There are ways to do this, unfortunately the software is illegal in the United States.
This is exactly the way that Microsoft does it, ie. with digital authentication.
I never trusted the software update program so I have mine set to manual and never use it. I direct download from Apple. Of course some hacker could spoof the main apple.com but there is a much smaller chance of that happening.
Regardless apple should of used digital authentication from the beginning like Microsoft.
This could reek havoc on a local LAN. Mac world is coming up and like always, every one is going to be checking for updates during the show.