Can we gain enough trust to Android-based key-storages with any particular manufacturers within the zoo of secure hardware units?
To solve the problem of information about Android security properties (which is not easisly resolvable even by design), Google peredictable goes with unification and standartization:
Stronbox Keymaster which is stricter (than Global Platform) and standardized approach of Secure Enclave utilization within Security architecture.
The bad news is that there are only 8 devices supporting Strongbox:
https://www.android-device-security.org/client/datatable?sba=true
The good news is that latest Samsungs already checked-in!
Recent Android Ready SE announce in attempt to force situation with the support and inertia of european SE suppliers and push Android Strongbox into even wider mass than smartphones.
The bad news is that there are predictably still no devices that are Android Ready SE-based.
We reviewed Huawei’s TEE, called TC, and uncovered several design flaws... We found several issues in the loader’s design, like protecting a constant key using white-box cryptography, and were able to break the code confidentiality of encrypted TAs distributed to many Huawei devices. Furthermore, we examined the keystore system and revealed considerable design flaws that allowed us to leak export-protected cryptographic keys from the TEE.we were finally able to escalate our privileges to the highest privilege level present on this platform
(LINK)
Insider Attack Resistance is subject to your personal trust to smartphone manufacturer
.