[TF-A] Who better implements a safe environment: cortex-M or cortex-A?