Hello yeyuan.
Suppose that the network access is available for it. mobaXterm would be a good option.
1, connect you host to board, and then get the network information which assigned to it.
2, use ssh to remote to the board. there is convenient way to drag files.
The lk.bin that generated by trusty build named tee-imx8qx.bin is actually trusty os.
You might refer to 8.6.1 Initializing the secure storage for Trusty OS for how to enable security with it, and refer to 2.2 Trusty OS security recommendations for i.MX 8 SoC configuration.
Best regards
Harvey