Firmware over the air (FOTA), also called firmware update over the air (FUOTA), lets a team update devices after they have been deployed—without physically connecting to each one. It can deliver security fixes, feature changes, and configuration changes, including to devices in remote locations.
A dependable FOTA system is more than a server that sends a file. It must establish who authorized the update, confirm that the image is intact and meant for that device, transfer and store it safely, install and verify it, report the result, and provide a recovery path if something goes wrong.
What firmware over the air means
FOTA is a way to deliver and install firmware remotely over a device’s network connection. It is a lifecycle capability: the manufacturer or operator can maintain deployed hardware after installation, rather than relying on a person to visit each device and connect a programmer.
The update may change executable firmware, or—in a broader device-management workflow—configuration. The critical distinction is that installing firmware changes code that runs on the device. The update process therefore needs stronger safeguards than an ordinary file download.
Recommended Free Tools
#1 Best Overall
- SIMPLE TO SET UP WITH ALEXA: Get started in minutes with multiple setup options, including a zero touch experience when you select "Link device to your Alexa account" at checkout
- CONTROL FROM ANYWHERE: Schedule plugged-in appliances like lights or fans to turn on/off automatically, or control them remotely via the Alexa app when you’re away
- COMPACT DESIGN: The plug fits perfectly into 1 socket, leaving remaining sockets and outlets free for use; ideal for multiple appliances like holiday lighting, heaters, fans, lamps, water kettles, coffee makers, and more
- CUSTOMIZE ROUTINES: Schedule your smart plug to turn on/off either at designated times, with a voice command, or even at sunrise and sunset
- NO 3RD PARTY APPS OR HUBS REQUIRED: Set up and manage connected devices directly in the Alexa app; no need for additional smart hubs or 3rd party apps
How an IoT firmware update works
An update typically moves through several components: the image, information that describes and authorizes it, a delivery mechanism, device storage, installation and boot logic, and status reporting. The IETF’s RFC 9019, A Firmware Update Architecture for Internet of Things (April 2021), describes this as an end-to-end architecture rather than a single transfer protocol.
- Prepare the release. The update author builds a firmware image and a manifest. The manifest carries authenticated information used to decide whether the image is trusted, compatible with the target device, and acceptable as an update.
- Make the update discoverable. A device or its management service needs a way to learn that an update is available and determine whether it should be offered to that device.
- Transfer and store the payload. The device receives the manifest and image over a suitable transport and stores the payload persistently, commonly in flash. The transfer needs to account for interruption, corruption, and the device’s storage limits.
- Validate and install. The device checks authorization, integrity, compatibility, and version information before handing the image to its installer or bootloader. The boot process should verify the firmware before it runs.
- Report the outcome. The device or management system records whether the update succeeded, failed, or needs recovery. Without status tracking, an operator cannot reliably tell which devices are running which release.
RFC 9019 names Lightweight M2M (LwM2M) as one device-management protocol and discusses MQTT, CoAP, and HTTP among commonly used application-layer protocols. A manifest standard, transport protocol, or download server alone does not provide a complete fleet-update service, and none of those protocols is a universal best choice.
Rank #2
- 【Easy Setup, One Control】With Matter, Skip the step of downloading and registering multiple manufacturers' apps every time you buy a new device. Instead, head straight to certified smart home platforms like Apple Home, Alexa, Google Home, SmartThings, or AiDot to control all your Matter devices.【TIP】Matter-certified hub or controller (HomePod, Echo Dot, Nest, SmartThings Hub) is required for Apple Home/Alexa/Google Home/SmartThings platforms. Alternatively, the AiDot app can be used without hub
- 【Offline-Ready Control】Once you've set up your Matter-certified devices on your LAN, they'll be able to communicate with each other directly, using the Matter protocol. This means that if your home internet connection goes offline, your Matter-certified devices will still be able to communicate and be controlled within your LAN, without relying on the internet or cloud services.
- 【Remote Control from Anywhere】Use the app to turn electronics on before you arrive home and off after you leave, no matter where you are. Using the smart plug that work with alexa manage your power usage and save money.
- 【Hands-free Voice Control】Control linkind homekit plug using simple voice commands through Apple HomeKit, Siri, Amazon Alexa, Google Assistant, and SmartThings, without the need for physical input such as buttons or switches.
- 【Flexible Scheduling & Timer】Effortlessly reduce energy usage with automatic device shutdown after a set time. For example Chrismas Tree, TV, Lamp, Fan, Humidifier,Blenders, Lightbulbs
How to secure an IoT firmware update
RFC 9019 puts the risk plainly: “An update is essentially authorized remote code execution, so any security problems in the update process expose that remote code execution system.” This is an architectural warning about the consequences of a compromised update path, not a claim that every implementation is vulnerable.
Before accepting an update, the device should make a set of distinct checks. RFC 9019 describes the architecture and trust decisions; RFC 9124, A Manifest Information Model for Firmware Updates in Internet of Things (IoT) Devices, sets out manifest information and security requirements.
Rank #3
- Amazon Smart Plug works with the Alexa app and compatible Alexa devices to add voice control to any electrical outlet.
- Simple setup - No smart home hub required. Just plug it in, open the Alexa app and follow the stress-free directions to get started in minutes.
- Compatible with many lamps, fans, coffee makers, and other household devices with a physical on/off switch.
- Make any outlet a smart outlet. Compact design keeps your second outlet free for an additional smart plug.
- Use as a timer for lights or create lighting schedules for when you are away from your home.
- Authenticate the authority. Verify that the signer chains to a trust anchor provisioned on the device and is authorized for the requested update action. A valid signature alone does not mean that every signer is allowed to install every type of update.
- Verify integrity. Authenticate the manifest and verify the image’s integrity before installation. Encryption of the image is optional; it may protect proprietary code or sensitive payloads, but does not replace authorization or integrity checks.
- Check the target. Authenticate compatibility identifiers such as vendor, class, and device identifiers, and confirm the payload type so that content for another product or purpose is rejected.
- Block unsafe downgrades. Use authenticated sequence or version information to reject an older, still-valid image if it would restore a vulnerable release.
- Protect where the device gets the image. Authenticate the storage destination and remote resource location. RFC 9124 calls for cryptographic protection of remote resource locations when a device dereferences them.
- Verify what will run. At boot, check the firmware against authenticated payload size and digest information rather than assuming that a successful download means the installed image is sound.
- Constrain differential updates. If an update is a delta rather than a complete image, authenticate the digest of the precursor image so the delta is applied only to the expected base version.
- Keep the trusted code small. Manifest parsing code can be part of the trusted computing base, including in a bootloader. It should be kept small and carefully reviewed.
These controls solve different problems: a secure connection can protect a transfer in transit, but it does not by itself prove that the update is authorized for this device, prevent a downgrade, or verify the firmware at boot.
What happens when an update fails
A download can stop or become corrupted; a device can lose power; flash storage can be insufficient; installation can fail; or a nominally valid image can prove incompatible in practice. A robust design treats these as expected failure cases and defines how the device detects the problem and returns to a known working state.
Rank #4
- Stability Upgrade Quick Connection:Supports Bluetooth or WiFi connection.The improved WiFi technology let you quick connection and stay stable,no disconnection worries. Please keep the smart plug connected to your stable 2.4GHz network.(Note: Only 2.4Ghz WiFi)
- Hand-Free Voice Control:Smart plugs that work with Alexa and Googel Assistant. Just give a simple voice command to Alexa or Google Assistant to control your connected home devices. Enjoy the joy of smart home devices.
- APP Remote Control From Anywhere:You also can control your outlet timers anywhere anytime via the APP directly when you are away. Monitor and control connected electrical equipment in your home.The smart outlet plug compatible with GHome APP, Smart Life App and Tuya App.
- Schedules and Timer Function:Easy to set timers and add schedules to connected smart home devices circularly or randomly, making them work as scheduled like auto-off and auto-on to save energy and money. Such as lamps, fan, humidifier, Christmas light timers etc.
- Group Control and Sharing:You can set a group for some wifi smart plugs and control connected appliances with one tap. Also you can share your wifi outlet plug by App with your families and enjoy the smart life together.
Before installation
- Confirm that the image is complete and passes its integrity and compatibility checks before handing it to installation logic.
- Account for persistent-storage capacity and the energy needed to write firmware to flash, particularly on battery-powered devices.
- Use a transfer mechanism that can handle fragmentation and reassembly and resume an interrupted or corrupted transfer, as RFC 9019 recommends.
During installation and boot
- Design installation behavior around power loss and installation errors; the device must not treat a partially written or unverified image as ready to run.
- Verify firmware at boot using authenticated size and digest information.
- Provide a tested recovery strategy if the new image cannot be installed or does not boot successfully. The exact mechanism depends on the device architecture; no single recovery method is specified here for every IoT product.
For the fleet operator
Track update status and device health so failed or incomplete installations can be identified. NIST SP 800-193, Platform Firmware Resiliency Guidelines (published May 4, 2018), frames firmware resiliency around protecting against unauthorized changes, detecting unauthorized changes that occur, and recovering rapidly and securely. It is general platform-firmware guidance, not a step-by-step IoT OTA implementation recipe.
Why the network changes the update plan
Image size, link quality, duty-cycle limits, multicast support, device receive windows, and battery capacity all affect update time and energy use. Radio communication and writing firmware to flash can both consume substantial energy on battery-powered devices. A strategy suitable for a device on a reliable, high-throughput connection may be impractical on a constrained radio link.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- Stability Upgrade Quick Connection:Supports Bluetooth or WiFi connection.The improved WiFi technology let you quick connection and stay stable,no disconnection worries. Please keep the smart plug connected to your stable 2.4GHz network.(Note: Only 2.4Ghz WiFi)
- Hand-Free Voice Control:Smart plugs that work with Alexa and Googel Assistant. Just give a simple voice command to Alexa or Google Assistant to control your connected home devices. Enjoy the joy of smart home devices.
- APP Remote Control From Anywhere:You also can control your outlet timers anywhere anytime via the APP directly when you are away. Monitor and control connected electrical equipment in your home.The smart outlet plug compatible with GHome APP, Smart Life App and Tuya App.
- Schedules and Timer Function:Easy to set timers and add schedules to connected smart home devices circularly or randomly, making them work as scheduled like auto-off and auto-on to save energy and money. Such as lamps, fan, humidifier, Christmas light timers etc.
- Note: To use Alexa and Google Home, please note that this product cannot be connected directly. You need to connect the product to the network and the GHome APP first.
A 2020 paper, “How to make Firmware Updates over LoRaWAN Possible,” illustrates the scale of the constraint: for a 50 kB image at data rate DR2 (SF10/125 kHz), it calculates about 1,004 downlink packets using 51-byte maximum packets, plus a similar number of uplink requests under its described approach—even assuming a perfect channel. This is the paper’s calculation for those stated settings, not a general LoRaWAN benchmark. The paper discusses fragmentation, multicast, and clock-synchronization specifications as ways to make FUOTA more practical, and evaluates trade-offs with a simulation tool; its results should not be read as field-test measurements.
For a low-rate or duty-cycle-limited network, fragmentation, multicast, and scheduling may help, but they bring their own constraints. The practical design has to account for the device’s receive behavior, the network’s rules, rollout duration, and the energy budget rather than treating the image as an ordinary download.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to evaluate an update architecture
Compare designs against the conditions of the actual deployment. Useful questions include:
- What CPU, RAM, flash layout, and bootloader does the device have, and can it stage or recover an image?
- How large are updates? Is delivery by full image or differential update appropriate, and how is the delta’s base image authenticated?
- What are the network’s throughput, reliability, cost, duty-cycle rules, multicast availability, and device reachability?
- How much battery energy and update time can the device spend?
- How are signing keys held, trust anchors provisioned, signer permissions managed, and compromised credentials revoked? How is downgrade protection enforced?
- Can the system target compatible devices, control rollouts, report status, diagnose failures, and support recovery?
- Will critical updates remain available throughout the product’s supported life, including if the vendor or service provider stops operating? RFC 9019 identifies long-term update availability as a lifecycle concern.
Standards and guidance at a glance
| Reference | What it contributes | How to use it |
|---|---|---|
| IETF RFC 9019, A Firmware Update Architecture for Internet of Things (April 2021) | End-to-end update architecture, trust decisions, transfer needs, and responsibilities for authors and operators. | Use it to understand the components and security boundaries a complete IoT update system must cover. |
| IETF RFC 9124, A Manifest Information Model for Firmware Updates in Internet of Things (IoT) Devices | Manifest information and security requirements, including compatibility and protection of remote resource locations. | Use it when designing or evaluating the authenticated information a device relies on to accept an update. |
| NIST SP 800-193, Platform Firmware Resiliency Guidelines (May 4, 2018) | Broader guidance organized around protection, detection, and recovery for platform firmware. | Use it as a resiliency framework, not as a complete IoT OTA protocol specification. |
| NIST Federal Profile 8259A materials, Software and Firmware Update | Operational guidance on evaluating update effectiveness and side effects, and communicating criticality, dependencies, likely impacts, and timing. | Use it to inform update testing and communication with customers or operators. |
| ITU-T Recommendation X.1368 summary (January 2021) | A summary of secure IoT firmware/software update models and procedures. | Use it as additional standards context when reviewing secure update models. |
Run updates as an operational process
Secure code and resilient boot behavior do not remove the need for release discipline. NIST’s Federal Profile 8259A materials call for testing update effectiveness and possible side effects before installation and after updates, as well as communicating an update’s criticality, dependencies, likely impact, and recommended timing.
Plan rollout stages, health checks, and response procedures around the product and deployment. The appropriate rollout size, waiting period, and success threshold depend on operational needs; there is no universal percentage or timeout that fits every fleet. Keep update ownership, authorization, monitoring, and recovery integrated with the organization’s change-management process.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

