BL1: Add KDF, use to derive BL2 decryption key

Instead of always using the same key, derive based on security counter.
Change signing script to use same derivation.

Change-Id: I6975fcad55dfc8b767aa5f8ed28dae3b7e8e37a2
Signed-off-by: Raef Coles <raef.coles@arm.com>
7 files changed