Honestly, that never happens.
We had built some devices that did encrypt they local stores and used keys burned into separate silicon (really, keys derived from multistep mutual authentication with that silicon), but the attack model was that attacker would not possess both parts of device at once (as the key-containing part was able to be located in different part of the building from rest of the device, was reasonably tamper-proof and detected movement).