FRM-120 · Firmware & MCU

Bootloaders & Firmware Update

Updating firmware in the field without bricking devices, including signature verification and rollback.

Practitioner 3 days in person6 half-days online Max 14 in person

Who this course is for

Firmware engineers shipping connected MCU products who must update devices in the field without bricking them — and prove the update path is safe before a regulator or customer asks.

Prerequisites

FRM-101-level bare-metal knowledge: memory maps, linker scripts, startup codeC programmingBasic public-key signing concepts (what signing and verification mean)

Course outline

Day 1 — Bootloader design

  • Why a bootloader exists: update, recovery and factory provisioning roles
  • Flash layout for a two-image system: slots, metadata and the scratch question
  • The handoff: relocating the vector table, setting the stack and jumping to the application
  • Shared state between bootloader and application: retention registers and no-init sections
  • Boot-time cost and what to strip for fast startup

Day 2 — MCUboot and signed images

  • MCUboot architecture: image format, header and TLVs
  • Slot strategies: swap-scratch, swap-move and overwrite-only, and their wear implications
  • Signing with imgtool and verifying signatures at boot
  • Key provisioning: where the public key lives and what an attacker can reach
  • Version checks, security counters and anti-rollback enforcement

Day 3 — Transport and power-loss safety

  • Getting the image to the device: UART, USB, BLE and network transports
  • Chunking, flow control and resumption after an interrupted transfer
  • Power-loss safety at every point: worst-case timing and the recovery walk-through
  • Failure paths: revert, test images and the confirm step
  • Factory recovery and the un-brickable fallback position

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: write a minimal bootloader that validates, selects and jumps to an application; trace the handoff with gdb over SWD
  2. Lab: sign and flash MCUboot images with imgtool, boot them through each swap strategy, and measure the boot-time cost of verification
  3. Lab: tamper with a signed image and roll back the version counter, watch each attack get rejected, then prove a good image still boots
  4. Lab: pull power at scripted points during an update — first chunk, mid-swap, final commit — and prove the device recovers every time
  5. Lab: build a resumable update transport over UART with chunking, then interrupt it mid-transfer and resume

Capstone project

Deliver a complete update path for the lab board: an MCUboot-based flash layout with signed images, anti-rollback counters, a resumable transport and a documented power-loss safety case. Your evidence pack is the threat analysis, the layout, boot logs for the negative tests (tampered image, downgrade attempt, interrupted transfer, repeated power cuts) and a recovery demonstration a reviewer can repeat.

What you leave with

  • A working MCUboot integration: slots, signing, verification, anti-rollback
  • A flash layout and bootloader/application handoff contract you can adapt to your own part
  • A power-loss safety case built from scripted fault injection, not hope
  • Key-provisioning habits that keep signing keys out of the wrong places
  • A resumable transport pattern with measured interruption behaviour

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Firmware engineers shipping connected MCU products who must update devices in the field without bricking them — and prove the update path is safe before a regulator or customer asks. It sits at practitioner level within the Firmware & MCU track.

What do I need to know already?

Specific prerequisites for this course: FRM-101-level bare-metal knowledge: memory maps, linker scripts, startup code; C programming; Basic public-key signing concepts (what signing and verification mean). We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
15 Nov – 17 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 4 of 14 SAR 7,090until 16 OctSAR 7,880
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 9 of 14 KWD 580until 23 OctKWD 650
22 Nov – 24 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 4 of 14 OMR 730until 23 OctOMR 810
29 Nov – 6 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 6 of 20 US$1,350until 30 OctUS$1,500
30 Nov – 2 Dec 20263 full days OttawaIn person · Kanata North Tech Park 9 of 14 CAD 2,570until 31 OctCAD 2,860
30 Nov – 7 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 11 of 20 US$1,350until 31 OctUS$1,500
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 4 of 14 CAD 2,570until 7 NovCAD 2,860
7 Dec – 9 Dec 20263 full days LondonIn person · Shoreditch Works 9 of 14 GBP 1,480until 7 NovGBP 1,640
7 Dec – 14 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 16 of 20 US$1,350until 7 NovUS$1,500
14 Dec – 16 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 4 of 14 EUR 1,740until 14 NovEUR 1,930

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Firmware & MCU