BootSecurityInfo was 0x0 for most of my Jetsons. My settings were 0x209.
I got a new one where it was 0x1e0, so combine them for 0x3e9, just for that one unit.
1e0 - 0001 1110 0000
209 - 0010 0000 1001
0011 1110 1001 - 3E9
I had a quick look at your post and I think your OemK’s did burn, because it got past that point to burning BootSecurityInfo, they just don’t show up in the query because they’re secret.
I got the 0x209 value from the example here
The first 3 bits from the right are Secure Boot mode and the 4th activates it, according to Jetson Orin Fuse Specification - Application Note
And bit 9 is “ODM key valid” which activates the OEMK1 for disk encryption.
So I guess you aren’t trying to use Secure Boot.
I’ve seen other posts in passing that suggest you can do encryption without Secure boot like this one
You mention recreating the keys which worries me because won’t that mean they’ll be different to what’s already been fused?
Also It looks like you haven’t set SecurityMode yet, don’t we need that for any of this to take effect? Seek further advice first though, I don’t want you to brick your Jetson based on something I said!