> ## Documentation Index
> Fetch the complete documentation index at: https://dragonwingdocs-staging.qualcomm.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 安全附录文档

本附录是《Qualcomm® Linux® 安全指南》的扩展,为授权用户提供更多安全方面的深入内容。

## **安全附录概述**

<CardGroup cols={1}>
  <Card title="安全附录概述" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/overview-addendum.html">
    安全附录概述,重点介绍面向持证用户的高级安全增强功能。
  </Card>
</CardGroup>

## **与内核和设备交互**

<CardGroup cols={2}>
  <Card title="使用用户空间 API" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/user-space-apis.html">
    使用用户空间 API 实现 Linux 与内核之间的通信。
  </Card>

  <Card title="使用 Qualcomm TEE API" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/trusted-execution-environment-apis.html">
    使用 Qualcomm TEE API 实现内存、日志记录、安全存储、监听器和加密功能。
  </Card>
</CardGroup>

## **自定义内存**

<CardGroup cols={1}>
  <Card title="为可信应用程序自定义内存" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/customize-fru.html">
    自定义内存和 SEPolicy。
  </Card>
</CardGroup>

## **开发可信服务和客户端服务**

<CardGroup cols={3}>
  <Card title="开发可信应用程序和客户端应用程序" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/develop.html">
    使用默认的 GlobalPlatform 接口文件开发并运行可信应用和客户端应用。
  </Card>

  <Card title="配置可信应用程序" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/develop-trusted-application-and-client-application.html">
    根据您的需求设置配置。
  </Card>

  <Card title="开发 GlobalPlatform 可信应用程序" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/develop-gp-ta.html">
    构建和开发 GlobalPlatform 可信应用程序。
  </Card>

  <Card title="开发 GlobalPlatform 客户端应用程序" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/develop-ga-ca.html">
    使用基于 GlobalPlatform 的客户端与 Qualcomm TEE 中的可信应用程序进行通信。
  </Card>

  <Card title="运行客户端和可信应用程序" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/executing-client-application-and-trusted-application.html">
    使用日志验证并运行客户端和可信应用程序。
  </Card>
</CardGroup>

## **使用示例**

<CardGroup cols={3}>
  <Card title="使用安全服务示例" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/examples.html">
    通过各种接口加载客户端和可信应用程序以运行安全服务。
  </Card>

  <Card title="GlobalPlatform 骨架客户端应用程序源码清单" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/gp-skeleton-ca-source-listing.html">
    使用示例代码和命令编译客户端应用程序。
  </Card>

  <Card title="使用 Qualcomm TEE 服务 API" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/use-qualcomm-tee-service-apis.html">
    使用示例代码从可信应用程序调用 SFS 接口。
  </Card>

  <Card title="使用基于 IDL/对象的 Qualcomm TEE 服务 API" href="https://docs.qualcomm.com/doc/80-70023-11A/topic/use-idl-object-based-qualcomm-tee-service-apis.html">
    使用示例代码从可信应用程序调用用于 AES 操作的加密接口。
  </Card>
</CardGroup>

## **相关文档**

| 标题 | 文档编号 |
| :- | :- |
| MiniDump Software User Guide | 80-P8754-71 |
| Qualcomm Linux Build Guide | 80-80023-254 |
| Qualcomm Linux Kernel Guide | 80-80023-3 |
| Qualcomm Linux Security Guide - Addendum | 80-80023-11A |
| Qualcomm Linux Wireless Edge Services Guide | 80-80023-11B |
| SecTools v2: Secure Debug User Guide | 80-NM248-23 |
| SecTools V2: Metabuild Secure Image User Guide | 80-NM248-17 |
| SecTools V2: Fuse Blower User Guide | 80-NM248-9 |
| SecTools V2: ELF Tool User Guide | 80-NM248-18 |
| SecTools V2: MBN Tool User Guide | 80-NM248-19 |
| SecTools V2: ELF Consolidator User Guide | 80-NM248-20 |
| SecTools V2: Secure Image User Guide | 80-NM248-12 |

<Note>
  MiniDump、Qualcomm Linux Security Guide - Addendum、Qualcomm Linux Wireless Edge Services 和 SecTools 指南仅向具有授权访问权限的持证用户提供。
</Note>

## **缩略语和术语**

| 缩略语或术语 | 定义 |
| :- | :- |
| API | 应用程序编程接口 |
| CBC | 密码分组链接 |
| DRM | 数字版权管理 |
| EL0、EL1、EL2 和 EL3 | 异常级别 |
| eMMC | 嵌入式多媒体卡 |
| GPCE | 通用加密引擎 |
| HAL | 硬件抽象层 |
| HLOS | 高级操作系统 |
| HMAC | 哈希消息认证码 |
| I2C | 内部集成电路 |
| ICE | 内联加密引擎 |
| IOCTL | I/O 控制 |
| KDF | 密钥派生函数 |
| KEK | 密钥交换密钥 |
| LLVM | LLVM 项目是一组模块化、可复用的编译器和工具链技术。尽管其名称如此,LLVM 与传统虚拟机关系不大,但它确实提供了可用于构建虚拟机的实用库。LLVM 这个名称本身并不是缩写,而是该项目的全名。 |
| MAC | 消息认证码 |
| MINK | 迷你内核 |
| MPU | 内存保护单元 |
| OCIMEM | 片上内部存储器 |
| OEM | 原始设备制造商 |
| PIL | 外设镜像加载器 |
| pIMEM | 受保护内存 |
| PRNG | 伪随机数生成器 |
| RMA | 返厂分析物料 |
| QFPROM | Qualcomm 熔丝可编程只读存储器 |
| QRNG | Qualcomm 随机数生成器 |
| Qualcomm TEE | Qualcomm 可信执行环境 |
| Qualcomm WES | Qualcomm 无线边缘服务 |
| RPMB | 防重放保护内存块 |
| SELinux | 安全增强型 Linux |
| SEL0 和 SEL1 | 安全异常级别 |
| SFS | 安全文件系统 |
| SKU | 库存单位 |
| SMC | 安全监控调用 |
| SoC | 片上系统 |
| SPI | 串行外设接口 |
| SSL | 安全套接字层 |
| TZBSP | TrustZone 板级支持包 |
| UEFI | 统一可扩展固件接口 |
| UFS | 通用闪存存储 |
| UIE | 统一镜像加密 |
| XBL | 可扩展引导加载程序 |
| xPU | 外部保护单元 |
