Skip to content

About

Secure SPI-based bootloader for STM32 featuring AES-128 CTR encrypted firmware updates, CRC32 verification, and reliable packet transfer via ESP32.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

SecureBoot-SPI

Table of Contents

About the Project

Aim

To develop a secure bootloader for STM32 that enables reliable, encrypted firmware updates over SPI using an ESP32 as the firmware host.

Description

SecureBoot-SPI is a custom secure firmware update framework that uses an ESP32 to host and transmit firmware images to an STM32 over SPI. It implements a custom packet-based communication protocol with ACK/NACK flow control and CRC32 integrity verification to ensure reliable data transfer. Firmware packets are encrypted using a self-implemented AES-128 CTR mode before transmission and decrypted on the STM32 prior to flash programming. Upon successful verification and programming, the bootloader automatically transfers execution to the updated application.

Tech Stack

C ESP-IDF STM32 HAL ESP32 STM32 SPI SPIFFS AES-128 AES-CTR CRC32

Firmware Update Workflow

        Web Browser
             │
             ▼
     Upload Firmware (.bin)
             │
             ▼
     ESP32 Firmware Host
             │
             ▼
     Read Firmware Packet
             │
             ▼
   Calculate CRC32 (Plaintext)
             │
             ▼
     AES-128 CTR Encryption
             │
             ▼
     SPI Packet Transfer
             │
             ▼
      STM32 Bootloader
             │
             ▼
     AES-128 CTR Decryption
             │
             ▼
   Calculate CRC32 (Plaintext)
             │
             ▼
      CRC Verification
             │
      ┌──────┴──────┐
      │             │
    PASS          FAIL
      │             │
      ▼             ▼
 Flash Packet    Send NACK
      │
      ▼
 Receive CMD_END
      │
      ▼
 Jump to Application

About

Secure SPI-based bootloader for STM32 featuring AES-128 CTR encrypted firmware updates, CRC32 verification, and reliable packet transfer via ESP32.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages