From OP-TEE to ProvenCore: Migrating Trusted Applications
Transitioning trusted applications from OP-TEE to a fully certified microkernel like ProvenCore enables organizations to strengthen security, achieve formal certification, and maintain compatibility with GlobalPlatform TEE specifications.
Why Migrate to ProvenCore?
ProvenCore provides a formally verified, high-assurance environment that preserves the functionality of existing OP-TEE-based Trusted Applications. This ensures that applications can continue to operate securely while benefiting from the robustness, auditability, and certification standards required for critical systems.
Key Migration Considerations
- Compatibility: ProvenCore aligns with GlobalPlatform TEE APIs, allowing existing OP-TEE Trusted Applications to be reused with minimal modification.
- Security and Certification: Migrating to a fully certified microkernel provides stronger guarantees of confidentiality, integrity, and isolation. This is particularly important in regulated or high-assurance environments.
- Deployment and Lifecycle: ProvenCore supports lifecycle management of Trusted Applications, including secure provisioning, updates, and retirement, ensuring operational reliability.
- Performance: Applications can leverage the optimized microkernel design to maintain or improve execution efficiency while meeting strict security requirements.
Practical Guidance
Organizations should perform a phased migration: assess application dependencies, verify API compatibility, and validate security properties in a controlled test environment. ProvenCore’s adherence to formal methods and TEE standards simplifies compliance and reduces migration risk.
By moving from OP-TEE to ProvenCore, teams gain enhanced security, formal certification, and continued support for existing applications, providing a future-proof foundation for trusted computing on embedded systems.








