====== encryption ====== https://yairgadelov.me/swupdate-build-sign-install-a-minimal-.swu-that-updates-only-an-app--config/ ===== signing ===== * ''sw-description'' with image hashes is signed. New file ''sw-description.sig'' is added to container. * public key is on device (swupdate can verify ''sw-description.sig''). * private key is used only internally during build of .swu bundle ===== secure storage of keys ===== SWUpdate can use PKCS provider.