
RISC-V ISA extension for hardware-enforced secret computation using ML-KEM-512 key encapsulation and SIMON-128 encryption, enabling data-oblivious execution with near-native performance.
Mojo-V (pronounced “mojo-five”) is a new RISC-V extension that introduces privacy-oriented programming capabilities for RISC-V. Mojo-V implements secret computation, enabling secure, efficient, and data-oblivious execution without reliance on fragile software and programmer trust. By sequestering sensitive data in dedicated secret registers and encrypting memory under a third-party key, Mojo-V prevents disclosures and enforces computation that is both blind (no direct disclosures) and silent (no side channel leakage). The design integrates seamlessly into the existing RISC-V ISA with only a mode bit and four new instructions, enforced entirely at decode. Early results show near-native execution speeds while offering over 5-7 orders of magnitude performance improvement compared to fully homomorphic encryption (FHE), with a clear roadmap for integration into CPUs, GPUs, and specialized accelerators.
To learn more...
The current Mojo-V ISA Extension Specification (release 1.02):
To contact the developers of Mojo-V:
The Mojo-V Reference Platform release 1.03 implements a reference Spike simulator platform for RISC-V RV64GC and the EXO compiler for the Mojo-V ISA Specification v1.02. The current implementation supports fast, strong, and proof-carrying encryption modes, along with safe disclosure of encrypted computation results and certified random number generation. The release includes a wide range of Mojo-V tests, privacy-oriented benchmarks, and demonstrator applications for safe disclosure. It also includes the complete Mojo-V ISA specification and developer documentation.
This release is appropriate for use as i) a Mojo-V application development platform, ii) a golden model for validating Mojo-V hardware implementations, and iii) a reference implementation for security analysis. Current work focuses on the development of i) an LLVM-based Mojo-V compiler, ii) a gem5-based Mojo-V model for architectural exploration and analysis, and iii) a reference CVA6 SystemVerilog RTL implementation of RISC-V RV64GC with Mojo-V extensions.
Specification Version: 1.02 (August 2026)
Contact: [email protected]
Mojo-V ISA Spec v1.02
doc/Spike (Instruction Set Simulator) with Mojo-V Extensions
riscv-isa-sim, and feature-complete for an RV64GC CPU with ML-KEM-512 key encapsulation for data contract loading, and SIMON-128 symmetric key encryption for secret computation protection.--isa=rv64gc_zicond_zkmojov_zicntr flag when running spikeData Contract Multi-tool
Data contracts are encrypted packets that allow a Mojo-V CPU's hardware to access the data access key and configuration information (e.g., memory encryption mode) for a Mojo-V encrypted data set. The DC Multi-tool enables the following capabilities:
Mojo-V Bringup-Bench Benchmarks
Note, the remainder of the Bringup-bench benchmarks have NOT been ported to Mojo-V, as yet.
You’ll need an LLVM-based RISC-V cross-compiler capable of producing RV64GC binaries.
Here is a good place to start: https://github.com/openssl/openssl
You’ll need a developer's installation of OpenSSL version 3.6 or newer. This provides libraries that implement ML-KEM512, used by Spike for protected key exchange.
Here is a good place to start: https://clang.llvm.org/get_started.html
git clone https://github.com/toddmaustin/mojo-v.git
cd mojo-v
sudo apt-get install device-tree-compiler libboost-regex-dev libboost-system-dev
cd riscv-isa-sim
mkdir build
cd build
../configure --prefix=$RISCV
make
Data contracts are encrypted packets that allow a Mojo-V CPU's hardware to access the data access key and configuration information (e.g., memory encryption mode) for a Mojo-V encrypted data set.
cd dc-tool
make clean build test
Build the Spike device driver
cd bringup-bench/target
make
Configure your compiler
Edit ../Makefile and set TARGET_CC for the mojov target to the location of your LVM Clang-based RISC-V compiler.
Build and test the Bringup-Bench test programs
cd .. # go to the top-level bringup-bench directory
make TARGET=mojov-spike mojov-tests # run all Mojo-V tests
As an alternative, you can run an individual benchmark by going into its directory and running the following command.
cd ../mojov-test
make TARGET=mojov-spike clean build test