Intel® Dynamic Application Loader (Intel® DAL) Developer Guide
ID
773482
Date
3/24/2023
Public
For API Level 1 - Intel® ME 7.x - Sandy Bridge
For API Level 1.1 - Intel® ME 8.x lite - Sandy Bridge
For API Level 2 - Intel® ME 8.0 - Ivy Bridge
For API Level 3 - Intel® ME 8.1 - Ivy Bridge
For API Level 3 - SEC1.0, SEC1.1, SEC1.2, SEC2.0
For API Level 4 - Intel® ME 9.5, Intel ME 9.5.55 - Haswell
For API Level 4 - Intel® ME 9.1, Intel ME 9.1.35 - Haswell
For API Level 5 - Intel® ME 10.0.0 - Haswell
For API Level 6 - Intel® ME 10.0.20 - Broadwell
For API Level 7 - ME 11.0 - Skylake_LP and Skylake_H
For API Level 8 - TXE3.0 - Broxton, ME 11.5/11.8 - Kabylake_LP, Kabylake_H
For API Level 9 - Intel® ME 12.0 - Cannon Lake
Trusted Application Validation Guidelines
Validating the Manifest
Memory and Performance
Error Handling and Recovery
Functional Validation and Multi-Instance Support
Pack and DALP Generation and Validation
Host-Side Software Validation Guidelines
Trusted Application Management Flows
Error Handling and Recovery Flows
Multi-Instance and Interoperability Testing of Trusted Application Management
General and Platform-Related Events
End-to-End and Setup Validation Guidelines
Cross Trusted Application Interoperability Functional Testing
Creating a New Project
Importing an Existing Project
Converting an Existing Project
Building and Packaging Your Project and Running in Emulated Environment
Running Your Project
Running and Testing on Emulation and on Silicon
Debugging Trusted Applications
Preparing and Submitting Your Project for Signing
Signing an Applet
Signing New Versions
TEE Management API Sample
This sample shows how you can use the Intel® DAL TEE Management Client API to load an Admin Command Package (ACP).
The sample also demonstrates a simple flow of the Query TEE Metadata interface which is used to retrieve version numbers and general information on the Intel DAL VM from the firmware.
Loading Admin Command Package (ACP) Sample Flow
- Open a Security Domain (SD) session.
- Read the Admin Command Package (ACP) binary file as a blob.
- Send an Admin Command Package.
- Close the SD session.
Note: The TEE Management sample communicates with an Intel DAL Security Domain (SD). In order to run the host application, the user needs to fill in the ACP path and the SD ID within the main class of the host application. The UUID of the Intel Security Domain (default SD) is BD2FBA36A2D64DAB9390FF6DA2FEF31C.
Following is the section of the sample code where these need to be filled in:
// The path to the Admin Command Package (ACP) file. char* acpPath = ""; // The UUID of the DAL Security Domain (SD). char* sdId = "";
Query TEE Metadata Sample Flow
- Query the TEE Metadata.
- Parse the Metadata output structure.