Implement alternate SE root-of-trust provisioning.

Bug: 219076736
Test: VtsAidlKeyMintTargetTest
Ignore-AOSP-First: No path from AOSP; will be cherry-picked there.
Change-Id: I28c13d9b201b831a1d339d5dd9d7bb8c2b176f59
8 files changed