what is NXP’s recommended architecture on i.MX8M Plus to achieve AES-GCM with hardware-protected keys? If direct black-key use with AES-GCM isn’t supported, what is NXP’s recommended pattern to provide the same security property while maintaining high-performance AES-GCM?