Hello,
There is no secure mechanism for flashing, I think that it is not needed nor see any use case for this, the best usage would be secure boot that would make it that even if an image is flashed if it is not signed then it won't boot.
Also, regarding your second question if the device went under serial downloader then there is no uboot, meaning no fastboot protocol, just disable fastboot from uboot, and everytime you need to flash a new image, the Uboot image that will be run using UUU needs to have fastboot enabled.
For third question, yes you are correct the image won't be authenticated unless it is closed, as specified above secure boot enabled.
Best regards/Saludos,
Aldo.