Trusted Runtime Environment (TEE)
Google has taken a wonderful step in the right direction, moving all print manipulation to a runtime environment (TEE) and providing strong guidelines for storing fingerprint data that manufacturers must follow.
All fingerprint data processing is done in TEE
All fingerprint data must be protected in the hardware or trusted memory of the sensor so that fingerprint images are not available.
The fingerprint data can be stored in the file system only in encrypted form,
regardless of whether the file system itself is encrypted or not.
Deleting a user should delete existing user fingerprint data
Root access should not compromise fingerprint data
Data source infinum.co
source share