Google Cast provisioning,
operated as governed infrastructure.

OnBoard™ IoT Security (OBIS) governs Cast certificate operations, provisioning workflows, and lifecycle operations through one operational trust chain — whether OEMs retain their own CA hierarchy or operate through OBIS-managed infrastructure.

Cast certificate, plus everything else the device needs.

Devices with Chromecast built-in typically require multiple credentials — Cast certificates, OEM identities, Matter DACs, and OTA credentials — each governed across separate operational workflows. OBIS governs them through one provisioning workflow and one operational trust chain.

Built for the Cast security bar.

The Google Cast program defines security requirements across key management, certificate operations, and provisioning workflows. OBIS governs these operational controls end-to-end.

Key Management

Keys never leave the hardware boundary.

All key operations execute inside HSM boundaries with no extraction path for factory operators or platform administrators.
CA Operation

Every certificate operation is authorized and recorded.

OBIS records every certificate operation with operator, timestamp, approval chain, and governed operational records.
Factory Provisioning

Provisioning runs under authorization, not implicit trust.

EdgeHSM enforces offline-capable provisioning, per-line authorization, and encrypted payload delivery directly on the programming station.

The trust chain behind every Cast device.

Google operates the Cast root, while each device carries a unique device certificate. Between them sit the OEM CA and Model CA layers, which establish operational trust across the provisioning workflow. OBIS governs Model CA operations and device certificate issuance, while OEMs retain flexibility over the OEM CA trust model.

Built for governed Google Cast provisioning and lifecycle operations at scale.

Discuss your certificate provisioning workflow, factory architecture, device authentication model, and operational requirements with the OBIS engineering team.