DPE: Support using provisioned RoT attestation key

Changes the DPE service to get the key ID of the RoT attestation key via
a platform function, and uses it to derive the RoT CDI_ID and sign the
RoT layer.

Signed-off-by: Jamie Fox <jamie.fox@arm.com>
Change-Id: I2e9c8b93adfdc11a7b8a28967f9327d72aaf81c5
3 files changed