The network key is registered and held by the Service Center, which hands it to base stations as devices attach. If application-layer encryption is used, the separate application key goes only to the Application Center, never to the network operator, and the guideline recommends running the two provisioning processes independently so there is no correlation between them. For getting a key onto the device in the first place, the security guideline documents three approaches used in practice: printed keys, where the manufacturer prints the key as a barcode or QR code on the device and it is scanned in during commissioning, a central key server, where the manufacturer uploads the key indexed by device ID and the operator retrieves it on demand, and local key generation, where the device or a manufacturer-provided tool generates the key itself on premises so no third party, including the manufacturer, ever holds it. Each has a real trade off between usability and how many parties ever see the key, and which of the three a specific product supports depends on that manufacturer, not on the mioty standard itself.

