Learning path

Full curriculum

Full curriculum

Unit content

Trust boundaries and the trusted computing base

A trust boundary separates components that are trusted to enforce a security property from components that are not.

When data or control crosses that boundary, the trusted side must apply the validation or enforcement required by the design rather than assuming the untrusted side behaved correctly.

The trusted computing base (TCB) is the collection of components whose correct behavior is necessary for the system's security guarantees.

A component can be small yet security-critical if every protected operation depends on it. Conversely, a large component outside the TCB may be allowed to fail without violating the particular property being protected.

Adding privileged or security-critical code expands the TCB and creates more behavior that must remain correct. A smaller TCB is generally easier to reason about and audit.

Trust is therefore a design dependency, not a statement that a component is familiar or well intentioned: if its failure can violate the guarantee, the system trusts it.