Implement alternate SE root-of-trust provisioning. am: f9a58ae4ff am: 91cf66e2fc am: 8daf455098 am: a8fd36bb89 am: 26c5966ab2

Original change: https://android-review.googlesource.com/c/platform/system/keymaster/+/2109825

Change-Id: I20da4d0fcb6f975c92150f9d02fb05b2fe5c56bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>