RF Wireless World

Browse articles, tutorials, tools, and vendors.

Matter DAC Vs PAI vs PAA : Certificate Differences

By RF Wireless Expert Team

Based on the Matter 1.6.1 Core Specification, the security model relies heavily on a Public Key Infrastructure (PKI) to ensure that every device joining a smart home is genuine, certified and safe. This is called the Device Attestation procedure.

To achieve this, Matter uses a strict three tier certificate hierarchy. Rather than relying on a single certificate, the protocol uses a chain of trust consisting of three distinct certificates: the PAA, the PAI and the DAC. Let us understand differences between them.

The Analogy: The Passport System

Before diving into the technical specifications, it helps to think of this three tier system like a government issuing passports:

  • PAA (like the Federal Government): The ultimate, universally trusted root authority.
  • PAI (like the Regional Passport Office): An authorized branch dedicated to a specific region or manufacturer.
  • DAC (like your Physical Passport): The unique, individual document assigned to one specific person (or device) that proves who they are.

1. PAA: Product Attestation Authority (The Root)

The PAA is the root certificate at the very top of the trust chain.

  • Its Role: It acts as the ultimate anchor of trust. It is a “self signed” certificate, meaning its authenticity is inherently trusted by the system.
  • Where it Lives: The PAA certificate is not stored on your smart home device. Instead, a list of globally trusted PAAs is maintained in the Distributed Compliance Ledger (DCL); a secure, blockchain backed database managed by the Connectivity Standards Alliance (CSA). Your smartphone (the Commissioner) checks this ledger to verify the PAA.
  • What it Contains: According to the specification, the PAA is highly restricted. It can optionally include a Vendor ID (identifying a specific manufacturer), but it must never contain a Product ID. This ensures the root authority remains broad and top level.
  • What it Does: The PAA’s only job is to cryptographically sign and authorize the intermediate certificate (the PAI).

2. PAI: Product Attestation Intermediate (The Middleman)

The PAI is the intermediate certificate sitting between the root authority and the physical device.

  • Its Role: It acts as a delegated signing authority. By using a PAI, manufacturers do not have to keep their highly sensitive PAA root keys online at the factory. Instead, they keep the PAA safely locked away and use the PAI to sign the certificates for devices rolling off the assembly line.
  • Where it Lives: The PAI certificate is typically sent by the smart home device to the Commissioner (your phone) during the setup process, alongside the DAC.
  • What it Contains: The PAI must contain a Vendor ID (VID) tying it to a specific manufacturer. It may optionally contain a Product ID (PID) if the manufacturer wants to restrict that specific PAI to only issue certificates for a single product line (like a specific model of smart bulb).
  • What it Does: The PAI proves that the manufacturer authorized the creation of the final leaf certificate (the DAC).

3. DAC: Device Attestation Certificate (The Leaf)

The DAC is the leaf certificate injected directly into the silicon of the device itself.

  • Its Role: This is the device’s unique cryptographic identity. No two devices; even two identical smart bulbs from the same box will share the same DAC and associated private key.
  • Where it Lives: It is permanently flashed into the device’s secure hardware during manufacturing. The private key associated with the DAC is heavily protected and is designed so that it can never be extracted or exported from the device.
  • What it Contains: The DAC must contain both the Vendor ID (VID) and the Product ID (PID). This tells the Commissioner exactly who made the device and exactly what model it is. It also has a serial number and a validity period (which is usually set to never expire).
  • What it Does: During setup, the device uses the private key tied to its DAC to digitally sign a random challenge sent by your phone. Your phone uses the DAC to verify that signature, proving the hardware is genuine.

How They Work Together

When you plug in a new Matter device and scan its QR code, the device hands your phone its DAC and its PAI.

  1. Your phone looks at the DAC and says, “This DAC claims to belong to a genuine ACME Smart Plug.”
  2. Your phone then looks at the PAI and says, “The DAC was signed by this ACME Factory PAI, so the DAC is mathematically valid.”
  3. Finally, your phone checks the PAA by looking it up in the globally trusted Distributed Compliance Ledger. It says, “The ACME Factory PAI was signed by the ACME Root PAA, and the CSA confirms that this Root PAA is fully certified and trustworthy.”

Conclusion

Because the chain is unbroken from DAC to PAI to PAA; the smartphone knows with absolute cryptographic certainty that the device is not a counterfeit, hasn’t been tampered with, and is safe to bring onto your Smart home network.

Continue Learning Matter Protocol

Compare Matter With Other Technologies

Keep Reading