Implement alternate SE root-of-trust provisioning. am: fdeafb864c am: 391b2ca3fe am: c0a816b4f7 am: fd8ae19199

Original change: https://googleplex-android-review.googlesource.com/c/platform/system/keymaster/+/18638885

Change-Id: I7cda124bfe8fb37e8eab4914717e95662bf5c63f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>