I don't use auto-provisioning, so I may not be the best one to advise on this...but, the auto-provisioning feature seem to cover the basics, on devices. in other words, if you are trying to do something out of the ordinary, then you may have to improvise, manually.
In your case, once the device has been provisioned, you can keep the Patton internal settings and simply tell it to not re-provision. You will probably have to go into the Patton and change the trunk parameters User/Password, for the second trunk, given that it will now use a new trunk number. In 3CX make note of the Patton trunk settings and using that information, delete it and manually create two trunks. The first will look pretty much the same as the one you just deleted but only have one member, and use the first port of the device. The second can be the next trunk number (in sequence, unless that number is already used), using the next port number.
As an example, you'd have trunk 10006, port 5060 and trunk 10007, port 5061, same IP address but different credentials for registering.
Be sure that 3CX knows that each trunk group can handle only one call or a second attempt on a busy trunk one may go out on trunk two. there might be some setting in the Patton that are required to also prevent that.
As I say, there is probably someone much more familiar with this particular device, that can offer more compete information.