Device Certificate Options#
The HSE-SVH devices are each programmed with a MCU device certificate during IC production. The device certificate is signed with the private batch key allowing the device certificate to be validated against the Silicon Labs certificate chain Verification for Certificates and Certificate Chain Verification.
The device certificate private key never leaves the Secure Key Storage on the HSE-SVH device. Three device certificate options (standard, modified, and external) are provided to meet different requirements. Silicon Labs provides Custom Part Manufacturing Service (CPMS) to program custom certificates at Silicon Labs factories. For more information about CPMS, see Custom Part Manufacturing Service User's Guide.
Standard MCU Device Certificate#
Comes standard with Series 2 HSE-SVH devices.
Can be injected into other Series 2 (HSE or VSE SVM devices) and Series 3 devices using CPMS.
Cryptographically proves the device is an authentic Silicon Labs device.
Does not protect against overproduction or counterfeit products that are built with authentic Silicon Labs devices.
Signed to a Silicon Labs Certificate Authority (CA).
The device can prove that it possesses the private key associated with the public key in its certificate by signing the response to a given challenge (Remote Authentication Process and Certificate Chain Verification and Remote Authentication).


Modified MCU Device Certificate#
Available as a customization service via CPMS on Series 2 and Series 3 devices.
Cryptographically proves the device is an authentic Silicon Labs device that was produced for a specific OEM.
Protects against overproduction by Contract Manufacturer (CM).
Device Certificate X.509 fields can be customized, with some restrictions. See the CPMS User's Guide for more details.
Signed to a Silicon Labs Certificate Authority (CA).


External Chain - MCU Device Certificate#
Available as a customization service via CPMS on Series 2 and Series 3 devices.
Cryptographically proves the device is an authentic Silicon Labs device that was produced for a specific OEM.
Protects against overproduction by Contract Manufacturer (CM).
Factory Certificate is custom for each OEM.
Device Certificate and Factory Certificate X.509 fields can be customized, with some restrictions. See the CPMS User's Guide for more details.
Signed to a OEM Certificate Authority (CA).
Root Certificate Authority is OEM-specified.
Electronic delivery of all batch and device certificates signed under this OEM factory certificate is supported.

