Embedded software engineer who likes to understand systems from first principles. I've been working professionally since 2018, mostly in C on IoT devices, focusing on secure communication, device provisioning, secure key management, cryptography and reliable storage.
A C implementation of EDHOC (RFC 9528), a lightweight authenticated key exchange for constrained IoT devices.
- Handle-only key material: private keys and derived secrets stay in the key store (software, TrustZone or a secure element).
- Post-quantum ready: the key exchange is modeled as a KEM, so post-quantum algorithms such as ML-KEM drop straight in.
- PSK authentication: EDHOC-PSK for a lighter handshake, with session resumption.
- Portable: runs on Linux, macOS and Zephyr RTOS, with no heap required.
- Quality: verified against the RFC 9529 test vectors, with static analysis, sanitizers and fuzzing in CI.
A volume manager for raw flash on Zephyr RTOS, based on the design of Linux UBI.
- Named volumes: created, resized and removed at runtime, with wear spread across the whole partition.
- Power-loss safe: a block update either completes or leaves the old data intact.
- Authenticated metadata: AES-CMAC over headers and the volume table, with damage and tampering reported separately.
- Built for microcontrollers: no background threads and small, predictable stack usage.
- Quality: model-based tests with injected power cuts, fuzzing, and testing on real hardware.
- AeternusDB: an embeddable, persistent key-value store in Rust, built on an LSM-tree.
- Software Engineer at ASSA ABLOY, Core IoT team
- M.Sc. Eng. in Automation and Robotics, Wrocław University of Science and Technology

