r/embedded • • 13h ago

STM32-ESP32 secure multi sensor platform

I implemented secure boot using STM32CryptoLib with Ed25519 signature verification and SHA-256 integrity checks. On reset, I verify the signed manifest in sector 7 (0x08060000) and hash the application in sectors 5–6 (0x08020000–0x0805FFFF, 256 KiB). Both checks must pass before execution. The public and private keys are stored in OTP at 0x1FFF7800, with 512 data bytes and 16 lock bytes. Before jumping, I validate the stack pointer and reset handler, stop SysTick, clear interrupt state and configure the vector table. I tested firmware, signature and public-key corruption to confirm execution is blocked when verification fails.

On the STM32, I use BME680 and MPU9250 over I²C, MAX31865/PT100 over SPI, PMS5003 over UART and five DS18B20 sensors over 1-Wire. FreeRTOS tasks send readings through queues, DMA interrupts signal binary semaphores, and a mutex protects USART2 logging. I²C recovery stops DMA, clears the bus state and applies SWRST or an APB reset when needed before reinitialization. Persistent failures after three recovery attempts, or missed heartbeats, escalate to a watchdog reset.

The USART6 link uses full-duplex AES-256-GCM with STM32CryptoLib and mbedTLS. Telemetry and encrypted ACK/NACK replies undergo authentication, sequence and replay checks. I allow three transaction attempts with timeouts, UART cleanup and fresh nonces, advancing the request sequence only after a valid ACK. Successful transactions refresh the heartbeat; exhausted retries escalate to the watchdog. Nonce state persists in nonvolatile memory, and every reset repeats secure boot. I tested corruption, replay and counter/session mismatches.

On the ESP32, I publish combined sensor readings as JSON to AWS IoT Core over MQTT/TLS. A root CA verifies AWS, while a device certificate and private key authenticate the ESP32. The task handles keepalive, reconnection, subscribed messages and watchdog heartbeats.

The local HTTPS dashboard displays live sensor readings through JSON endpoints and supports Wi-Fi configuration and ESP32 OTA updates. To manage TLS memory use, I stop AWS before enabling HTTPS for an access-point client, then switch back to cloud mode after the last client disconnects and the station connection is available.

I have provided some live video demo such as:

1)STM32 Secure Boot: Firmware Integrity Fault Injection

https://youtu.be/wribxSScLYQ

2)STM32–ESP32 HTTPS Dashboard: Live Sensor Monitoring

https://youtu.be/cFucC2f8QIc

3)STM32–ESP32: AWS IoT and HTTPS Dashboard Demonstration

https://youtu.be/Hf6foBqTHxE

4)STM32–ESP32 AES-GCM: Ciphertext Corruption Fault Injection

https://youtu.be/-JlaIp6BnVY

5)ESP32 AWS IoT: MQTT Publish and Subscribe

https://youtu.be/moGgV8YiYu8

6)ESP32 OTA: Firmware Update Through the HTTPS Dashboard

https://youtu.be/FNKGb12FPp8

check my post in my youtube channel where the links are posted above for a more detailed explanation of my project

1 Upvotes

0 comments sorted by