enables the following capabilities:
- Hardware developers can create public/private ML-KEM512 key pairs: public keys are shared with service providers, private keys are embedded into the Mojo-V hardware implementation.
- Data owners can create data contracts and encrypt them under the public ML-KEM512 keys of service providers. The matching Mojo-V hardware can then perform secret computation on the protected 3rd-party encrypted data.
-
Mojo-V Bringup-Bench Benchmarks
- Full battery of security tests for RV64GC+Mojo-V
- Full battery of integrity attack tests for RV64GC+Mojo-V
- Full battery of EXO compiler library tests
- Full batteries of EXO math and string library tests
- Numerous privacy-oriented benchmarks build using the EXO Mojo-V compiler library
- Full battery of safe disclosure demonstration applications
- Full battery of certified TRNG demonstration applications
- Hand-coded examples (e.g., bubble-sort) showing Mojo-V working secret computation
Note, the remainder of the Bringup-bench benchmarks have NOT been ported to Mojo-V, as yet.
⚙️ Building and Running the Mojo-V Reference Platform
A. Install a RISC-V LLVM Compiler
You’ll need an LLVM-based RISC-V cross-compiler capable of producing RV64GC binaries.
Here is a good place to start: https://github.com/openssl/openssl
B. Install OpenSSL version 3.6 or newer
You’ll need a developer's installation of OpenSSL version 3.6 or newer. This provides libraries that implement ML-KEM512, used by Spike for protected key exchange.
Here is a good place to start: https://clang.llvm.org/get_started.html
C. Clone the Mojo-V Repository
git clone https://github.com/toddmaustin/mojo-v.git
cd mojo-v
D. Build the RISC-V Spike simulator with Mojo-V Support
sudo apt-get install device-tree-compiler libboost-regex-dev libboost-system-dev
cd riscv-isa-sim
mkdir build
cd build
../configure --prefix=$RISCV
make
E. Build and test the Data Contract Multi-tool
Data contracts are encrypted packets that allow a Mojo-V CPU's hardware to access the data access key and configuration information (e.g., memory encryption mode) for a Mojo-V encrypted data set.
cd dc-tool
make clean build test
E. Build and Run Mojo-V Bringup-Bench Benchmark Tests
-
Build the Spike device driver
cd bringup-bench/target make -
Configure your compiler
Edit
../Makefileand setTARGET_CCfor themojovtarget to the location of your LVM Clang-based RISC-V compiler. -
Build and test the Bringup-Bench test programs
cd .. # go to the top-level bringup-bench directory make TARGET=mojov-spike mojov-tests # run all Mojo-V testsAs an alternative, you can run an individual benchmark by going into its directory and running the following command.
cd ../mojov-test make TARGET=mojov-spike clean build test