-
@CopperheadOS that is exactly what we suggested nearly 2 years ago: root of trust for boot attestation should be a secure element, not Trustzone.
-
@CopperheadOS ins.jku.at/research/publications/practical-hardware-assisted-approach-customize-trusted-boot-mobile-devices is the link to the original paper, refined later internally