The Case for a Virtualization-Based Trusted Execution Environment in Mobile Devices
Saeed Mirzamohammadi, Ardalan Amiri Sani · 2018
ARM processors used in modern mobile devices, such as smartphones and tablets, use TrustZone to implement a trusted execution environment (TEE). In this paper, we argue that virtualization hardware, already available on many ARM processors, should be used for this purpose instead. Virtualization hardware can be used to implement multiple isolated trusted environments, as opposed to a single such environment provided by TrustZone. This can prevent the bloat of the Trusted Computing Base (TCB) of the TEE and support new security services not currently possible, such as sandboxing of untrusted operating system kernel components.