Hello Songge,
The fuses are providing by NXP at moment of sale. ROM keys are provisioned by NXP in the secure Fuse Box before delivery to customer, i.e., before the life cycle CUST_DEL. These ROM keys act as the root of trust of the silicon.
MRK (Master Root Key) and UID are device-specific.
For end user, usage of MRK is transparent, for example, when installing and updating the Blue-image or SYS_IMG. HSE offers specific security services to do that, and user just call for services to finish that.
Regards