Trusted Security TEE Analysis 1 concept
TEE (Trusted Execute Environment) is a concept put forward by the Global Platform organization, so the TEE usually refers to GP TEE.
TEE is a running environment that coexists with Rich OS on the device (usually Android, etc.) and provides security services to Rich OS. It has its own execution space and has a higher level of security than Rich OS. The hardware and software resources that TEE can access are separate from Rich OS.
In order to ensure the trusted root of TEE itself, TEE is verified and isolated from Rich OS during secure startup. In TEE, each TA is independent of each other and cannot access each other without authorization.
TEE internal API mainly includes key management, cryptographic algorithms, secure storage, secure clock resources and services, as well as extended trusted UI and other API. Trusted UI means that when the key information is displayed and the user's key data (such as password) is input, the hardware resources such as screen display and keyboard are completely controlled and accessed by TEE, while the software in Rich OS can not access. The internal API is the programming interface that TEE provides to TA.
Focus on: