wolfSSL (Booth 6027) is joining Toradex at their booth 6222 for Embedded World North America, September 22 to 24. We are demonstrating post-quantum cryptography running on both halves of the Toradex SMARC iMX95 module. pane what it shows left wolfCrypt ML-KEM and ML-DSA benchmarks in a container on the six Cortex-A55 cores, under Torizon OS […]
Read MoreMore TagCategory: Uncategorized
Live Webinar: Rock-Solid curl: Long-Term Support for Stable Deployments
Products with long deployment lifecycles must continue receiving curl security fixes. Moving through frequent curl releases, however, can introduce unrelated features and behavioral changes, requiring additional integration and regression testing. Join this webinar to learn how Rock-Solid curl supports a stable curl and libcurl release branch for five years. See how security and selected stability […]
Read MoreMore TagAnnouncing wolfCOSE v2.0.0
We are excited to announce wolfCOSE 2.0.0, a major update to wolfSSL’s complete, zero-allocation C implementation of CBOR (RFC 8949) and COSE (RFC 9052) built on wolfCrypt. This release adds standardized HSS/LMS stateful hash-based signatures, RFC 9338 countersignatures, RFC 9783 PSA/EAT attestation, RFC 9864 fully specified signature algorithms, delegated signing, and experimental COSE-HPKE, while preserving […]
Read MoreMore TagTop 10 Things to Reduce wolfSSL Code Size
wolfSSL is one of the smallest commercial TLS / crypto libraries available. Pulling the right configuration levers is the biggest challenge. This post is a short tour of the ten biggest knobs. Two ways to configure the build Every define and flag below can be supplied through either of these paths: Autoconf / configure(./configure): Pass […]
Read MoreMore TagwolfCrypt on the Silicon Labs EFR32xG25 Secure Element
wolfSSL now supports hardware-accelerated crypto on the Silicon Labs EFR32 Series 2 Secure Element using wolfCrypt crypto callbacks. Simply define WOLFSSL_SILABS_CRYPTOCB. wolfCrypt automatically registers the Secure Element at startup and routes supported operations to hardware, including: Symmetric Ciphers: AES (ECB, CBC, CTR, GCM, CCM), ChaCha20-Poly1305 MAC & KDF: AES-CMAC, HKDF, PBKDF2 Hashing: SHA-2 Asymmetric: ECDSA, […]
Read MoreMore TagPost-Quantum Secure Boot on the NXP i.MX95 Cortex-M7
We ported wolfBoot to the Cortex-M7 on NXP’s i.MX95, running on a Toradex SMARC iMX95 module, and measured ML-DSA-87 verified boot with the core at 800 MHz. Verification and boot completed in 5.25 ms, and the ML-DSA-87 build of wolfBoot came out 940 bytes smaller than the ECDSA P-256 build of the same target. Algorithm […]
Read MoreMore TagAnnouncing wolfTPM v4.2.0
wolfTPM 4.2.0 centers on TCG TPM 2.0 v1.85 specification compliance in the firmware TPM (fwTPM), expanded post-quantum support up to TLS 1.3 authentication, and new platform backends. The result is a portable, hardware-backed root of trust that is standards-compliant and quantum-ready on hardware ranging from microcontrollers to Linux edge devices. TPM 2.0 v1.85 Specification Compliance […]
Read MoreMore TagPost-Quantum Benchmarks on the NXP i.MX95 and Toradex SMARC
We benchmarked wolfSSL’s post-quantum algorithms against OpenSSL on a Toradex SMARC iMX95 Hexa 8GB module running Torizon OS 7.7.0. Both stacks ran on the same silicon, one Cortex-A55 core, governor pinned at 1800 MHz, one second per measurement. Torizon ships OpenSSL 3.5.7, which has native ML-KEM and ML-DSA, so this compares two builds you can […]
Read MoreMore TagwolfBoot Adds Secure Boot Support for Altera Agilex 5
wolfSSL is adding a native wolfBoot port for the Altera Agilex 5 SoC FPGA. The port integrates with the existing Agilex 5 platform boot flow and verifies signed Linux FIT images before they are launched. This gives Agilex 5 platforms a portable wolfSSL secure boot layer without replacing the vendor’s platform initialization or security services. […]
Read MoreMore TagTLS 1.3 in 30.8 KB: wolfSSL vs MbedTLS
wolfSSL’s new tinytls13 profile against a parity-matched MbedTLS, measured on Cortex-M33, x86_64, and aarch64. wolfSSL and MbedTLS both target small embedded TLS, but configured and built with parity options they are not the same size. The new tinytls13 profile is a TLS 1.3-only build that strips everything which is not TLS 1.3 and defaults to […]
Read MoreMore Tag
