Almost all commercial devices need a unique ID, private key, etc burned in on the production line. For a big enough production run, you'd likely ship an HSM to the factory
> For a big enough production run, you'd likely ship an HSM to the factory
I figure that the factory is exactly the adversary in the whole threat model? So why give them the keys to the castle so they can moonlight their own genuine batch?
> Almost all commercial devices need a unique ID, private key, etc
Serious question: why?
IMO it's better to ship preprogrammed ICs to the factory, so you can do your secure burning in-house.