MSC C6B-SLH
MSC C6B-SLH User Manual
124 / 144
6.20
Trusted Update
General Information
The Trusted Update feature is a combination of bios-based features and external tools which provides security for the bios update process. The aim
is to secure the bios against attacks that try to change the bios flash content, while still allowing trusted parties to update the bios.
The following items are part of Trusted Update:
Flash write-protection
The bios will write-protect its own flash to prevent malicious applications from changing the bios code. This write-protection can only be disabled by a
global reset, so flash writes can only be done by the bios code itself.
Hash-based checksum checks for bios images
Bios images include a hash-based checksum to safeguard against file and/or memory corruption. This hash will be checked before programming a
new bios.
Bios update security with cryptographic signatures
As an optional enhancement, customers can patch a bios with their own public key. If a bios includes a public key for trusted updates, the bios will
only accept bios update images signed with the corresponding private key.