AnyTEE: An Open and Interoperable Software Defined TEE Framework
David Cerdeira, José Carlos Martins Junior, Nuno M. Santos, Sandro Pinto · IEEE Access · 2025
Trusted Execution Environments (TEEs) are fundamental in securing a broad spectrum of applications and are prevalent on various platforms, from mobile and embedded devices to cloud servers. However, the existing landscape of TEE technologies is notably heterogeneous, posing substantial interoperability and compatibility challenges for application developers and system designers. These hurdles are not limited to well-established technologies like Arm TrustZone and Intel SGX, but also extend to newer generations of TEE models. In this context, we introduce AnyTEE, a new framework that allows application developers to use multiple TEE models in their applications and system designers to engineer customized TEE models across multiple Instruction Set Architectures (ISAs). Essentially, AnyTEE harnesses widely available hardware virtualization primitives to facilitate the development of Software Defined TEEs (sdTEEs). Our implementation of AnyTEE includes sdTEE versions of the SGX and TrustZone models for Arm and RISC-V, respectively, along with an sdTEE variant of SGX that incorporates fine-grained isolation mechanisms. Our evaluation shows that AnyTEE achieves near-native performance (<3% overhead).