FOXMAN-UN R18 : FOXMAN-UN Cybersecurity Deployment Guideline : Product Related Details : Verify Authenticity of Obtained SW Distribution
Hitachi Energy
Verify Authenticity of Obtained SW Distribution
During Product life cycle, you may update/upgrade SW, respectively, of the devices or the Product. The distribution means of such code may vary over time. To verify the authenticity of the obtained code two methods exist, depending on the type of SW:
The code is signed with an Hitachi Energy-certificate that is based on a trusted certificate of a Certification Authority (CA), currently DigiCert. The Product software is normally distributed using this method.
In case the code is not signed due to technical restrictions the authenticity can be verified by an associated hash-value. Before loading a new software, the user can generate a SHA-256 hash and cross-check it against the values published on the Hitachi Energy website.