Apple’s Secure Enclave has replay protection since Apple A11.

Generally, I don’t see why a modern security platform wouldn’t have its own private SRAM to be used as a root of trust for encrypted blobs stored in shared DRAM.

Right, that is in addition to mere encryption.