GlobalPlatform TEE Scheme Creation and Operation

GlobalPlatform is the cross-industry association that develops specifications for secure digital services, including the Trusted Execution Environment (TEE) — a secure area inside the main processor of a mobile device that runs trusted applications isolated from the rich operating system. As TEE deployments grew across payment, content protection, and identity use cases, GlobalPlatform needed a structured certification scheme so device manufacturers, TEE vendors, and relying parties could demonstrate and rely on TEE security consistently.

Client / Project Need

Objectives & drivers

Create and operate a security evaluation and certification scheme for GlobalPlatform TEE implementations that gives market participants confidence in the isolation, key management, and trusted-application lifecycle properties of TEE products.

Challenge

Key hurdles

Bridging the highly technical TEE specifications — covering hardware-rooted isolation, trusted OS, APIs, and trusted application management — with the formal language of Common Criteria evaluation, while keeping the scheme practical for mobile device timelines and vendor ecosystems.

Approach

What we did

01

Mapped GlobalPlatform TEE specifications to Common Criteria security objectives, assumptions, and requirements.

02

Defined Protection Profile-style documents specifying the security problem, functional requirements, and assurance level for TEE products.

03

Designed evaluation and certification processes adapted to TEE vendors, device integrators, and evaluation laboratories.

04

Operated the scheme governance, maintained scheme documents, and coordinated with certification bodies and labs.

05

Supported stakeholders through interpretation requests, scheme updates, and alignment with evolving mobile security standards.

Key outcomes

Impact delivered

Lessons learned

What we took away

Scheme creation for a platform technology like TEE requires close coupling between specification authors, scheme operators, and evaluation labs. The earlier security objectives are embedded in the specification, the smoother the certification path becomes.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

CRA Box Unified Standard for HWSB

Read case study →

O-RAN Security Test Plan and Assurance Program Development

Read case study →

Security Analysis of 5G Network Products

Read case study →

Contact us

Request this document

We’ll send you access by email.