SYSFW/TIFS supports binary blob verification and decryption on AM6xx family SoC (HS-SE).
https://software-dl.ti.com/tisci/esd/latest/6_topic_user_guides/authentication.html
The FAQ lists how to call the TISCI API TISCI_MSG_PROC_AUTH_BOOT in AM62x Linux SDK
https://software-dl.ti.com/tisci/esd/latest/2_tisci_msgs/security/PROC_BOOT.html#proc-boot-authenticate-image-and-configure-processor
It shows how to verify and decrypt the signed Linux kernel image and kernel DTB file in the extended RoT secure boot flow with AM62x Linux SDK 11.1.5.3 (TIFS 11.1.2). The scripts and the u-boot patch in the FAQ is applicable to other AM6xx devices with some adaptations.
https://www.ti.com/tool/download/PROCESSOR-SDK-LINUX-AM62X/11.01.05.03