Add the support of Android Verified Boot: https://source.android.com/docs/security/features/verifiedboot/avb The verification should be done through AVB Trusted Application: https://github.com/OP-TEE/optee_os/tree/master/ta/avb