Security Design for Auto-Update - Why HTTPS Alone Is Not Enough (archived 2026-09-01)
We treat auto-update as a trust boundary and walk through signed metadata, client-side verification, key separation, rollback protection, and fail-closed design from a practical standpoint. Archived version of https://comcomponent.com/en/blog/2026/04/09/000-comcomponent-autoupdate-security/, as published on 2026-09-01. The live article is maintained and may change after this date. First published 2026-04-09.
Authors
- Go Komura (ORCID: https://orcid.org/0009-0008-8895-8390)
Institutions
- Fujikura (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-01
- DOI
- https://doi.org/10.5281/zenodo.21614602
- Primary Topic
- User Authentication and Security Systems
- Type
- article
- Field-Weighted Citation Impact
- 0.00