---
title: "14-STM32+W5500 Basic Control (Self-built IoT Platform) - Porting mbedtls to enable STM32+W5500"
url: "https://maker.wiznet.io/gavinchang/projects/14-stm32-w5500-basic-control-self-built-iot-platform-porting-mbedtls-to-enable-stm32-w5500/"
markdown_url: "https://maker.wiznet.io/gavinchang/projects/14-stm32-w5500-basic-control-self-built-iot-platform-porting-mbedtls-to-enable-stm32-w5500/md"
type: "UCC: User Created Content"
author: "Yang Fengwu"
author_url: "https://www.cnblogs.com/yangfengwu/p/15869618.html"
editor: "WIZnet"
editor_url: "https://maker.wiznet.io/"
original_author: "Yang Fengwu"
original_url: "https://www.cnblogs.com/yangfengwu/p/15869618.html"
published: "2025-12-04"
language: "en"
likes: 0
views: 468
comments: 0
source: "WIZnet Makers (https://maker.wiznet.io/)"
---

# 14-STM32+W5500 Basic Control (Self-built IoT Platform) - Porting mbedtls to enable STM32+W5500

> 14-STM32+W5500 Basic Control (Self-built IoT Platform) - Porting mbedtls to enable STM32+W5500 to connect to an MQTT server using SSL one-way authentication (wi

Original author: Yang Fengwu (source: https://www.cnblogs.com/yangfengwu/p/15869618.html)

## Article

## **illustrate**

### **In network communication, without SSL, information is exposed in plaintext.**

### **This section demonstrates how to port the mbedtls library to enable the W5500 to connect to the MQTT server using SSL.**

### **First, let me briefly explain SSL. Essentially, it's all about TCP communication with the server.**

### **However, after establishing a TCP connection with the server, the encryption method and password must first be negotiated with the server.**

### **The data is then transmitted in encrypted form.**

## **test**

### **1. Open the code in this section.illustrate**

### **In network communication, without SSL, information is exposed in plaintext.**

### **This section demonstrates how to port the mbedtls library to enable the W5500 to connect to the MQTT server using SSL.**

### **First, let me briefly explain SSL. Essentially, it's all about TCP communication with the server.**

### **However, after establishing a TCP connection with the server, the encryption method and password must first be negotiated with the server.**

### **The data is then transmitted in encrypted form.**

## **test**

### **1. Open the code in this section.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847359%2Epng)

### **2. Modify to your own Alibaba Cloud device information**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847379%2Epng)

### **3. Download to the microcontroller (connect via network cable)**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847398%2Epng)

### **4. Observe the log printing port to confirm that the server is connected.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847434%2Epng)、

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847450%2Epng)

## **Program Description**

### **1. To facilitate the use of mbedtls' SSL functionality, I have encapsulated it as follows.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847479%2Epng)

### **2. First, let me mention a few functions that I need to implement, as mbedtls will call these functions at the underlying level.**

#### **Random number function and timestamp return function (not needed if certificate time is not verified).**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847501%2Epng)
**Network receive processing function (mbedtls automatically calls this function at its underlying level)**

The underlying way SSL retrieves data is by specifying how much data is needed, and then returning that amount of data.

So after I receive the data, I store it in a circular queue, and then I provide the SSL with as much data as needed.

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847525%2Epng)

#### **Network sending function (mbedtls automatically calls this function at the underlying level)**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764847548%2Epng)

**3. Functions for sending and retrieving data using SSL**

#### **We could actually use these two functions directly, but I wrapped them in another function for easier calling.**

#### **After the SSL negotiation is complete, the data we send needs to call the functions provided by mbedtls. **

#### **Internally, our data will be encrypted before being sent out via TCP; **

#### **Similarly, we also need to use the functions provided by mbedtls to retrieve the data received via TCP.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848046%2Epng)

### **4. SSL Initialization**

#### **The last two functions, highlighted in red, are the TCP data sending and receiving functions we mentioned above.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848069%2Epng)

### **5. Wait for the SSL handshake to complete.**

#### **This function needs to be called in a polling manner after our TCP connection is successfully established. It automatically implements SSL internally, and returns 0 once SSL is successfully implemented.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848091%2Epng)

## **Now let's look at the specific usage.**

### **1. After establishing a TCP connection, poll and wait for SSL to succeed.** ![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848114%2Epng)

### **2. After successful connection, send the MQTT protocol connection request.**

#### **Please note that Alibaba Cloud stipulates that if using an SSL connection, the securemode parameter of the MQTT client_id must be set to 2.** ![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848135%2Epng) ![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848148%2Epng)

### **3. Retrieving data from SSL**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848168%2Epng)

### **4. Of course, the underlying MQTT data transmission mechanism was also changed to use SSL for transmission.**

![](https://maker.wiznet.io/upload/ckeditor5/1066384665%5F1764848186%2Epng)

**Conclusion**

### **In reality, it's still TCP communication, only the plaintext data has been encrypted.**

### **After the TCP connection is established, the encryption method and password negotiated with the server are implemented internally by mbedtls.**

### **Once the agreement is reached, we can send and receive data normally, except that it goes through mbedtls' internal functions in the process;**

---

Source: https://maker.wiznet.io/gavinchang/projects/14-stm32-w5500-basic-control-self-built-iot-platform-porting-mbedtls-to-enable-stm32-w5500/
