It is tough reading the TCG specs. I am beginning to see thru them to the goals. I do not criticize the lack of explicit goals for they may be very difficult to ennunciate. I think that I can state a few here and suggest what may be a simpler proposal that meets the short list of goals.
There seems to be at least two nested degrees of protection:
An abreviated mechanism must be evaluated on what signals go over the memory bus even while in super-privileged mode. The memory bus is probably not “shielded” in their sense.