This is called Arm TrustZone (don’t remember the name of the Intel version) and is used for Netflix DRM.
Note that DRM as usually designed is made to protect the program from the user (and the OS, which the user can compromise alter). The same principle can be used to protect the user from the OS.