Original title:
Zabezpečení a vzdálená správa na mikrokontroleru ESP32
Translated title:
Hardening and remote management of ESP32 microcontroller
Authors:
Novota, Marek ; Mašek, Pavel (referee) ; Štůsek, Martin (advisor) Document type: Bachelor's theses
Year:
2026
Language:
slo Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[slo][eng]
Táto bakalárska práca sa zaoberá analýzou a praktickým overením bezpečnostných mechanizmov mikrokontroléra ESP32 a návrhom systému bezpečnej aktualizácie firmware. V teoretickej časti sú popísané mechanizmy Secure Boot v2, Flash Encryption a podpisovanie firmware, ako aj možnosti lokálnej a vzdialenej aktualizácie zariadenia. Pozornosť je venovaná aj OTA aktualizáciám, organizácii flash pamäte, OTA partíciám, rollback a anti-rollback mechanizmom. V praktickej časti sú uvedené bezpečnostné mechanizmy implementované a overené na mikrokontroléri ESP32. Súčasťou riešenia je webová aplikácia na správu a distribúciu firmware, ktorá umožňuje nahrávanie nových verzií, generovanie manifestu, výpočet SHA-256 hashu a poskytovanie firmware súborov zariadeniu. Aplikácia podporuje lokálnu aktualizáciu v servisnom režime cez UART a vzdialenú OTA aktualizáciu cez Wi-Fi sieť. OTA mechanizmus umožňuje automatickú distribúciu aktualizácií v prípade existencie novšej verzie firmware. Práca ďalej hodnotí dopad bezpečnostných mechanizmov na výkon zariadenia, najmä na rýchlosť čítania a zápisu do flash pamäte, vyťaženie procesora, dostupnú SRAM pamäť a čas štartu systému. Výsledky ukazujú, že bezpečnostné mechanizmy zvyšujú ochranu zariadenia za cenu mierneho obmedzenia výkonu.
This bachelor thesis deals with the analysis and practical verification of the security mechanisms of the ESP32 microcontroller and the design of a secure firmware update system. The theoretical part describes the Secure Boot v2, Flash Encryption, and firmware signing mechanisms, as well as the options for local and remote device updates. Attention is also paid to OTA updates, flash memory organization, OTA partitions, rollback, and anti-rollback mechanisms. The practical part presents the implementation and verification of these security mechanisms on the ESP32 microcontroller. The solution includes a web application for firmware management and distribution, which enables uploading new versions, generating a manifest, calculating the SHA-256 hash, and serving firmware files to the device. The application supports local updates in service mode via UART as well as remote OTA updates over a Wi-Fi network. The OTA mechanism allows for automatic distribution of updates whenever a newer version of the firmware is available. Furthermore, the thesis evaluates the impact of the security mechanisms on the device’s performance, specifically focusing on flash memory read and write speeds, CPU utilization, available SRAM, and system boot time. The results demonstrate that while the security mechanisms significantly enhance device protection, they introduce a minor trade-off in overall performance.
Keywords:
anti-rollback; eFuse; ESP-IDF; ESP32; firmware signing; Flash Encryption; Flask; FreeRTOS; manifest; microcontroller; OTA update; rollback; Secure Boot v2; SHA-256; UART; web application
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258293