Hello Jonas Karlsson,
There is no much publicly available documentation regarding this other than the Security Reference Manuals, which require an NDA. In general terms the JTAG may request to debug in TrustZone or in the Normal World, depending on the request one of the two keys would be used for the challenge by the Authenticated Debug Module (ADM) which would then allow to enable the debug mode.
As for the Lauterbach scripts, they are available, but I would need to ask you to please open a service ticket/case requesting them as they are not publicly available. You can find details on how to open a Case on the following document:
https://www.nxp.com/support/support:SUPPORTHOME
My apologies for the inconvenience.
Regards,