![]() |
Deeptrust for PCI security architecture
SPEC98T17 rev E
Specification of Deeptrust, the Security Architecture for Cortex-M.
|
One or more boxes that run applications (e.g. VISA, EMV, Mastercard, Main application, etc) may exist and leverage RPC API of other boxes (Boxes can communicate with each other through Remote Procedure Calls aka RPC).
Their identification (box ID) will grant them access to their private data or specific privileges when using the API.
Those boxes run in independent threads.
PRIVILEGE LEVEL: "Box Trusted" or "Box Other"
They actually implement the high-level services proposed by the device (e.g. payment application). By using the Secure Sandbox services box and the PCI Security Services box, the applications may be kept out of the certification perimeter. Code can also run out of any box.