
Master encryption and cryptography for embedded systems with hands-on practice on STM32 microcontrollers, covering AES, RSA, elliptic curves, and cryptographic firmware fundamentals.
Understand how cryptography delivers confidentiality, integrity, and availability for embedded systems in IoT, while resource constraints and applications like pacemakers and brake controls make encryption essential for trust and compliance.
Explore STM32 security features, including secure boot, flash protection, memory protection unit with trustzone and firewall, and cryptographic support like random number generator, aos, public key accelerator, and hash.
Explore security on an MCU by applying the CIA properties—confidentiality, integrity, and availability—through cryptography to protect assets like consumer data, firmware, and intellectual property.
Explore threats to embedded systems, including unauthorized access, service disruption, data breaches, and social engineering. Apply mitigations like network assessments, firewalls, patches, and strong passwords to protect devices and data.
Learn how data integrity in embedded systems combines CRC and encryption for robust protection, using layered security, hardware security modules, and redundancy to guard against tampering and errors.
Identify assets as valuable items to protect, including hardware, data, software, and brand reputation. Assess threats and vulnerabilities to quantify risk as the intersection of assets, threats, and vulnerabilities.
Identify all assets, analyze threats, pinpoint vulnerabilities, and determine countermeasures in a four-step threat analysis process; maintain ongoing evaluation to stay ahead of evolving risks in embedded systems.
Explore threat analysis for a smart thermostat by identifying hardware, software, and data assets and evaluating external, internal, and environmental threats to secure the device.
Download the STM32 cube IDE for Windows from the STM32 website, sign in or register, accept the license, and start the download to prepare for the next lesson on installation.
Extract the package, run the installer, and click next to install Cube IDE. Ensure space by choosing a larger drive, set the workspace, and allow firewall access.
Download the stm32 f401 reference manual, datasheet, and nucleus user guides; create a stm32 bare metal project workspace; assemble the project tree to access registers and block diagrams.
Learn to create a bare metal stm32 f4 project in cube ide, set up the workspace and project tree, and integrate cmsis header files to access peripherals via symbolic addresses.
Test and configure a bare metal stm32f4 project by linking chip headers, including stm32f4x.h, enabling clock via the Ahb one enable register, and blinking PA5.
Develop modular bare-metal drivers for FPU, UART, GPIO, and timebase across STM32 boards, and enable the floating point unit by setting CP ten and CP eleven in the CP ECR.
Develop the STM32 UART driver by enabling clock access to USART2 on APB1, configuring PA2/PA3 as AF7 for TX/RX, and using USB for debugging.
Develop a tx-only debugging uart by configuring pa2 as an alternate function for uart2, enabling clocks, setting baud rate, transfer direction, and enabling the module to transmit data.
Enable the gpio a clock, configure pa2 for alternate function af7, and enable the usart2 clock. Compute and set baud rate to 115200, then enable the transmitter.
Implement a static uart_write function that polls the transmit data register empty flag, writes to the usart data register, and retargets printf for sending characters.
Test the uart driver by wiring in the init function, including uart.h, and printing via printf to uart2, then view the serial output on a computer with real time.
Develop a system timebase with the systick timer on STM32 Cortex-M4. Learn to configure enable and interrupt bits, and choose internal or external clock sources, including pll and crystal concepts.
Define symbolic names for the control and load registers. Initialize systick to generate a one-second tick by loading cycles per second, clearing the current value, and enabling interrupts.
Develop a robust system timebase by implementing a tick-based delay driven by systick interrupts, maintaining a global tick counter, and exposing an atomic get_tick function for accurate timing.
Test the system timebase by moving from pseudo to actual delay, expose required functions, and print a message every second while preparing the BSP and ADC driver integration.
Develop a board support package for the stm32f4 nuclear board by implementing gpio drivers to configure pa5 led and pc13 push button, including led on/off and button state functions.
Enable clock access to GPIO A and GPIO C via the AHB1ENR, configure PA5 as an output, and drive the LED pin high and low with the output data register.
Implement the push button driver for the embedded bsp by enabling gpio c clock, configuring pc13 as an input, and reading the active-low button to return pressed state.
Develop and validate the system BSP by testing the GPIO input/output drivers, initializing the LED and button, and observing live button state on an STM32 board.
Develop an ADC driver by configuring ADC1, enabling clocks on the APB2 bus, mapping GPIO pins to 16 analog channels to read sensor data, and analyzing the datasheet.
Configure the gpio pin PA1 and adc module, set the conversion sequence and length, enable the adc, start conversion, and read the sensor value after waiting for completion.
The lecture details implementing the PA1 ADC init: enable GPIO and ADC clocks, configure PA1 as analog, set ADC1 conversion sequence, and enable the ADC via CR2 for conversion.
Develop and test a continuous conversion ADC driver by enabling continuous mode, starting conversion, polling the end of conversion, and reading the 12-bit data register with a 3.3 V reference.
Learn core cryptography terms, including encrypt, decrypt, cipher, key, plaintext, and ciphertext, and the process from plaintext to ciphertext and back through decryption.
Define the cipher as a mathematical algorithm transforming data with a key, and compare symmetric, asymmetric, block versus stream inputs, including classical ciphers like the Caesar cipher.
Explore the Caesar cipher, an early encryption method named after Julius Caesar, shifting each letter by a fixed k within the 26-letter alphabet using modulo 26, demonstrated with apple.
Explore the rot13 cipher, a Caesar cipher with a fixed shift of 13 used for obfuscation, not security, and preview monoalphabetic and polyalphabetic ciphers.
Develop foundational cryptography algorithms by organizing a copied project workspace in stm32 cube ide, importing drivers like uart and adc, and preparing for the Caesar cipher in the next lesson.
Develop a caesar cipher encryption function in c for embedded systems cryptography, taking plaintext and a shift, using a length parameter, and writing ciphertext to a buffer with 26-letter wrap.
Develop a caesar cipher decryption function that uses a shift to decrypt text, handling lowercase and uppercase letters, and storing results in a buffer for testing with a main function.
Develop a variant of the Caesar cipher for 16-bit integers, implementing encrypt and decrypt functions, handling blocks of sensor data, and applying shifts to mask values in embedded systems.
Learn how to crack the Caesar cipher by iterating over possible keys, implementing a hack function, and printing decrypted candidates to reveal readable plaintext.
Explore monoalphabetic ciphers, a fixed substitution that maps each plaintext letter to a ciphertext letter, and contrast with polyalphabetic ciphers like the Vigenere that use a keyword.
Develop and implement a monoalphabetic cipher encryption function in C. Learn to handle lowercase and uppercase letters, preserve non-letters, and apply the key to produce encrypted text.
Develop and test a monoalphabetic cipher decryption function that takes ciphertext and a key, handling lowercase, uppercase, and non-letter characters while storing results in a decrypted text buffer.
Explore how polyalphabetic ciphers use a keyword aligned with plaintext to perform substitution via the Vigenère approach, including encryption and decryption with x_i plus k_i mod 26.
Develop the Vigenere cipher encryption function to transform plaintext with a keyword, storing the result in an encrypted text buffer while preserving non letters and case.
Develop the vigenere cipher decrypt function, processing encrypted text with the keyword, storing the decrypted text in a buffer, and handling uppercase/lowercase during decryption.
The lecture demonstrates normalizing the vigenere cipher keyword to uppercase, converting plaintext to uppercase, and implementing encryption and decryption with case-insensitive inputs.
Examine the multiplicative cipher, a monoalphabetic substitution using a key k coprime with 26 to encrypt by x k mod 26, and use the modular multiplicative inverse for decryption.
Develop and implement the multiplicative cipher encryption function in C, handling uppercase and lowercase letters with modulo 26 wraparound, and prepare for decryption in the same project.
Implement the multiplicative cipher decryption by computing the modular multiplicative inverse of the key modulo 26, apply it to each letter, and handle case and nonalphabetic characters.
Implement real cryptography in embedded firmware with confidence.
Learn how to design, understand, and integrate practical cryptographic building blocks for ARM-based microcontrollers, including AES, SHA-256, HMAC, RSA, ECC, DRBG, and STM32 cryptographic middleware.
This is not a theory-only cryptography course.
It is a practical embedded systems training built for engineers who want to understand how modern cryptography is actually applied in firmware.
What you will learn:
• symmetric encryption with AES
• hashing with SHA-256
• message authentication with HMAC
• random number generation with DRBG
• public key foundations with RSA and ECC
• STM32 cryptographic library integration
• host-side Python tooling for validation and test workflows
If you build embedded systems that store data, communicate externally, receive updates, or interact with connected environments, this is a capability worth building now.
Why This Course Matters
Embedded security is no longer optional
Modern embedded products are expected to do more than function correctly. They are expected to protect data, resist tampering, support secure communication, and form part of a trustworthy system.
Yet many embedded engineers were never taught how cryptography is actually implemented at the firmware level.
They may know the terminology.
They may understand the high-level concepts.
But when it is time to work with encryption, hashing, authentication, randomness, or key-based security in a real embedded workflow, that confidence often disappears.
This course was created to close that gap.
You will move beyond abstract definitions and begin understanding how practical cryptography fits into embedded systems engineering.
What Makes This Training Different
Built for embedded engineers, not general software audiences
Most cryptography training is either too academic or too disconnected from firmware reality.
This course takes a different approach.
It focuses on the practical needs of embedded developers working with ARM microcontrollers and STM32-class devices. Instead of teaching cryptography as a purely mathematical subject, it teaches it as an engineering capability.
You will learn not only what the major cryptographic components are, but also how they are used, how they fit together, and how to reason about them inside a real embedded development context.
You will cover topics such as:
• why encryption matters in embedded products
• common embedded threat scenarios
• symmetric vs asymmetric cryptography
• practical cipher workflows
• padding and block handling
• secure digests and authentication
• deterministic random bit generation
• public key fundamentals
• embedded implementation flow using STM32 tools and libraries
• host-side verification using Python
What You Will Learn
By the end of this course, you will understand how to:
• explain the role of cryptography in embedded systems
• distinguish between encryption, hashing, authentication, and randomness
• implement and reason about AES-based workflows
• work with PKCS#7 padding correctly
• understand and apply SHA-256 and HMAC concepts
• use DRBG-based random generation principles
• understand the practical purpose of RSA and ECC in embedded environments
• integrate STM32 cryptographic software components into a firmware workflow
• validate key cryptographic behavior with supporting Python tools
• build stronger security awareness as an embedded firmware engineer
Course Curriculum Snapshot
A practical path from foundations to implementation
This training includes a structured progression through the key areas embedded engineers need in order to begin working confidently with cryptography.
Core areas include:
1. Security context and embedded threat awareness
Understand why cryptography matters, where embedded systems are vulnerable, and how security capabilities fit into modern product design.
2. Cryptographic foundations
Build a clean understanding of the major categories of cryptographic systems and when they are used.
3. Symmetric encryption workflows
Learn the principles behind practical encryption approaches including AES and common operating considerations.
4. Hashing and message authentication
Understand how SHA-256 and HMAC contribute to integrity and trust.
5. Randomness and key-related foundations
Study DRBG concepts and why randomness matters in cryptographic systems.
6. Public key cryptography
Develop a practical understanding of RSA and ECC in embedded use cases.
7. STM32 implementation and validation workflows
Work through firmware-oriented integration using STM32 cryptographic software and Python-based support tooling.
Who This Course Is For
This course is a strong fit for:
• embedded firmware engineers working with ARM-based microcontrollers
• STM32 developers who want practical security knowledge
• engineers building connected or updateable products
• developers moving into embedded security responsibilities
• technical professionals who want to understand cryptography beyond buzzwords
• students and early-career engineers who want stronger real-world embedded skills
This course is not designed for:
• people looking for a purely mathematical cryptography program
• learners who want only abstract theory without firmware context
• general software audiences with no interest in embedded systems
Why Learn This Now
The embedded engineer who understands security has an advantage
As products become more connected, more updateable, and more exposed to hostile environments, embedded teams increasingly need engineers who can think beyond drivers and peripherals.
They need engineers who understand trust, integrity, confidentiality, and secure system behavior.
That does not mean every engineer must become a cryptography specialist.
But it does mean that practical security literacy is becoming a more valuable capability.
This course helps you build that capability in a way that is grounded in embedded reality.
Learn from an embedded systems educator with real engineering depth
This training is taught by Israel Gbati, embedded systems educator, engineer, and founder of EmbeddedExpertIO.
Israel has taught embedded systems to engineers around the world and is known for practical, implementation-focused training that goes beyond theory and into real firmware workflows.
His teaching is built around one core principle:
Engineers should leave with skills they can actually apply.
That same philosophy shapes this course.
You will not just hear definitions.
You will build understanding that is usable in real embedded work.