hardware//firmware//OTA update

An OTA (over-the-air) update is the installation of new firmware or software on a device in the field through its network link, without physical access, and it is how fleets of drones, cars, robots and IoT sensors receive fixes, features and new models. Its danger is obvious: a device bricked by a failed update in a field, on a roof or at sea must be recovered by hand, or not at all.


An OTA (over-the-air) update is the installation of new firmware or software on a device in the field through its network link, without physical access, and it is how fleets of drones, cars, robots and IoT sensors receive fixes, features and new models. Its danger is obvious: a device bricked by a failed update in a field, on a roof or at sea must be recovered by hand, or not at all.

The robust scheme uses two partitions, A/B. The device runs from partition A while the new image is downloaded and written into the inactive partition B, then verified by checksum and signature. The device reboots into B and runs health checks (it boots, the sensors answer, the control loop runs on time, the link comes up). If they pass, B becomes the confirmed image; if they fail, or if the device never confirms because it hangs, the bootloader returns to A by itself. A power cut halfway through the download leaves A untouched.

Rollback has to be automatic, because a device that fails its update may not be able to ask for help; the bootloader counts boot attempts and falls back when a new image has not confirmed itself, and the watchdog timer turns a hang into such a failed attempt.

Images must be signed and checked before they are installed. An update channel is the most powerful door into the device, so an unsigned update is an invitation to install an attacker's firmware (cyber-physical security).

A/B protects one unit; the fleet is protected by releasing in waves, 1 %, 10 % and all, with metrics that halt the release (staged rollout). Together they are the deployment end of MLOps for embedded devices, and the record of which image each unit runs is part of versioning everything.

It costs flash: two full images instead of one, which on a small MCU can decide the memory size of the chip. Cheaper schemes keep a small recovery image instead of a full second copy, trading recovery capability for space.