Formation Embedded Security for STM32-based devices | Ac6 Formation

ac6-formation, un département d'Ac6 SAS
FR
FrançaisEnglish
 
go-up

ac6 ac6-formation Programmation Safety and security Embedded Security for STM32-based devices
SEC5Embedded Security for STM32-based devices

Objectives

  • Understand embedded and STM32-specific security challenges, attack vectors, and threats.
  • Apply modern security standards and best practices to STM32 devices.
  • Implement secure boot and firmware protection on STM32.
  • Apply secure network protocols (TLS/SSL, LoRaWAN, Sigfox, WiFi) on STM32.
  • Follow IoT security best practices across communication layers.
  • Implement secure firmware updates and OTA management for STM32.
    • Course will be using STM32 Tools (STM32CubeIDE, STM32CubeProgrammer, …)
    • Students will be given access to a shared filesystem to save and share their work.
    • PDF course material
    • Familiarity with computer architecture
    • Programming skills: Some programming experience, particularly in C
    • Knowledge of STM32 Implementation and ARM implementations
    • Basic understanding of Security Algorithms and Secure coding
  • Cours théorique
    • Support PDF (en anglais), imprimé en présentiel ; à distance via Teams.
    • Assistance du formateur tout au long de la formation.
  • Activités pratiques (40-50% de la durée)
    • Exemples de code, exercices et solutions.
    • À distance : un PC Linux en ligne par stagiaire, avec carte émulée ou physique selon le cours.
    • Présentiel / sur site : un PC (un par binôme au-delà de 6 stagiaires), carte cible et manuel d'installation si nécessaire.
  • Machine virtuelle préconfigurée téléchargeable pour refaire les TP après le cours.
  • Chaque session débute par un point avec les stagiaires.
  • Tout ingénieur ou technicien en systèmes embarqués possédant les prérequis ci-dessus.
  • Les prérequis sont évalués avant la formation.
  • Les progrès sont évalués par le formateur via les exercices pratiques, et par des quizz pour les sections sans exercices.
  • Chaque stagiaire reçoit une attestation de réussite.
  • En cas de prérequis manquant, une formation différente ou complémentaire est proposée.

Plan du cours

  • Overview of embedded security and its importance
  • STM32 Microcontroller overview and security features
    • STM32 MCUs and capabilities
    • Security features
    • ARM TrustZone overview
  • Threads and attack vectors specific to embedded systems
    • Common attack vectors
    • Malware and exploits
    • Threat landscape for embedded systems
Exercise :  Familiarizing with STM32 Security Tools
  • Secure coding practices
    • Code reviews and audits
    • Input validation and sanitization
    • Memory management and buffer overflows
  • Static and dynamic code analysis tools
    • Using static analysis tools
    • Using dynamic analysis tools
  • Secure development lifecycle for STM32-based devices
    • Requirements gathering and threat modeling
    • Design and implementation
    • Testing and validation
    • Deployment and maintenance
Exercise :  Using static and dynamic analysis tools to find vulnerabilities in sample STM32 Code
  • Secure boot on STM32 Devices
    • Introduction to secure boot
    • Secure boot implementation
    • Secure boot verification and toubleshooting
  • Firmware protection on STM32 devices
    • Introduction to firmware protection
    • Techniques for protecting firmware on STM32 Devices
    • Implementation of firmware protection on STM32
  • Haardware assisted security on STM32 devices
    • Introduction to hardware assisted security
    • STM32’s Cortex-M security features
    • Implementation of hardware assisted security on STM32
Exercise :  Implementing secure boot on STM32 devices
  • Network Architecture for STM32-based Devices
    • Overview of network communication protocols for embedded systems
    • Secure communication protocols
    • Designing a secure network architecture for STM32-based devices
  • Transport Layer Security (TLS)
    • Introduction to TLS and SSL
    • Implementing TLS/SSL on STM32-based devices
    • Secure communication using TLS/SSL on STM32
  • WiFi security
    • Overview of WiFi security mechanisms and standards
    • Implementing secure WiFi communication on STM32
    • Best practices
  • BLE security
    • Introduction to BLE
    • Overview of BLE security Mechanisms and standards
    • Implmeneting secure BLE Communications
    • Best practices for securing BLE communication
  • LoRaWAN security
    • Introduction to LoRaWAN
    • Overview of LoRaWAN security mechanisms and standards
    • Implementing secure LoRaWAN communication on STM32-based devices
    • Best practices
  • Sigfox Security
    • Overview of Sigfox
    • Implementing secure Sigfox communication on STM32-based devices
    • Best practices
  • Introduction to IoT Security
    • Unique security challenges faced by IoT devices
    • Overview of the common attack vectors and threats faced by IoT devices
  • IoT security best practices
  • Securing IoT devices at the network layer
    • IoT-specific network security protocols
  • Access control and secure data transfer
    • Overview of authentication and authorization mechanisms for IoT devices
    • Discussion of secure data transfer protocols for IoT, such as MQTT and HTTPS
    • The role of application-level encryption in securing IoT devices
  • Implementing secure application communication
    • Secure application communication between STM32 devices and the cloud or other systems
    • implementing secure access control, such as using JSON Web Tokens (JWT) and OAuth
  • Best practices
  • Introduction to firmware update and management
    • Importance of firmware updates in maintaining the security of embedded systems
    • Overview of firmware update methods including manual and over-the-air (OTA) updates
  • Secure firmware update processes
  • OTA update mechanisms
    • Overview of OTA update mechanisms
    • Implementing OTA updates, including server-side and device-side
    • Best practices for OTA updates, including testing and deployment
Plus d'information

Pour vous enregistrer ou pour toute information supplémentaire, contactez nous par email à l'adresse info@ac6-formation.com.

Les inscriptions aux sessions de formation sont acceptées jusqu'à une semaine avant le début de la formation. Pour une inscription plus tardive nous consulter

Vous pouvez aussi remplir et nous envoyer le bulletin d'inscription

Ce cours peut être dispensé dans notre centre de formation près de Paris ou dans vos locaux, en France ou dans le monde entier.

Les sessions inter-entreprises programmées sont ouvertes dès deux inscrits. Sous condition d'un dossier complet, les inscriptions sont acceptées jusqu'à une semaine avant le début de la formation.

Dernière mise à jour du plan de cours : 20 mai 2026

L'inscription à nos formations est soumise à nos Conditions Générales de Vente