Isolated Hardware Execution Platforms
摘要
We introduce ways in which trusted execution can be realised principally in hardware. We begin by the most well-known isolated execution platforms: the smart card (e.g. debit and credit cards), and how they are certified as being ‘secure’ under the Common Criteria framework. We also explore Java Card and secure elements (SEs), security-hardened modules based on smart card technology, which are incorporated into a wide range of platforms and devices, such as SIM cards, tablets, and smartphones. Afterwards, we discuss host-based card emulation (HCE), which aims to virtualise SE-based services, and describe the Google Titan M and Apple Secure Enclave: two widely deployed proprietary security technologies on flagship Google and Apple phones, respectively.