This document proposes an extension to the GlobalPlatform TEE Internal Core API Specification, to address common vulnerabilities in Trusted Applications by having the TEE perform certain validation that was previously the responsibility of the Trusted Application (but often erroneously omitted).
The extension can be applied to implementations of any version of the TEE Core API.
Free
Download