DexterLab

🔥 New release: Parser AXI-Full Edition v1.0.0 now available🔥 Roadmap updated: AXI-Lite & AHB-Full/Lite in development📘 Unified command architecture — new documentation planned📘 Timing diagrams and bus models coming in next updates📘 Theory ↔ Design Library integration continues

Secure Provisioning — Manufacturing and Injection Flow

Overview

Secure provisioning is the process through which a device receives its cryptographic identity, root secrets, certificates, and lifecycle configuration. It is one of the most sensitive phases in the entire security chain: if provisioning is compromised, the device can be cloned, impersonated, or permanently weakened.

A secure provisioning flow ensures that:

  • each device receives unique, non‑guessable secrets
  • keys are injected or derived without ever being exposed
  • OEM tools are authenticated and authorized
  • lifecycle transitions are enforced and irreversible
  • supply‑chain attacks are detectable and traceable

This page describes the conceptual flow from silicon manufacturing to field deployment.

Provisioning Flow — High‑Level Diagram

1. Foundry Stage — No Secrets on Silicon

At the semiconductor foundry, chips are manufactured without any cryptographic secrets. Only hardware identifiers exist:

  • die ID
  • wafer ID
  • lot number
  • manufacturing test fuses

Why no secrets here?

  • foundries are not trusted with OEM keys
  • silicon must remain generic until OEM provisioning
  • prevents large‑scale key leakage

This stage ends with a “blank” device.

2. OEM Provisioning — Injecting or Deriving Secrets

This is the most critical phase. The OEM uses secure equipment to:

  • inject per‑device keys
  • derive secrets from PUF
  • program certificates
  • configure lifecycle state
  • enable secure boot
  • lock debug access

Provisioning must occur in a controlled, authenticated, and audited environment.

Secure Key Injection

Keys are injected using:

  • encrypted transport channels
  • authenticated programming tools
  • challenge/response with the device
  • anti‑replay protections
  • tamper‑resistant provisioning stations

PUF‑Based Derivation

Instead of injecting keys, the OEM may:

  • enroll the PUF
  • store helper data
  • derive the Device Root Key (DRK) on demand
  • avoid storing long‑term secrets in NVM

Per‑Device Uniqueness

Each device receives:

  • a unique symmetric key
  • a unique asymmetric keypair
  • a unique certificate or attestation identity
  • unique seeds for key derivation

This prevents cloning and impersonation.

Lifecycle Configuration

The OEM sets:

  • secure boot enable
  • debug lockdown
  • anti‑rollback counters
  • allowed lifecycle transitions

Once set, these values are irreversible.

3. Field Deployment — Secure Operation

Once provisioned, the device enters User / Field state.

In this state:

  • keys cannot be replaced
  • debug access is restricted or disabled
  • secure boot enforces firmware integrity
  • updates require OEM signatures
  • provisioning interfaces are permanently locked

The device now operates with its permanent identity.

4. RMA / Repair Mode — Controlled Access

Some devices support a special RMA (Return Material Authorization) mode.

Characteristics:

  • requires OEM‑signed authorization
  • may wipe sensitive data before enabling debug
  • allows limited diagnostics or re‑provisioning
  • cannot be entered without cryptographic proof

RMA prevents unauthorized rollback to manufacturing/debug states.

5. End‑of‑Life — Secure Decommissioning

At the end of its lifecycle, a device must be decommissioned securely.

Typical actions:

  • erase or invalidate keys
  • disable secure boot
  • lock all debug interfaces
  • set irreversible EoL fuses
  • wipe user data

This ensures the device cannot be reused or repurposed maliciously.

Threats to Provisioning

ThreatDescription
Key extractionProbing, sniffing, or intercepting injected keys
CloningCopying keys to replicate devices
Supply‑chain compromiseMalicious provisioning stations or operators
Unauthorized lifecycle transitionsForcing device back into debug mode
Weak entropyPredictable key generation
Tampering during provisioningManipulating injected values
Compromised OEM toolsLeaked credentials or unauthorized access

Mitigation Techniques

  • encrypted provisioning channels
  • authenticated programming tools
  • hardware‑anchored lifecycle states
  • PUF‑based key derivation
  • per‑device certificates
  • tamper detection and zeroization
  • secure audit logs
  • anti‑rollback counters
  • OEM‑only programming permissions

Related Pages