The public keys are provided by the developer. Google, or Apple, for example. It's how they know that nothing was tampered with before it left the factory.
Nothing has been tampered with doesn't mean there's no factory backdoor, it just only means same as factory, nothing more.
Nothing has been tampered with doesn't mean there's no factory backdoor, it just only means same as factory, nothing more.