Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT security engineering

Signed update

Also known as: Signed firmware, Signed software package

German: Signierte Aktualisierung

In product security, a signed update is a software, firmware or configuration package that carries the manufacturer's digital signature, allowing the device or installer to verify its origin and integrity before installation and to reject packages that have been altered or come from an unauthorized source.

  • Security engineering
  • OT security

In one sentence

A signed update carries the manufacturer's digital signature so the device can verify origin and integrity before installing it.

Example

The I/O module accepts the new firmware only after verifying its signature with the manufacturer's public key stored in the device; a tampered file is rejected with a diagnostic message.

How it applies

  • Product development: The signature is created with a private key protected by the manufacturer and verified with a public key or certificate trusted by the device. Key management, including rotation and revocation, must be planned for the full product lifetime.
  • Operation: Verification is strongest when the device itself checks the signature. Where devices cannot, the engineering tool or the technician should verify the signature or published hash before installation.
  • Maintenance: A valid signature proves origin and integrity, not suitability. Signed updates still need compatibility checks, tests and change control before installation in production.
  • Documentation: Update instructions should explain how the signature is checked, what error appears if verification fails and what the user should do then. Do not tell users to bypass signature checks as a troubleshooting step.

Signed update vs. secure boot

A signed update is verified at installation. Secure boot verifies software at every start, which also catches manipulation that happens after installation. Many devices use both.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on IEC 62443-4-2 and embedded security practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!