Implement alternate SE root-of-trust provisioning. am: f9a58ae4ff

Original change: https://android-review.googlesource.com/c/platform/system/keymaster/+/2109825

Change-Id: I4d6849a99657f09f674a530141ebd0def82dd7d0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>