Do you have more details?
Why can't you upload your own private key in the new bios payload, like you can for SecureBoot?
Everything is sitting in a flash chip. Some parts may be RO, but it can be replaced by another chip if you can't tweak it directly with flashrom.