1. Export Serial Number and ECC public key
4. Ship packaged device
2. Authenticate IC with Factory Key
3. Inject a signed x.509 certificate into the device