Encrypt profile with public key

Hello,


I tried to encrypted the profile and I know it should be encrypted by Public key.

But I don't know what kind of public key would be used.

So I searched and found about "Over-The-Air and SCEP payload"


But I don't understand what it means

"Encrypted configuration profiles are signed with the public key associated with a device’s identity certificate."


What is "Device's identity certificate"?

Also I got Challenge key from device.


Please help

and Thank you in advance