Skip to main content

Trusted Execution Environment (TEE)

A TEE is an execution environment isolated from software outside the TEE. It protects selected code and data against a defined set of threats.

What is Trusted Execution Environment (TEE)?

A TEE is an execution environment isolated from software outside the TEE. It protects selected code and data against a defined set of threats. The implementation can use processor modes, confidential-computing extensions, a coprocessor, or other hardware-backed isolation. Security varies by design and threat model. A TEE does not guarantee protection after every operating-system or hardware compromise.

Why it matters

A TEE can reduce the exposure of sensitive code, keys, and data when they must be processed on a system that also runs less trusted software.

How it works

  1. Hardware and trusted software isolate selected execution and memory from the normal operating environment.
  2. A controlled interface passes approved inputs into the TEE and returns limited results.
  3. Where supported, attestation or sealed storage binds evidence or secrets to a measured TEE state.

Example

A confidential workload releases a signing key only inside a measured TEE and returns signatures without exposing the key to the host operating system.

Pomerium boundary

Pomerium WebAuthn device identity can use a platform authenticator that has hardware-backed key protection. Pomerium validates the WebAuthn result, but it does not provide general workload TEE attestation or execute upstream application code inside a TEE.

Limits and non-claims

  • TEE protection depends on the specific implementation and stated threat model.
  • Hardware defects, firmware defects, physical attacks, and side channels can remain relevant.
  • A TEE does not correct defects or unsafe input handling in the trusted code itself.

Evaluation checklist

  • Which security property does the TEE claim against the stated host and physical adversary?
  • Which verifier, reference values, freshness proof, and lifecycle state make attestation acceptable?
  • Which input, output, host service, rollback, side channel, and denial-of-service risk remains?

Sources and further reading

Keep learning

Security Operations and Risk

Secure Enclave

Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave.

Learn this term
Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term
Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo