wolfJSSE and wolfJCE Now Support Post-Quantum Cryptography

Post-quantum cryptography (PQC) support has been added to wolfSSL’s Java providers! wolfJSSE, our JSSE provider built on the wolfSSL embedded SSL/TLS library, and wolfJCE, our JCE provider built on the wolfCrypt encryption engine, now include the NIST-standardized post-quantum algorithms along with the stateful hash-based signature schemes: ML-KEM (FIPS 203) key encapsulation with parameter sets ML-KEM-512, […]

Read MoreMore Tag

Post-Quantum Signatures for Signed Messages: ML-DSA in PKCS#7

wolfSSL’s PKCS#7/CMS implementation has long produced and verified SignedData with the signature algorithms you’d expect — RSA and ECDSA. It now speaks post-quantum as well: PKCS#7 SignedData can be signed and verified using ML-DSA, the Module-Lattice-Based Digital Signature Algorithm standardized by NIST in FIPS 204 (formerly CRYSTALS-Dilithium). The encoding follows the conventions the IETF LAMPS […]

Read MoreMore Tag

White House EO 14412

By now, anyone who tracks security protocols has heard ad nauseum about the White House Executive Order 14412 regarding post-quantum cryptography (PQC). In case you’ve been hiding under a rock, it can be found here. The TL;DR is that all High Value Assets (HVAs) must use PQC key establishment by 2030 and PQC digital signatures […]

Read MoreMore Tag

Merkle Tree Certificates

If you’re part of the Web PKI community and haven’t heard of Merkle Tree Certificates then you must have been hiding under a rock for the past year! These are the new format of certificates that are being pushed by Google and Cloudflare to solve the issue of large public keys and signatures in ML-DSA […]

Read MoreMore Tag

wolfBoot for CNSA 2.0 Secure Boot on Zynq UltraScale+ MPSoC

Executive Summary Problem: Zynq UltraScale+ MPSoC secure boot authenticates the FSBL with RSA-4096 in immutable BootROM. CNSA 2.0 requires post-quantum algorithms for long-term software and firmware verification. RSA-4096 is not quantum-resistant, so the BootROM cannot be the final CNSA 2.0 firmware-authentication answer. Solution: Use wolfBoot as the system-level post-quantum authorization layer. Keep AMD secure boot […]

Read MoreMore Tag

wolfSSH Continues on the Post-Quantum Hybrid Key Exchange Journey

Go checkout the master branch of wolfSSH. Two new hybrid KEX methods have been added. Both are defined in draft-ietf-sshm-mlkem-hybrid-kex: mlkem768x25519-sha256 — ML-KEM-768 paired with X25519 mlkem1024nistp384-sha384 — ML-KEM-1024 paired with NIST P-384 This joins mlkem768nistp256-sha256 which has been there for a long time. Why hybrid The “harvest now, decrypt later” threat model means ciphertext […]

Read MoreMore Tag

PQC in cURL

When curl is built with wolfSSL as the TLS backend, you can get ML-KEM and ML-DSA post-quantum algorithm support in TLS 1.3, provided wolfSSL was configured with –enable-curl, –enable-mlkem and –enable-mldsa. Getting started with wolfSSL? Download the latest libraries here and start exploring. The following ML-KEM groups are available: Pure ML-KEM (post-quantum only) ML_KEM_512 ML_KEM_768 […]

Read MoreMore Tag

Performance and Portability: Post-Quantum Cryptography with wolfSSL and Vulkan

Post-quantum standards like ML-DSA introduce significant compute challenges. These lattice-based schemes rely on high-degree polynomial math that can overwhelm traditional CPUs, making GPU acceleration essential for high-volume environments. The primary bottlenecks occur during Key Generation and Signing. In ML-DSA, signature generation is particularly intensive due to rejection sampling. This process requires the algorithm to repeatedly […]

Read MoreMore Tag

Posts navigation

1 2 3 4