Glossary · OT security engineering
Signed update
Also known as: Signed firmware, Signed software package
German: Signierte Aktualisierung
In product security, a signed update is a software, firmware or configuration package that carries the manufacturer's digital signature, allowing the device or installer to verify its origin and integrity before installation and to reject packages that have been altered or come from an unauthorized source.
- Security engineering
- OT security
In one sentence
A signed update carries the manufacturer's digital signature so the device can verify origin and integrity before installing it.
Example
The I/O module accepts the new firmware only after verifying its signature with the manufacturer's public key stored in the device; a tampered file is rejected with a diagnostic message.
How it applies
- Product development: The signature is created with a private key protected by the manufacturer and verified with a public key or certificate trusted by the device. Key management, including rotation and revocation, must be planned for the full product lifetime.
- Operation: Verification is strongest when the device itself checks the signature. Where devices cannot, the engineering tool or the technician should verify the signature or published hash before installation.
- Maintenance: A valid signature proves origin and integrity, not suitability. Signed updates still need compatibility checks, tests and change control before installation in production.
- Documentation: Update instructions should explain how the signature is checked, what error appears if verification fails and what the user should do then. Do not tell users to bypass signature checks as a troubleshooting step.
Signed update vs. secure boot
A signed update is verified at installation. Secure boot verifies software at every start, which also catches manipulation that happens after installation. Many devices use both.