There is no such restriction ... You never make complete physical interface memeber of a security zone.. instead you do it on sub-interface level with liberty to put them under any zone ..
e.g.
if you have
set interface ge-0/0/0.1 family inet address 192.168.1.1/24
set interface ge-0/0/0.2 family inet address 192.168.2.1/24
then you can place them under different zones
set security zone security-zone trust interfae ge-0/0/0.1
set security zone security-zone untrust interfae ge-0/0/0.2
Mark it "Accepted" if rocks
regards