hello shengnan0509.chen,
you should works with eMMC since we do not support Jetson security with SD-card.
please check Jetson Nano Boot Flow, you may also refer to Topic 157952 for reference;
FYI,
secure boot is enabled when you begin production and burn the ODM production fuse (i.e. production_mode), it means JTAG debug is disabled, and all the fuses become inaccessible except Reserved_ODM.
however,
Reserved_ODM fuse are programmable until it disabled by the ODM_lock fuse.
thanks