Implement alternate SE root-of-trust provisioning. am: f9a58ae4ff am: 91cf66e2fc am: 8daf455098 am: a8fd36bb89

Original change: https://android-review.googlesource.com/c/platform/system/keymaster/+/2109825

Change-Id: I11dc8df13b935fbbf2fb1d9536b2bb7c60829b32
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>