It means generating a signature of the binaries being installed, and having this signature be authenticated by Microsoft (using their signing key).

The signature is distributed alongside the binaries.

I'm not certain if the Windows Update system uses the same Autheticode system used for application binaries, but you can start reading here:


