Technology · Security

Firmware you can trust: how we protect our inverters against tampering

An inverter runs in the field for years and receives many firmware updates during that time. Every one of them is a potential point of attack. We have developed a security concept that makes sure our inverters only execute firmware that verifiably comes from us – and that nobody can read or alter it on the way. From 2027 it is included in all Persystems inverters.

At a glance

Applies toall Persystems inverters
Statusimplementation under way, included in every inverter from 2027
SignatureECDSA P-256 / SHA-256, verified in the device
EncryptionAES-128, a separate key per image
Rollback protectionolder security versions are rejected
Keysin hardware security modules, separated per customer and country – on request per series and end customer
Regulationaligned with the EU Cyber Resilience Act

Published September 30, 2026 · updated October 2, 2026 · Persystems GmbH, Regensburg, Germany

Why firmware security matters now

Inverters are no longer isolated devices. They sit in drives and systems that are operated, maintained and updated for years. Whoever controls the firmware of an inverter controls the device.

With the EU Cyber Resilience Act (CRA), legislators are therefore placing new requirements on products with digital elements: the integrity of the software must be protected, updates must be installable securely over the entire product lifetime, and manufacturers must handle vulnerabilities systematically.

Our customers are already asking about this, and they are right: anyone planning a system that will still be running in 2040 has to settle the security question now. That is why we developed a security concept for our inverters that addresses exactly these requirements. It covers the whole family, from the 48 V inverter INV-60V-120A and the GaN inverter INV-120V-40A to the INV-25V-100A currently in development. Implementation is under way, and from 2027 the concept is included in all our inverters.

What the concept delivers

Only genuine firmware is executed. Every firmware image is signed with a cryptographic method (ECDSA with curve P-256, SHA-256). The inverter verifies the signature before every activation. An image that has been altered or does not come from us is rejected. In that case the existing firmware remains active and unchanged.

Firmware cannot be read in transit. Every image is encrypted with AES, with a separate key for each update. Anyone who gets hold of an update file can neither read nor analyze the code.

No way back to vulnerable versions. Every image carries a security version. The inverter remembers the highest installed version and rejects older images, even if their signature is valid. An attacker therefore cannot reinstall an old update with a known vulnerability.

Keys separated per customer and country. We do not use one key for all devices. Every customer and every country forms its own device group with its own keys. Should a key ever be compromised, only the devices of that group are affected. All others remain untouched. And because every group is bound to an offline root key through a signed certificate chain, a group key can be replaced at any time without touching a single device. The same applies to your products: on request your series gets a signature of its own, and if you supply your own customers, each of them can in turn receive a separate signature – firmware released for one will not run on the devices of another.

Keys never leave the hardware. All private keys are generated and used in hardware security modules. They cannot be exported, copied or read out, not even by us. The root key is kept offline in a safe and is only used in a documented, witnessed ceremony. Every signature is logged tamper-evidently in the module. So we can prove at any time which update was released when and with which key.

Updates without risk. A new image is first loaded into a separate memory area and fully verified before it is activated. A power failure during the update never leaves a device without valid firmware.

Security starts in production

A security concept is only as good as its weakest link, and that is often manufacturing. That is why at Persystems all programming, key injection and locking of the controller take place exclusively in-house at an access-restricted workstation. Suppliers and manufacturing partners see neither software nor keys. A device can only be provisioned with an order package of a fixed quantity, so overproduction or device clones are ruled out.

Every provisioned device is recorded in a device register with serial number, group, date and test report. On request, customers receive the list of their devices and can check every device themselves over the CAN interface: serial number, group, lock state and versions can be read out without revealing any secret. A device that is not in the register did not come from our production.

Built for the next controller generation

We designed the concept to work independently of the microcontroller in use – and therefore for all our inverters, whatever their voltage and power class. The update format, the key hierarchy, the signing infrastructure and the production processes stay the same when we move to the next controller generation with an integrated hardware security module and secure boot. For our customers this means: a device shipped in 2027 and a device shipped three years later belong to the same security architecture and are supported with the same tools and processes.

The concept at a glance

FeatureImplementation
SignatureECDSA P-256 with SHA-256, verified in the device before every activation
EncryptionAES-128, a separate key for every firmware image
Rollback protectionsecurity version in the image, older versions are rejected
Key separationseparate keys per customer and country – on request a separate signature per series and per end customer; centrally revocable
Key managementhardware security modules, root key offline, tamper-evident log
Update safetystaging area, verification before activation, safe against power loss
Productionprovisioning exclusively at Persystems, complete device register
Proofstatus query over CAN: serial number, group, lock state, versions
Regulationaligned with the EU Cyber Resilience Act (Regulation (EU) 2024/2847)
Future-proofcontroller-independent architecture, prepared for hardware secure boot
Productsall Persystems inverters, included in every inverter from 2027

What we explicitly do not promise

There is no absolute security, and anyone who promises it has not understood the problem. Our concept therefore states explicitly what it protects against and where its limits are. We disclose this openly to our customers so that every release decision is based on complete information. This transparency is exactly what the Cyber Resilience Act demands from manufacturers.

Frequently asked questions

Which inverters does the concept cover?

All of them. The security concept is designed for the entire Persystems inverter family, from the INV-60V-120A and the GaN inverter INV-120V-40A to the INV-25V-100A. From 2027 it is included in all our inverters.

What happens if an update image was altered in transit?

The inverter verifies the signature before every activation. An altered or foreign image is rejected and the existing firmware remains active and unchanged.

Can I install an older firmware image?

Not if its security version is lower than the highest one already installed – not even with a valid signature. This way no version with a known vulnerability can be brought back.

How do I know a device comes from your production?

Every provisioned device is listed in our device register with serial number, group, date and test report. On request you receive the list of your devices and can query serial number, group, lock state and versions over CAN directly on the device.

Can my series get a signature of its own?

Yes, on request. Your devices then form a group of their own with its own key, and firmware for your series is released only with that key. If you supply your own customers, this can be split further: each of your customers can in turn get a separate signature.

Are your inverters prepared for the Cyber Resilience Act?

The concept is aligned with the requirements of the EU Cyber Resilience Act and is being implemented now; from 2027 it is included in all our inverters. We disclose to our customers what it covers and where its limits are – talk to us.

Contact

Firmware security for your project?

Are you planning a system where firmware security matters, or is your purchasing department already asking about the CRA readiness of your suppliers? We are happy to present our security concept in detail.

Persystems

Echtzeit-Simulation und Leistungselektronik für elektrische Antriebe – entwickelt und gefertigt in Regensburg.

Persystems GmbH
Franz-Mayer-Straße 1 · 93053 Regensburg
info@persystems.org · +49 941 462 974 40

© 2026 Persystems GmbHPLECS, LTspice, Simulink, CarMaker und DroneCAN sind Marken ihrer jeweiligen Inhaber.
Persystems

Real-time simulation and power electronics for electric drives – developed and manufactured in Regensburg, Germany.

Persystems GmbH
Franz-Mayer-Straße 1 · 93053 Regensburg · Germany
info@persystems.org · +49 941 462 974 40

© 2026 Persystems GmbHPLECS, LTspice, Simulink, CarMaker and DroneCAN are trademarks of their respective owners.