OBIS™ OnBoard IoT Security delivers a trusted operational chain that unifies Google Cast certificate management, secure device provisioning, and lifecycle credential operations — enabling OEMs to maintain their own CA infrastructure or seamlessly adopt OBIS-managed security services.
Devices with Chromecast built-in typically require multiple credentials — Cast certificates, OEM identities, Matter DACs, and OTA credentials — each governed across separate operational workflows. OBIS governs them through one provisioning workflow and one operational trust chain.

Google operates the Cast root, while each device carries a unique device certificate. Between them sit the OEM CA and Model CA layers, which establish operational trust across the provisioning workflow. OBIS governs Model CA operations and device certificate issuance, while OEMs retain flexibility over the OEM CA trust model.

The Google Cast trust ecosystem is rooted in Google’s certificate infrastructure, while Matter device identity is built on the CSA certificate framework.
OBIS unifies HSM infrastructure, certificate management platforms, and secure provisioning workflows to enable Google Cast and Matter certificate injection on the same production line — allowing the proven infrastructure built for large-scale Matter manufacturing to also power global deployment of Google Cast devices.

Regardless of the trust model you choose, OBIS provides a unified platform for CA lifecycle management, device certificate issuance, and secure factory provisioning.

From manufacturing to worldwide deployment, and from certificate issuance to OTA updates, OBIS provides device identity management and secure provisioning capabilities across the entire device lifecycle.
Discuss your certificate provisioning workflow, factory architecture, device authentication model, and operational requirements with the OBIS engineering team.