Secure Enclave / Trusted Execution Environment (TEE)
Definition
A hardware-isolated execution environment within the SoC that stores device-unique encryption keys and handles cryptographic operations. The encryption key never leaves this boundary, making it the primary barrier to decryption on locked modern devices.
- Location
- Isolated region within the SoC
- Stores
- Device-unique encryption keys
- Key rule
- Keys never leave the hardware boundary
- Consequence
- Primary barrier to decrypting a locked device
Common questions
Why can't an examiner simply copy the keys out for offline decryption?+
The design deliberately prevents the key material from ever being exposed outside the isolated hardware, so decryption operations must be requested of the enclave itself rather than performed on extracted key bytes.
Does every smartphone platform implement this the same way?+
No, Apple's Secure Enclave and the TEE implementations found on Android devices (such as ARM TrustZone-based designs) differ in architecture, though they serve the same purpose of isolating cryptographic operations from the main OS.
Related terms
- Baseband Processor
- A separate processor that manages all radio functions: cellular calls, SMS, and data connections. It runs its own real-time OS and holds...
- eMMC (Embedded MultiMediaCard)
- A flash storage standard that packages NAND memory chips and a controller into one soldered module using a parallel interface. Common in...
- Flash Translation Layer (FTL)
- Firmware inside the flash storage controller that maps logical block addresses to physical NAND blocks and implements wear levelling. Deleted files may...
- System on Chip (SoC)
- A single integrated circuit that combines the application processor, GPU, memory controller, image signal processor, and often the secure enclave. The SoC...
- UFS (Universal Flash Storage)
- A newer flash storage standard using a serial interface that allows simultaneous reads and writes. Faster than eMMC and common in flagship...