Jamie, Thanks for your feedback.
I'd like to summarize like below and ask some questions. If there is anything that I misunderstood, please let me know.
1. TF-M itself doesn't operate as an secure enclave. 2. To operate as an secure enclave, we must adapt secure enclave IP or RSS. 3. RSS is a collection of IPs (LCM, KMU, CryptoCell...). 4. With HW support listed above, keys and crypto operations can be isolated from SW(CPU). 5. Should we have separate dedicated memory and ROM for RSS core? or is there any IP to provide a dedicated region? or it doesn't necessary?
Kind Regards, Sunguk