Alea,
Great questions and I can only offer an Opinion based on my readings. I'm not a SL or awk they understand the technology at a micro level.
"Beyond the proprietorial argument, I am curious which features you have identified which make ARM's TZ superior to Intel's Deepsafe. I have been looking on Google for side by side comparisons of features, but haven't had much luck.
Is the difference mainly about providing a common domain for TCG-enabled trustlets, versus an Intel-controlled one?"
For me, I keep looking at the GlobalPlatform Standards around the Rich OS running beside the Trusted Execution Environment (TEE) and how the Secure Elements are tied to that Whole Security System. The TPM/MTM as we know is a Trusted Application Running in the TEE and provides the fuctionality of a Discrete TPM as seen on a PC.
There will be many Applications created going forward that need various levels of Security to execute. Some Apps can run in the Rich OS, Some can execute in the TEE and others need to use the Secure Elements with the TEE. All software and Apps. running on the device will be cryptographicaly signed/sealed and need life cycle management. What and who will provide this service leads into the Applets discussion and are the Secure Elements needed at that point etc. I don't want to go there it's down the road JMO.
I keep looking in the Intel world trying to see how they will do something similar to tie into the Global Standards for Mobile devices and cannot find anything that looks like what ARM and their partners are providing.
The TPM exists in the x86 world but the TEE does not exist as far as I understand it. Applications either run in the Rich OS (Windows/Android/IOS) or the Secure Elements.
So I expect awk is correct that Intel must find a bridge to the Arm Security eco system by doing what AMD is doing or be isolated.
I see G&D will provide Trusted Services Management for the Secure element in Intel's phones so maybe there is something coming?? Plus the last post of mine showed Intel has an Arm Licensing Agreement through the Infineon purchase so maybe there is something there.
Deep Safe is Intel proprietary security and I'm not sure what they are attempting by re-inventing the wheel but who am I, they did not consult me. Hope this helps.