This is quite common, you add the private key to some secure hardware module, so that only that device can sign using the certificate, and then use TLS to connect
I get that this is how iMessage works, as I understand it. I am wondering what tradeoffs make Apple decide to use the Secure Enclave versus more mundane certificate infrastructure and how they would make it hard for us to get at this with a debugger if they chose that route.
I don’t think Apple would have much trouble burying a certificate and key in a IOS device that would be very hard to access.