How is a firmware update delivered to a remote device in a way the device can trust?
The manufacturer burns a public key into the device at production; later it signs the hash of each firmware image with the matching private key, and the device re-hashes the image it received and checks the signature before installing anything.
* The manufacturer signs the firmware hash; the device uses its provisioned public key and a freshly computed hash to verify authenticity and integrity before installation. *
The two requirements the scheme must meet are: the update comes from an authentic source, and the image was not changed on the way.
At manufacture (t₀):
- The backend generates a public/private key pair.
- The public key is burned into the device during manufacture. This is the trust anchor — it is fixed, it ships with the hardware, and it is the one thing the device does not have to receive over the network.
When an update is published:
- The backend calculates the hash value of the firmware image.
- It generates a signature over that hash using its private key.
- It sends image + hash + signature of the hash to the device.
On the device (verification phase):
- The device runs the same hash function over the image it received, producing its own hash value.
- It checks the signature on the hash using the public key already burned in.
- If the check passes, it installs the image — otherwise it refuses.
Each step earns its place. Hashing the image reduces an arbitrarily large firmware to a fixed-size fingerprint, so only a small value has to be signed and verified — which matters when the verifier is a microcontroller. Re-computing the hash locally is what detects modification in transit. And checking the signature with the burned-in public key is what proves authorship: only the holder of the private key could have produced a signature that verifies, so an attacker who tampers with the image cannot produce a matching signature without it.
Tip: note what the device never does — it never receives the key it trusts. Any scheme where the update channel also supplies the verification key is circular, and an attacker who controls the channel controls both halves.
Go deeper:
-
Wikipedia — Digital signature — why signing a hash rather than the whole image still yields both authenticity and tamper detection, and why forgery without the private key is infeasible.
-
Wikipedia — Over-the-air update — the same scheme in production, including the genuineness check before installation and the integrity check after it.
-
RFC 9019 — IoT firmware update architecture — extends signature checking to manifests, authorisation and the full update lifecycle.