Secure Provisioning — Manufacturing and Injection Flow
Overview
Secure provisioning is the process through which a device receives its cryptographic identity, root secrets, certificates, and lifecycle configuration. It is one of the most sensitive phases in the entire security chain: if provisioning is compromised, the device can be cloned, impersonated, or permanently weakened.
A secure provisioning flow ensures that:
- each device receives unique, non‑guessable secrets
- keys are injected or derived without ever being exposed
- OEM tools are authenticated and authorized
- lifecycle transitions are enforced and irreversible
- supply‑chain attacks are detectable and traceable
This page describes the conceptual flow from silicon manufacturing to field deployment.
Provisioning Flow — High‑Level Diagram

1. Foundry Stage — No Secrets on Silicon
At the semiconductor foundry, chips are manufactured without any cryptographic secrets. Only hardware identifiers exist:
- die ID
- wafer ID
- lot number
- manufacturing test fuses
Why no secrets here?
- foundries are not trusted with OEM keys
- silicon must remain generic until OEM provisioning
- prevents large‑scale key leakage
This stage ends with a “blank” device.
2. OEM Provisioning — Injecting or Deriving Secrets
This is the most critical phase. The OEM uses secure equipment to:
- inject per‑device keys
- derive secrets from PUF
- program certificates
- configure lifecycle state
- enable secure boot
- lock debug access
Provisioning must occur in a controlled, authenticated, and audited environment.
Secure Key Injection
Keys are injected using:
- encrypted transport channels
- authenticated programming tools
- challenge/response with the device
- anti‑replay protections
- tamper‑resistant provisioning stations
PUF‑Based Derivation
Instead of injecting keys, the OEM may:
- enroll the PUF
- store helper data
- derive the Device Root Key (DRK) on demand
- avoid storing long‑term secrets in NVM
Per‑Device Uniqueness
Each device receives:
- a unique symmetric key
- a unique asymmetric keypair
- a unique certificate or attestation identity
- unique seeds for key derivation
This prevents cloning and impersonation.
Lifecycle Configuration
The OEM sets:
- secure boot enable
- debug lockdown
- anti‑rollback counters
- allowed lifecycle transitions
Once set, these values are irreversible.
3. Field Deployment — Secure Operation
Once provisioned, the device enters User / Field state.
In this state:
- keys cannot be replaced
- debug access is restricted or disabled
- secure boot enforces firmware integrity
- updates require OEM signatures
- provisioning interfaces are permanently locked
The device now operates with its permanent identity.
4. RMA / Repair Mode — Controlled Access
Some devices support a special RMA (Return Material Authorization) mode.
Characteristics:
- requires OEM‑signed authorization
- may wipe sensitive data before enabling debug
- allows limited diagnostics or re‑provisioning
- cannot be entered without cryptographic proof
RMA prevents unauthorized rollback to manufacturing/debug states.
5. End‑of‑Life — Secure Decommissioning
At the end of its lifecycle, a device must be decommissioned securely.
Typical actions:
- erase or invalidate keys
- disable secure boot
- lock all debug interfaces
- set irreversible EoL fuses
- wipe user data
This ensures the device cannot be reused or repurposed maliciously.
Threats to Provisioning
| Threat | Description |
|---|---|
| Key extraction | Probing, sniffing, or intercepting injected keys |
| Cloning | Copying keys to replicate devices |
| Supply‑chain compromise | Malicious provisioning stations or operators |
| Unauthorized lifecycle transitions | Forcing device back into debug mode |
| Weak entropy | Predictable key generation |
| Tampering during provisioning | Manipulating injected values |
| Compromised OEM tools | Leaked credentials or unauthorized access |
Mitigation Techniques
- encrypted provisioning channels
- authenticated programming tools
- hardware‑anchored lifecycle states
- PUF‑based key derivation
- per‑device certificates
- tamper detection and zeroization
- secure audit logs
- anti‑rollback counters
- OEM‑only programming permissions