Hi, please check steps inside manual RM758221-HSE-B Firmware Reference Manual, chapter Host debug.
Step 1) Provision the ADKP using the HSE_APP_DEBUG_KEY_ATTR_ID attribute.
Step 2) Set authorization method: password-based or challenge-response based, using the HSE_DEBUG_AUTH_MODE_ATTR_ID system attribute.
Step 3) Set the life cycle to OEM_PROD or IN_FIELD using the HSE_SECURE_LIFECYCLE_ATTR_ID system attribute.
All the above steps can be implemented in a DID/UDS routine no issue with that. After the 3rd step you ECU will be JTAG locked. You will need to provide the same password to debug tooling (Lauterbach Trace32 for ex, .