Login
User Agreement & LicensingPrivacy Policy
FIPS 140-3
Common Criteria EAL5+

Products

  • ProvenHSM
  • ProvenBox
  • Native Security Applications
  • Software Developer Kit (SDK)
  • ProvenCore OS and TEE
  • ProvenVisor

Use Cases

  • Data Protection
  • PQC Migration
  • Key Management & Cloud KMS
  • Confidential Computing
  • Finance Innovation
  • Digital Signature (eIDAS 1.0)
  • Wallet & Identity (eIDAS 2.0)
  • Multi-Party Computation (MPC)
  • Enterprise PKI
  • Strengthening HPC Platforms

Resources

  • Blog and Whitepapers
  • Security and Certifications
  • Integrations

Company

  • Careers
  • About

In this article :

  • Why Migrate to ProvenCore?
  • Key Migration Considerations
  • Practical Guidance

From OP-TEE to ProvenCore: Migrating Trusted Applications

Transitioning trusted applications from OP-TEE to a fully certified microkernel like ProvenCore enables organizations to strengthen security, achieve formal certification, and maintain compatibility with GlobalPlatform TEE specifications.


Why Migrate to ProvenCore?


ProvenCore provides a formally verified, high-assurance environment that preserves the functionality of existing OP-TEE-based Trusted Applications. This ensures that applications can continue to operate securely while benefiting from the robustness, auditability, and certification standards required for critical systems.


Key Migration Considerations


  1. Compatibility: ProvenCore aligns with GlobalPlatform TEE APIs, allowing existing OP-TEE Trusted Applications to be reused with minimal modification.
  2. Security and Certification: Migrating to a fully certified microkernel provides stronger guarantees of confidentiality, integrity, and isolation. This is particularly important in regulated or high-assurance environments.
  3. Deployment and Lifecycle: ProvenCore supports lifecycle management of Trusted Applications, including secure provisioning, updates, and retirement, ensuring operational reliability.
  4. Performance: Applications can leverage the optimized microkernel design to maintain or improve execution efficiency while meeting strict security requirements.


Practical Guidance


Organizations should perform a phased migration: assess application dependencies, verify API compatibility, and validate security properties in a controlled test environment. ProvenCore’s adherence to formal methods and TEE standards simplifies compliance and reduces migration risk.

By moving from OP-TEE to ProvenCore, teams gain enhanced security, formal certification, and continued support for existing applications, providing a future-proof foundation for trusted computing on embedded systems.

Our others articles :

  • ai

    An HSM protects cryptographic keys. But nobody actually wants protected keys; they want the things keys make possible — payments that cannot be forged, identities that cannot be usurped, signatures that stand up in court, updates that cannot be hijacked.

  • RIP Legacy HSM, Enter ProvenHSM

    A side-by-side look at how ProvenHSM compares with legacy network HSMs across operations, cloud readiness, crypto agility, extensibility, multi-tenancy, TCO, and business model

  • Abstract mathematical structures transition through flowing lines into a rack appliance

    ProvenRun spent 15 years proving low-level software correct. Here's why the team behind the world's only EAL7-certified OS decided its next product had to be a cloud-operated hardware security module.

Explore ProvenHSM
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo