Trusted execution environment (TEE)
A hardware-isolated area of a processor where code and data are protected from the rest of the system, including the host operating system: the basis of confidential computing.
A trusted execution environment is a hardware-isolated area of a processor in which code and data are protected from the rest of the system, including the host operating system and, in some designs, the hypervisor. Examples include Arm TrustZone, Intel Software Guard Extensions (SGX) enclaves, and the confidential virtual machine technologies AMD SEV-SNP and Intel TDX. The processor commonly encrypts or fences off the TEE’s memory, and attestation lets a remote party check what code is running inside before trusting it with data.
The TEE addresses the data state that conventional encryption leaves exposed: data in use, which normally must be decrypted for processing. Processing inside an attested TEE is how the Confidential Computing Consortium describes confidential computing. A TEE is not the same as a trusted platform module, which stores keys and measurements rather than running application code, nor the trusted computing base, the full set of protection mechanisms a system relies on. Several TEE designs have been broken through side-channel attacks, so a TEE reduces risk rather than removing it.
Exam relevance: a scenario is likely to describe sensitive data that must stay protected while processed on shared or cloud infrastructure. Candidates are expected to connect that need to a TEE or confidential computing, and to tell it apart from encryption at rest, encryption in transit and the TPM.