Glossary · OT security engineering
Secure firmware update
Also known as: Secure firmware upgrade
German: Sichere Firmwareaktualisierung
In embedded security, a secure firmware update is the process of installing new firmware on a device such that only authentic, unaltered and authorized firmware is accepted, typically by verifying a digital signature, protecting against downgrades to vulnerable versions and preserving a working state if the update fails.
- Security engineering
- OT security
In one sentence
A secure firmware update installs only authentic, unaltered, authorized firmware, with signature checks, downgrade protection and failure recovery.
Example
A safety relay module checks the signature of the new firmware, refuses an older version with a known vulnerability and falls back to the previous image when the transfer is interrupted.
How it applies
- Product development: Typical mechanisms are signed images, verification before activation, anti-rollback counters that block downgrades to vulnerable versions, dual image banks for recovery and authorization checks for who may start the update.
- Operation: Firmware updates on controllers usually require a stop. Plan them with production, and check whether the update affects certified or validated functions.
- Safety: For safety-related devices, the manufacturer should state whether an update changes safety functions or their parameters and what verification the user must perform afterward. Changes may need to go through change control and revalidation.
- Documentation: Update instructions must include prerequisites (versions, tools, backups), the verification of the result, behavior on failure and whether the update can be reversed. Release notes should list security fixes with CVE IDs.
Secure firmware update vs. rollback
Downgrade protection prevents installing an older, vulnerable version. Rollback capability restores the previous version after a failed or faulty update. Designs must allow safe rollback without reopening known vulnerabilities.