Tool/software:
SYSFW/TIFS supports key revoke use case via TISCI API TISCI_MSG_WRITE_KEYREV.
https://software-dl.ti.com/tisci/esd/latest/6_topic_user_guides/otp_revision.html#dual-signed-certificate-for-writing-keyrev
https://software-dl.ti.com/tisci/esd/latest/2_tisci_msgs/security/otp_revision.html#sec-api-wr-keyrev-otp
The FAQ lists how to call the TISCI API TISCI_MSG_WRITE_KEYREV by secure OPTEE running on ARM TZ A53.
There is an companion FAQ on how to call the API from R5 core
https://e2e.ti.com/support/processors-group/processors/f/791/t/1202686