keystore2 may return a different BBinder for each getSecurityLevel call, so the initial registration during setup might not cover all binder instances that client apps receive. Intercept getSecurityLevel replies to register our hook on every new BBinder, deduplicated by identity hash.