2.9 Confirm Device Code Signing and Validation

2.9 Confirm Device Code Signing and Validation

Requirement Description:

Verify that the device uses code signing and validates firmware upgrade files before installation.


DUT Confirmation Details:

(To be filled by vendor or evaluator after collecting confirmation of implemented signing mechanisms)


DUT Software Details:

(Include OS version, firmware version, build number, etc.)


Hash Checksum Verification for DUT’s Software Image:

(Add SHA-256 or similar cryptographic hash of the current running image)


DUT Configuration:

(Include update method—OTA/local USB update, signing algorithm, root-of-trust key source, etc.)


Pre-Conditions:

The vendor shall provide the following:

  • Documentation of the secure firmware upgrade process.

  • Details of cryptographic keys used and their management life cycle (e.g., generation, rotation, destruction).

  • Explanation of the signature validation process before firmware installation.

  • Information on any secure boot or hardware root-of-trust mechanisms used.


Test Plan:

Total Number of Test Cases: 2


Test-bed Diagram with Interfaces and IPs:

(To be provided as a labeled diagram, including management interface, update path, and connectivity to signing server/USB/network.)

Last updated

Was this helpful?