Open-Source Secure Bootloader Demos
CycloneBOOT on STM32

Discover how our CycloneBOOT solution performs across different evaluation boards. Below, you’ll find an overview of the firmware update scenarios and available demos, including the protocols used for seamless firmware delivery.

Supported Firmware Update Scenarios

  • Dual-Bank Configuration (with CycloneBOOT Update Library)

    Dual-Bank Configuration (with IAP)

    With this scenario, based on In-Application Programming (IAP), firmware updates are handled entirely by the CycloneBOOT Update Library, without the presence of a dedicated bootloader. This mode is supported only on dual-bank flash microcontrollers, where the internal flash memory is divided into two independent banks. When a new firmware image is received, the update library processes the incoming update image, performs verification and compatibility checks and installs the validated firmware into the inactive bank while execution continues from the active bank. Before rebooting, the update library configures the MCU to select the newly programmed bank as the primary boot bank. On reset, execution seamlessly switches to the updated user application. This approach minimizes system complexity, while providing update capability on platforms that support bank swapping.

    Note: The update library also enforces anti-rollback protection.

  • Hybrid Configuration (with CycloneBOOT Bootloader & CycloneBOOT Update Library)

    Hybrid Configuration (Application/Bootloader)

    This Hybrid mode combines the CycloneBOOT Update Library with the CycloneBOOT Bootloader to form a cooperative update mechanism. In this configuration, the user application is responsible for downloading and validating the new firmware image using the update library, and storing it in a designated download slot. Once the update is ready, control is transferred to the bootloader during the next reboot. The bootloader then performs final integrity checks, installs the validated firmware into its execution slot, and launches the updated user application. This mode cleanly separates the acquisition of updates from their installation. It also provides support for configurations using external flash memory.

    Note: This mode enables boot-time application firmware verification at every startup (Verified Boot) and advanced fallback support.

  • Standalone Configuration (with CycloneBOOT Standalone Bootloader)

    Standalone Configuration (Autonomous Bootloader)

    The CycloneBOOT Standalone Bootloader is an independent, self-contained bootloader that manages the entire firmware update lifecycle without relying on the user application. Unlike Hybrid mode, all communication protocols, image validation, version control, and update logic are implemented directly within the bootloader itself. When a new firmware image is received, the standalone bootloader processes the update image, performs verification and compatibility checks, and installs the validated firmware into flash memory. After the installation is complete, the bootloader resumes its normal startup sequence and launches the updated user application.

    Note: This solution also applies to MCUs supporting program execution from an external memory (EXecute-in-Place - XiP)

Available Demos by Evaluation Board and Scenario

The table below summarizes our available demos, organized by evaluation board and scenario (Dual-Bank, Hybrid, Standalone). It also highlights the protocol used for fetching new firmware updates.

It follows the STM32 MCU portfolio segmentation proposed by ST:


STMicroelectronics | High-Performance STM32

'Verified Boot' feature enabled
'Multi-Stage Bootloader' feature enabled
Integration Examples (Secure Key Storage, Secure Element, Update Server, Persistent Boot Flags with FS — depending on the evaluation board)
Evaluation BoardDual-Bank
Configuration
Hybrid
Configuration
Standalone
Configuration
NUCLEO-F429ZIHTTP Server
UART/Y-Modem
--
NUCLEO-F439ZI--TFTP Server
STM32429I-EVALHTTP ServerHTTP Server-
NUCLEO-F767ZIHTTP Server--
STMF769I-DKHTTP ServerHTTP Server-
STMF769I-EVALHTTP Server
UART/Y-Modem
HTTP Server
MQTT Client
UART/Y-Modem
-
NUCLEO-H563ZIHTTP Server
SFTP Server
HTTP Server-
STM32H573I-DKHTTP Server
USB-CDC
HTTPS Client
FTP Server
USB-CDC
UART/Y-Modem
-
NUCLEO-H743ZI2HTTP ServerHTTP Server-
STM32H753I-EVAL2HTTP ServerHTTP Server-
NUCLEO-H755ZI-QUART/Y-Modem
(Dual Core M4/M7)
--
NUCLEO-H7A3ZI-QUART/Y-Modem--
STM32H750B-DK--UART/Y-Modem
(XIP enabled)
STM32H7S78-DKNEW--TFTP Server
(XIP enabled)
NUCLEO-N657X0-QNEW--HTTP Server
(XIP enabled)

STMicroelectronics | Mainstream STM32

'Verified Boot' feature enabled
Evaluation BoardDual-Bank
Configuration
Hybrid
Configuration
Standalone
Configuration
NUCLEO-G0B1RENEWUART/Y-ModemUART/Y-Modem-
NUCLEO-G474RENEWUART/Y-ModemUART/Y-ModemUART/Y-Modem
NUCLEO-G491RENEW-UART/Y-Modem-
NUCLEO-C562RENEW-UART/Y-Modem-

STMicroelectronics | Ultra-Low-Power STM32

'Verified Boot' feature enabled
'Multi-Stage Bootloader' feature enabled
Evaluation BoardDual-Bank
Configuration
Hybrid
Configuration
Standalone
Configuration
NUCLEO-L476RG-UART/Y-Modem-
NUCLEO-L496ZGUART/Y-Modem--
NUCLEO-L552ZE-QUART/Y-ModemUART/Y-Modem-
NUCLEO-U083RCNEW-UART/Y-Modem-
NUCLEO-U385RG-QNEW-UART/Y-Modem-
NUCLEO-U575-ZI-QUART/Y-ModemUART/Y-Modem-

STMicroelectronics | Wireless STM32

'Verified Boot' feature enabled
Evaluation BoardDual-Bank
Configuration
Hybrid
Configuration
Standalone
Configuration
STM32WB5MM-DKNEW-UART/Y-Modem-

Other Boards

'Verified Boot' feature enabled
VendorEvaluation BoardDual-Bank
Configuration
Hybrid
Configuration
Standalone
Configuration
MicrochipSAME54-XPlained-PROHTTP ServerHTTP Server-

Toolchains Used for Demonstration Projects

We have now standardized the use of CMake across all projects. However, our demonstration projects can also use the following toolchains: STM32CubeIDE, Microchip Studio, KEIL MDK-ARM, or Makefile.

Need a Custom Demo?

If you’d like to see a demo using your preferred toolchain, or if you need support for a different evaluation board, MCU part number, protocol or scenario, just let us know. We can tailor the demo to your needs!