Hello Uthappa,
Job Ring number is an input to the BKEK derivation function only for Secure Memory blobs, not general memory blobs.
And the Job Ring number used is the Job Ring that owns the Secure Memory partition, not the Job Ring number where the blob encapsulation/decapsulation descriptor is run.
So you would have to dedicate one or more job rings to the m4, have the m4 claim one or more Secure Memory partitions, set the access permissions for those partitions to exclude the a7, and use Secure Memory blobs to save the data in the partitions across power cycles.
Regards