6. TrustZone¶
The secure world: TrustZone (TZ) and the hypervisor (HYP) images, the QSEE trustlets running under them, and the hardware crypto engine (QCE/ICE/HWKM) that backs keymaster/keystore and storage encryption. Split out into its own section because it’s a genuinely distinct execution environment from the non-secure boot chain and SoC fabric documented elsewhere.