Trusted Execution Environment (TEE)
🚧 Documentation is under development
The RidgeRun Platform Security Manual guide is currently under active development. Some sections may be incomplete or change without notice.
Questions? Contact RidgeRun or email to support@ridgerun.com.
- Introduction
- General Security Concepts
- Getting Started
- Contact Us
- Sponsor your Favorite Feature
Trusted Execution Environment
When it comes to embedded systems, a Trusted Execution Environment (TEE) is a secure execution environment that is isolated from the rest of the system. This isolation protects sensitive code and data from unauthorized access, including access from software running in the normal operating environment.
Applications that run inside a TEE are known as Trusted Applications (TAs). TAs execute within the protected environment and can access resources that are isolated from the normal world. This allows sensitive operations, such as cryptographic operations or credential handling, to be performed with additional protection from potentially compromised software running outside the TEE.
A TEE typically relies on hardware-enforced isolation mechanisms to separate the secure and non-secure worlds. TEE implementations in embedded systems are commonly based on ARM TrustZone, which provides hardware mechanisms for separating system resources into secure and non-secure environments.
TrustZone enables the processor and other system resources to operate in two security states, commonly referred to as the Secure World and Normal World. Hardware-based access controls determine which resources can be accessed from each world, allowing security-sensitive software and data to remain isolated from software running in the Normal World.
An example of a TEE implementation based on ARM TrustZone is OP-TEE. This open-source implementation is used on several embedded platforms, including NVIDIA Jetson and NXP i.MX platforms. Two of its main components are OP-TEE OS, which runs in the Secure World, and the OP-TEE client, which provides the software components required for applications in the Normal World to communicate with the TEE.
OP-TEE OS is a Trusted Execution Environment operating system that runs in the Secure World. On ARMv8-A systems, the OP-TEE core typically executes at Secure EL1, while Trusted Applications execute at Secure EL0. OP-TEE OS provides services such as thread management, memory management, interrupt handling, cryptographic services, and communication between the Secure and Normal Worlds.
OP-TEE implements the GlobalPlatform TEE Internal Core API, which provides an interface that Trusted Applications can use to access services provided by the TEE.
On the other hand, the OP-TEE client operates in the Normal World and includes the user-space components used by Client Applications (CAs) to communicate with Trusted Applications. It provides an implementation of the GlobalPlatform TEE Client API, which defines the interface through which a Client Application can open sessions with a Trusted Application, invoke commands, and exchange data with it.
The implementation of OP-TEE on NVIDIA Jetson platforms is illustrated in the following image:

And OP-TEE works in the following way:
- When a client application (CA) must perform a secure operation, it sends a request to a trusted application (TA) by calling functions in the TEE Client API library.
- The TEE Client API library routes the request to the OP-TEE Linux Kernel Driver.
- The OP-TEE Linux Driver routes the client application request to Arm Trusted Firmware (ATF).
- A monitor routes the request to the OP-TEE OS.
- The OP-TEE OS framework determines which trusted application (TA) is to handle the request.
- The OP-TEE OS framework passes control to the TA to handle the request.
- Upon completion, execution control returns along the reverse path to the client application, which receives a return value and any processed data.
Potential applications
OP-TEE OS may offer the following features in which developers can build potential applications:
- Memory Segregation: establish memory boundaries between the normal world and the trusted world.
- Inter-world Communication: a way to receive data, interrupts, and events from the normal world.
- Crypto and Storage: to facilitate cryptography and secure storage.