UM2262 Rev 6 15/94
UM2262 Secure Boot and Secure Firmware Update (SBSFU)
93
Figure 1. Secure Boot Root of Trust
3.3 Secure Firmware Update
Secure Firmware Update (SFU) provides a secure implementation of in-field firmware
updates, enabling the download of new firmware images to a device in a secure way.
As shown in Figure 2, two entities are typically involved in a firmware update process:
• Server
– OEM manufacturer server / web service
– Stores the new version of device firmware
– Communicates with the device and sends the new image version in an encrypted
form if it is available
• Device
– Deployed in the field
– Embeds a code running firmware update process.
– Communicates with the server and receives a new firmware image.
– Authenticates, decrypts and installs the new firmware image and executes it.
Figure 2. Typical in-field device update scenario