wolfSSL ESP32 Hardware Acceleration Support

wolfSSL is excited to announce support for Espressif ESP32 hardware acceleration to the wolfSSL embedded SSL/TLS library!

The ESP32-WROOM-32 is a powerful, generic Wi-Fi+BLE MCU module with high flexibility, and is easily interactable with the wolfSSL embedded SSL/TLS library. As wolfSSL is highly portable and the ESP32-WROOM-32 is highly flexible, if your application has any special features that interfere with the existing wolfSSL port, they are easily remedied.

The new wolfSSL ESP32-WROOM-32 port functionality was added into the existing ESP-IDF port, and the ESP32-WROOM-32 functionality can be enabled by either defining the "WOLFSSL_ESPIDF" and “WOLFSSL_ESPWROOM32” or “WOLFSSL_ESPWROOM32SE” options in the settings.h file (or user_settings.h alternatively, if WOLFSSL_USER_SETTINGS is defined). For more details about this new ESP32 support, please see the REAMDE.md placed in the “<wolfssl-root>/wolfcrypt/src/port/Espressif” directory of the wolfSSL source tree. Details about the ESP-IDF port can be found in the README.md file located in "<wolfssl-root>/IDE/Espressif/".

wolfSSL's support for the onboard hardware cryptography of the ESP32 and ATECC608A gives users code size reductions and performance advantages.  A full set of benchmarks and performance comparisons can be found on our ESP32-specific webpage, located here: https://www.wolfssl.com/docs/espressif/.

Espressif ESP32-WROOM-32SE, Beta

The wolfSSL master branch can be cloned from here: https://github.com/wolfSSL/wolfssl
The README about ESP-IDF porting can be found here: https://github.com/wolfSSL/wolfssl/blob/master/IDE/Espressif/ESP-IDF/README.md
The README about HW acceleration can be found here: https://github.com/wolfSSL/wolfssl/blob/master/wolfcrypt/src/port/Espressif/README.md
The README about 32SE can be found here: https://github.com/wolfSSL/wolfssl/blob/master/IDE/Espressif/ESP-IDF/README_32se.md

For more information, please contact facts@wolfssl.com.

Resources:
ESP32-WROOM-32 Overview: https://www.espressif.com/en/products/hardware/esp-wroom-32/overview

wolfSSL support for the ATECC508A/ATECC608A crypto coprocessor

wolfSSL embedded SSL/TLS support the latest Microchip ATECC508A and ATECC608A I2C cryptographic coprocessors. Not only is wolfSSL compatible with CryptoAuthLib, wolfSSL has also been tested on both the 508A and the 608A.

Prerequisites:

Examples:

  • wolfSSL uses PK (Public Key) callbacks for the TLS crypto operations
  • wolfCrypt uses the WOLFSSL_ATECC508A macro to enable native wc_ecc_* API support
  • wolfCrypt also uses the WOLFSSL_

The README.md and reference PK callbacks can be found here: https://github.com/wolfSSL/wolfssl/tree/master/wolfcrypt/src/port/atmel

Additional demos for wolfSSL TLS Client/Server and wolfCrypt test/benchmarks can be found:

https://www.wolfssl.com/download/downloadMoreForm.php
https://github.com/dgarske/atmel

Preprocessor Macros:

  • WOLFSSL_ATECC508A
  • WOLFSSL_ATECC_PKCB
  • WOLFSSL_ATMEL

PK Callbacks:

wolfSSL’s TLS layer PK callbacks expose API’s to set ECC callbacks. These are enabled with: #define HAVE_PK_CALLBACKS or ./configure --enable-pkcallbacks.

Reference API’s:

  • atcatls_create_key_cb
  • atcatls_verify_signature_cb
  • atcatls_sign_certificate_cb
  • atcatls_create_pms_cb

For more questions please email us at facts@wolfssl.com.

wolfCrypt v4 FIPS

Recently, the National Institute of Standards and Technology (NIST) completed the validation of the wolfCrypt module version 4 for an updated Federal Information and Processing Standards (FIPS) 140-2 certificate. This new certificate includes updated and more secure algorithms added to the wolfCrypt module's boundary, some of which are listed below.

FIPS 140-2 is a government standard that specifies a software module is compatible and allowed to be used in government systems. This includes such areas as drone software, government databases, and other high-security/high-power uses.

The new FIPS 140-2 validation has certificate #3389. The Operating Environments (OEs) tested are Ubuntu Linux (16.04) and Windows 10 on Intel Core i5 processors. Full details about the OEs can be found on the CSRC certificate page. Additionally, the certificate also includes the following algorithms: AES (CBC, GCM, CTR, ECB), CVL, Hash DRBG, DHE, ECDSA (key generation, sign, verify), HMAC, RSA (key generation, sign, verify), SHA-3, SHA-2, SHA-1, and Triple-DES.

For more information about wolfSSL, wolfCrypt, or our FIPS 140-2 validations, please view our resources below.

Other information can be obtained, or questions can also be answered by contacting facts@wolfssl.com.

Building Secure Socket Funneling (SSF) with wolfSSL

wolfSSL can now be used to replace OpenSSL in Secure Socket Funneling (SSF)!

Secure Socket Funneling (SSF) is a network tool and toolkit. It provides simple and efficient ways to forward data from multiple sockets (TCP or UDP) through a single secure TLS tunnel to a remote computer.

Features:

  • Local and remote TCP port forwarding
  • Local and remote UDP port forwarding
  • Local and remote SOCKS server
  • Local and remote shell through sockets
  • File copy
  • Native relay protocol
  • TLS connection with the strongest cipher-suites

Since SSF is dependent on Boost.Asio for TLS purposes and Boost.Asio is now compatible with wolfSSL (see blog post), you now have the option to run SSF with wolfSSL’s high standard of internet security.

If you are interested in using wolfSSL with SSF in your project, please contact us at facts@wolfssl.com and we will happily provide you with the needed source code and instructions on how to build everything together successfully.

wolfSSH Support for Windows CE

wolfSSL's wolfSSH lightweight SSH library shares some similarities with the wolfSSL library - it has minimal resource usage, high performance, and is highly portable. An example that showcases the portability of wolfSSH is its ability to also be built within multiple operating environments, including Windows CE. Windows CE is an operating system that is a subfamily of the Microsoft Windows operating system.

The wolfSSH library provides many different features that could be utilized effectively on machines running Windows CE, such as pseudo-terminals, remote execution, and SFTP. wolfSSH also has example applications that can be run on Windows that show these features in action. More information on the wolfSSH example applications can be found here: 

For more information about wolfSSH and its usage, please contact facts@wolfssl.com.

wolfSSL Support’s Speedy Response Times

While wolfSSL does provide one of the most secure embedded SSL/TLS libraries a high-powered and lightweight encryption engine, and other products, wolfSSL also provides various services. One of these services is the exemplary support offered by the wolfSSL support team.

On average, wolfSSL receives between 700 and 800 support inquiries each year through support@wolfssl.com. These inquiries cover topics ranging from certificate signing, certificate verification errors, RSA operations, and much more. These inquiries are received, assigned to the appropriate members of the wolfSSL support team whose specialty applies to the topic, and is resolved efficiently and effectively. On average, wolfSSL support tickets are received and resolved in under 2 hours. In some cases, wolfSSL support tickets can even be resolved in under 30 minutes. These fast turnaround times can be incredibly beneficial when working on time-sensitive or blocking issues.

wolfSSL Support is offered at four levels (1 free, 3 paid). Details on these support levels can be viewed in a side-by-side comparison on wolfSSL's support options page, here: https://www.wolfssl.com/products/support-packages/.

To have your own questions answered, or to obtain support for wolfSSL, please contact support@wolfssl.com. Additionally, other general information about the wolfSSL library can be obtained by contacting facts@wolfssl.com.

wolfSSL also supports TLS 1.3! More information can be viewed here: https://www.wolfssl.com/docs/tls13/.

Remote Execution via wolfSSH

wolfSSL provides many different embedded, lightweight, and portable products. One of which is the wolfSSH lightweight embedded SSH Library, based on the SSHv2 protocol. wolfSSH comes with support for a long list of platforms, multiple hashing functions, SCP, SFTP, and more.

Additionally, wolfSSH provides support for remote execution, one of the core features of an SSH library or SSH clients/servers. Remote execution is exactly what its name implies, the execution of commands on a device which is typically remote and may not be physically accessible from another device. wolfSSH remote execution allows the user to execute commands, update devices, and also allows the user to pipe input/output from the remote device to the client. Remote execution can be used to trigger a single action on a device, or can be used to trigger several actions. This speed up development processes on embedded devices, and can also eliminate the need for physical access in some cases.

For more information about wolfSSH and its usage, please contact facts@wolfssl.com.

wolfTPM 1.5.0 Now Available

wolfTPM version 1.5.0 was recently released, and features many new updates and additions to the wolfTPM library.

Summary:

  • Added support for the Microchip ATTPM20 TPM 2.0 module
  • Added Barebox bootloader support.
  • Added TPM wrappers for HMAC, AES Key Loading.
  • Added Benchmarking support for RNG, AES, Hashing and TLS.
  • Improvements for TLS client/server examples and overall performance.

Detail:

  • Fixed issue with cleanup not unregistering the crypto callback.
  • Added support for Microchip ATTPM20 part.
  • Added support for Barebox (experimental).
  • Added TLS benchmarking for CPS and KB/Sec. Enabled with TLS_BENCH_MODE.
  • Added TLS client/server support for symmetric AES/HMAC/RNG. Enabled with WOLFTPM_USE_SYMMETRIC.
  • Added TLS client/server support for mutual authentication.
  • Added TIS locking protection for concurrent process access. Enabled using WOLFTPM_TIS_LOCK.
  • Added symmetric AES encrypt and decrypt wrappers and examples.
  • Added HMAC wrappers and examples.
  • Added wrappers and examples for loading external HMAC and AES keys.
  • Added delete key wrapper and example.
  • Added ECDH support for ephemeral key generation and shared secret.
  • Added benchmark support for RNG, AES (CTR, CBC, CFB) 128/256 and SHA-1, SHA-256, SHA-384 and SHA-512.
  • Added new wolfTPM2_GetCapabilities wrapper API for getting chip info.
  • Added command and response logging using ./configure --enable-debug=verbose or #define WOLFTPM_DEBUG_VERBOSE.
  • Added option to enable raw IO logging using WOLFTPM_DEBUG_IO.
  • Added option to disable TPM Benchmark code using NO_TPM_BENCH.
  • Added examples/README.md for setup instructions.
  • Tuned max SPI clock and performance for supported TPM 2.0 chips.
  • Cleanup to move common test parameters into examples/tpm_test.h.
  • Updated benchmarks and console output for examples in README.md.

For more information about wolfTPM or other wolfSSL libraries, please contact facts@wolfssl.com.

wolfSSH SFTP Performance

wolfSSL provides many different products, one of which is the wolfSSH library. wolfSSH itself provides a lightweight embedded SFTP solution. SFTP can be used to securely transfer files, and to manage the filesystem of a peer. wolfSSH’s implementation of SFTP uses less than a third of the memory that OpenSSH does for a SFTP connection. The following figures outline the performance of wolfSSH's SFTP solution compared with OpenSSH's performance.

wolfSSH v1.3.0 configured with " ./configure --enable-static --disable-shared --enable-sftp CFLAGS="-DDEFAULT_WINDOW_SZ=4096" ":

In comparison the default OpenSSH SFTP on the system used 103 KiB of memory. “OpenSSH_7.2p2 Ubuntu-4ubuntu2.6, OpenSSL 1.0.2g”:

For more information about using wolfSSH and its features, please contact facts@wolfssl.com.

Additionally, wolfSSL also provides support for using TLS 1.3! More information is available here: https://www.wolfssl.com/docs/tls13/.

Differences between TLS 1.2 and TLS 1.3 (#TLS13)

wolfSSL's embedded SSL/TLS library has included support for TLS 1.3 since early releases of the TLS 1.3 draft. Since then, wolfSSL has remained up-to-date with the TLS 1.3 specification. In this post, the major upgrades of TLS 1.3 from TLS 1.2 are outlined below:

TLS 1.3

This protocol is defined in RFC 8446. TLS 1.3 contains improved security and speed. The major differences include:

  • The list of supported symmetric algorithms has been pruned of all legacy algorithms. The remaining algorithms all use Authenticated Encryption with Associated Data (AEAD) algorithms.
  • A zero-RTT (0-RTT) mode was added, saving a round-trip at connection setup for some application data at the cost of certain security properties.
  • Static RSA and Diffie-Hellman cipher suites have been removed; all public-key based key exchange mechanisms now provide forward secrecy.
  • All handshake messages after the ServerHello are now encrypted.
  • Key derivation functions have been re-designed, with the HMAC-based Extract-and-Expand Key Derivation Function (HKDF) being used as a primitive.
  • The handshake state machine has been restructured to be more consistent and remove superfluous messages.
  • ECC is now in the base spec  and includes new signature algorithms. Point format negotiation has been removed in favor of single point format for each curve.
  • Compression, custom DHE groups, and DSA have been removed, RSA padding now uses PSS.
  • TLS 1.2 version negotiation verification mechanism was deprecated in favor of a version list in an extension.
  • Session resumption with and without server-side state and the PSK-based ciphersuites of earlier versions of TLS have been replaced by a single new PSK exchange.

More information about the TLS 1.3 protocol can be found here: https://www.wolfssl.com/docs/tls13/. Additionally, please contact facts@wolfssl.com for any questions.

Posts navigation

1 2 3 110 111 112 113 114 115 116 189 190 191