
INTELLIGENT NMC USER MANUAL
77
Secure Boot Protection
•
The product uses industry standard code signature algorithms to protect firmware
booted by the device.
•
A signature block is appended to the bootloader.
•
The signature block contains a signature of the bootloader and the RSA 3072-bit
public key.
•
A digest of the RSA 3072-bit public key is stored in a write-once eFuse (which
cannot be read or written to after being set) and used to verify the signature
block.
•
The public key signature is verified against the signature block and a digest of
the bootloader to establish authenticity and integrity of the bootloader.
•
The bootloader continues the chain of trust by verifying the authenticity and
integrity of the application executable, by applying the same algorithm as used by
the ROM bootloader to load the bootloader.
Firmware Update Protection
•
The product uses industry standard cryptography to verify a firmware update
package, to establish authenticity and integrity.
•
The package contains a manifest describes items contained in the package
payload.
•
The items are described as a chunk size and a SHA256 hash of each sub-item
and the payload container in the package.
•
The manifest is hashed using SHA256 and signed using an RSA 4096 bit key.
•
The package contains the signature of the hash of the manifest.
•
The package contains a payload container holding the sub-items.
•
The signature of the payload is verified before parsing the content of the manifest
or the payload.
Other Features
•
The product includes a real-time clock and a capacitor that maintains time for a
short amount of time when no power is applied. When combined with NTP,
accurate timestamps on logs are provided.
Secure deployment
To maintain the highest level of security from, Panduit recommends the user configures