Lifecycle and Provisioning Security
Overview
Lifecycle and provisioning security ensures that a device remains trustworthy from manufacturing to end‑of‑life. It defines how identities are established, how keys are injected or derived, how debug access is controlled, and how transitions between lifecycle states are enforced.
Each lifecycle stage exposes different attack surfaces. Strong controls are required to prevent:
- unauthorized programming
- cloning
- tampering
- rollback to insecure states
- unauthorized key injection
Provisioning security also ensures that only the OEM—not the end user—can program or modify cryptographic material.
Supply‑Chain Stages and Trust Boundaries
A secure lifecycle spans multiple actors, each with different privileges and responsibilities.
Foundry (Silicon Manufacturing)
- No secrets present
- Only hardware identifiers (die ID, wafer ID)
- Debug fully open
- Test firmware allowed
OEM (Provisioning and Personalization)
- Keys, certificates, and lifecycle fuses injected
- Secure boot enabled
- Debug restricted or authenticated
- Device identity established
User / Field Deployment
- Keys locked
- Debug disabled or authenticated
- Only authenticated updates allowed
- Device operates in secure state
FAR / RMA (Field Application Repair)
- Controlled mode for OEM‑authorized recovery
- Limited re‑provisioning allowed
- Debug partially enabled under authentication
End‑of‑Life
- Keys erased or invalidated
- Trust anchors disabled
- Debug may be reopened for recycling or permanently disabled
Figure 1 — Lifecycle Stages and Trust Boundaries

Each lifecycle stage has different privileges, attack surfaces, and trust boundaries.
Lifecycle States and Enforcement
Lifecycle states define what operations are allowed at each stage. Transitions must be strictly controlled and irreversible where required.
Manufacturing State
- Unrestricted debug
- No secrets
- Test firmware allowed
Provisioning State
- OEM injects keys and certificates
- Secure boot configuration applied
- Lifecycle fuses programmed
Secure State
- Device deployed
- Keys locked
- Debug disabled or authenticated
- Only signed firmware accepted
RMA / FAR State
- Restricted mode for authorized repair
- Limited re‑provisioning
- Debug partially enabled under OEM control
Decommissioned State
- Secrets erased
- Trust anchors invalidated
- Device no longer trusted
Enforcement Mechanisms
- OTP fuses
- Secure registers
- HSM‑controlled transitions
- Cryptographic authorization
Figure 2 — Lifecycle State Enforcement

Lifecycle transitions are controlled by fuses, secure registers, and cryptographic authorization.
Provisioning Security
Provisioning is the most sensitive phase because secrets are created or injected.
Encrypted Key Injection
Keys are provisioned using encrypted and authenticated channels.
Per‑Device Uniqueness
Each device receives a unique symmetric key or certificate to prevent cloning.
Secure Provisioning Equipment
OEM tools must be authenticated to prevent rogue programming.
PUF‑Based Provisioning
Secrets derived from silicon characteristics instead of being injected.
Audit and Traceability
Provisioning events logged to detect supply‑chain compromise.
OEM‑Only Programming
End users cannot modify keys, certificates, or lifecycle fuses.
Threats Across the Lifecycle
Unauthorized Key Injection
Attackers attempt to program their own keys during provisioning.
Lifecycle Rollback
Forcing the device back into manufacturing or debug mode.
Cloning Attacks
Copying keys or certificates to replicate devices.
Supply‑Chain Compromise
Malicious actors inserting backdoored firmware or keys.
Insecure Debug Access
Using JTAG/SWD/UART to bypass lifecycle restrictions.
Weak Provisioning Tools
Compromised OEM equipment leaking secrets.
Invasive Attacks
Probing or decapping to extract lifecycle fuses or keys.
Mitigation Techniques
Hardware‑Anchored Lifecycle States
OTP fuses enforce irreversible transitions.
Authenticated Debug
Debug interfaces require cryptographic authorization.
Secure Boot Enforcement
Unauthorized firmware cannot execute at any stage.
Key Diversification
Multiple keys derived from a single root secret.
Tamper Detection
Keys erased when invasive attacks are detected.
Secure Provisioning Protocols
Encrypted, authenticated, and audited key injection.
PUF‑Based Identity
Eliminates stored secrets and binds identity to silicon.
End‑of‑Life Sanitization
Securely erasing keys and disabling trust anchors.
Relationship with Safety
Safety
Ensures correct operation under random faults.
Security
Ensures correct operation under malicious manipulation.
Overlap
- Lifecycle states protect safety mechanisms from being disabled
- Secure provisioning prevents replacement of safety‑critical firmware
- Tamper detection protects both domains
Related Pages
All real, existing pages: