Near Field Communications Handsets and Tags, NFC Pilots and Projects

GlobalPlatform releases new Trusted Execution Environment specification

Monday, July 26, 2010

GlobalPlatform has announced the launch of a Trusted Execution Environment (TEE) Client Application Programming Interface (API) Specification designed to support mobile devices entrusted with sensitive information.

The TEE is a secure area that resides in the main processor of the phone and guarantees that sensitive data is stored, processed and protected in a trusted environment.


With the ability to work independently or complementary to a secure element and standard handset applications, one of the key appeals of the TEE is its capability to create a trusted user interface, according to GlobalPlatform. For example, a mobile payment application can display payment information in a window of the mobile device screen and the end-user can input a PIN to accept the wireless transaction in the same window.

GlobalPlatform’s TEE Client API Specification, designed specifically for smart phone operating systems, establishes communication interoperability and supports the migration of sensitive services into the TEE, enabling an application to become isolated, easier to control and secure, says GP.

Christophe Colas, Chair of GlobalPlatform’s Device Committee, comments, “Downloading applications directly onto a wireless device is increasing in popularity, yet it is raising the end user’s risks towards privacy and theft of sensitive or valuable data. Phones are vulnerable to viruses and malware, and we are not fully aware of the impact such unknown threats will have on a mobile handset. GlobalPlatform supports the use of the TEE as a foundation that will facilitate the deployment of sensitive applications such as digital content protection as well as access to enterprise applications and mobile financial services on a device, while protecting against malicious attacks.

“In addition to launching the specification, we have formed the TEE Road Map Working Group as part of the Device Committee. As well as defining the internal TEE API, the group will generate a white paper explaining the role, definition and value of the TEE, and a road map to facilitate the production of the different versions of the APIs. The specification is a new step to promote the interoperability of the TEE, and with the creation of the working group we will continue to dedicate resources to support this technology in achieving its potential.” [end] 

GlobalPlatform announced that it will hold a two-day card specification training session March 1-2 at the Mirage Hotel in Las Vegas.

Directly preceding CARTES North America 2012 (March 5-7, Las Vegas), the training session will aim to educate CARTES delegates and other participants on the importance of GlobalPlatform Specifications, their capabilities and functionality.

read more »

FIME, an independent consulting and market integration testing service, has been selected by

digital security provider Gemalto to validate its UICC NFC 2.0 product. The goal is to achieve qualification status by GlobalPlatform, which launched its compliance program earlier this year.

read more »

GlobalPlatform has announced that Clear2Pay, a global payment solutions provider, and Shanghai COS, a chip operating system (COS) developer, have become the organization’s newest members.

read more »

GlobalPlatform and SIMalliance have signed a Memorandum of Understanding to improve application security on mobile devices.

Through the formal partnership, the associations say they will work together to develop an end-to-end solution that will enable a mobile device application to communicate with an application loaded in a secure element.

read more »

GlobalPlatform extended its compliance program for validation that secure products meets the requirements of GlobalPlatform’s new basic financial configuration.

This advancement meets industry demand for a qualification process which confirms that a financial card product operates within the payment landscape.

read more »

Collis has announced the launch of its Visa Mobile Payment Specification (VMCPS) Test Suite, enabling the functional testing of UICC or secure element-based contactless mobile payments applications.

read more »