
Building a drop-in cellular replacement for a legacy field modem, wire for wire
Challenge
A huge installed base of field-deployed industrial equipment talks to the outside world through an old-style serial modem: dial-style AT commands, and hardware handshake lines (DTR, DCD, DSR, RI) the host software was written decades ago to expect. As older cellular networks are switched off region by region, those modems stop working, but the host equipment itself is expensive or impractical to touch - so any replacement has to be electrically and behaviorally identical to the modem it replaces, down to the same serial wiring and command set, while actually reaching the network over a modern cellular radio underneath.
Solution
We built the replacement module's firmware on an STM32L496 (Cortex-M4), managing three independent serial channels in parallel: one to the host device, one for local service/debug access, and one to the onboard cellular radio module. On the host-facing channel, the firmware runs a full AT-command interpreter that reproduces the legacy modem's command set and RS-232 control-line behavior entirely in software - driving and monitoring DTR, DCD, DSR, and RI, and handling dial-style ATD/ATA/ATH sequences plus an extended configuration command set - so existing host software and provisioning tools work completely unmodified. Internally, that layer is bridged onto the cellular module's own AT dialect for PDP context setup, TCP/UDP sockets, and DNS resolution, with the firmware translating an outgoing dial command into a TCP socket open, an inbound TCP connection into an emulated ring-and-answer sequence, and so on - the host believes it's still dialing and receiving calls on a phone-style modem, while the real transport is an IP socket over cellular data. We layered on DNS resolution, SNTP time sync, periodic connectivity checking, and tiered retry/backoff timers tuned per failure type so the module degrades gracefully instead of hammering the network when signal is poor. Because these units are deployed unattended with no physical access, we also built a fail-safe over-the-air update path: new firmware arrives over an X-modem transfer through the cellular link, is buffered and CRC-checked in RAM, written into the STM32L4's unused flash bank, and only then is the boot bank switched via the chip's option bytes - so a corrupted transfer or bad update can never brick a unit in the field; it just keeps running the last known-good firmware.
Results
The result is a firmware platform that lets a legacy modem be swapped for a module running on modern cellular technology without touching a single line of the host device's software or its wiring - the same serial port, the same AT commands, the same handshake lines and dial behavior the host was built to expect. The dual-bank fail-safe update path means the fleet's firmware can keep evolving after deployment with no risk of a bad update stranding a unit that's no longer physically reachable, and the tiered reconnection backoff keeps units resilient through real-world network instability instead of retrying aggressively and draining a cellular data plan.
Kick-start your project
Get in touch with our team to discuss your business needs and see how we can help with a project like this one.