4 Key Takeaways from GlobalPlatform’s TEE Seminar
By FF Newsroom · 19 September 2017

After a busy day hearing from the industry’s trusted execution environment (TEE) experts at GlobalPlatform’s TEE Seminar in Beijing, I’m back to business as usual. Amid the varied use cases, new deployments and vast potential for the TEE to provide security for digital services and devices, there were several stand-out themes and important takeaways for organisations involved in delivering digital services.
- It’s official – TEE is no longer an emerging technology. The advancements and adoption of connected devices have brought new security challenges to the table for device manufacturers, and also for service providers who need to protect their applications. This has given the TEE its chance to shine, demonstrating its ability to enable digital security and user privacy across a range of devices, including smartphones, wearables, set top boxes, tablets, connected cars and other IoT devices.
- Nowhere is TEE’s maturity more visible than in China. Seven out of ten products that comply with GlobalPlatform’s TEE configurations are produced by companies based in China and there’s a good reason for that. TEE is not only a recognised technology in China, it’s a ubiquitous one. Nearly all mobile payments in the region, particularly those that utilise biometric authentication, are secured using the TEE – including big names like Alipay and WeChat Pay. As China is the manufacturing hub for so many devices that benefit from embedded government-level security, such as smartphones and wearables, it is no wonder the TEE has already been adopted so widely.
- Adoption rates vary between vertical markets. While using TEEs to secure mobile payments is not yet as ubiquitous internationally as it is in China, adoption levels are still high – products like Samsung Pay, which uses TEE, are used around the world every day. And adoption is growing rapidly.
- Certification is crucial. Thorough, independent security evaluation is the only way to implement a globally interoperable ecosystem of connected devices, as it ensures a consistent and appropriate level of security. Certification allows device manufacturers to demonstrate that their product is of the highest security standard. It also means that service providers can trust the devices their applications are hosted on and the entire industry can rely on certification as an effective way to manage risk in the market. There are now three labs accredited to certify TEE products (and raring to go!) with four more pre-accredited. Four of these labs were in attendance, highlighting the importance of this event to the TEE ecosystem.