Any secure boot design can achieve that, you don't need TrustZone to do that