FRM-120 · Firmware & MCU
Bootloaders & Firmware Update
Updating firmware in the field without bricking devices, including signature verification and rollback.
Who this course is for
Firmware engineers shipping connected MCU products who must update devices in the field without bricking them — and prove the update path is safe before a regulator or customer asks.
Prerequisites
Course outline
Day 1 — Bootloader design
- Why a bootloader exists: update, recovery and factory provisioning roles
- Flash layout for a two-image system: slots, metadata and the scratch question
- The handoff: relocating the vector table, setting the stack and jumping to the application
- Shared state between bootloader and application: retention registers and no-init sections
- Boot-time cost and what to strip for fast startup
Day 2 — MCUboot and signed images
- MCUboot architecture: image format, header and TLVs
- Slot strategies: swap-scratch, swap-move and overwrite-only, and their wear implications
- Signing with imgtool and verifying signatures at boot
- Key provisioning: where the public key lives and what an attacker can reach
- Version checks, security counters and anti-rollback enforcement
Day 3 — Transport and power-loss safety
- Getting the image to the device: UART, USB, BLE and network transports
- Chunking, flow control and resumption after an interrupted transfer
- Power-loss safety at every point: worst-case timing and the recovery walk-through
- Failure paths: revert, test images and the confirm step
- Factory recovery and the un-brickable fallback position
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: write a minimal bootloader that validates, selects and jumps to an application; trace the handoff with gdb over SWD
- Lab: sign and flash MCUboot images with imgtool, boot them through each swap strategy, and measure the boot-time cost of verification
- Lab: tamper with a signed image and roll back the version counter, watch each attack get rejected, then prove a good image still boots
- Lab: pull power at scripted points during an update — first chunk, mid-swap, final commit — and prove the device recovers every time
- Lab: build a resumable update transport over UART with chunking, then interrupt it mid-transfer and resume
Capstone project
Deliver a complete update path for the lab board: an MCUboot-based flash layout with signed images, anti-rollback counters, a resumable transport and a documented power-loss safety case. Your evidence pack is the threat analysis, the layout, boot logs for the negative tests (tampered image, downgrade attempt, interrupted transfer, repeated power cuts) and a recovery demonstration a reviewer can repeat.
What you leave with
- A working MCUboot integration: slots, signing, verification, anti-rollback
- A flash layout and bootloader/application handoff contract you can adapt to your own part
- A power-loss safety case built from scripted fault injection, not hope
- Key-provisioning habits that keep signing keys out of the wrong places
- A resumable transport pattern with measured interruption behaviour
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Firmware engineers shipping connected MCU products who must update devices in the field without bricking them — and prove the update path is safe before a regulator or customer asks. It sits at practitioner level within the Firmware & MCU track.
What do I need to know already?
Specific prerequisites for this course: FRM-101-level bare-metal knowledge: memory maps, linker scripts, startup code; C programming; Basic public-key signing concepts (what signing and verification mean). We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 15 Nov – 17 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 4 of 14 | SAR 7,090until 16 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 9 of 14 | KWD 580until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 4 of 14 | OMR 730until 23 Oct | ||
| 29 Nov – 6 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 6 of 20 | US$1,350until 30 Oct | ||
| 30 Nov – 2 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 9 of 14 | CAD 2,570until 31 Oct | ||
| 30 Nov – 7 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 11 of 20 | US$1,350until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 4 of 14 | CAD 2,570until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | LondonIn person · Shoreditch Works | 9 of 14 | GBP 1,480until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 16 of 20 | US$1,350until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 4 of 14 | EUR 1,740until 14 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Firmware & MCU
FRM-1013 days
Bare-Metal C for Microcontrollers
Writing firmware with no operating system underneath: startup, linker scripts, peripherals and interrupts.
Practitioner-taught
SAR 6,750Next 1 Nov
FRM-1103 days
RTOS Fundamentals: Zephyr & FreeRTOS
Task scheduling, synchronisation and driver models in a small real-time operating system.
Practitioner-taught
SAR 7,880Next 11 Oct
FRM-2013 days
I2C, SPI & CAN Protocol Firmware
Implementing and debugging the buses embedded systems communicate over, from the firmware side.
Practitioner-taught
SAR 7,880Next 22 Nov
FRM-2103 days
CMIS & Optical Module Firmware
Firmware for pluggable optical modules: the CMIS management interface and the state machines behind it.
Practitioner-taught
SAR 9,000Next 1 Nov