Every security argument terminates somewhere. Software verifies software, which verifies more software, and at the bottom of that chain is something that verifies nothing because there is nothing beneath it. That thing is the root of trust, and the whole edifice is worth exactly what it is worth.
If the root is software, it can be replaced — and an attacker who replaces it inherits every guarantee that depended on it. If the root is in silicon, replacing it means replacing the part, which changes the economics of attack entirely.
Hardware-rooted identity goes one step further than hardware-stored identity. A key written into fuses is in hardware but it is stored, which means it exists at rest and can in principle be read. An identity derived from physical properties of the die is re-derived at each verification and does not sit anywhere waiting to be extracted. That difference is the substance of the distinction, and further detail belongs under a non-disclosure agreement.