Securing firmware updates
Depending on the industry, only authorized firmware from the manufacturer, supplier, or enterprise should be flashed onto the device. To ensure this takes place, a robust update mechanism must be used upon download, of firmware and when applicable, for updating functions pertaining to third-party software or libraries. A cryptographic signature should be used for all firmware to allow for verification that files have not been modified or otherwise tampered with since the developer created and signed them. The signing and verification process uses public-key cryptography and it is difficult to forge a digital signature (for example, a PGP signature) without first gaining access to the private key. When using public-key ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access