The document presents a secure storage architecture utilizing OP-TEE, detailing key management and atomic operations required for reliable data handling. It outlines mechanisms for file encryption, enforced confidentiality, and integrity guarantees while allowing atomic updates to mitigate risks such as rollback attacks. Future work includes strengthening the separation of storage among different Trusted Applications (TAs) and improving protections against unauthorized access.