Or used.
sk_identity is static over the lifetime of the device, so doesn't need new entropy.
sk_device is generated after pk_user is recieved, so can use HASH(sk_identity,pk_user) as entropy. This results in the same pk_device for every session with a given pk_user, which theoretically enables traffic analysis, but the security model implies traffic analysis is out-of-scope.
signature and enc_sig might need entropy as well, but can still use HASH(sk_identity,pk_user).