Přístupnostní navigace
E-application
Search Search Close
Bachelor's Thesis
Author of thesis: Bc. Marek Novota
Acad. year: 2025/2026
Supervisor: Ing. Martin Štůsek, Ph.D.
Reviewer: doc. Ing. Pavel Mašek, Ph.D.
This bachelor thesis deals with the analysis and practical verification of the security mechanisms of the ESP32 microcontroller and the design of a secure firmware update system. The theoretical part describes the Secure Boot v2, Flash Encryption, and firmware signing mechanisms, as well as the options for local and remote device updates. Attention is also paid to OTA updates, flash memory organization, OTA partitions, rollback, and anti-rollback mechanisms. The practical part presents the implementation and verification of these security mechanisms on the ESP32 microcontroller. The solution includes a web application for firmware management and distribution, which enables uploading new versions, generating a manifest, calculating the SHA-256 hash, and serving firmware files to the device. The application supports local updates in service mode via UART as well as remote OTA updates over a Wi-Fi network. The OTA mechanism allows for automatic distribution of updates whenever a newer version of the firmware is available. Furthermore, the thesis evaluates the impact of the security mechanisms on the device’s performance, specifically focusing on flash memory read and write speeds, CPU utilization, available SRAM, and system boot time. The results demonstrate that while the security mechanisms significantly enhance device protection, they introduce a minor trade-off in overall performance.
ESP32, microcontroller, ESP-IDF, Secure Boot v2, Flash Encryption, firmware signing, OTA update, UART, web application, Flask, manifest, SHA-256, rollback, anti-rollback, eFuse, FreeRTOS
Date of defence
16.06.2026
Result of the defence
Defended (thesis was successfully defended)
Grading
B
Process of defence
Otázky oponenta: Jakým způsobem je možné využít hardwarovou akceleraci na ESP32 pro operace zápis/šifrování a čtení/dešifrování? Pro jaké další šifrovací operace (kromě samotného dešifrování obsahu flash paměti) využívá architektura ESP32 hardwarovou akceleraci? V zadání práce není specifikována bezdrátová technologie pro vzdálenou aktualizaci zařízení. Z jakého důvodu byl zvolen standard IEEE 802.11? Existují možné alternativy? Student prezentoval výsledky své práce a komise byla seznámena s posudky. Student obhájil bakalářskou práci a odpověděl na otázky členů komise a oponenta.
Language of thesis
Slovak
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Information Security (BPC-IBE)
Composition of Committee
doc. Ing. Jiří Hošek, Ph.D. (předseda) doc. Ing. Petr Sysel, Ph.D. (místopředseda) Mgr. Andrej Krištofík, Ph.D. (člen) Ing. Martin Štůsek, Ph.D. (člen) Ing. Radek Možný, Ph.D. (člen) Ing. Michal Lares, Ph.D. (člen) Ing. Patrik Dobiáš (člen)
Supervisor’s reportIng. Martin Štůsek, Ph.D.
Grade proposed by supervisor: B
Reviewer’s reportdoc. Ing. Pavel Mašek, Ph.D.
Grade proposed by reviewer: B
Responsibility: Mgr. et Mgr. Hana Odstrčilová