Google Cast Devices,
Beyond Certificate Injection

OBIS™ OnBoard IoT Security delivers a trusted operational chain that unifies Google Cast certificate management, secure device provisioning, and lifecycle credential operations — enabling OEMs to maintain their own CA infrastructure or seamlessly adopt OBIS-managed security services.

Google Cast security compliance with end-to-end certificate lifecycle protection
Unified credential management across Google Cast, Matter, and connected devices
Secure delegation of issuance authority to global factories with policy-based controls, expiration management, and instant revocation
Offline provisioning execution after authorization, without requiring continuous connectivity
50+
Industry Certification Standards (Including Google Cast & Matter)
13  Years
Device Identity & PKI Expertise
Worldwide
Secure Factory, ODM & EMS Provisioning Coverage

Cast certificate, plus everything else the device needs

Devices with Chromecast built-in typically require multiple credentials — Cast certificates, OEM identities, Matter DACs, and OTA credentials — each governed across separate operational workflows. OBIS governs them through one provisioning workflow and one operational trust chain.

Identity

Google Cast Device Certificates & Model CA Trust Chain

Independent Google Cast certificate issuance and secure provisioning. Private keys are generated and retained within secure hardware, establishing trusted device identities from manufacturing onward.
Interoperability

OEM Device Identity Credentials

OEM certificates and Google Cast certificates are provisioned through a unified workflow and securely linked with device and production data, enabling complete identity traceability.
Ecosystem

Matter DAC

Matter and Google Cast certificates are provisioned at the same workstation through a unified process, enabling seamless onboarding across both Google Cast and Matter ecosystems.
Firmware Security

OTA Update Trust Framework

OTA update credentials and device identity credentials are provisioned together, providing a trusted foundation for secure long-term firmware updates.

The trust chain behind every Cast device

Google operates the Cast root, while each device carries a unique device certificate. Between them sit the OEM CA and Model CA layers, which establish operational trust across the provisioning workflow. OBIS governs Model CA operations and device certificate issuance, while OEMs retain flexibility over the OEM CA trust model.

Layer 1 · Google Trust Root
Google Cast Root CA · Cast Root Certificate Authority
The root trust anchor of the Google Cast ecosystem, managed and controlled by Google.
Layer 2 · OEM Trust Domain
OEM CA · OEM Certificate Authority
The organizational-level trust domain representing the OEM. It can be independently managed by the OEM or operated through OBIS-managed infrastructure.
Layer 3 · OBIS Governance & Operations
Model CA · Product Model Certificate Authority
An intermediate certificate authority dedicated to each product model. Operated and governed by OBIS to ensure secure, controlled, and auditable certificate issuance.
Layer 4 · Secure Factory Provisioning
Device Certificate · Device Identity Credential
A unique identity credential issued for each individual device. Provisioned into the device’s secure environment through controlled manufacturing workflows and used for identity authentication when connecting to the Google Cast ecosystem.

Google Cast + Matter certificate provisioning through a unified secure manufacturing workflow

The Google Cast trust ecosystem is rooted in Google’s certificate infrastructure, while Matter device identity is built on the CSA certificate framework.

OBIS unifies HSM infrastructure, certificate management platforms, and secure provisioning workflows to enable Google Cast and Matter certificate injection on the same production line — allowing the proven infrastructure built for large-scale Matter manufacturing to also power global deployment of Google Cast devices.

Smart TVs
Streaming Players
TV Sticks
Smart Speakers
Smart Displays
Soundbars
Projectors
Smart Gateways

Use your own CA or leverage Snowball’s managed CA

Regardless of the trust model you choose, OBIS provides a unified platform for CA lifecycle management, device certificate issuance, and secure factory provisioning.

Option A

Use Snowball's CA

Fast-track your Google Cast deployment
Leverage Snowball’s managed CA infrastructure as your trust foundation. Snowball operates the CA hierarchy, certificate issuance, and PKI workflows — enabling Google Cast-compliant products without requiring dedicated HSM infrastructure or in-house PKI expertise.
Option B

Use Your Own Root CA / OEM CA

Keep control of your trust foundation
For OEMs that already operate their own Root CA or OEM CA, Snowball manages the Model CA layer and device certificate operations while you retain ownership of your trust anchor — extending PKI operational capabilities without changing your existing trust architecture.

Built for the global deployment of Google Cast devices

From manufacturing to worldwide deployment, and from certificate issuance to OTA updates, OBIS provides device identity management and secure provisioning capabilities across the entire device lifecycle.

Google Cast Device Brands
ODM, OEM & EMS Manufacturers
Chromecast Built-in Smart Home Providers
TV, Audio & Display Solution Providers
Device Identity & Certificate Management Teams
Google Cast + Matter Ecosystem Companies

Built for governed Google Cast provisioning and lifecycle operations at scale

Discuss your certificate provisioning workflow, factory architecture, device authentication model, and operational requirements with the OBIS engineering team.